Gobierno de IA (ISO 42001 / NIST AI RMF)AI Governance (ISO 42001 / NIST AI RMF)
Sistema de gestión de IA y control de riesgos de modelos y agentes.AI management system and risk control for models and agents.
¿Qué es este servicio?What is this service?
Es el montaje del gobierno de la inteligencia artificial en la organización, apoyado en ISO/IEC 42001 —que es certificable— y en el marco de gestión de riesgos de IA del NIST. Cubre modelos propios, modelos de terceros y agentes que ejecutan acciones.
Setting up AI governance in the organisation, based on ISO/IEC 42001 — which is certifiable — and the NIST AI risk management framework. It covers in-house models, third-party models and agents that take actions.
¿Para qué se usa?What is it used for?
Permite saber qué IA se está usando, quién la aprobó y qué pasa si se equivoca. La mayoría de las organizaciones tienen hoy IA en producción que nadie inventarió, muchas veces contratada por un área sin pasar por seguridad. El trabajo empieza por ese inventario y sigue con clasificación por riesgo, controles y responsables.
It establishes what AI is in use, who approved it and what happens when it gets things wrong. Most organisations today have AI in production that nobody inventoried, often procured by a business area without going through security. The work starts with that inventory and continues with risk classification, controls and owners.
Qué beneficios traeBenefits it delivers
- Saca a la luz la IA en la sombra, que es el riesgo más común y el menos visible.
- Da un procedimiento claro para aprobar casos de uso, en vez de frenarlos todos o dejarlos pasar todos.
- Prepara para exigencias regulatorias que ya están llegando por vía contractual antes que legal.
- ISO 42001 es certificable, lo que da una respuesta cerrada a los cuestionarios de clientes sobre IA.
- Surfaces shadow AI, the most common and least visible risk.
- Provides a clear route to approve use cases instead of blocking all of them or waving all of them through.
- Prepares for regulatory demands that are already arriving contractually before they arrive legally.
- ISO 42001 is certifiable, which gives a closed answer to client questionnaires about AI.
¿En qué momentos es obligatorio?When is it mandatory?
Costa RicaCosta Rica
- No hay hoy una ley costarricense específica de inteligencia artificial que obligue a esto.
- Si la IA trata datos personales, aplica la Ley 8968 con todas sus obligaciones.
- En el sector financiero supervisado, el uso de IA cae dentro del marco de gestión de riesgos tecnológicos del Acuerdo CONASSIF 5-24 aunque no se le nombre.
- There is currently no specific Costa Rican AI law mandating this.
- If the AI processes personal data, Law 8968 applies with all its obligations.
- In the supervised financial sector, AI use falls within the technology risk management framework of CONASSIF Agreement 5-24 even though it is not named.
InternacionalInternational
- ISO/IEC 42001 es voluntaria y certificable; no la impone ninguna ley.
- El marco de gestión de riesgos de IA del NIST también es voluntario.
- Donde sí hay obligación es en el Reglamento (UE) 2024/1689, el AI Act, para quien opere en la Unión Europea.
- ISO/IEC 42001 is voluntary and certifiable; no law imposes it.
- The NIST AI risk management framework is likewise voluntary.
- Where obligation does exist is Regulation (EU) 2024/1689, the AI Act, for anyone operating in the European Union.
Requisitos mínimosMinimum requirements
- Inventario de los usos de IA existentes, incluidos los contratados directamente por áreas de negocio.
- Definir quién aprueba un caso de uso nuevo y con qué criterio.
- Claridad sobre qué datos alimentan cada modelo y de dónde salieron.
- Involucrar a legal y a negocio: el riesgo de IA rara vez es solo técnico.
- An inventory of existing AI uses, including those procured directly by business areas.
- Defining who approves a new use case and against what criteria.
- Clarity on what data feeds each model and where it came from.
- Involving legal and the business: AI risk is rarely only technical.
Plazo típico de entregaTypical delivery time
El rango de mercado va de tres a ocho meses según si se busca certificación en ISO 42001 o solo un marco de gobierno funcionando. El inventario y la clasificación por riesgo, por separado, se entregan en cuatro a seis semanas y suelen ser lo que más sorprende al cliente.
The market range runs from three to eight months depending on whether ISO 42001 certification is the goal or just a working governance framework. The inventory and risk classification on their own are delivered in four to six weeks and are usually what surprises the client most.
NomenclaturaTerminology
Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.