Skip to main content
Category: Data Governance & Quality

Data Quality (ISO/IEC 5259)

Also known as: ISO/IEC 5259 series, Data quality for analytics and machine learning
Simply put

ISO/IEC 5259 is a multi-part international standard series that sets out tools and methods for assessing and improving the quality of data used for analytics and machine learning. It defines what "good" data looks like through measurable characteristics and provides guidance on how organizations can oversee and report on data quality. As an ISO/IEC standard, it is a voluntary framework rather than a law, though organizations may adopt it to support their AI and data practices.

Formal definition

The ISO/IEC 5259 series, published by ISO and IEC, addresses data quality in the context of analytics and machine learning. Part 1 (ISO/IEC 5259-1:2024) serves as the foundational document for the series, whose stated aim is to provide tools and methods to assess and improve the quality of data used for analytics and ML. Part 2 (ISO/IEC 5259-2:2024) specifies a data quality model, a set of measurable data quality characteristics/measures, and guidance on reporting data quality. Part 5 (ISO/IEC 5259-5:2025) provides a governance framework to help organizations oversee and direct data quality for analytics and ML. Note that data quality as scoped here concerns the fitness of data for analytics and ML use; it should not be conflated with broader AI governance (ISO/IEC 42001 addresses AI management systems) or with model risk management practices such as validation and performance monitoring, which operate on models rather than on the underlying data. The specific technical content of individual parts beyond the scoping statements provided is not detailed in the available evidence.

Why it matters

Data quality directly conditions the reliability of analytics and machine learning outputs, yet organizations frequently lack a shared vocabulary for describing what "good" data looks like or how to measure it. The ISO/IEC 5259 series addresses this gap by offering a voluntary, internationally recognized set of tools and methods to assess and improve the quality of data used for analytics and ML. Adopting a common data quality model and measurable characteristics can help teams communicate consistently across data engineering, analytics, and oversight functions, and can support more defensible reporting on the state of the data feeding AI systems.

The series matters because data quality problems are often the upstream source of downstream model issues, but the two should not be conflated. Poor fitness of data for its intended use is a distinct concern from model performance degradation or the validation of a model itself. ISO/IEC 5259 operates on the data, providing a structured way to characterize and report its quality; it does not, on its own, validate models or monitor their behavior in production. Treating data quality assessment as a substitute for model risk management practices would misapply the standard.

It is equally important to scope ISO/IEC 5259 correctly relative to broader AI governance. The data quality governance framework in Part 5 helps organizations oversee and direct data quality specifically, and should not be treated as a general-purpose AI management system standard; ISO/IEC 42001 addresses AI management systems and covers different ground. Because ISO/IEC 5259 is a voluntary international standard rather than binding law, its adoption reflects an organizational choice to support data and AI practices rather than a legal requirement, and the specific technical content of individual parts beyond their stated scope is not detailed in the evidence available here.

Who it's relevant to

Data scientists and ML engineers
Practitioners building and maintaining analytics and ML pipelines can use the series' data quality model and measurable characteristics to assess whether data is fit for its intended use and to report on that quality consistently. This concerns the data feeding models, and is distinct from validating or monitoring the models themselves.
Data governance and stewardship teams
Those responsible for overseeing and directing data quality can draw on the governance framework in Part 5 to structure their oversight of data used for analytics and ML. Its scope is data quality specifically, and it should not be treated as a substitute for a broader AI management system standard such as ISO/IEC 42001.
Model risk managers and validators
Data quality is often an upstream contributor to model issues, so understanding how data fitness is characterized under ISO/IEC 5259 can inform risk assessments. However, the standard operates on data rather than models and does not perform validation or performance monitoring, which remain separate model risk management activities.
Auditors and compliance professionals
Because ISO/IEC 5259 is a voluntary international standard rather than binding law, professionals evaluating an organization's data practices can reference it as an adopted framework where the organization has chosen to apply it, while being careful not to present its adoption as a legal requirement.

Inside Data Quality (ISO/IEC 5259)

Data quality dimensions
ISO/IEC 5259 is commonly understood to address characteristics used to assess data suitability, such as accuracy, completeness, consistency, and currency, framed specifically for analytics and machine learning contexts. The precise set and definitions of dimensions should be confirmed against the standard text rather than assumed to match other data quality frameworks.
Data quality management for ML
The standard is oriented toward managing data quality across the machine learning and analytics lifecycle, rather than treating data quality as a one-time or purely operational-database concern. This lifecycle framing distinguishes it from general enterprise data quality practices, though the two overlap.
Measurement and metrics guidance
It typically concerns how data quality can be measured and reported, supporting repeatable assessment. The specific metrics, formulas, or thresholds are a matter for the standard's own provisions and should not be inferred without reference to the text.
Governance and process elements
As a management-oriented standard, it addresses processes and controls for governing data quality. This connects to AI governance (organizational accountability and oversight) but is distinct from model risk management, which addresses risks arising from model use rather than data quality processes as such.
Voluntary standard status
ISO/IEC standards are issued by ISO and IEC as voluntary consensus standards, not binding law. Conformance is elective unless incorporated by reference into a contract, regulation, or internal policy. It is not a regulatory instrument in the sense that the EU AI Act is, nor supervisory guidance in the sense of SR 11-7.

