Implementing ISO standards? Don't overlook GDPR. Try Cookiebot free →

ISO 24028

Artificial Intelligence - Overview of Trustworthiness in AI

Technology & Innovation Published: 2020

ISO 24028:2020 at a glance

Current edition
ISO/IEC TR 24028:2020 - Information technology — Artificial intelligence — Overview of trustworthiness in artificial intelligence
Published
2020
Status
Published
Type of standard
Technical report
Certifiable
No — used for reference and implementation, not certification
Official ISO page
View ISO 24028:2020 on iso.org
Last verified

Overview

A technical report surveying the factors that affect the trustworthiness of systems providing or using AI, including transparency, explainability, controllability, robustness, safety, security and privacy.

ISO/IEC TR 24028:2020 is a Technical Report — an informative document rather than a standard containing requirements. It analyses the factors that can affect the trustworthiness of systems providing or using artificial intelligence, and surveys the approaches available for establishing and assessing that trustworthiness. It was published by ISO/IEC JTC 1/SC 42, the joint subcommittee responsible for artificial intelligence.

What it covers. The report surveys three broad areas. First, approaches to establishing trust in AI systems through properties such as transparency, explainability and controllability. Second, engineering pitfalls in AI systems together with the typical threats and risks associated with them, and the mitigation techniques and methods available. Third, approaches to assessing and achieving availability, resiliency, reliability, accuracy, safety, security and privacy in AI systems. It covers AI-specific vulnerabilities — adversarial manipulation, data poisoning, bias in training data, unpredictability of learned behaviour — alongside conventional concerns such as hardware faults.

The document explicitly places the specification of levels of trustworthiness outside its scope. It does not grade AI systems or define thresholds; it maps the terrain so that organizations, developers and later standards can reason about it with common terminology. This is characteristic of a Technical Report published early in a standardization programme — its function was to establish shared understanding for the AI standards that followed.

Where it sits in the AI standards landscape. ISO/IEC TR 24028 predates and informed ISO/IEC 42001, the AI management system standard, which is the certifiable document in this family, and ISO/IEC 23894, which gives guidance on AI risk management. Organizations building an AI governance programme typically use ISO/IEC 42001 for the management system, ISO/IEC 23894 for risk management method, and ISO/IEC TR 24028 as background for reasoning about what trustworthiness means for a specific system. ISO/IEC 27001 and ISO/IEC 27701 remain relevant for the information security and privacy dimensions.

Certification. Technical Reports are not certifiable and ISO/IEC TR 24028 is no exception. It can be used by any organization regardless of size or sector as a reference document, and is frequently cited in AI assurance and regulatory literature, but organizations seeking certification in this area certify against ISO/IEC 42001.

Purpose

To provide an overview of the factors affecting trustworthiness in artificial intelligence systems, surveying the concepts, threats, engineering pitfalls and available approaches for establishing and assessing trust.

Key Benefits

  • Common vocabulary and conceptual map for AI trustworthiness discussions
  • Survey of AI-specific threats, vulnerabilities and mitigation approaches
  • Coverage of transparency, explainability and controllability concepts
  • Useful background for implementing ISO/IEC 42001 and ISO/IEC 23894
  • Applicable to any organization regardless of size or sector
  • Frequently referenced in AI assurance and regulatory discussions

Key Requirements

  • Note: as a Technical Report this document contains no auditable requirements; the topics it covers include:
  • Concepts and terminology of trustworthiness in AI
  • Approaches to transparency, explainability and controllability
  • Identification of AI-specific threats, risks and vulnerabilities
  • Engineering pitfalls in AI system development and available mitigations
  • Approaches to availability, resiliency, reliability and accuracy
  • Approaches to safety, security and privacy of AI systems
  • Considerations for assessing trustworthiness of an AI system

Who Needs This Standard?

AI and machine learning engineers, AI governance and risk teams, information security and privacy professionals extending their scope to AI, regulators and policy teams, and organizations preparing to implement ISO/IEC 42001 who need conceptual grounding first.

Where to get ISO 24028

The full text of ISO 24028 is copyrighted and is sold by ISO and its national member bodies — buy the official edition on iso.org, or order the same document from your national standards body, often at a member price. Sites offering a free PDF of the complete standard are not authorised to distribute it, and the files circulating there are frequently superseded editions, partial scans or altered copies, with no way to tell which. What is legitimately free is the standard's page on iso.org: the abstract, the current edition and status, the table of contents, and a preview of the opening sections. This page summarises the scope and requirements of ISO 24028 in our own words; it does not reproduce the standard's text and is not a substitute for the published document.

Get our free implementation resources

Our AI Risk Assessment Workbook is a set of blank, printable templates for running an AI risk process: an AI system inventory, a risk register with worked example rows, a likelihood and impact scoring matrix, a treatment plan and a monitoring log. Free, no account needed.

We'll only email you about this standard. Unsubscribe anytime.

Looking to get certified?

You cannot be certified to ISO 24028 — it is guidance, and no accredited scheme exists for it. The closest standards you can certify against are ISO 42001 (Artificial Intelligence Management Systems), ISO 27001 (Information Security Management Systems) and ISO 27701 (Privacy Information Management Systems).

If that is the direction you are heading, tell us what stage you are at and we will put you in touch with people who work with them. Free and no obligation.

Get help with certification

In a hurry? You can also compare quotes from verified providers on CertBetter (affiliate link — we earn a commission, and it stays free for you).

Related Standards