> For the complete documentation index, see [llms.txt](https://trust.memori.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://trust.memori.ai/en/certifications/certifications-overview/iso-certifications/iso-42001-2023-certificate.md).

# ISO 42001:2023 Certificate

The first international standard dedicated to AI governance — ensuring that AIsuru is developed and managed responsibly, transparently and in compliance with the European AI Act.

### What it is

ISO/IEC 42001:2023 is the first international standard specifically dedicated to Artificial Intelligence Management Systems. It requires organizations that develop or use AI systems to define policies, roles, risk assessment processes and mitigation measures specific to artificial intelligence.

### Why it is fundamental for AIsuru

AIsuru is an AI platform that integrates artificial intelligence components at multiple levels:

* Proprietary NLP trained in-house on public corpora (Italian, English, French)
* Integration with external LLMs (OpenAI, Anthropic, Mistral, Google Vertex, Amazon Bedrock, Azure OpenAI)
* Contextual memory features (Deep Thinking)
* Automatic content moderation through AI systems
* Document import with automatic Q\&A generation via LLM

ISO 42001 provides the framework to govern all of these components responsibly.

### What it concretely guarantees

**AI governance and responsibility**

The standard requires a clear definition of roles and responsibilities for AI systems:

* **Memori (platform provider):** responsible for the AI architecture, security measures and regulatory compliance
* **Agent Owners and Authors:** responsible for the configuration, content and use of the Agent
* **Platform Admins (in PaaS models):** responsible for user management and monitoring
* **End users:** responsible for conscious use and for reporting inappropriate behavior

**AI risk assessment**

Memori systematically assesses the specific risks of its AI systems:

* **Hallucinations:** generative AI responses may be incorrect. Mitigation measure: human validation of responses, "AI generated" visual flag, ability to disable generative features
* **Privacy:** sending data to LLM providers entails risks. Measure: documented data retention policies for each provider, DPA with all sub-processors
* **Bias and discrimination:** the NLP system could have linguistic biases. Measure: training on diverse corpora, calibration and testing of thresholds for each supported language
* **Misuse:** the platform could be used to generate harmful content. Measure: automatic content moderation system, NSFW flag for Agents with sensitive content

**Transparency towards users**

ISO 42001 requires that users are always aware they are interacting with an AI system:

* **"AI generated" flag:** visual indicator for responses generated by generative AI (opt-out available)
* **Multilingual descriptive tooltip:** warning about the possible incorrectness of generated responses
* **Explicit identification:** the Agent can be configured to identify itself as an AI assistant
* **Provider alerts:** automatic notification to users when LLM providers report problems

**Transparency of the proprietary NLP system**

Memori's proprietary NLP system is trained on public corpora and documented in its fundamental characteristics. Complete technical documentation is available on request to qualified parties (e.g. auditors, supervisory authorities). The system is classified as low computational impact, well below the systemic risk thresholds set by the AI Act.

**Human oversight** The standard requires that AI systems cannot operate in a completely autonomous way in critical contexts:

* AI-generated responses can be validated and modified by the Agents' authors
* The Memori team supervises Manuela (the official support Agent) periodically
* The channels <ccare@memori.ai> and <abuse@memori.ai> are monitored, with replies within 48 working hours

**Alignment with the European AI Act**

ISO 42001 is designed to be aligned with Regulation (EU) 2024/1689 (**AI Act**). For AIsuru this means:

* Risk classification of the AI systems used
* Technical documentation of the AI models employed
* Transparency obligations towards end users
* Training of staff using AI systems (mandatory from 2 February 2025)

***

{% file src="/files/7DmN0TwNFwPFHaHkNfv0" %}
