The guidance layer — why these documents are not certifiable
Lesson 1 of 5 in Trustworthiness, Bias, and AI Quality: The TR Series and 25059.
You already know from the standards-landscape module that ISO documents come in grades: an International Standard carries normative shall statements you can be audited against; a Technical Report carries no requirements at all. This module lives almost entirely in that second, informative world — and understanding why is the key to using it well.
Trustworthiness is where AI standardisation started, not where it finished. When SC 42 convened in 2018, nobody could yet write auditable requirements for "unbiased" or "explainable" — the science was (and largely still is) unsettled, the metrics conflict with each other, and what counts as acceptable depends on context. So WG 3 did what standards bodies do when a field is too young for shall: it published surveys of the state of the art. TR 24028 mapped trustworthiness. TR 24027 mapped bias. TR 24368 mapped ethical and societal concerns. Each says, in effect: here is the vocabulary, here is the threat and failure catalogue, here is what mitigation currently looks like — now go make your own justified choices.
One document in this module breaks the pattern: ISO/IEC 25059:2023 is a full International Standard, because it does something more tractable — it extends an existing, mature quality model (ISO/IEC 25010, the SQuaRE family) with AI-specific characteristics. Defining what quality characteristics exist is standardisable; decreeing how fair is fair enough is not.
| Document | Title | Type & year | Question it answers | Feeds into the AIMS as… |
|---|---|---|---|---|
ISO/IEC TR 24028 | Overview of trustworthiness in AI | Technical Report, 2020 | What makes an AI system worthy of trust, and what threatens each attribute? | Risk sources for clause 6 risk assessment; mitigation options for risk treatment |
ISO/IEC TR 24027 | Bias in AI systems and AI-aided decision making | Technical Report, 2021 | Where does bias enter, how is it measured, how is it treated? | Data controls (A.7) and lifecycle V&V controls (A.6); fairness metrics for clause 9 monitoring |
ISO/IEC TR 24368 | Overview of ethical and societal concerns | Technical Report, 2022 | Which ethical themes should governance address, and how do they become process? | Value commitments behind the AI policy (clause 5.2) and Annex C objectives |
ISO/IEC 25059 | Quality model for AI systems | International Standard, 2023 | Which quality characteristics must AI systems be specified and evaluated against? | Requirement and acceptance-criteria structure for A.6 lifecycle controls |
Around the four core documents sits a supporting ring of measurement standards — the pieces that turn qualitative attributes into numbers: ISO/IEC TS 4213 for assessing ML classification performance, the ISO/IEC 24029 series for robustness of neural networks (including formal methods in Part 2), and the ISO/IEC 5259 series (Parts 1–5) for data quality in analytics and ML, now also adopted in Europe as EN standards. When clause 9.1 of 42001 asks what will you measure, how, and with what methods that ensure valid results — these are the methods.
Hold this architecture in your head for the rest of the module: TRs name the problems, 25059 names the qualities, the TS/measurement series name the numbers, and 42001 makes somebody accountable for all of it.
Key terms: technical report, normative vs informative, trustworthiness, SQuaRE series, AI management system
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.