Domain II · Competency II.D

Understand the main industry standards and tools that apply to AI

The voluntary, non-binding scaffolding that complements AI law: the OECD AI Principles and AI-system definition; the NIST AI Risk Management Framework (Govern, Map, Measure, Manage), its Playbook and trustworthiness characteristics; and the core ISO/IEC AI standards — 22989 (terminology), 42001 (AI management system) and 42005 (AI impact assessment).

Exam weight: 3–5 questions

Quick check not attempted yet — take it below to track your score.

Performance indicators

Key terms

OECD AI Principles
The most widely adopted values-based, non-binding AI principles (2019, updated 2024): inclusive growth/well-being, human-centred values & fairness, transparency & explainability, robustness/security/safety, and accountability.
OECD AI-system definition
The internationally referenced definition of an AI system adopted (almost verbatim) by the EU AI Act — a machine-based system that infers from input how to generate outputs, with varying autonomy and adaptiveness.
NIST AI RMF
A voluntary U.S. framework (AI RMF 1.0, 2023) to manage AI risks, organised around four functions — Govern, Map, Measure, Manage.
Govern (NIST)
The cross-cutting NIST function: a culture of risk management — policies, roles, accountability and processes that span the other three functions.
Map (NIST)
NIST function to establish context and frame risks — identify the use case, stakeholders, and where harms could arise.
Measure (NIST)
NIST function to analyse, assess, benchmark and monitor AI risks using quantitative and qualitative methods.
Manage (NIST)
NIST function to prioritise, respond to and treat risks (mitigate, transfer, avoid, accept) on an ongoing basis.
NIST AI RMF Playbook
A companion resource giving suggested, voluntary actions, references and documentation for each function's categories and subcategories.
Trustworthy AI characteristics (NIST)
Valid & reliable (foundational); safe; secure & resilient; accountable & transparent; explainable & interpretable; privacy-enhanced; and fair with harmful bias managed.
ISO/IEC 22989
The foundational ISO/IEC standard for AI concepts and terminology — standard definitions of AI system, ML, life-cycle stages, etc.
ISO/IEC 42001
The certifiable AI management system (AIMS) standard — a Plan-Do-Check-Act management system for AI, analogous to ISO 27001 for security.
ISO/IEC 42005
Guidance for conducting and documenting AI system impact assessments across the life cycle.

At a glance

Where II.A–II.C are about binding law, this competency is about voluntary standards and tools — the soft-law scaffolding organisations use to operationalise governance and to demonstrate due diligence. Three bodies of work:

  1. OECD — the foundational principles and the AI-system definition the world borrowed (II.D.1)
  2. NIST AI RMF — the Govern/Map/Measure/Manage operating model plus its Playbook (II.D.2)
  3. Core ISO/IEC standards — 22989 (terminology), 42001 (management system), 42005 (impact assessment) (II.D.3)

These are non-binding, but they inform regulators, contracts and audits — and ISO/IEC 42001 is certifiable.

II.D.1 — OECD principles, framework and definition

The OECD AI Principles (2019, updated 2024) are the most widely adopted, values-based statement of trustworthy AI — endorsed by dozens of countries and echoed by the G20. The five values-based principles:

  1. Inclusive growth, sustainable development and well-being
  2. Human-centred values and fairness (rule of law, human rights, autonomy)
  3. Transparency and explainability
  4. Robustness, security and safety
  5. Accountability

They are paired with recommendations to policymakers (e.g., investment in R&D, an enabling ecosystem, building human capacity, international cooperation).

Crucially, the OECD authored the definition of an AI system that the EU AI Act adopted almost verbatim — a machine-based system that infers from input how to generate outputs (predictions, content, recommendations, decisions), with varying autonomy and adaptiveness.

The OECD Framework for the Classification of AI Systems is the OECD’s practical companion tool: it profiles any AI system along five dimensions — people & planet (who is affected), economic context (sector, function), data & input, AI model (technique, transparency), and task & output — so policymakers and organisations can describe a system consistently before judging its risk. Think of it as the structured “describe the system” step that precedes classification decisions like the EU AI Act’s tiers.

II.D.2 — NIST AI Risk Management Framework

The NIST AI RMF 1.0 (2023) is a voluntary framework for managing AI risk, designed to be rights-preserving and sector-agnostic. Two parts to know.

Four core functions:

FunctionPurpose
GovernCross-cutting. Cultivate a culture of risk management — policies, accountability, roles, processes. Underpins the other three.
MapEstablish context and frame risk — use case, stakeholders, where harms could arise.
MeasureAnalyse, assess, benchmark and monitor risks (quantitative + qualitative).
ManagePrioritise and act on risks — mitigate, transfer, avoid or accept; allocate resources.

Each function breaks into categories and subcategories, and the AI RMF Playbook offers suggested (voluntary) actions, references and documentation for each subcategory. A companion Generative AI Profile extends the RMF to GenAI risks.

Characteristics of trustworthy AI (the qualities the RMF aims to produce): valid & reliable (the foundation), safe, secure & resilient, accountable & transparent, explainable & interpretable, privacy-enhanced, and fair – with harmful bias managed.

II.D.3 — Core ISO/IEC AI standards

The BOK names three. Keep their distinct jobs straight:

StandardWhat it doesAnalogy / note
ISO/IEC 22989Terminology and concepts — the foundational vocabulary (AI system, ML, life-cycle stages)The dictionary the others build on
ISO/IEC 42001AI management system (AIMS) — a certifiable Plan-Do-Check-Act management standard to govern AI organisation-wideThe “ISO 27001 for AI” — the one you can be certified against
ISO/IEC 42005AI system impact assessment — guidance to conduct and document impact assessments across the life cycleThe “how-to” for the impact assessments the AI Act/GDPR demand

Adjacent instruments to recognise on sight (one line each — distractor material more than deep content):

How this shows up later

Sources

Flashcards

1 / 8

Quick check

Quick check1 / 8 · score 0

Which statement about the OECD AI Principles is correct?

  • AThey are legally binding on all member states.
  • BThey are a widely adopted, non-binding set of values-based principles, and the OECD’s AI-system definition was adopted almost verbatim by the EU AI Act.
  • CThey apply only to generative AI.
  • DThey replace the GDPR.