ISO standards relating to the governance, management and quality of AI (I)

Artificial Intelligence (AI) is having an ever-greater impact on people’s daily lives and plays a key role in the digital transformation of businesses and public administrations, thanks to its ability to automate and facilitate decision-making. Consequently, practices are required to govern, manage and ensure the quality of Artificial Intelligence Systems (AIS).

Fortunately, organisations such as UNE [1], CEN/CENELEC and ISO/IEC are constantly proposing new standards that incorporate the best available practices to improve the transparency, data quality and reliability of AIS, whilst mitigating risks and maximising benefits. In a series of publications, we will summarise the main standards proposed by the ISO/IEC JTC1/SC42 subcommittee, which is the most active in this area.

In this article, we set out the standards that address issues relating to the governance of AI [2].

Governance framework

ISO/IEC 38507 Information technology — Governance of IT — Governance implications of the use of artificial intelligence by organizations.

This standard provides the international framework for governing bodies (senior management, boards of directors) to address the strategic and ethical challenges arising from the implementation of Artificial Intelligence (AI); and sets out the governance of AI through the following key areas:

  • Responsibility and Accountability: Emphasises that ultimate responsibility for the use of AI and its automated decisions lies with human leadership, not with the technological system. Defines clear structures for decision-making and oversight.
  • Strategic Alignment: Ensures that AI projects are not developed in isolation, but rather respond directly to the business strategy and contribute to the organisation’s objectives.
  • Risk Management and Compliance: Integrates AI-specific risks (biases, opacity, hallucinations, security breaches) into the existing corporate risk management framework, treating them with the same rigour as financial or legal risks.
  • Ethical and Social Considerations: Sets out the need to assess the impact of AI on human rights, equity and organisational values, promoting the development of policies that guide ethical use and prevent negative social effects.
  • Transparency and Traceability: Promotes the implementation of mechanisms that enable the operation of algorithms to be audited and explained, ensuring that the organisation can justify its decision-making processes.

Implementing this standard enables organisations to:

  • Building Trust: It instils confidence in customers, regulators and society by demonstrating robust control over the deployment of AI.
  • Regulatory Readiness: Facilitates compliance with emerging regulations (such as the AI Act), which explicitly require governance and risk management systems for high-risk applications.
  • Operational Resilience: Establishes cycles of regular reviews, monitoring of key performance indicators (KPIs) and escalation procedures for incidents, ensuring that the organisation is able to respond to changes or failures in its smart systems.

Risk

ISO/IEC 23894 Information technology — Artificial intelligence — Guidance on risk management

This international standard provides clear and detailed guidelines on how organisations that develop, provide or use artificial intelligence systems should manage AI-related risks, and is specifically designed to help organisations integrate AI risk management into their governance, decision-making and general operations. It applies to all types of organisations (public, private or not-for-profit) and is independent of their size or sector.

The regulatory provisions are intended to ensure that organisations accurately achieve the following:

  • Alignment of objectives: To ensure that AI risk management is directly linked to the organisation’s strategic objectives and purpose.
  • Promoting reliability: Managing risks to enhance the reliability of AI systems in the eyes of users, regulators and society.
  • Addressing uncertainty: Formally addressing the risks arising from opacity (the "black box" effect), the evolving nature of AI models (continuous learning) and the use of data.

ISO/IEC CD TS 25568 Information technology — Artificial Intelligence — Guidance on addressing risks in generative AI systems.

This document provides specific guidance aimed at identifying, assessing and addressing the unique and characteristic risks associated with generative AI systems (such as large language models, image, video or code generators), complementing the ISO/IEC 23894 standard, and offering controls, methodologies and technical recommendations designed exclusively for the properties and behaviour of generative models.

Ethics

ISO/IEC TR 24368 Information technology — Artificial intelligence — Overview of ethical and societal concerns.

This technical report provides an overview of the ethical and social concerns relating to AI systems. Its main purpose is to identify, describe and organise the non-technical challenges arising from the development, deployment and use of AI, serving as a common knowledge base to help organisations, developers and standardisation committees understand the socio-ethical impact of these technologies.

Other related standards

ISO/IEC FDIS 42105 Information technology — Artificial intelligence — Guidance for human oversight of AI systems.

This standard provides guidelines and practical advice on the design, implementation and evaluation of human oversight mechanisms in AI systems. Its primary purpose is to define methodologies that enable organisations to ensure that humans retain control, understanding and the ability to intervene appropriately in AI decisions and operations, in order to mitigate risks, protect fundamental rights and ensure safety.

ISO/IEC FDIS 24970 Artificial intelligence — AI system logging.

This document sets out the requirements and provides guidelines for event logging in artificial intelligence systems, with the aim of defining what information must be persistently logged throughout the lifecycle of an AI system to enable traceability, auditability, accountability and transparency regarding its behaviour and decisions.

ISO/IEC AWI 25870 Artificial intelligence — Reporting framework for AI incidents.

This document is being developed to provide a standardised framework for the notification and reporting of artificial intelligence incidents, with the aim of establishing the structure, data formats, classification criteria and communication channels necessary to consistently document any event or anomaly in an AI system that results (or has the potential to result) in harm, damage or breaches of security, privacy or rights.

ISO/IEC TR 21221 Information technology – Artificial intelligence – Beneficial AI systems

This technical report provides an overview and conceptual guidelines on "beneficial AI Systems". Its main purpose is to explore how AI Systems can be designed, developed and deployed in such a way as to actively maximise positive impacts for humanity, aligning their objectives with social wellbeing, sustainable development and fundamental human values.


[1] It is worth highlighting the excellent work carried out by UNE, not only in translating standards (which can be found in Spanish on its website) but also in promoting and developing both international and national standards and specifications.

[2] The summaries of the content presented in this post have been provided directly by GEMINI and reviewed by I2SC.