2.2 Core Trustworthy & Responsible AI Principles

Key Takeaways

  • ISO/IEC 42001 requires an organization to define its own responsible-AI objectives and principles in context; it does not prescribe one universal six-pillar list.

  • Responsible-AI characteristics can conflict, so the AIMS must make and document context-sensitive trade-offs.

  • Transparency means providing appropriate information to relevant parties, not publishing every model detail or proprietary asset.

  • Fairness must be defined for the use case because reasonable metrics can measure different and sometimes incompatible properties.

  • Human oversight patterns are possible controls, not three categories universally mandated by ISO/IEC 42001.

Last updated: October 2026

Responsible AI principles in an AIMS

Responsible AI is not a decorative ethics statement. In ISO/IEC 42001, the organization turns its chosen principles into policy, objectives, risk criteria, lifecycle processes, controls, monitoring, and improvement. The standard does not mandate one fixed list of six principles. Instead, the organization determines objectives and controls appropriate to its purpose, role, context, interested parties, and applicable requirements.

Common characteristics include accountability, transparency, explainability, fairness, privacy, security, safety, robustness, accessibility, and human-centred values. Frameworks such as the OECD AI Principles, applicable laws, sector rules, and organizational values can inform the selection. A Foundation candidate should understand the concepts and how the AIMS operationalizes them, without claiming that one external framework is compulsory everywhere.

Accountability

Accountability means that responsibilities and decision authority are allocated to people and organizational bodies. An AI system is not the accountable management actor. Clause 5 assigns specific leadership actions to top management, while responsibilities can be allocated to system owners, developers, validators, users, risk owners, and suppliers. Accountability is made concrete through those assigned duties and decision rights; do not add a separate Clause 5.1 “accountability for effectiveness” bullet that ISO/IEC 42001 does not contain.

Accountability is supported by:

  • clear roles and escalation paths;
  • documented decisions and approvals;
  • traceability from objectives and risks to controls;
  • mechanisms for reporting concerns and incidents; and
  • review of outcomes and corrective actions.

Accountability is not the same as making one individual legally liable for every outcome. Legal liability depends on jurisdiction and facts. The management-system point is that duties and decision rights cannot be left ambiguous.

Transparency and explainability

Transparency concerns appropriate information about the existence, purpose, capabilities, limitations, operation, and governance of an AI system. Explainability concerns making relevant aspects of outputs or behavior understandable to a target audience.

The information needed by a model developer differs from what an end user, affected person, customer, auditor, or regulator needs. Annex A.6 addresses technical documentation, and A.8 addresses information for users and other interested parties. The organization determines the necessary content, form, and recipients in light of risk, impact, and applicable obligations.

Transparency does not require public release of model weights, source code, confidential security details, or training records in every case. Over-disclosure can itself create privacy, intellectual-property, or security risks. Good governance balances legitimate information needs with protection requirements.

Global explanations describe general model behavior; local explanations address a particular output. Either can be useful, but a technique such as SHAP, LIME, a decision tree, or a counterfactual is an implementation choice, not a universal ISO requirement.

Fairness and non-discrimination

Fairness is contextual. It can involve fair treatment, equitable outcomes, consistent error rates, accessibility, procedural rights, or the avoidance of unjustified discrimination. Metrics capture different ideas:

Metric familyExample question
Demographic parityAre positive outcome rates comparable across groups?
Equal opportunityAre true-positive rates comparable?
Equalized oddsAre both true-positive and false-positive rates comparable?
CalibrationDoes a score mean the same observed likelihood across groups?
Individual fairnessAre relevantly similar cases treated similarly?

These properties can conflict depending on base rates, data quality, model imperfection, and the decision context. The organization should identify the relevant harms, consult applicable requirements and stakeholders, choose justified measures, and document trade-offs. A single threshold such as an “80 percent rule” may be relevant in a particular legal analysis but is not a universal ISO/IEC 42001 fairness requirement.

Removing a protected attribute does not necessarily remove discrimination because other features can act as proxies. Conversely, using sensitive attributes for evaluation may be necessary to detect disparities, subject to privacy and legal constraints.

Privacy, security, safety, and robustness

Privacy concerns lawful and appropriate handling of personal data, including collection, purpose, access, retention, and disclosure. Security protects systems and information against threats such as unauthorized access, data poisoning, model extraction, and prompt injection. Safety addresses unacceptable harm to people, property, or the environment. Robustness concerns reliable behavior under expected variation, errors, and adversarial conditions.

These objectives overlap but are not interchangeable. Encryption can support security but does not prove fairness. High predictive accuracy does not prove privacy. A safe fallback may reduce immediate harm but not correct a discriminatory decision process. The AIMS integrates these objectives through risk and impact assessment rather than treating one metric as proof of responsible AI.

Human agency and oversight

Human oversight can be a treatment where consequences warrant it. Common patterns include:

  • human-in-the-loop: a person reviews or authorizes an output before action;
  • human-on-the-loop: a system acts while a person monitors and can intervene; and
  • human-in-command: people set boundaries and retain strategic control or shutdown authority.

These labels are useful design vocabulary, not three oversight categories prescribed by ISO/IEC 42001. Meaningful oversight depends on competence, time, information, interface design, authority, and escalation. A nominal reviewer who cannot understand or override the output does not provide an effective control. In other contexts, automated checks, strict operating limits, or system redesign can be more effective than inserting a human into every transaction.

Turning principles into the AIMS

A principle becomes operational through a chain:

  1. Clause 4 identifies context and relevant interested-party requirements.
  2. Clause 5 establishes policy and responsibilities.
  3. Clause 6 establishes risk, impact, and objective-setting processes.
  4. Clauses 7 and 8 provide competence, information, and controlled execution.
  5. Clause 9 monitors results and evaluates conformity and effectiveness.
  6. Clause 10 corrects nonconformities and improves the AIMS.

Annex A controls can support this chain when selected. For example, fairness concerns can affect impact assessment, data-quality requirements, verification and validation, user information, monitoring, and concern reporting.

Tip

In exam scenarios, reject answers that promise “zero bias,” require public disclosure of everything, or assume a human click automatically creates accountability. Look for a risk-based, documented, context-sensitive process.

Test Your Knowledge

How does ISO/IEC 42001 treat responsible-AI principles?

A

It mandates exactly six principles with fixed definitions

B

It allows the organization to establish context-appropriate objectives and controls informed by requirements and interested parties

C

It treats principles as optional marketing language outside the AIMS

D

It requires the OECD framework to be adopted verbatim

Test Your Knowledge

Why can selecting a fairness metric require documented judgment?

A

All fairness metrics always give identical results

B

Fairness cannot be evaluated quantitatively

C

Different metrics capture different fairness concepts and can conflict in some contexts

D

Only regulators may measure model outcomes

Test Your Knowledge

Which statement about human oversight is most accurate?

A

Human oversight removes the need for impact assessment

B

A human approval button always makes an AI system responsible

C

Every AI output must receive advance human approval

D

HITL, HOTL, and human-in-command are useful design patterns, but ISO/IEC 42001 does not prescribe all three for every system

Sections you finish are checked off in the contents.