error
Subscriptions are not available for this site while you are logged into your current account.
close
Skip to main content

      A conversation with Kareem Sadek (Partner and National Leader of Trusted AI and Digital Assets) and Zia Shah (Chief Information Security Officer) on AI governance, certification and building trusted AI.

      Key takeaways

      • ISO 42001 translates responsible AI principles into an operational AI governance framework with defined accountability, controls and evidence.
      • Certification can strengthen trust, improve decision-making and prepare organizations for increasing customer, regulatory and contractual scrutiny.
      • Effective AI governance is enterprise wide. It requires active participation from business, technology, risk, privacy, legal and internal audit.
      • Organizations should begin by understanding where AI is used, who owns it and which applications carry the greatest potential impact.
      • Certification is not the end point. The value comes from maintaining and continually improving the AI Management System (AIMS).

      What is ISO 42001, and why does it matter now?

      Kareem Sadek: ISO 42001 is the international management system standard for organizations that develop, provide or use artificial intelligence. It provides a framework for establishing and continually improving an AI Management System or AIMS.

      An AIMS brings structure to how an organization governs AI. It addresses areas such as leadership accountability, AI policies and objectives, roles and responsibilities across the AI lifecycle, risk and impact assessment, data governance, lifecycle controls, third-party oversight, monitoring, internal audit and continual improvement.

      This matters because AI has moved beyond isolated experimentation. As organizations embed AI into operations and decision-making, broad statements of principle are no longer sufficient. Leaders need clear responsibilities, repeatable processes and evidence that controls are operating as intended.

      ISO 42001 provides that operating structure. It can be applied by organizations of different sizes and across sectors, ISO describes it as the first international standard for AI management systems.

      Why is ISO 42001 an important consideration for Canadian businesses?

      Kareem Sadek: AI can influence strategic decisions, customer and employee experiences, regulatory exposure, financial performance and organizational trust. As reliance on AI grows, so does the need to manage processes relating to accountability, fairness, explainability, privacy, security, reliability and legal compliance of the AIMS.

      The executive question is simple: Are we using AI in a way that aligns with our strategy, risk appetite, obligations and values?

      ISO 42001 helps organizations answer that question consistently. It requires leadership to set direction, assign responsibilities, provide appropriate resources and review whether the management system is effective. This makes AI governance an enterprise responsibility rather than something delegated solely to technology teams.

      The business value extends beyond compliance. A functioning AIMS can give leaders better visibility into where AI is being used, how risks are being assessed and managed, who is accountable and if you have the right guardrails in place and of those guardrails and controls are working. Certification can provide independent validation that the management system operates within its defined scope to enable your stakeholder and users to gain trust in your AIMS and the related outputs.

      That discipline is increasingly relevant as AI adoption accelerates. KPMG's Global AI Pulse Q2 2026 found that 71 per cent of organizations surveyed said they were making progress toward a fully integrated AI-human workforce.

      Why did KPMG Canada pursue certification?

      Zia Shah: We believe that organizations advising clients on responsible AI should be prepared to apply the same discipline within their own AI processes and use cases.

      KPMG pursued ISO/IEC 42001 certification for the defined scope covered by its certification to strengthen the connection between its responsible AI principles and day-to-day practices. The process brought together accountability, risk-based decision-making, lifecycle controls, monitoring and continual improvement within a formal management system.

      This Client Zero experience matters because it gave us first-hand insight into the questions organizations face: How should the AIMS be scoped? Who owns it and who is responsible for maintaining the AI system for ongoing management and maintenance? Which existing controls and processes can be uplifted and aligned? Where are the AI-specific gaps? And what evidence will demonstrate that the system works in practice?

      The objective was not simply to obtain a certificate. It was to strengthen how AI is governed, build trust within the AI use cases and to build practical experience that can inform our work with clients.

      What did KPMG learn through its ISO 42001 certification journey?

      Zia Shah: The journey began with defining the scope of the AI Management System. We then assessed existing governance practices against the standard, identified gaps and strengthened areas such as accountability, risk and impact assessments, lifecycle controls and monitoring and the related documentation

      The most important lesson was that certification is not primarily a documentation exercise. Organizations need to demonstrate that their management system operates consistently, with clear ownership, relevant roles and responsibilities across key areas like Security, Privacy, Data integrity and Third-party management defined repeatable processes and evidence that controls are working.

      We also learned the importance of building on existing capabilities. Privacy, cybersecurity, enterprise risk, legal, third party management and internal audit can provide a strong foundation. The goal is to connect these functions, address AI-specific gaps and avoid creating unnecessary parallel processes.

      Finally, cross-functional ownership is essential. Effective AI governance brings together technical expertise, business context and risk oversight throughout the AI lifecycle.

      "We understand that the challenge is not writing another AI policy. It is turning policies into repeatable decisions, controls and evidence across the organization."

      Which organizations should consider certification, and how can KPMG help?

      Kareem Sadek: ISO/IEC 42001 certification may be particularly relevant for organizations that use AI at scale, embed it in customer-facing products or significant decisions, rely on third-party models, or face regulatory and contractual scrutiny.

      KPMG can help organizations assess their readiness, define the scope of their AI Management System and identify gaps in governance, accountability and controls. We can then help build on existing capabilities across privacy, cybersecurity, risk, legal and internal audit to create a practical path toward certification.

      The goal is not to add bureaucracy. It is to help organizations scale AI responsibly, demonstrate that their controls are working and strengthen trust with customers, regulators and other stakeholders.

      What should executives do now to lead on AI governance?

      Kareem Sadek: Start by establishing or validating your AI inventory. Organizations cannot govern what they cannot see. Leaders need to understand where AI is being used, its intended purpose, who owns it, what data and third parties it relies on, the risks it creates, and which controls are in place.

      From there, AI governance needs to become part of how the organization makes decisions, develops products, procures technology and manages enterprise risk. Leading organizations will establish clear accountability, apply controls according to risk and maintain meaningful human oversight and monitoring throughout the AI lifecycle.

      They will also be able to demonstrate that their responsible AI commitments operate in practice. Organizations that rely mainly on principles, policies and committees may struggle to scale, as each new use case can create uncertainty, duplicated effort and inconsistent decisions.

      The differentiator will not be who adopts AI the fastest. It will be who can scale it responsibly, demonstrate trust and adapt as technology, regulation and stakeholder expectations evolve across their AIMS.

      Explore what certification could mean for your organization

      Whether your organization is assessing its AI governance maturity or considering ISO 42001 certification, KPMG can help you understand your readiness, identify gaps with support to remediate the gaps with a defined roadmap for a practical path forward, conduct Internal Audits and facilitate your certification process.

      Contact our team to discuss your objectives and where to begin.

      Kareem Sadek

      Partner, Advisory, Tech Risk, Trusted AI and Digital Assets National Leader

      Toronto

      KPMG Canada

      Insights

      KPMG is among the first firms in Canada to receive the leading global certification for AI governance.

      Connect with us

      KPMG. Make the Difference.

      We’re here to help your organization thrive.

      building