50+Published Standards
30+In Development
5Major Bodies
2023NIST AI RMF

Table of Contents

1. Overview

Technical standards translate high-level AI governance principles into concrete, implementable requirements. They are increasingly referenced in legislation (the EU AI Act explicitly references harmonised standards) and serve as the practical bridge between policy intent and engineering practice.

Key Standards Bodies

Organization Type AI Standards Scope Website
ISO/IEC JTC 1/SC 42InternationalFoundational AI standards; management systems; trustworthiness; data qualityiso.org
IEEE SAInternationalEthically aligned design; autonomous systems; algorithmic bias; transparencyieee.org
NISTUS (widely adopted)AI Risk Management Framework; trustworthy AI; evaluation methodsnist.gov
CEN/CENELECEuropeanHarmonised standards for EU AI Act compliance; AI management; risk assessmentcencenelec.eu
ETSIEuropeanAI security; securing AI in networks; trustworthy AI architectureetsi.org

2. ISO/IEC 42001 — AI Management System

ISO/IEC 42001:2023 is the world’s first international standard for AI management systems. Published December 2023, it provides a certifiable framework for organizations developing, providing, or using AI systems. It follows the Annex SL structure familiar from ISO 9001 and ISO 27001.

2.1 Structure

Clause Title Key Requirements
4Context of the OrganizationUnderstanding the organization, interested parties, scope, and AIMS
5LeadershipManagement commitment; AI policy; roles and responsibilities
6PlanningRisk assessment; AI impact assessment; objectives and plans
7SupportResources; competence; awareness; communication; documented information
8OperationAI system lifecycle processes; data management; third-party considerations
9Performance EvaluationMonitoring; internal audit; management review
10ImprovementNonconformity; corrective action; continual improvement

2.2 Annex Controls

Annex A provides 38 controls across 8 domains; Annex B provides implementation guidance. The controls cover AI policy, responsible AI, impact assessment, AI system lifecycle, data for AI, information for interested parties, use of AI systems, and third-party relationships.

3. NIST AI Risk Management Framework (AI RMF 1.0)

3.1 Background

Published January 2023, the NIST AI RMF is a voluntary framework designed to help organizations manage risks associated with AI systems. Referenced by the US Executive Order on AI (EO 14110) and widely adopted internationally.

3.2 Core Structure

Function Description Key Categories
GOVERNCultivate a culture of risk management; establish policies, processes, proceduresGovernance structure; risk management strategy; organizational roles
MAPContext is recognized and risks related to context are identifiedIntended use; stakeholder identification; risk characterization
MEASUREIdentified risks are assessed, analyzed, or trackedTesting; metrics; bias evaluation; monitoring
MANAGERisks are prioritized and acted uponResponse plans; risk treatment; post-deployment monitoring

3.3 Companion Resources

4. IEEE AI Standards

4.1 P7000 Series (Ethically Aligned Design)

Standard Title Status Scope
IEEE 7000-2021Model Process for Addressing Ethical Concerns During System DesignPublishedEthical value-based design process for any system
IEEE 7001-2021Transparency of Autonomous SystemsPublishedMeasurable transparency levels for autonomous systems
IEEE 7002-2022Data Privacy ProcessPublishedPrivacy engineering for AI and autonomous systems
IEEE 7003-2023Algorithmic Bias ConsiderationsPublishedBias detection and mitigation across AI lifecycle
IEEE P7004Child and Student Data GovernanceIn developmentProtecting minors’ data in AI systems
IEEE P7005Employer Data GovernanceIn developmentWorkplace data governance for AI
IEEE P7006Personal Data AI AgentIn developmentStandards for AI agents managing personal data
IEEE P7007Ontological Standard for Ethically Driven Robotics and Automation SystemsIn developmentOntology for ethical robotics
IEEE P7008Ethically Driven Nudging for Robotic, Intelligent, and Autonomous SystemsIn developmentEthical persuasion in AI systems
IEEE P7009Fail-Safe Design of Autonomous and Semi-Autonomous SystemsIn developmentFail-safe engineering for AI
IEEE P7010Wellbeing Metrics Standard for Ethical AI and Autonomous SystemsIn developmentMeasuring human wellbeing impact

