Skip to content

United Nations Joint Staff Pension Fund

International Organisation Global

Responses

In your opinion, what outcomes would make the first Global Dialogue on AI Governance a success?

The first Global Dialogue on AI Governance would be successful if it demonstrates that AI governance can be operationalized in real institutions through auditable management systems, not only articulated through high-level principles. From this perspective, a key success outcome would be broad recognition of, and commitment to, practical assurance mechanisms, including certification-ready approaches that make governance measurable, comparable, and enforceable. Our submission, the first UN-system ISO/IEC 42001 certification for an Artificial Intelligence Management System, illustrates what such success looks like in practice. It shows that effective governance can be achieved by defining a precise and auditable scope for a concrete use case, embedding AI governance into enterprise-wide risk management, conducting documented AI risk and impact assessments, implementing structured risk treatment with named risk owners, and maintaining continuous oversight through internal audit and external surveillance. This approach makes accountability explicit and enables stakeholders to verify that safeguards are in place across the AI lifecycle. Accordingly, the Dialogue would be successful if it results in convergence around several outcomes: a shared minimum baseline for AI governance grounded in risk management; guidance on how to scope AI systems for assurance and audit; stronger interoperability between AI governance standards and existing information security and privacy management systems; and a practical roadmap for adoption in public-sector and international contexts, supported by reusable templates and exemplars. If the Dialogue elevates replicable, management-system-based governance models that can be independently assessed, and accelerates their adoption across the UN system and beyond, it will have delivered meaningful progress.

From your perspective, which of the following thematic areas identified by the General Assembly Resolution 79/325 for the AI Dialogue reflect your priorities for urgent action and active engagement?

  • Safe, secure and trustworthy AI
  • Interoperability of governance approaches
  • Protection and promotion of human rights
  • Transparency, accountability, and human oversight

Please briefly explain your selection.

4

We selected these four thematic areas because they are the most directly actionable priorities for our entity and are central to translating AI governance from principles into verifiable operational practice, including through ISO/IEC 42001. Safe, secure and trustworthy AI is essential to maintaining the integrity and reliability of AI-enabled services in high-stakes contexts. In our case, the certified scope covers an AI module embedded in the UNJSPF Digital Certificate of Entitlement that is used to prevent and detect deepfakes during proof-of-life verification, where security, robustness, and dependable performance are critical. Transparency, accountability, and human oversight are necessary to ensure that AI-related decisions and risk treatments are documented, traceable, and subject to responsible ownership. ISO/IEC 42001 operationalizes these requirements through governance roles, auditable documentation, risk ownership, and continuous monitoring across the AI lifecycle. Interoperability of governance approaches is a priority because fragmented guidance increases burden and reduces adoption. A management-system approach aligned with the harmonized structure of ISO standards enables AI governance to integrate with established information security and privacy management practices (for example, ISO/IEC 27001 and ISO/IEC 27701), supporting consistent implementation across organizations and jurisdictions. Protection and promotion of human rights is fundamental in UN-system contexts, particularly when AI systems process biometric and identity-related data. Our approach emphasizes impact assessments, privacy safeguards, and continuous reassessment to help ensure that AI-enabled identity verification supports access to services while protecting individuals' rights and dignity.

In your opinion, are there any cross-cutting or emerging issues not captured by the listed themes above? If so, please explain.

3

Yes. A few cross-cutting and emerging issues merit explicit attention in addition to the listed themes: 1) Assurance, auditability, and independent conformity assessment: Beyond general "trust," there is a need for internationally comparable methods to verify that AI governance is implemented in practice. This includes defining auditable evidence, assurance levels, and credible third-party assessment pathways (for example, management-system-based certification such as ISO/IEC 42001), particularly for public-sector and International Organisations. 2) Lifecycle change management and "continuous governance": Many failures arise after deployment due to model updates, data drift, changing threats (including deepfakes), and shifts in operational context. Governance should explicitly address triggers for reassessment, post-deployment monitoring, incident response, and periodic internal and external review. 3) Third-party and supply-chain AI risk: AI services increasingly rely on vendors, integrated components, and cloud platforms. Governance should cover procurement requirements, contractual controls, verification of supplier claims, and ongoing oversight of outsourced AI functions. 4) Identity, biometrics, and digital public infrastructure use cases: AI-enabled identity verification and biometric processing raise distinct risks and safeguards needs (including accessibility, non-discrimination, error remediation, and proportionality) that cut across security, human rights, and operational resilience. 5) Cross-border data governance and jurisdictional complexity: International deployments often involve multiple legal regimes, data transfer constraints, and varying accountability expectations. Practical guidance is needed for governance in multi-jurisdictional environments, including recordkeeping and responsibility allocation. Making these issues explicit would strengthen the Dialogue's ability to move from broad principles to implementable, measurable, and sustainable governance.

