S · 06 · Governance & Risk Management · Gobernanza y gestión de riesgosGovernance & Risk Management

Gobernar la IA para poder acelerar.Govern AI so you can go faster.

Diseñamos sistemas de gestión ágiles y marcos de gobernanza basados en ISO/IEC 42001 y 42005, NIST AI RMF y buenas prácticas, para que despliegues y escales IA con velocidad y control, sin frenar el negocio.We design agile management systems and governance frameworks based on ISO/IEC 42001 and 42005, the NIST AI RMF and best practice, so you can deploy and scale AI with speed and control, without slowing the business.

Mapa de madurez de la gobernanza de IAAI governance maturity mapISO/IEC 42001 × NIST AI RMF▲ Organización ilustrativaIllustrative organisation
Pulsa una cláusulaClick a clause

Cobertura por función NISTCoverage by NIST function

01El ciclo del riesgoThe risk cycle

Gobernar, mapear, medir y gestionar.Govern, map, measure, manage.

Seguimos el marco de gestión de riesgos de IA del NIST estadounidense (AI RMF), el más usado junto a la ISO/IEC 42001. La gobernanza está en el centro y se aplica en todo el ciclo.We follow the US NIST AI Risk Management Framework (AI RMF), the most widely used alongside ISO/IEC 42001. Governance sits at the centre and applies across the whole cycle.

Pulsa una funciónClick a function

02Qué construimosWhat we build

Las piezas de un sistema de gestión de IA que funciona.The pieces of an AI management system that works.

LiderazgoLeadership

Política y roles de IAAI policy and roles

Quién decide, quién responde y con qué criterios se aprueba un uso de IA.Who decides, who is accountable and by which criteria an AI use is approved.

Te llevas:You get: política de IA y mapa de responsabilidades.AI policy and responsibility map.
ContextoContext

Inventario y clasificaciónInventory and classification

Todos tus sistemas de IA, propios y de terceros, con su nivel de riesgo y su dueño.All your AI systems, in-house and third-party, with their risk level and owner.

Te llevas:You get: inventario vivo de IA.a living AI inventory.
Risk_Control

Evaluación de riesgosRisk assessment

Un procedimiento repetible para mapear, evaluar y mitigar riesgos, alineado con ISO/IEC 42005 y NIST.A repeatable procedure to map, assess and mitigate risks, aligned with ISO/IEC 42005 and NIST.

Te llevas:You get: metodología y mapa de riesgos.methodology and risk map.
OperaciónOperation

Proveedores y tercerosVendors and third parties

Requisitos contractuales, evaluación previa y seguimiento de la IA que compras.Contract requirements, prior assessment and monitoring of the AI you buy.

Te llevas:You get: cláusulas tipo y checklist de compra.model clauses and purchasing checklist.
MejoraImprovement

Monitorización e incidentesMonitoring and incidents

Indicadores, alertas y un protocolo para cuando algo sale mal.Indicators, alerts and a protocol for when something goes wrong.

Te llevas:You get: cuadro de indicadores y protocolo de incidentes.indicator dashboard and incident protocol.
CertificaciónCertification

Preparación ISO/IEC 42001ISO/IEC 42001 readiness

Auditoría interna y evidencias para certificarte cuando tenga sentido para tu negocio.Internal audit and evidence to get certified when it makes sense for your business.

Te llevas:You get: informe de auditoría interna.internal audit report.
03EnfoqueApproach

Gobernanza ágil: la justa, donde hace falta.Agile governance: just enough, where it matters.

ProporcionalProportionate

Más control donde más riesgoMore control where there is more risk

Un asistente de redacción no necesita el mismo proceso que un sistema que decide créditos.A writing assistant does not need the same process as a system that decides on loans.

IntegradaIntegrated

Sobre lo que ya tienesOn top of what you have

Aprovechamos tu gestión de riesgos, ISO/IEC 27001 y RGPD en lugar de crear burocracia paralela.We build on your risk management, ISO/IEC 27001 and GDPR instead of creating parallel bureaucracy.

MedibleMeasurable

Si no se mide, no existeIf it is not measured, it does not exist

Indicadores que la dirección entiende y que muestran si la gobernanza funciona.Indicators leadership understands and that show whether governance works.

04Cómo trabajamosHow we work

Del diagnóstico a la certificación, al ritmo del negocio.From diagnosis to certification, at the pace of the business.

01

Diagnóstico de madurezMaturity diagnosis

Dónde estás frente a ISO/IEC 42001 y NIST AI RMF, en semanas y no en meses.Where you stand against ISO/IEC 42001 and NIST AI RMF, in weeks not months.

02

Diseño del sistemaSystem design

Política, roles, procesos y controles a la medida de tu riesgo.Policy, roles, processes and controls sized to your risk.

03

Implantación acompañadaGuided implementation

Lo ponemos en marcha con tus equipos, empezando por los sistemas críticos.We roll it out with your teams, starting with critical systems.

04

Auditoría y mejoraAudit and improvement

Auditoría interna, revisión por la dirección y preparación para certificar.Internal audit, management review and certification readiness.

Diagnóstico de madurezMaturity diagnosis
Política y gobierno de IAAI policy and governance
Inventario de sistemas de IAAI system inventory
Metodología de riesgos (Risk_Control)Risk methodology (Risk_Control)
Protocolo de incidentesIncident protocol
Informe de auditoría interna ISO/IEC 42001ISO/IEC 42001 internal audit report
// Primer pasoFirst step

Gobierna tu IA antes de que te gobierne a ti.Govern your AI before it governs you.

En 30 minutos te decimos dónde está tu organización y cuál es la pieza de gobernanza que más valor aporta primero.In 30 minutes we tell you where your organisation stands and which governance piece adds the most value first.