Skip to main content
Category: Fairness & Bias

Bias Assessment and Mitigation (ISO/IEC TR 24027)

Also known as: ISO/IEC TR 24027, ISO/IEC TR 24027:2021, Bias in AI systems and AI aided decision-making
Simply put

ISO/IEC TR 24027 is a technical report from ISO and IEC that describes ways to detect, measure, and reduce unwanted bias in AI systems and in decisions those systems help make. It sets out practices intended to be applied across the stages of an AI system's life, rather than a one-time check. As a technical report it offers guidance and methods rather than binding requirements or a certifiable specification.

Formal definition

ISO/IEC TR 24027:2021 is a technical report, jointly published by ISO and IEC, that articulates practices for identifying, measuring, and treating bias in AI systems and AI-aided decision-making, regardless of the bias source. Per the evidence, it describes measurement techniques and methods for assessing bias with the aim of addressing bias-related vulnerabilities, and applies across the AI system lifecycle. Practitioners should note that, as a technical report (TR), it functions as informative guidance and is not itself a requirements standard against which conformity is certified; related normative or specification work such as ISO/IEC TS 12791:2024 builds on it to describe steps for treating unwanted bias. The evidence does not detail the specific metrics, thresholds, or the relationship this document draws between bias and fairness, which are distinct concepts that should not be conflated; consult the standard text directly for those particulars.

Why it matters

Unwanted bias in AI systems can produce outcomes that disadvantage particular groups or individuals, and it can arise from data, model design, or the way systems are used in decision-making. ISO/IEC TR 24027 matters because it offers a structured vocabulary and set of practices for detecting, measuring, and treating such bias, giving organizations a common reference point rather than ad hoc approaches. For teams building governance programs, having an established technical report to cite can support internal consistency and communication with auditors, regulators, and other stakeholders.

Because the document advocates a holistic, lifecycle-based approach, it reinforces the idea that bias is not something addressed once at deployment but managed across development, use, and ongoing operation. This framing aligns with broader model risk management thinking, where risks are identified, measured, monitored, and controlled on a continuing basis rather than certified as resolved. Organizations that treat bias assessment as a one-time exercise may miss bias that emerges as data, populations, or use contexts change.

It is important to be clear about what this document is and is not. As a technical report, ISO/IEC TR 24027 provides informative guidance and methods; it is not a requirements standard against which an organization can be certified, and adopting it does not by itself demonstrate legal compliance with any particular jurisdiction's law. It also should not be read as guaranteeing that bias has been eliminated. The evidence digest does not specify particular metrics, thresholds, or how the document treats the distinction between bias and fairness, which are related but distinct concepts; practitioners should consult the standard text directly for those details.

Who it's relevant to

Data scientists and ML engineers
Those building and maintaining AI systems can use the report's described measurement techniques and methods as a reference for detecting and assessing bias during development and operation. Because the document takes a lifecycle view, it is relevant not only at model build time but also to monitoring after deployment. The specific metrics and procedures are not detailed in the evidence digest, so practitioners should consult the standard directly.
Model risk and AI governance teams
Second-line risk and governance functions may cite ISO/IEC TR 24027 as a common reference when defining internal practices for identifying and treating bias. It can help structure how bias is measured and monitored over the lifecycle, though as a technical report it provides guidance rather than binding requirements, and it does not by itself satisfy any jurisdiction's legal obligations.
Auditors and independent reviewers
Reviewers assessing an AI system's bias controls may find the report useful as a benchmark for expected practices. However, because it is a technical report and not a certifiable specification, it cannot serve as a conformity standard against which certification is issued; reviewers should treat it as informative guidance and note this distinction in their findings.
Compliance and policy specialists
Those mapping organizational controls to external frameworks can position ISO/IEC TR 24027 as one input among others, while being careful not to present adoption of the report as evidence of legal compliance. Its scope covers bias in AI systems and AI-aided decision-making; the evidence digest does not indicate how it treats the bias-versus-fairness distinction, which should be handled explicitly in any policy language.

Inside Bias Assessment and Mitigation (ISO/IEC TR 24027)

Scope as a technical report (TR)
ISO/IEC TR 24027 is published as a technical report rather than a certifiable management system standard. Technical reports in the ISO/IEC catalogue typically provide informative guidance and discussion of the state of the art rather than auditable requirements, so it is generally used as a reference resource rather than a basis for conformity assessment.
Sources of bias across the AI lifecycle
The report commonly addresses where bias can enter AI systems, including data collection and sampling, feature selection and labeling, model design and training, and deployment and use contexts. This reflects the view that bias is not confined to a single stage.
Categories of bias
It discusses distinctions among types of bias frequently drawn in the literature, such as data-related bias, algorithmic or model-related bias, and human cognitive or societal bias that can be introduced through design and interpretation choices.
Assessment considerations
Guidance on how bias may be identified and measured, including consideration of relevant metrics and evaluation approaches. Specific metrics are context-dependent, and the report generally frames measurement as a matter of selecting approaches appropriate to the system and use case rather than prescribing one universal metric.
Mitigation considerations
Discussion of measures that can be applied to reduce or manage bias. These are described as risk-reducing measures rather than techniques that eliminate bias, and appropriate mitigation typically depends on the identified source and the deployment context.
Relationship to bias, not fairness definitions
The report concerns bias in AI systems. Bias (a systematic difference or skew) and fairness (a normative judgment about acceptable treatment or outcomes) are related but distinct; the report addresses bias rather than resolving contested fairness definitions.

