ISO/IEC TR 24028:2020 is a technical report that provides a foundational overview of trustworthiness in artificial intelligence (AI) systems. It offers definitions and a conceptual framework to help organizations understand how AI systems can be made secure, reliable, and accountable throughout their lifecycle.

This standard guides policymakers, developers, auditors, and organizational leaders in recognizing the critical attributes of trustworthy AI, including transparency and ethics.
With AI being deployed across sensitive and high-impact domains such as healthcare and public administration, ISO/IEC TR 24028 is increasingly becoming a reference framework for aligning AI development with safety, security and societal expectations.
Looking to integrate trustworthy AI principles into your ISO/IEC 27001 or ISO/IEC 42001 management system? Contact support@demo.pacificcert.com.
ISO/IEC TR 24028 provides guidance on defining and assessing trustworthiness attributes of AI systems by identifying associated risks and dependencies across the AI lifecycle. The standard applies to a wide range of stakeholders, including AI system developers, IT risk managers, auditors, regulatory bodies, and system integrators. It is particularly useful in domains where the use of AI must be auditable and compliant with legal and ethical standards.
This technical report supports integration into Information Security Management Systems (ISMS) and emerging AI Management Systems (AIMS) such as ISO/IEC 42001.
This technical report is structured around a multi-dimensional view of trustworthiness. It categorizes trust-related concerns into key areas:
Trustworthiness Dimension | Attributes Covered | AI-Specific Focus |
Security | Cybersecurity, access control, data integrity | AI-specific threat models, adversarial attacks |
Privacy | Data minimization, user consent, anonymization | AI training data, user profiling, facial recognition |
Safety | Risk of physical or psychological harm | Autonomous systems (e.g., drones, vehicles, robotic surgery) |
Reliability & Robustness | Performance consistency under varying or unexpected conditions | Model degradation, black-box behaviors, model drift |
Transparency & Explainability | Clarity of inputs, outputs, decision logic | Explainable AI (XAI), audit trails, traceability |
Accountability & Ethics | Compliance with legal norms, ethical alignment | Bias detection, fairness auditing, human oversight |
These dimensions form the foundation of AI risk assessment and governance strategies.
The standard encourages organizations to:
These considerations align closely with Annex A controls in ISO/IEC 27001 and emerging clauses in ISO/IEC 42001.Want to integrate these principles into your ISMS or AI governance system? Contact support@demo.pacificcert.com.
Organizations referencing ISO/IEC TR 24028 in audits or internal governance should document:

Want audit-focused documentation support aligned with ISO/IEC 27001 or ISO/IEC 42001? Email support@demo.pacificcert.com.

Trustworthiness has become a critical pillar of AI deployment across sectors. With increasing regulatory developments, including the EU Artificial Intelligence Act, OECD AI Principles, and U.S. Executive Orders on AI governance, organizations are expected to document, audit, and govern AI behavior rigorously.
ISO/IEC TR 24028 is increasingly cited by policymakers, technical working groups, and ethics committees as the baseline for defining trustworthy AI. Companies developing high-risk AI systems (medical diagnostics, financial scoring, autonomous vehicles) are aligning this technical report with ISO/IEC 27001, ISO/IEC 42001, and ISO/IEC 27701 to demonstrate security, privacy and ethical readiness.
Furthermore, trust metrics are being embedded into AI procurement processes, insurance assessments, and investor risk evaluations. Organizations that adopt ISO/IEC TR 24028 principles position themselves as responsible and resilient AI leaders in an increasingly regulated digital world.
Want to align your AI practices with global trust and security standards? Contact support@demo.pacificcert.com.
As a certification body, Pacific Certifications offers accredited audit and certification services for:
To integrate ISO/IEC TR 24028 guidance into your certified systems, contact support@demo.pacificcert.com.
It is a technical report offering guidance and definitions, not a certifiable management system.
It provides AI-specific trustworthiness attributes that can be applied to ISMS risk treatment plans and controls.
Healthcare, finance, government, mobility, defense, and any industry deploying high-impact AI systems.
Yes. It aligns with legal and ethical frameworks for AI governance and supports documentation required under GDPR, AI Act, and others.
No. But we assess its alignment as part of our ISO/IEC 27001 and ISO/IEC 42001 certification audits.
Contact Pacific Certifications to begin your certification journey today!
Suggested Certifications –
Read more: Pacific Blogs

Get a rough Estimate for your Required Certification by entering your basic details.
This will close in 0 seconds
Get in touch!
This will close in 0 seconds