At a glance
Where II.A–II.C are about binding law, this competency is about voluntary standards and tools — the soft-law scaffolding organisations use to operationalise governance and to demonstrate due diligence. Three bodies of work:
- OECD — the foundational principles and the AI-system definition the world borrowed (II.D.1)
- NIST AI RMF — the Govern/Map/Measure/Manage operating model plus its Playbook (II.D.2)
- Core ISO/IEC standards — 22989 (terminology), 42001 (management system), 42005 (impact assessment) (II.D.3)
These are non-binding, but they inform regulators, contracts and audits — and ISO/IEC 42001 is certifiable.
II.D.1 — OECD principles, framework and definition
The OECD AI Principles (2019, updated 2024) are the most widely adopted, values-based statement of trustworthy AI — endorsed by dozens of countries and echoed by the G20. The five values-based principles:
- Inclusive growth, sustainable development and well-being
- Human-centred values and fairness (rule of law, human rights, autonomy)
- Transparency and explainability
- Robustness, security and safety
- Accountability
They are paired with recommendations to policymakers (e.g., investment in R&D, an enabling ecosystem, building human capacity, international cooperation).
Crucially, the OECD authored the definition of an AI system that the EU AI Act adopted almost verbatim — a machine-based system that infers from input how to generate outputs (predictions, content, recommendations, decisions), with varying autonomy and adaptiveness.
The OECD Framework for the Classification of AI Systems is the OECD’s practical companion tool: it profiles any AI system along five dimensions — people & planet (who is affected), economic context (sector, function), data & input, AI model (technique, transparency), and task & output — so policymakers and organisations can describe a system consistently before judging its risk. Think of it as the structured “describe the system” step that precedes classification decisions like the EU AI Act’s tiers.
II.D.2 — NIST AI Risk Management Framework
The NIST AI RMF 1.0 (2023) is a voluntary framework for managing AI risk, designed to be rights-preserving and sector-agnostic. Two parts to know.
Four core functions:
| Function | Purpose |
|---|---|
| Govern | Cross-cutting. Cultivate a culture of risk management — policies, accountability, roles, processes. Underpins the other three. |
| Map | Establish context and frame risk — use case, stakeholders, where harms could arise. |
| Measure | Analyse, assess, benchmark and monitor risks (quantitative + qualitative). |
| Manage | Prioritise and act on risks — mitigate, transfer, avoid or accept; allocate resources. |
Each function breaks into categories and subcategories, and the AI RMF Playbook offers suggested (voluntary) actions, references and documentation for each subcategory. A companion Generative AI Profile extends the RMF to GenAI risks.
Characteristics of trustworthy AI (the qualities the RMF aims to produce): valid & reliable (the foundation), safe, secure & resilient, accountable & transparent, explainable & interpretable, privacy-enhanced, and fair – with harmful bias managed.
II.D.3 — Core ISO/IEC AI standards
The BOK names three. Keep their distinct jobs straight:
| Standard | What it does | Analogy / note |
|---|---|---|
| ISO/IEC 22989 | Terminology and concepts — the foundational vocabulary (AI system, ML, life-cycle stages) | The dictionary the others build on |
| ISO/IEC 42001 | AI management system (AIMS) — a certifiable Plan-Do-Check-Act management standard to govern AI organisation-wide | The “ISO 27001 for AI” — the one you can be certified against |
| ISO/IEC 42005 | AI system impact assessment — guidance to conduct and document impact assessments across the life cycle | The “how-to” for the impact assessments the AI Act/GDPR demand |
Adjacent instruments to recognise on sight (one line each — distractor material more than deep content):
- ISO 31000 — the general (non-AI-specific) risk-management guidelines that AI risk frameworks build on.
- IEEE 7000 — a process standard for addressing ethical concerns during system design (value-based engineering).
- HUDERIA / HUDERAF — the Council of Europe’s human-rights, democracy and rule-of-law risk-and-impact assessment methodology accompanying its Framework Convention.
- Asilomar AI Principles (2017) — an influential early set of 23 research-community principles (safety, failure transparency, judicial transparency, human control, personal privacy, shared benefit…). Soft ethics guidance, not law — but principle names appear as answer options.
- NIST ARIA — NIST’s Assessing Risks and Impacts of AI program: evaluation environments for testing how AI systems behave in realistic societal contexts (complements the AI RMF).
- Blueprint for an AI Bill of Rights (US, 2022) and the Singapore Model AI Governance Framework — non-binding national guidance documents; classic “which of these is actually binding?” distractors (answer: none of them — the EU AI Act is the binding one in such lists).
How this shows up later
- NIST’s Govern/Map/Measure/Manage is the operating model behind the lifecycle governance you build in Domains III–IV (mapping use cases, measuring with metrics, managing risk).
- ISO/IEC 42001 is the management-system spine for the policies and accountability structures from Domain I; 42005 and the DPIA/FRIA are the same impact-assessment muscle exercised across II.A, II.C and Domains III–IV.
- The OECD definition and principles tie back to I.A (definitions, responsible-AI principles) and forward into every legal regime that borrowed them.