Common questions

Answers to the questions practitioners most commonly ask about Bias Assessment and Mitigation (ISO/IEC TR 24027).

Does bias assessment under ISO/IEC TR 24027 measure the same thing as fairness?
No, and conflating the two is a common error. Bias, as commonly framed in this technical report, refers to systematic differences or skew in data, model behavior, or outcomes, and can be described and measured with technical metrics. Fairness is a broader, often normative and context-dependent judgment about whether outcomes are acceptable or just, which typically depends on legal, ethical, and stakeholder considerations that sit outside a purely technical measurement. Assessing bias can inform a fairness evaluation, but reducing measured bias does not automatically establish that a system is fair.
Is ISO/IEC TR 24027 a certifiable requirement or a binding standard I must comply with?
As a technical report (TR), it is generally informative rather than a specification containing certifiable requirements, and it is a voluntary international standard rather than binding law in any jurisdiction. It provides concepts, terminology, and approaches for assessing and treating bias, but on its own it typically does not impose auditable 'shall' requirements. Professionals should not treat it as equivalent to a regulatory mandate, and its use does not, by itself, demonstrate legal compliance with any applicable jurisdiction's obligations.
At what points in the AI lifecycle should bias assessment be applied?
Bias can enter at multiple stages, so assessment is commonly applied across the lifecycle rather than at a single checkpoint. This typically includes examining data sources and collection, feature and label definition, model training and selection, and outputs in deployment. Because bias sources differ by stage, the assessment techniques appropriate at each point often differ as well. Treating bias assessment as a one-time, pre-deployment activity is a frequent pitfall, since data drift and changing usage contexts can introduce or amplify bias over time.
What kinds of bias sources are distinguished when performing an assessment?
Assessments commonly distinguish among sources such as bias arising in the data (for example, unrepresentative sampling or historical patterns encoded in the data), bias introduced through the modeling or engineering process, and bias emerging from how a system is used or interpreted in its deployment context. Distinguishing the source matters because the appropriate mitigation differs: a data-sourced skew may call for different treatment than one introduced by algorithmic choices. This entry does not enumerate an exhaustive or authoritative taxonomy, as categorizations vary across frameworks and contexts.
How does bias mitigation relate to ongoing monitoring after deployment?
Mitigation is not typically a terminal step. Because a model's inputs and operating environment can change, bias metrics observed at validation may not hold in production, which connects bias mitigation to ongoing monitoring practices. In many programs, monitoring for shifts in inputs and outcomes is paired with predefined thresholds and escalation paths so that re-assessment or re-treatment can be triggered. It is important to characterize mitigation as reducing or managing bias-related risk over time rather than eliminating it.
Who is typically accountable for bias assessment, and how does it fit organizational oversight?
Bias assessment is a technical and process activity that usually needs to be embedded within broader governance and oversight structures rather than owned solely by a modeling team. In many organizations, those developing or operating the model perform initial assessment, while independent review functions provide challenge and validation, and governance bodies set policy and accountability. This layering reflects the distinction between the technical work of measuring and treating bias and the organizational responsibility for deciding whether residual bias is acceptable. Specific role assignments vary by organization and sector, and this entry does not prescribe a single accountability model.

Common misconceptions

ISO/IEC TR 24027 is a certifiable standard that organizations can be audited against to demonstrate they are 'unbiased.'
As a technical report, it typically provides informative guidance rather than auditable requirements, and there is generally no certification against a TR. It does not establish a threshold at which a system can be declared free of bias.
Following the report's mitigation guidance eliminates bias from an AI system.
Mitigation measures are best understood as reducing or managing bias, not eliminating it. Residual bias can remain, and appropriate measures depend on the source of bias and the specific use context.
Addressing bias per this guidance is the same as achieving fairness or satisfying legal non-discrimination obligations.
Bias and fairness are distinct: bias refers to systematic skew while fairness is a normative judgment. Reducing measurable bias does not by itself establish fairness, and legal non-discrimination requirements are set by applicable law in a given jurisdiction, not by this technical report.

Best practices

Treat the report as informative reference guidance and, where binding obligations apply, confirm requirements against the applicable law or certifiable standards in your jurisdiction rather than relying on the TR alone.
Assess for bias across the full AI lifecycle—data collection, labeling, model design, training, and deployment—rather than examining a single stage in isolation.
Identify the specific source and category of bias before selecting a mitigation, since appropriate measures differ for data-related, model-related, and human or societal sources.
Select assessment metrics that fit the system and use context, and document why those metrics were chosen rather than assuming a single universal measure applies.
Distinguish bias measurement from fairness judgments in documentation, so that reduced measurable bias is not overstated as demonstrated fairness or legal compliance.
Frame and record mitigations as risk-reducing controls, monitor for residual and emerging bias over time, and avoid representing any system as free of bias.