{"id":827,"date":"2025-12-22T08:46:32","date_gmt":"2025-12-22T08:46:32","guid":{"rendered":"https:\/\/i2sc.es\/?p=827"},"modified":"2025-12-22T10:39:26","modified_gmt":"2025-12-22T10:39:26","slug":"gobierno-de-la-ia-vs-gestion-de-la-ia-la-verdad-que-nadie-te-cuenta","status":"publish","type":"post","link":"https:\/\/i2sc.es\/en\/blog\/gobierno-de-la-ia-vs-gestion-de-la-ia-la-verdad-que-nadie-te-cuenta\/","title":{"rendered":"AI Governance vs. AI Management: the truth that nobody tells you"},"content":{"rendered":"<p class=\"translation-block\">In recent months, with the arrival of ISO\/IEC 42001, hundreds of articles, posts and opinions have proliferated on \"AI governance\", \"AI management systems\" and \"how to implement responsible AI\". Problem: analysing many of them, most confuse governance with management, or even use both terms as synonyms, which they are not. This confuses the reader and creates noise in the industry.<\/p>\n\n\n\n<p class=\"translation-block\">Understanding the difference between AI governance and AI management is <strong>critical<\/strong> for any organisation that wants to comply with standards, prepare for audits, or align with the European AI Act.<\/p>\n\n\n\n<p class=\"translation-block\">For this reason, we want to provide you with a <strong>rigorous, technical overview based on international standards<\/strong>, so that you have a clear understanding of:<\/p>\n\n\n\n<ul style=\"padding-right:25px;padding-left:25px\" class=\"wp-block-list\">\n<li class=\"translation-block\">what <strong>AI governance<\/strong> is,<\/li>\n\n\n\n<li class=\"translation-block\">what <strong>AI management<\/strong> is,<\/li>\n\n\n\n<li>which standard relates to each thing,<\/li>\n\n\n\n<li>and how they all fit together within a coherent organisational system.<\/li>\n<\/ul>\n\n\n\n<p><\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Common mistake: Talking about government and management as if they were the same thing<\/strong><\/h4>\n\n\n\n<p><\/p>\n\n\n\n<p class=\"translation-block\">In the business context, <strong>governance<\/strong> and <strong>management<\/strong> are complementary but radically different functions. Governance is the responsibility of <strong>senior management<\/strong> and is responsible for:<\/p>\n\n\n\n<ul style=\"padding-right:25px;padding-left:25px\" class=\"wp-block-list\">\n<li>seting principles and values,<\/li>\n\n\n\n<li>defining expectations, boundaries, and vision,<\/li>\n\n\n\n<li>assessing strategic, ethical and social impacts,<\/li>\n\n\n\n<li>assuming ultimate responsibility for decisions,<\/li>\n\n\n\n<li>and ensuring that the organisation behaves consistently.<\/li>\n<\/ul>\n\n\n\n<p><\/p>\n\n\n\n<p class=\"translation-block\">On the other hand, management is the responsibility of <strong>the management and operational teams<\/strong> and is responsible for:<\/p>\n\n\n\n<ul style=\"padding-right:25px;padding-left:25px\" class=\"wp-block-list\">\n<li>converting governance into policies, processes and controls,<\/li>\n\n\n\n<li>documenting roles, responsibilities, and procedures,<\/li>\n\n\n\n<li>monitoring the execution of activities,<\/li>\n\n\n\n<li>keeping records and evidence,<\/li>\n\n\n\n<li>assessing risks on an ongoing basis,<\/li>\n\n\n\n<li>auditing, reviewing and improving processes.<\/li>\n<\/ul>\n\n\n\n<p><\/p>\n\n\n\n<p>Therefore, management systems are responsible for operationalising governance.