How are the governance gaps and related developments/advances in the thematic areas you selected above affecting your country, region, or sector? Please highlight the most significant challenges.

Governance gaps and recent advances in the areas we selected are having a direct and tangible impact on the international public-sector and UN-system operating environment, particularly in identity-enabled and benefits-delivery services. Most significant challenges: A primary gap is the absence of consistent, auditable governance practices across institutions and jurisdictions. This fragmentation complicates cross-border service delivery, increases compliance burden, and makes it difficult to demonstrate due diligence to stakeholders. In parallel, the rapid evolution of adversarial threats, including deepfakes and other forms of synthetic media, is increasing operational and cybersecurity risk for identity verification processes. Another challenge is sustaining transparency, accountability, and human oversight in complex socio-technical systems, where responsibilities can become diffuse across internal teams and external vendors. Finally, applying human rights safeguards in AI systems that involve biometric and identity-related data remains difficult without clear operational guidance on proportionality, accessibility, non-discrimination, and effective recourse for impacted individuals. Most significant opportunities: At the same time, there is an emerging opportunity to shift from principle-based commitments to verifiable assurance. Management-system approaches such as ISO/IEC 42001 provide a structured, repeatable method to embed AI governance into existing enterprise risk, security, and privacy practices, supported by defined roles, documented risk treatment, lifecycle monitoring, and independent audit. This enables interoperability with other widely adopted ISO standards and supports comparable governance outcomes across entities. In practice, such approaches can strengthen public trust, improve resilience against evolving threats, and enable digital transformation that expands access to services while maintaining safeguards. For International Organisations, scalable and auditable governance models can also accelerate responsible innovation by providing clearer "rules of the road" for deployment and continuous improvement.

What role can the AI Dialogue play in advancing international cooperation on AI governance?

The AI Dialogue can advance international cooperation by aligning stakeholders on a small set of practical, implementable governance outcomes and by reducing fragmentation across jurisdictions. It can do this by (1) promoting convergence on a shared minimum baseline for risk-based AI governance and common terminology; (2) encouraging interoperability between governance approaches, including alignment with auditable management-system standards such as ISO/IEC 42001 and related security and privacy frameworks; (3) strengthening trust through shared expectations for evidence, assurance, and independent evaluation (for example, scoping, impact assessment, monitoring, and incident response); and (4) enabling capacity-building through reusable tools, templates, and a sustained community of practice. If the Dialogue prioritizes operational guidance and follow-through workstreams, it can help translate principles into comparable, verifiable practices that scale internationally.

What are some of the existing initiatives, partnerships, or mechanisms that the AI Dialogue should build upon or connect with, and what added value could the AI Dialogue bring?

The AI Dialogue should build upon and connect with existing multilateral, standards-based, and operational initiatives, including the Global Digital Compact follow-up mechanisms, the UN system's own AI governance work (including the UN System White Paper on AI Governance and inter-agency coordination), UNESCO's Recommendation on the Ethics of AI, and ITU-led multi-stakeholder platforms (including AI for Good). It should also connect with widely used international and regional governance approaches and tools, such as the OECD AI Principles, the Global Partnership on AI (GPAI), and practical risk-management frameworks increasingly used by institutions (for example, the NIST AI Risk Management Framework). In addition, the Dialogue should engage the international standards ecosystem, in particular ISO/IEC JTC 1/SC 42 and related work on AI management systems and risk management, including ISO/IEC 42001 and supporting standards. The added value of the AI Dialogue is that it can provide a universal UN convening space to align these efforts, reduce duplication, and elevate interoperability across frameworks. It can translate shared principles into implementable and auditable governance outcomes, including common expectations for evidence, assurance, and lifecycle oversight. The Dialogue can also accelerate capacity-building by curating reusable templates, exemplars, and communities of practice, and by disseminating lessons learned from real deployments, including in international public administration. By linking policy commitments with standards-based implementation pathways, the Dialogue can strengthen international trust and enable more consistent governance across jurisdictions and sectors.

How can different stakeholders contribute to the AI Dialogue? Please share recommendations for the format and structure of the AI Dialogue.

