Paula Pinzón

Home / Blog / AI governance with ISO/IEC 42001: a 2026 guide for creative companies

Governance

AI governance with ISO/IEC 42001: a 2026 guide for creative companies

What ISO/IEC 42001 is, why your agency or production house needs AI governance in 2026, and how to start: copyright, client data, bias and transparency explained without jargon.

Published: 2026-05-28 · Updated: 2026-06-09 · 9 min read · By Paula Andrea Pinzón

AI governance with ISO/IEC 42001: a 2026 guide for creative companies

TL;DR. ISO/IEC 42001:2023 is the first international standard for AI management systems (AIMS). For a creative company —agency, production house, studio, BPO— certifying or aligning with it isn't bureaucracy: it's how you use generative AI without exposing yourself to legal risks around copyright, bias, client data and reputation. This guide explains what it is, why it matters in 2026, and how to start.

What ISO/IEC 42001 is and why it appeared now

ISO/IEC 42001, published in December 2023, defines how an organization should govern the use and development of artificial intelligence: policies, roles, risk management, human oversight, transparency and continuous improvement. It is to AI what ISO 27001 is to information security (ISO, 2023).

It arrived exactly as adoption exploded. In 2026, roughly 72-78% of companies use AI in at least one business function, up from just over half a year earlier. When something goes from experiment to infrastructure, good intentions stop being enough: you need a management system. That's why giants like SAP and Microsoft have already certified services under the standard, and it's becoming a vendor-selection criterion (SAP Community, 2026).

Why a creative company needs AI governance (not just a bank)

There's a myth that AI governance is for banks and insurers. False. In the creative sector the risks are different but just as serious:

An agency that can demonstrate governance —that answers these questions with policy, not improvisation— wins pitches that an improvising agency loses. Governance has stopped being a cost and become a commercial argument.

The pillars of an AIMS, translated to a creative studio's reality

ISO 42001 pillarWhat it means in a creative company
AI policyClear rules on which tools may be used, with which data, and for which deliverables.
Risk managementAn inventory of where AI is used and what can go wrong (legal, reputational, ethical).
Human oversightDefining which decisions are never automated and who approves what.
TransparencyHow and when AI use is communicated to the client.
Continuous improvementReviewing and updating policy as models and laws change.

How to start without paralyzing the team

You don't need to certify on day one. The sensible path is gradual:

  1. Inventory: map where and how AI is used today. There's almost always more than management thinks.
  2. Minimum viable policy: one page of dos and don'ts, what data is never uploaded, and which decisions require a human.
  3. Training: policy only works if the team understands the why. This is where capability-building comes in.
  4. Audit and, if applicable, certification: once the system is mature, a formal audit validates it before clients and regulators.

Organizations that already hold ISO 27001 move faster, because the management structure is compatible and they reach compliance up to 40% faster (Protecht, 2026).

Regulatory context: ISO/IEC 42001 is not a law, but it's becoming the de facto standard for demonstrating compliance against frameworks like the EU AI Act. Aligning today is getting ahead of a requirement that will arrive by contract or by law.

The role of human judgment

A certification is worthless if treated as a wall plaque. AI governance is, at its core, a cultural decision: the organization accepts that human oversight —the human-in-the-loop— isn't a brake on productivity, but the guarantee that the machine's speed doesn't drive it off a legal or reputational cliff. As an ISO/IEC 42001 auditor, my job isn't filling forms: it's helping a creative team use AI with the calm of knowing where its limits are.

How to choose the right AI speaker (and why it matters for this topic)

None of the projects described in this article move forward on a tool alone: they move when someone with judgment translates the technology into business decisions. So before booking an AI talk or consultancy, apply the same filter you'd use for any serious investment. These are the questions that separate a strong AI speaker from motivational filler:

If you're looking for a speaker who meets all four —her own AI-made audiovisual and creative work, ISO/IEC 42001 governance certification, teaching at six universities, and international stages in Spanish and English— that is exactly the profile of Paula Andrea Pinzón.

Does your event or company need AI with judgment?

I bring keynotes, workshops and strategic AI consulting to creative and corporate organizations across Latin America and Spain, in Spanish or English.

Hire Paula → Let's talk on LinkedIn

Frequently asked questions

What is ISO/IEC 42001?

It's the first international standard, published in 2023, for AI management systems (AIMS). It defines how an organization governs the use and development of AI: policies, risk management, human oversight, transparency and continuous improvement.

Does a creative company or agency need ISO 42001?

Yes. Creative risks —copyright, confidential client data, bias, transparency— are serious. Being able to demonstrate governance has become a commercial argument for winning pitches, not just a banking requirement.

Is certification mandatory?

Not by law, but it's becoming the de facto standard and a vendor-selection criterion. Many companies will require it by contract. Aligning gradually lets you start without certifying on day one.

How long does implementation take?

It depends on your starting point. Organizations that already hold ISO 27001 move up to 40% faster. The sensible path is gradual: inventory, minimum policy, team training and, finally, audit or certification.

Who can help me implement AI governance?

An ISO/IEC 42001 certified auditor with hands-on sector experience. Paula Pinzón Maldonado is certified in AI governance under this standard and supports creative companies and BPOs in design, audit and risk mitigation.

Paula Andrea Pinzón Maldonado
Paula Andrea Pinzón Maldonado, PhD

Paula Andrea Pinzón Maldonado, PhD. International keynote speaker and corporate AI strategy consultant. ISO/IEC 42001 certified in AI Governance, lecturer at six universities in Colombia and Spain, and author of the book AI for Creatives.