Common questions

Answers to the questions practitioners most commonly ask about Data Quality (ISO/IEC 5259).

Is ISO/IEC 5259 a legally binding regulation that organizations must comply with?
No. ISO/IEC 5259 is a voluntary international standard developed under ISO/IEC, not a law or regulator-issued mandate. Conformance is elective unless a contract, procurement requirement, or a separate binding legal instrument specifically incorporates it. It should not be treated as equivalent to statutory requirements such as those found in binding legislation, nor as regulatory guidance issued by a supervisory authority.
Does meeting a data quality standard guarantee that a model will perform well or be free of bias?
No. Data quality practices are intended to reduce and manage certain data-related risks, not to eliminate them or to guarantee model outcomes. High data quality does not by itself ensure strong model performance, and it is distinct from fairness and bias considerations, which involve additional analysis beyond data quality dimensions. Data that meets quality criteria can still encode historical patterns that raise fairness concerns, so data quality should be treated as one input among several rather than a proxy for model soundness.
How does a data quality framework typically relate to an organization's existing model risk management activities?
Data quality work commonly feeds into, but does not replace, model risk management. In many frameworks, the assessment and control of input data quality supports model development and validation activities, since data weaknesses can be a source of model risk. Organizations typically position data quality controls as one component of a broader control environment rather than as a substitute for independent validation, monitoring, or governance oversight. The precise integration depends on the organization's chosen framework and, where applicable, sector-specific expectations.
Which roles or lines of defense usually take responsibility for data quality?
Responsibility is typically distributed rather than assigned to a single function. Data producers and model developers, often described as a first line of defense, commonly own day-to-day data quality within their processes. A second line, such as risk or compliance functions, may set standards and provide oversight, while independent assurance functions may review adherence. The specific allocation depends on the organization's operating model, and the standard itself does not dictate a universal assignment of these responsibilities.
What data quality dimensions are commonly considered when applying such a framework?
Data quality is generally treated as multidimensional, and frameworks in this area typically address characteristics that can be assessed and measured across the data lifecycle. Rather than a single pass/fail measure, organizations commonly define which dimensions are relevant to their use case and set expectations accordingly. Because the relevant dimensions and their relative importance vary by context and intended use, professionals should scope them to the specific model or application rather than assume a fixed universal set.
How should data quality be monitored over time rather than assessed only once?
Data quality is generally treated as a lifecycle concern rather than a one-time checkpoint, because data sources, distributions, and collection processes can change after initial assessment. In many implementations, organizations establish ongoing monitoring so that emerging data issues can be detected and addressed. This monitoring is conceptually distinct from monitoring model performance degradation, though the two can be related, and the appropriate cadence and methods depend on the organization's context and risk appetite.

Common misconceptions

ISO/IEC 5259 is a legal requirement organizations must comply with.
As an ISO/IEC standard it is, as commonly understood, a voluntary consensus standard rather than binding law. It becomes obligatory only where a contract, internal policy, or a jurisdiction's regulation specifically requires adherence; it does not by itself impose legal duties.
Meeting ISO/IEC 5259 data quality dimensions eliminates model risk or guarantees model performance.
Improving data quality can reduce certain sources of risk, but it does not eliminate model risk and is not the same as model performance. Data quality is one input; models can still degrade, be misapplied, or produce biased outcomes despite high-quality data, which is why model risk management addresses risks arising from model use separately.
ISO/IEC 5259 is interchangeable with frameworks like the NIST AI RMF, ISO/IEC 42001, or SR 11-7.
These instruments differ in scope, issuing body, and status. ISO/IEC 5259 focuses on data quality for analytics and machine learning; ISO/IEC 42001 concerns AI management systems; the NIST AI RMF is a voluntary U.S. framework; and SR 11-7 is U.S. supervisory guidance on model risk management. They are not substitutes for one another.

Best practices

Consult the actual text of ISO/IEC 5259 to confirm its specific dimensions, definitions, and measurement provisions before designing controls, rather than importing assumptions from other data quality frameworks.
Treat data quality assessment as a lifecycle activity across data collection, preparation, training, and monitoring, not as a one-time gate at ingestion.
Position data quality controls within your broader AI governance structure while keeping them distinct from model risk management activities, so that data quality, model validation, and ongoing monitoring each have clear ownership.
Clarify internally whether conformance with ISO/IEC 5259 is voluntary or contractually or policy-mandated in your context, and document that basis before asserting compliance obligations.
Define measurable, repeatable data quality metrics with recorded thresholds and assessment procedures so that quality claims can be audited and reproduced.
Avoid overstating the effect of data quality controls; describe them as measures that reduce specific risks, and pair them with monitoring for model performance degradation and fairness that data quality alone does not address.