Libelium adds ISO 42001 and consolidates its Artificial Intelligence governance model
Table of Contents

Libelium has obtained the ISO/IEC 42001 certification, the international standard that regulates the ethical and responsible management of Artificial Intelligence. With this step, the company expands a portfolio of accreditations that already covers cybersecurity, software quality, and urban platforms, and reinforces the pillar of trust upon which iris360, its data governance and intelligence platform, is based.
Behind the change, there is always a solid technical foundation. This time, that foundation has a name and a number: ISO/IEC 42001.
What is an ISO standard and why does it matter?
ISO (International Organization for Standardization) is the organization that defines the reference standards used by companies around the world to demonstrate that a process, service, or system meets minimum quality, safety, or management requirements. An ISO certification is not a decorative seal: it implies that an external and independent entity has audited the organization and verified that its processes (documented, measurable, and continuously improved) meet the corresponding standard.
For public administrations and companies evaluating technology providers, an ISO certification translates something abstract (can I trust this platform?) into an objective and auditable criterion. It is, ultimately, the common language that allows comparing guarantees between different organizations.
What exactly does ISO/IEC 42001 imply?
ISO/IEC 42001:2023 is the first international standard that establishes requirements for implementing, maintaining, and improving an Artificial Intelligence Management System (AIMS) within an organization. Unlike a specific technical certification, it does not evaluate an isolated algorithm, but the entire governance framework: how AI systems are designed, trained, supervised, and audited throughout their entire lifecycle.
In practice, this requires the certified organization to demonstrate:
- Traceability: Each algorithmic decision can be documented and explained.
- AI-specific risk management: Identification and mitigation of biases, errors, or misuse before they reach production.
- Human oversight: AI systems do not operate without control and review mechanisms.
- Continuous improvement: The management system is audited and updated periodically; it is not a certificate that is obtained once and filed away.
For Libelium, this certification consolidates the core of iris360: the application of artificial intelligence, advanced analytics, and predictive algorithms within the platform now meets the highest operational and European demands, offering public and private managers reliable and bias-free information for decision-making.
The 3 pillars of Libelium’s AI governance model
To address AI governance with peace of mind and technical rigor, Libelium structures its operational framework by uniting three key pieces:
- Management Framework (ISO/IEC 42001): Defines internal governance, roles, and human oversight throughout the entire lifecycle of the algorithm.
- Metrology and Testing (under scientific methodology of testing and evaluation (Test, Evaluation, Verification, and Validation) from NIST TEVV-Athlon): Puts the model to the test through stress testing (red teaming, hallucination and bias detection) to measure its real-world performance.
- Independent Verification (ISO/IEC 17029): Provides the auditable evidence and legal validity required by European regulators.
For Libelium, this approach consolidates the core of iris360: the application of artificial intelligence, advanced analytics, and predictive algorithms within the platform now meets the highest operational and European demands, offering public and private managers reliable and bias-free information for decision-making.
A regulatory ecosystem that covers the entire value chain
ISO 42001 does not arrive alone. It adds to an infrastructure of quality and security that the Libelium Group has built over years and that covers every link in its technological proposal:
- Cybersecurity and data protection: ISO/IEC 27001 and the accreditation in the National Security Scheme (ENS) at the High Category ensure that Libelium can operate with public administrations and critical infrastructures, two environments where security is not negotiable.
- Metrological excellence: UNE-EN ISO/IEC 17025:2017, with ENAC accreditation, supports the technical competence of Libelium Lab in sensor calibration. It is the guarantee that the data, at its origin, is accurate.
- Service management and software development: ISO/IEC 20000-1:2018 certifies ICT service management, while ISO/IEC 33000 accredits the high level of maturity (SPICE) in software development. Two standards that speak of robust internal processes, not just the final product.
- Smart territories and cities: The standards UNE 178104 (interoperability of city platforms), UNE 178502 (indicator systems for Smart Tourist Destinations), and UNE 178503 (data semantics) place Libelium within the specific regulatory framework of smart urban management.
Read together, these certifications are not a list of logos on a corporate website: they are evidence that every layer of iris360 (from the sensor that captures the data to the algorithm that converts it into a decision) is subject to an auditable standard.
Why this matters now: alignment with the EU
zThe adoption of ISO 42001 does not come at just any moment. The European Union has placed responsible AI management at the center of its regulatory agenda with the Artificial Intelligence Act (AI Act), the world’s first comprehensive law on this technology, which requires organizations that develop or deploy AI systems (especially “high-risk” ones, a category that includes many applications in critical infrastructure and public services) to accredit risk management, traceability, human oversight, and transparency processes.
Althoug ISO/IEC 42001 is not the AI Act, it functions as its natural management framework: while the European regulation sets the legal requirements, the ISO standard provides the operational structure (the management system) with which an organization can demonstrate, in an auditable way, that it meets that standard. For public and private managers who must respond to the new European regulation, having a provider certified in ISO 42001 simplifies that task: it reduces regulatory uncertainty and shifts the burden of proof to a process already verified by an independent third party.
In this sense, the certification reinforces Libelium’s position as a technological partner prepared to operate within the European regulatory framework, both today and as the requirements of the AI Act are phased in over the coming years.
For public and private managers, having a provider certified in ISO 42001 simplifies compliance and shifts the burden of proof to an independently verified process.
Datocracy with guarantees
Libelium promotes datocracy: the idea that data should be the transparent language that connects administrations, companies, and citizens. But data can only support a decision if the process that generates it, analyzes it, and converts it into a recommendation is reliable from beginning to end.
With the addition of ISO 42001 to its base of accreditations, Libelium reaffirms an integral governance model that offers connected, auditable solutions with the highest market guarantees (the same commitment that has guided the company in its first 20 years, and that will continue to mark the path in the years to come).
Ready to build a compliant and trusted AI roadmap? Whether you are managing public infrastructure or industrial operations, our team of technical consultants can help you deploy secure, auditable, and European-aligned AI solutions.
Behind the Change.
Beyond the Challenge.