Overview
ISO/IEC 25389:2025 - Information technology - The Safe Framework - defines a flexible, practical framework of recommendations for organizations that operate public-facing digital products or services and run trust and safety operations. The standard focuses on managing content- and conduct-related risks and provides guidance both for designing responsible practices and for assessing how well those practices are implemented. It is intended for internal use by organizations and emphasizes adaptable, product-specific approaches rather than a one-size-fits-all mandate.
Key Topics
- Core commitments: structured recommendations across five commitment areas - product development, product governance, product enforcement, product improvement, and product transparency.
- Terminology and scope: clear definitions for terms such as content, conduct, product governance, risk, and trust and safety, enabling consistent implementation.
- Assessment framework: a modular approach covering scoping, tailoring, and assessment execution. Tailoring includes methodology for:
- Evaluating organization size and scale (e.g., monthly active registered users)
- Assessing product or service impact
- Determining an initial recommended assessment level (L1/L2/L3)
- Factoring additional business landscape considerations
- Assessment lifecycle: recommended execution phases - Discover, Identify, Assess, Test, and Report - with guidance on assessment methodology and evidence collection.
- Supporting materials: informative annexes such as tailoring examples, a risk profile questionnaire, differences between L1/L2/L3 assessments, a question bank, and sample reporting templates.
Applications
Who uses ISO/IEC 25389:2025 and why:
- Trust & Safety teams: to design safety-by-design features, governance policies, and enforcement workflows aligned with industry best practices.
- Product managers and engineers: to integrate content-risk mitigations into product development and lifecycle planning.
- Compliance officers and internal auditors: to assess maturity of trust-and-safety operations and prepare for third-party reviews.
- External assessors: to apply the standard’s assessment framework (scoping, tailoring, testing, reporting) when evaluating platforms.
Practical uses include mapping existing policies to the framework, running maturity assessments, prioritizing controls against content- and conduct-related risk, and improving transparency and governance processes.
Related Standards
- ISO/IEC TS 5928 (digital service definitions)
- ISO 31073:2022 (risk terminology)
- ISO/IEC 27000:2018 (information security terms)
- ISO 32110:2023 (terms of service)
- ISO/IEC TS 5723 and ISO/IEC Guide 51 (trustworthiness and safety definitions)
These related standards help align risk, security, and governance concepts when implementing ISO/IEC 25389:2025.