<\/p>\n\n\n\n<h4 class=\"wp-block-heading translation-block\"><strong>What standard covers <em>AI governance<\/em>? \u2014 ISO\/IEC 38507<\/strong><\/h4>\n\n\n\n<p><\/p>\n\n\n\n<p class=\"translation-block\">ISO\/IEC 38507 is part of the ISO 38500 family (IT governance) and its purpose is to <strong>guide senior management in the governance of AI within the organisation.<\/strong><\/p>\n\n\n\n<p>ISO 38507 establishes principles for:<\/p>\n\n\n\n<ul style=\"padding-right:25px;padding-left:25px\" class=\"wp-block-list\">\n<li>responsibility,<\/li>\n\n\n\n<li>strategy,<\/li>\n\n\n\n<li>acquisition,<\/li>\n\n\n\n<li>performance,<\/li>\n\n\n\n<li>compliance,<\/li>\n\n\n\n<li>human behaviour<\/li>\n<\/ul>\n\n\n\n<p><\/p>\n\n\n\n<p class=\"translation-block\">and applies them to AI to ensure that corporate decisions on technology are safe, ethical and aligned with the corporate purpose. Therefore, ISO 38507 defines <em>what<\/em> senior management should decide regarding AI, but <strong>does not<\/strong> go into detail on \"how\" it should be managed internally.<\/p>\n\n\n\n<h4 class=\"wp-block-heading translation-block\"><strong>Which standard covers the organisational <em>management<\/em> of AI? \u2014 ISO\/IEC 42001<\/strong><\/h4>\n\n\n\n<p><\/p>\n\n\n\n<p class=\"translation-block\">This is where the ISO\/IEC 42001 standard <strong>\u201cAI Management System \u2014 Requirements\u201d<\/strong> comes in, representing the organisational and certifiable counterpart to the governance principles defined by ISO 38507.<\/p>\n\n\n\n<p>ISO 42001 requires:<\/p>\n\n\n\n<ul style=\"padding-right:25px;padding-left:25px\" class=\"wp-block-list\">\n<li>responsible AI policies,<\/li>\n\n\n\n<li>procedures for the use, development and implementation of AI,<\/li>\n\n\n\n<li>AI risk assessment,<\/li>\n\n\n\n<li>documented human supervision,<\/li>\n\n\n\n<li>criteria for accepting tools and suppliers,<\/li>\n\n\n\n<li>ethical, legal and operational controls,<\/li>\n\n\n\n<li>records and traceability,<\/li>\n\n\n\n<li>training,<\/li>\n\n\n\n<li>performance indicators,<\/li>\n\n\n\n<li>mandatory internal audit,<\/li>\n\n\n\n<li>management review,<\/li>\n\n\n\n<li>continuous improvement.<\/li>\n<\/ul>\n\n\n\n<p><\/p>\n\n\n\n<p class=\"translation-block\">This is <strong>organisational management<\/strong> in its purest form, not strategic governance. But be careful, because ISO 42001:<\/p>\n\n\n\n<ul style=\"padding-right:25px;padding-left:25px\" class=\"wp-block-list\">\n<li><strong>is NOT for training models.<\/strong><\/li>\n\n\n\n<li><strong>does NOT regulate AI engineering or MLOps.<\/strong><\/li>\n\n\n\n<li><strong>does NOT cover aspects of the development life cycle, AI software quality or data quality for AI, which are covered by ISO 5338, ISO 25059 and ISO 5259 respectively.<\/strong><\/li>\n<\/ul>\n\n\n\n<p><\/p>\n\n\n\n<p>A simple way to look at it is that ISO\/IEC 42001 is for a management system, like ISO 9001 or ISO 27001, but applied to the use, development, and\/or deployment of AI.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>How do ISO 38507 and ISO 42001 fit together?<\/strong><\/h4>\n\n\n\n<p><\/p>\n\n\n\n<p class=\"translation-block\">It should be noted that <strong>ISO 38507 establishes governance <\/strong>(what senior management must decide), while <strong>ISO 42001 is responsible for operationalising that governance <\/strong>(through policies, processes, controls and records).<\/p>\n\n\n\n<p>As is the case with other normative pairs.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>And what about the more technical aspects of AI?