Insights · AI Governance

Responsible AI as a requirement: ISO/IEC 42001, NIST AI RMF and IEEE 7000

Fairness, transparency and accountability are easy to agree on and harder to build. This piece is for heads of AI governance and delivery leads: how ISO/IEC 42001 turns those values into requirements, where NIST AI RMF names them as outcomes, and how IEEE 7000 gives a team the method.

By Reinhardt Mühlhäusser · Published

Written against
ISO/IEC 42001:2023 · NIST AI RMF 1.0 · IEEE 7000-2021
Last updated

Responsible-AI principles are easy to write. The hard part comes next, when a delivery team receives a value like fairness and has no way to act on it. The standards treat ethics as something a system has to meet. ISO/IEC 42001 requires an impact-assessment process and supplies reference controls to implement it. NIST AI RMF names, as an outcome, the integration of trustworthy-AI characteristics into policies and practice. IEEE 7000 adds a method for turning stakeholder values into design requirements. The sections below take each in turn.

01

Responsible AI is a requirement, not a posture

Permalink to “Responsible AI is a requirement, not a posture”

Ethics arrives in both standards as a requirement rather than an aspiration. ISO/IEC 42001 clause 6.1.4 requires a process for assessing the potential consequences of AI systems for individuals, groups of individuals and societies — that one sits in clauses 4 to 10, and an audit tests it. Annex A then supplies the reference controls that implement it: the impact-assessment process and its documentation (A.5.2, A.5.3), and the assessment of impacts on individuals and on society across the lifecycle (A.5.4, A.5.5). Responsible development and responsible use have their own reference controls (A.6.1.2, A.6.1.3 and A.9.2, A.9.3). Whether each belongs in your control set is a Statement of Applicability decision — but excluding all of them while claiming a responsible-AI posture is a position that will not survive an audit.

NIST puts it no more softly. GOVERN 1.2 states the outcome plainly: the seven characteristics of trustworthy AI — valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair, with harmful bias managed — are integrated into organizational policies, processes, procedures and practices. Not published as principles. Integrated.

Nor is the content left to interpretation. ISO/IEC 42001's Annex C is informative rather than binding, but it sets out the objectives the standard has in mind, and points to ISO/IEC 23894 for how each one relates to risk management.

Objectives named in ISO/IEC 42001 Annex C, which states it is not exhaustive
AccountabilityAI expertiseAvailability and quality of training and test dataEnvironmental impactFairnessMaintainabilityPrivacyRobustnessSafetySecurityTransparency and explainability
02

The gap is method, and that is where IEEE 7000 earns its place

Permalink to “The gap is method, and that is where IEEE 7000 earns its place”

A requirement to be fair does not tell a delivery team what to build. That is the gap: an obligation everyone accepts, expressed as a values statement, handed over with no way to act on it. IEEE 7000 closes it by treating ethical values as requirements — elicited from stakeholders, and traced into the design the way a performance or security requirement would be.

It is a technique for satisfying the obligation the standards already create, not a separate obligation and not a certification anyone is asked to hold. Its provenance is largely European, developed out of Vienna and supported by German standards work, which tends to matter where the buyer expects ethics handled with method rather than assertion.

One distinction to keep clean: the value in value-based engineering is ethical, not financial. Conflating the two produces the worst of both — ethics defended only while it is profitable, and business cases padded with sentiment.

A good place to start is your Statement of Applicability. Check which of the impact-assessment and responsible-use controls you included, and why. Then pick one value your organization has committed to, fairness for example, and ask whether a delivery team could test for it today. If the answer is no, IEEE 7000 offers a way to elicit it from stakeholders and trace it into the design. In Valment's approach this runs inside one management system: the same impact assessments, controls and audits that carry everything else, with AI integrated into what the organization already runs.

Get direction and delivery working together.

Tell us what governance exists today and where AI actually runs. We will respond with a read on how the direction and the management system line up, and a sensible first step — often an ISO/IEC 42001 gap analysis.