AI Management Policy

Objectives

To develop, implement, and manage artificial intelligence solutions ethically, safely, transparently, and in a human-centered manner that creates sustainable value for clients and communities, optimizing processes and supporting decision-making in compliance with applicable legal, regulatory, and normative requirements.

Justification

At Sofis Solutions, we understand that artificial intelligence (AI) offers a transformative opportunity to enhance people's lives, optimize public and private sector processes, and advance sustainable development. As a company committed to ethics, transparency, and social impact, we take responsibility for ensuring that the design, development, implementation, and operation of AI systems are carried out in a trustworthy, safe, and human-centered way.

This policy establishes the framework of principles and commitments guiding our AI management in line with our mission, organizational values, and the requirements of ISO/IEC 42001:2023.

Scope

This policy applies to all processes, projects, solutions, and services developed or provided by Sofis Solutions that include artificial intelligence or automated decision-making capabilities, including those offered to public, private, and international cooperation sector clients.

Audience

Internal audience:

  • All Sofis Solutions personnel, regardless of role or location.
  • Development, implementation, testing, and maintenance teams for AI solutions.
  • Project management and functional management teams.
  • AI governance and ethics committee or responsible persons.
  • Support areas involved in providing or supervising AI (cybersecurity, quality, legal, HR).

External audience:

  • Clients and strategic partners who use, acquire, or integrate Sofis Solutions' AI solutions.
  • Suppliers and third parties providing AI-related data, models, algorithms, or infrastructure.
  • Regulatory and certification bodies auditing or overseeing the AI management system.
  • Communities and end-users of the solutions, when applicable for transparency and information rights.

Responsibilities

Senior Management

  • Approve the AI Policy and its updates.
  • Ensure availability of human, technical, and financial resources for its implementation.
  • Regularly review the effectiveness of the AI management system.

AI Lead / AI Governance Committee

  • Lead the implementation and maintenance of the AI Management System.
  • Ensure policy compliance across all projects and services.
  • Coordinate risk and impact assessments for AI systems.
  • Approve or reject high-impact AI projects prior to deployment.

Project Management / Technical Leads

  • Integrate the policy’s principles and commitments into the AI system lifecycle.
  • Ensure data and model quality, traceability, and security.
  • Report incidents, deviations, or non-conformities related to AI.

Cybersecurity / Information Security Area

  • Implement and monitor protection measures against AI-specific threats.
  • Integrate security requirements in AI development, operation, and maintenance.

Legal and Compliance Area

  • Ensure alignment with data protection laws, copyright, sector regulations, and applicable contractual requirements for AI.

All employees and collaborators

  • Understand and comply with the policy in AI-related activities.
  • Participate in training and awareness activities.
  • Report questions, risks, or incidents to the AI Lead.

Company Commitments

As part of its Artificial Intelligence Management System, Sofis Solutions commits to:

  1. Comply with applicable legislation, including data protection laws, sector regulations, and international ethical AI frameworks.
  2. Design and implement AI risk management processes, covering technical, social, legal, and ethical aspects.
  3. Assess the potential impact of AI systems, especially those directly affecting individual rights or critical decisions.
  4. Ensure data quality and governance, including traceability, integrity, and representativeness of training data.
  5. Promote continuous improvement of the AI management system through internal audits, management review, and regular policy updates.
  6. Encourage training and awareness so all stakeholders understand the principles and risks associated with AI use.
  7. Establish governance mechanisms such as ethics committees or technical reviewers to oversee high-impact AI developments.
  8. Maintain active dialogue with stakeholders—clients, users, communities, and regulators—to ensure trust and shared responsibility.

Communication and Review

This policy:

  • Is approved by Senior Management and communicated across all organizational levels.
  • Is available to clients and stakeholders upon request.
  • Will be reviewed at least annually or whenever significant changes occur in regulations, organizational context, or technologies used.

Version: 4

Approval date: 2025-08-09.