Overview
ISO/IEC TR 24028:2020 - Information technology - Artificial intelligence - Overview of trustworthiness in artificial intelligence is a technical report from ISO/IEC JTC 1/SC 42 that surveys the landscape of trustworthiness in AI. It analyzes factors that affect trust in AI systems and summarizes approaches for improving transparency, explainability, controllability, safety, security, privacy, reliability and resiliency. The report is descriptive - it surveys methods, threats and mitigation strategies; it does not specify levels of trustworthiness.
Key topics
The report covers high-level and technical aspects relevant to building and assessing trustworthy AI:
- Transparency & explainability: approaches, ex-ante vs ex-post explanations, levels and evaluation of explanations.
- Controllability and human-in-the-loop: control points and governance mechanisms to keep systems aligned with human values.
- Vulnerabilities & threats: AI-specific threats including data poisoning, adversarial attacks, model stealing, hardware threats, and privacy risks.
- Bias, unpredictability and opaqueness: identification and mitigation strategies for fairness and interpretability issues.
- Engineering pitfalls & lifecycle challenges: specification, data acquisition/preprocessing, modelling, model updates, software defects and hardware faults.
- Mitigation measures: bias reduction strategies, privacy-preserving measures, robustness, resilience, functional safety, and hardware-assisted protections.
- Testing & evaluation: validation and verification, robustness testing, privacy considerations and predictability evaluation.
- Stakeholders & governance: types of stakeholders, assets, values, accountability and risk management approaches.
- Related frameworks: application of existing software/data quality standards, risk management practices and hardware-assisted approaches.
Practical applications
ISO/IEC TR 24028:2020 is a practical reference for organizations that need to design, assess or govern AI systems for trustworthy operation:
- AI developers and system architects - to identify engineering risks and mitigation options (robustness, privacy, testing).
- Security and privacy teams - to map AI-specific attack surfaces (adversarial examples, data leakage) and defensive techniques.
- Risk managers and compliance officers - to align AI risk-management practices with established frameworks.
- Product managers and procurement - to define trust-related requirements, labeling and expectations.
- Regulators, auditors and researchers - to understand common trustability concerns and evaluation approaches.
Related standards
The report complements other ISO/IEC work and industry standards on software quality, data quality, risk management and AI governance practices. It provides a survey-level foundation for applying those standards to AI systems.
Keywords: ISO/IEC TR 24028:2020, trustworthiness in AI, AI transparency, explainability, AI safety, adversarial attacks, data poisoning, model stealing, AI robustness, AI privacy, AI governance.