How stakeholders can contribute Member States: set shared priorities and support alignment on baseline governance and assurance. UN entities/IOs: share operational lessons learned, pilot practices, and publish reusable templates. Industry: provide implementable controls, evaluation methods, and supply-chain transparency. Civil society: surface real-world impacts and strengthen rights, accessibility, and recourse. Academia/technical community: contribute measurement methods, benchmarks, and emerging-risk research. Standards bodies: map interoperability and clarify audit-ready evidence expectations. Recommended format and structure A short plenary to agree 2–3 concrete outputs and a workplan. Time-bound working groups that produce publishable deliverables (templates, minimum evidence sets, procurement clauses, incident playbooks). Use-case clinics to test guidance against real deployments (public-sector and cross-border). An assurance track focused on auditability and conformity assessment (including ISO/IEC 42001). A roadmap with owners and milestones, plus periodic progress reviews to ensure follow-through.

Which voices, communities, or perspectives are currently underrepresented in global discussions on AI governance? How could they be included?

Voices that remain underrepresented in global AI governance discussions include: -Communities most affected by AI-enabled public services, including beneficiaries of social protection systems, migrants and displaced persons, and people whose access to services depends on identity verification. These groups can highlight practical risks around exclusion, errors, and lack of recourse. -People in low-connectivity and low-resource settings, where deployment constraints, language coverage, and digital identity infrastructure gaps shape real-world outcomes. -Minority language communities and local cultural stakeholders, who face uneven model performance, limited linguistic support, and risks to cultural and informational ecosystems. -Persons with disabilities and accessibility experts, who can identify where AI systems create barriers and what "reasonable accommodation" looks like in practice. -Operational practitioners (public administrators, auditors, cybersecurity teams, procurement officers, frontline service staff) who are responsible for implementing controls, handling incidents, and managing vendor risk, but are often absent from high-level debates. To include these perspectives, the Dialogue could: (1) reserve seats and speaking time for rights holders and affected-user representatives, with support for participation costs and interpretation; (2) run use-case clinics on high-impact domains (identity verification, benefits delivery, humanitarian services) and require concrete evidence on safeguards, error rates, and recourse; (3) adopt participatory methods such as structured consultations, surveys, and regional listening sessions; and (4) publish practical outputs (templates for impact assessments, grievance pathways, accessibility requirements, and audit-ready evidence expectations) so that inclusion translates into implementable governance.

What innovative engagement formats could most effectively foster meaningful and dynamic engagement during the AI Dialogue?

-Use-case clinics (work through a real deployment and produce a short set of controls, evidence, and recourse steps). -Assurance labs (agree on "minimum evidence sets" and templates aligned with auditable approaches such as ISO/IEC 42001). -Incident tabletop exercises (simulate deepfake/adversarial attacks, drift, vendor failure; test accountability and response). -Interoperability sprints (rapid crosswalks between major frameworks/standards with agreed mappings). -Rotating fishbowl discussions (structured turn-taking to balance voices, including affected users and implementers). -Commitment sprints + progress check (time-bound pledges with a published follow-up review).

Please share examples of policies, practices, platforms, or approaches that promote effective AI governance or offer concrete solutions to addressing its challenges.

3

Examples of effective AI governance policies, practices, and approaches include: -ISO/IEC 42001 (AI Management System) implementation and certification: a management-system approach that makes AI governance auditable through defined scope, roles and responsibilities, documented risk and impact assessments, risk treatment plans, internal audit, management review, and continual improvement. Our own experience achieving the first UN-system ISO/IEC 42001 certification demonstrates its value in turning principles into verifiable operational controls. -Risk and impact assessment processes with defined triggers: structured AI risk registers and AI system impact assessments performed at planned intervals and upon significant change (e.g., model updates, data drift, new threats), ensuring lifecycle governance rather than one-time review. -Integration with established security and privacy management systems: aligning AI governance with ISO/IEC 27001 (information security) and ISO/IEC 27701 (privacy) embeds AI controls into existing enterprise risk, incident response, and compliance workflows. -Operational "responsible use" guidelines and tool governance: clear policies that define acceptable and prohibited uses, require staff training, and establish approved tool registers and escalation channels (including for third-party tools), helping reduce misuse and uncontrolled data exposure. -Independent evaluation and assurance mechanisms: periodic external audits (security, privacy, and algorithmic audits), and documented monitoring metrics and user-feedback loops, to validate performance, fairness, and robustness in production, including against emerging threats such as deepfakes. Together, these approaches provide concrete solutions by combining clear accountability, measurable controls, and independent assurance across the AI lifecycle.