5. Other ISO/IEC AI Standards

Standard Title Year Key Content
ISO/IEC 22989AI Concepts and Terminology2022Foundational definitions; taxonomy of AI concepts
ISO/IEC 23053Framework for AI Systems Using ML2022Reference architecture for ML-based AI systems
ISO/IEC 23894AI Risk Management2023Risk management guidance specific to AI systems
ISO/IEC 38507Governance Implications of AI2022Board-level governance guidance for AI
ISO/IEC 25059Quality Model for AI Systems2023Quality characteristics specific to AI (extends SQuaRE)
ISO/IEC TR 24027Bias in AI Systems2021Sources of bias; measurement approaches; mitigation
ISO/IEC TR 24028Trustworthiness in AI2020Overview of trustworthiness concerns and approaches
ISO/IEC TR 24029Assessment of Neural Network Robustness2021Methods for evaluating robustness of neural networks
ISO/IEC TR 24030AI Use Cases2021Collection of AI use cases across sectors
ISO/IEC 5259 seriesData Quality for AI2024Multi-part standard on AI training/test data quality
ISO/IEC 12792Transparency Taxonomy2024Taxonomy of AI transparency concepts and requirements

6. AI Safety Standards

6.1 Emerging Safety Standards

Standard/Framework Organization Focus Status
ISO/IEC DIS 27090ISO/IECCybersecurity for AIDraft
ISO/IEC DIS 27091ISO/IECPrivacy protection for AIDraft
ETSI SAI GR 004ETSIProblem statement on securing AIPublished
ETSI SAI GR 005ETSIMitigation strategy for AI threatsPublished
NIST AI 100-2e2025NISTAdversarial ML — Taxonomy and terminologyPublished
NIST AI 600-1NISTGenerative AI Profile (AI RMF companion)Published
UL 4600Underwriters LaboratoriesSafety for autonomous products (vehicles, drones, robots)Published

7. Sector-Specific Standards

Sector Standard Scope
HealthcareIEC 62304 (medical device software); ISO 14971 (risk management); IEC 82304-1 (health software); WHO AI ethics guidanceMedical AI device lifecycle; clinical validation; patient safety
AutomotiveISO 26262 (functional safety); ISO/PAS 21448 (SOTIF); SAE J3016 (driving automation levels); UL 4600Autonomous vehicle safety; operational design domain; fail-safe requirements
Financial ServicesSR 11-7 (OCC model risk management); SS1/23 (PRA/BoE model risk); IEEE 2863 (org governance of ML)Model validation; explainability; fair lending; anti-money laundering
AerospaceEASA AI Concept Paper; SAE AIR6988; EUROCAE ED-324AI in aviation systems; certification; operational approval

8. Standards & Regulatory Compliance

8.1 EU AI Act Harmonised Standards

The EU AI Act relies on harmonised standards developed by CEN/CENELEC to operationalize its requirements. CEN/CENELEC JTC 21 has been tasked with developing standards that, when followed, create a presumption of conformity with the AI Act.

Standard Request Area Related AI Act Requirement Expected Standard
Risk managementArticle 9Based on ISO/IEC 23894
Data governanceArticle 10Based on ISO/IEC 5259 series
Technical documentationArticle 11New CEN/CENELEC standard
Record-keepingArticle 12Based on ISO/IEC 42001 Annex A
TransparencyArticle 13Based on ISO/IEC 12792
Human oversightArticle 14New CEN/CENELEC standard
Accuracy, robustness, cybersecurityArticle 15Based on ISO/IEC 25059, 27090
Quality managementArticle 17Based on ISO/IEC 42001

9. Comparative Analysis

Dimension ISO/IEC 42001 NIST AI RMF IEEE P7000 Series
TypeCertifiable management systemVoluntary risk frameworkProcess standards
ScopeOrganizational AI managementAI risk identification and mitigationEthical design processes
CertificationYes (third-party audit)No (self-assessment)No (guidance)
CostCHF 187 (standard purchase)Free (publicly available)Varies by standard
Regulatory linkageEU AI Act presumption of conformityUS EO 14110 referenceReferenced in policy discussions
Best forOrganizations seeking certificationOrganizations wanting flexible risk frameworkEngineering teams designing systems

10. References & Resources

ISO/IEC Standards

NIST

IEEE

European Standards

Previous International Frameworks Next Corporate Governance