Why an internally maintained AI governance file should be called documentation, not certification: the precise label survives follow-up questions from boards, funders and auditors, and matches what the law asks.
The last piece in this series set out the five artefacts that together constitute a demonstration: a policy, a tool inventory, a training attendance record, a competency assessment, a review record. Once that file exists, a specific temptation shows up almost immediately. It would sound so much more reassuring to a board or a funder to describe it as a certification rather than as documentation. The word carries more comfort. It is also, right now, not true, and the honest label is the stronger position, not the weaker one.
This piece argues the contrarian case directly: precision about what the file actually is beats a more comfortable word that cannot survive the first real follow-up question.
A certification means an independent third party assessed the organisation against a published external standard, and can be named and held accountable for that assessment. Nothing in the evidence file this series has built involves an external assessor. It is self-documented, internally maintained, reviewed on a fixed cycle, and that is a genuinely strong position. It is simply not the same claim as certification, and no accreditation scheme currently exists for the specific AI literacy obligation this file addresses. Being precise about that distinction is not an admission of being unprepared. It is an accurate description of a real and defensible piece of governance work.
The word invites a specific, entirely predictable follow-up: who certified this, against what published standard, and can we see their accreditation? A self-documented file has no honest answer to that question, because the premise of the question is false. That gap, exposed once in front of a board member, a funder's own counsel, or an auditor who simply asks the obvious next question, costs far more credibility than the honest label would ever have cost up front. An organisation that overclaims gets caught exactly once and is disbelieved on everything else it says afterwards, including the parts that were entirely true.
Certification is not a word an organisation gets to award itself. Documentation is what an organisation actually controls, and it is a stronger claim than a borrowed word that cannot survive a single follow-up question.
The safe, accurate phrasing is close at hand: describe it as a documented AI governance framework, name the specific obligation it addresses, and state plainly that it is internally maintained and reviewed on a fixed six-month cycle. Where genuinely true, it is fair to add that external counsel has reviewed the file, since that is a real and checkable fact rather than a borrowed word. What never belongs in that sentence is "certified," unless an actual accreditation body has issued one, because that single word is the one most likely to be tested and the one least likely to survive the test.
Describe the evidence file as documented, internally maintained governance rather than as certification, since no accreditation scheme currently exists for this obligation, and treat the precise label as a credibility advantage rather than a weaker substitute for a more impressive-sounding word.
No external statistic cited; this article presents an internal contrarian argument rather than third-party evidence.
The five documents that together let an organisation prove its AI governance to an auditor, board or funder: policy, tool inventory, training record, competency assessment and review record.
AI Use Policy · 4 minGuide · 25 September 2026Why an AI policy needs a fixed six-month review against four specific questions, plus four yes-or-no triggers (departed contact, changed tool, repeated escalation, changed law) that force an earlier one.
AI Use Policy · 4 minIf this is the question on your desk, a thirty-minute call tells you whether the service fits, or that you do not need us yet.