Article

AI Governance, Bias and Privacy: JAKALA Achieves ISO/IEC 42001 Certification

4 min read

Published on September 15, 2026

AI Governance, Bias and Privacy: JAKALA Achieves ISO/IEC 42001 Certification
As Marco Di Dio Roccazzella explains in this interview, JAKALA is among the first companies in Italy to achieve the international certification for AI governance

JAKALA is one of the few companies in Italy to have achieved ISO/IEC 42001 certification, the first international standard dedicated to Artificial Intelligence governance.

This achievement represents much more than a compliance milestone. It is the result of a joint effort between the teams designing and developing AI systems – data scientists, data engineers and AI architects – and those defining their responsibilities and boundaries – legal, compliance and data protection. Different areas of expertise came together to build a new way of working with AI.

The certification comes at a time when issues such as algorithmic bias, consumer data privacy and alignment with the European AI Act are increasingly central to public debate and to the decisions of clients and investors.

For JAKALA, which works with consumer data at scale and develops systems that support automated decision-making – from personalization and targeting to loyalty – this means being able to demonstrate, through a certified system, that innovation and responsibility can grow hand in hand.

We discussed this with Marco Di Dio Roccazzella, Shareholder and General Manager at JAKALA.

For those who may not be familiar with it: what is ISO/IEC 42001?

It is the first international standard to treat AI management as an organizational capability, rather than simply a technology project.

ISO/IEC 42001 defines a system encompassing roles, processes, controls, risk management, transparency and human oversight throughout the entire AI lifecycle. For the first time, the international community has established a shared framework for what it means, in practical terms, to govern AI.

For JAKALA, it is almost the formalization of an idea I have always emphasized: AI is not a toolbox to be distributed across an organization. It is an organizational capability that brings together strategy, governance, data, technology, people and processes.

At JAKALA, this idea has also been translated into practice thanks to the support of Enrico Bottacco, Managing Director, Corporate Affairs & Sustainability, and his team, who led the methodological and organizational development of the entire certification journey.

JAKALA works with AI by nature. Why should we, of all companies, get certified in AI governance?

Precisely because we live and work with it every day.

An organization is like a ship already at sea: it cannot stop to redesign itself. It has to keep navigating while evolving. And the faster the ship moves, the more important it is to know how to steer it.

For a company that industrializes AI at scale, both for itself and for its clients, ungoverned AI is a vulnerability.

Governance is what allows us to move fast without losing our course. Getting certified was therefore an act of execution: you cannot scale what you cannot manage.

In practical terms, how has ISO/IEC 42001 changed the way we work with AI? What did we do before, and what do we do now?

AI governance was already in place, but it was largely implicit and relied on individual expertise, project by project.

With ISO/IEC 42001, we have built a system of policies and methodologies that no longer depends on any single individual.

Through a structured process, we have moved from good practice to a repeatable capability, with a focus on methodology, scalability and impact.

Today, the real question is no longer whether a company uses AI, but whether it can govern AI in a reliable and secure way

We are an Anthropic partner. How does this partnership relate to the certification?

It is the same choice, expressed in two different ways. Anthropic is a frontier AI lab built around the idea that AI safety should be an integral part of the product, not an afterthought. We did not choose a partner first and then add governance as a framework around it. We chose a partner whose DNA is responsible AI.

ISO/IEC 42001 is how JAKALA demonstrates the importance we place on safety. Our partnership gives us access to frontier capabilities, which we are also putting into practice through international agentic AI projects. The certification demonstrates that we are developing those capabilities in a structured and responsible way.

Capability and responsibility are two sides of the same vision: scaling, but scaling well.

Algorithmic bias is a major topic of discussion today. How does ISO/IEC 42001 help you address it in practice?

Bias is not a bug that can be fixed once and then forgotten. It is a risk that must be monitored throughout the entire lifecycle of a model, because data changes, use cases evolve, and a model that appears “clean” today may behave differently tomorrow.

With ISO/IEC 42001, we have formalized specific controls from the design stage onward: evaluating training datasets, conducting fairness testing before deployment, and continuously monitoring outcomes in production.

It is a preventive rather than corrective approach. The goal is to make risk visible and measurable from the outset, so that it can be managed systematically rather than relying solely on the good intentions of the people who wrote the code.

JAKALA joined the AI Pact, the European Commission’s voluntary initiative, from the outset, and has now achieved ISO/IEC 42001 certification. What does this journey mean for us in the market?

The most important advantage is being ready today. The AI Pact represents an early, voluntary commitment to the principles of the European AI Act; ISO/IEC 42001 provides a management system that helps turn those principles into operational processes.

In the market, this can make a very tangible difference: in tenders, supplier qualification processes, and client and investor due diligence, the question is no longer simply whether a company uses AI, but whether it can govern AI in a reliable, secure and verifiable way.

What comes next?

ISO/IEC 42001 is not a destination. It is a system that needs to evolve continuously. We will therefore continue to strengthen our approach to risk management, awareness of AI impacts, and our ability to monitor the evolution of AI responsibly.

Because the future of AI will not be determined by technology alone, but by our ability to navigate change with vision, responsibility and purpose.