<\/strong><\/h4>\n\n\n\n<p><\/p>\n\n\n\n<p>It is important to understand that ISO 42001 serves to manage the use, development, and\/or deployment of AI, but does not address technical aspects. For this purpose, there are many other ISO standards, including the following:<\/p>\n\n\n\n<ul style=\"padding-right:25px;padding-left:25px\" class=\"wp-block-list\">\n<li class=\"translation-block\">ISO\/IEC <strong>5338<\/strong> \u2013 Defines the life cycle processes for the development of AI software.<\/li>\n\n\n\n<li class=\"translation-block\">ISO\/IEC <strong>25059<\/strong> \u2013 Determines a quality model for AI systems<\/li>\n\n\n\n<li class=\"translation-block\">ISO\/IEC <strong>5259<\/strong> \u2013 Defines a quality model and metrics for assessing the quality of data used in AI<\/li>\n\n\n\n<li class=\"translation-block\">ISO\/IEC <strong>29119-11<\/strong> \u2013 Defines guidelines for testing AI-based systems<\/li>\n<\/ul>\n\n\n\n<p><\/p>\n\n\n\n<p>Therefore, it is important to clear up the confusion that exists between AI management and governance, so that the truth, expressed with professional rigour and based on international standards, is that:<\/p>\n\n\n\n<ul style=\"padding-right:25px;padding-left:25px\" class=\"wp-block-list\">\n<li>ISO 38507 governs AI from senior management.<\/li>\n\n\n\n<li>ISO 42001 manages AI within the organisation.<\/li>\n\n\n\n<li>There are also technical standards to ensure the quality of the data, software and lifecycle processes used to develop AI systems.<\/li>\n<\/ul>\n\n\n\n<p><\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Three layers, three functions, three levels of different but related standards<\/strong><\/h4>\n\n\n\n<p><\/p>\n\n\n\n<p class=\"translation-block\">At I2SC, we work with AI governance and management standards, as well as the other technical standards presented in this post. If you are interested in learning more about any of them within your organisation, <a href=\"https:\/\/i2sc.es\/en\/contactar\/\" data-type=\"page\" data-id=\"58\" target=\"_self\">contact us<\/a>.<\/p>","protected":false},"excerpt":{"rendered":"<p>En los \u00faltimos meses, con la llegada de ISO\/IEC 42001, han proliferado cientos de art\u00edculos, posts y opiniones sobre \u201cgobierno de IA\u201d, \u201csistemas de gesti\u00f3n de IA\u201d y \u201cc\u00f3mo implantar IA responsable\u201d. Problema: analizando muchos de ellos, la mayor\u00eda confunde gobierno con gesti\u00f3n, o incluso usan ambos t\u00e9rminos como sin\u00f3nimos y\u2026 no lo son. Eso [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":831,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-827","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog"],"_links":{"self":[{"href":"https:\/\/i2sc.es\/en\/wp-json\/wp\/v2\/posts\/827","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/i2sc.es\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/i2sc.es\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/i2sc.es\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/i2sc.es\/en\/wp-json\/wp\/v2\/comments?post=827"}],"version-history":[{"count":3,"href":"https:\/\/i2sc.es\/en\/wp-json\/wp\/v2\/posts\/827\/revisions"}],"predecessor-version":[{"id":833,"href":"https:\/\/i2sc.es\/en\/wp-json\/wp\/v2\/posts\/827\/revisions\/833"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/i2sc.es\/en\/wp-json\/wp\/v2\/media\/831"}],"wp:attachment":[{"href":"https:\/\/i2sc.es\/en\/wp-json\/wp\/v2\/media?parent=827"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/i2sc.es\/en\/wp-json\/wp\/v2\/categories?post=827"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/i2sc.es\/en\/wp-json\/wp\/v2\/tags?post=827"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}