Skip to main content
Category: Trustworthy AI Principles

Ethical and Societal Considerations (ISO/IEC TR 24368)

Also known as: ISO/IEC TR 24368, ISO/IEC TR 24368:2022, Overview of ethical and societal concerns in AI
Simply put

ISO/IEC TR 24368:2022 is a technical report published by ISO and IEC that gives a high-level overview of the ethical and societal concerns that can arise from artificial intelligence, such as privacy and security breaches, discriminatory outcomes, and effects on human autonomy. It is an informational document rather than a certifiable standard, meaning it is intended to help organizations understand the issues and point them toward related standards, not to impose requirements they can be audited against. It surveys the landscape of AI ethics questions so that readers can consider them in their own governance work.

Formal definition

ISO/IEC TR 24368:2022 is a Technical Report (TR) jointly developed under ISO/IEC, providing a high-level, informational overview of ethical and societal concerns associated with AI systems. Per the evidence, it identifies example concern areas including privacy and security breaches, discriminatory outcomes, and impacts on human autonomy, and it references principles and related International Standards that address AI ethical and societal issues. As a Technical Report, it is a descriptive and orienting document rather than a requirements specification or management system standard; practitioners should not treat it as a certifiable framework or as binding law, and should distinguish it from standards such as ISO/IEC 42001 that establish auditable requirements. Its scope, based on the evidence, is limited to surveying concerns and pointing to other standards; it does not, on the evidence available here, prescribe controls, metrics, or conformity criteria.

Why it matters

AI systems can produce outcomes that raise ethical and societal concerns beyond narrow questions of technical performance, including privacy and security breaches, discriminatory outcomes, and effects on human autonomy. ISO/IEC TR 24368:2022 matters because it offers organizations a structured, high-level survey of these concern areas, helping teams recognize the breadth of issues they may need to address in their governance work before those concerns manifest as harm, reputational damage, or regulatory exposure.

For practitioners, the value of the document lies in orientation rather than obligation. As a Technical Report, it is descriptive and informational; it points readers toward related International Standards and principles rather than establishing requirements they can be certified against. This distinction is significant: organizations that mistake TR 24368 for a certifiable or auditable framework may overstate their compliance posture. It is best understood as a starting map of the AI ethics landscape that helps teams identify which further standards, controls, or governance measures they may need to pursue.

Because the report surveys concerns and references other standards rather than prescribing controls, metrics, or conformity criteria, it complements—but does not substitute for—management system standards such as ISO/IEC 42001, which establish auditable requirements. Treating the two as interchangeable would blur the line between an orienting document and a requirements specification, a distinction that matters when organizations make claims about their governance maturity.

Who it's relevant to

AI Governance and Policy Specialists
Those designing organizational AI governance structures can use TR 24368 as an orienting survey of ethical and societal concern areas—such as privacy, discrimination, and human autonomy—to inform which policies, principles, and further standards to adopt. They should treat it as a landscape overview rather than a source of auditable requirements.
Model Risk Managers
Practitioners identifying risks arising from AI use may draw on the report's enumeration of ethical and societal concerns to broaden their view of potential harms beyond model performance. Note, however, that the report does not prescribe controls or metrics, so it does not by itself provide a framework for measuring or controlling these risks.
Compliance and Audit Professionals
Those assessing an organization's AI governance posture should understand that TR 24368 is a Technical Report and, on the evidence here, is not a certifiable standard. It should not be represented as a basis for conformity claims; standards such as ISO/IEC 42001 serve that role, and the two should not be conflated.
Data Scientists and AI Practitioners
Teams building and deploying AI systems can use the report to become aware of ethical and societal concern areas—privacy and security breaches, discriminatory outcomes, and impacts on human autonomy—that their systems may raise, and to locate related standards that offer more specific guidance.
Legal Professionals
Counsel advising on AI can use the report to survey the range of ethical and societal concerns implicated by AI systems. They should note it is informational guidance rather than binding law, and that it references other standards and principles rather than establishing legal obligations.

Inside ISO/IEC TR 24368

Overview of AI ethical considerations
ISO/IEC TR 24368 is published as a Technical Report by ISO/IEC, providing an overview of ethical and societal concerns associated with artificial intelligence. As a Technical Report, it is informational and descriptive in nature rather than a certifiable management system standard or a binding legal instrument; it does not impose auditable requirements the way a Type 1 standard such as ISO/IEC 42001 does.
Societal impact framing
The document addresses considerations extending beyond a single organization to broader societal effects of AI systems, distinguishing organizational governance choices from the wider social consequences those choices may produce.
Ethical principles and values
It surveys ethical concepts commonly discussed in relation to AI, such as fairness, transparency, accountability, and human oversight, presenting them as considerations to inform decision-making rather than as prescriptive controls with defined pass/fail criteria.
Relationship to other AI guidance
The Technical Report sits alongside, and is complementary to, other instruments in the AI space. It is distinct from voluntary risk frameworks and from certifiable standards, and it does not itself substitute for jurisdiction-specific legal requirements that may apply to a given AI deployment.
Scope as guidance, not obligation
Because it is a Technical Report, its content is intended to raise awareness and orient practitioners to ethical and societal issues. It typically does not, on its own, create enforceable obligations, and adherence is voluntary unless incorporated by reference into a contract, policy, or regulation.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC TR 24368.

Does ISO/IEC TR 24368 set out binding requirements that an organization can be certified against?
No. ISO/IEC TR 24368 is published as a Technical Report (TR), which is typically an informative document that provides an overview and discussion of a subject rather than normative, auditable requirements. As commonly understood, a Technical Report of this type is not a management system standard against which an organization is certified. Professionals sometimes conflate it with ISO/IEC 42001, which is a certifiable AI management system standard; the two serve different purposes and should not be treated as interchangeable. TR 24368 is intended to inform and guide thinking on ethical and societal considerations, not to serve as a compliance benchmark.
Does following ISO/IEC TR 24368 satisfy legal obligations such as the EU AI Act?
Not on its own. As a voluntary international technical report, ISO/IEC TR 24368 is issued by ISO/IEC and does not constitute law in any jurisdiction. Binding legal instruments such as the EU AI Act are separate from voluntary standards and technical reports, and alignment with a technical report should not be assumed to demonstrate legal compliance. Organizations subject to specific regulatory regimes should scope their obligations to the applicable law and treat TR 24368 as one input that may support, but does not replace, a compliance analysis.
How can an organization use ISO/IEC TR 24368 alongside a certifiable standard like ISO/IEC 42001?
In many practices, a technical report of this kind is used as informative background to help teams reason through ethical and societal issues, while a management system standard provides the auditable structure for governance controls. Organizations often draw on the concepts in TR 24368 to enrich policy discussions, training, and impact assessment thinking, then implement those considerations through the documented processes required by a certifiable standard. The distinction to preserve is that the technical report typically informs judgment, whereas the management system standard establishes the controls that can be evidenced and audited.
Where does responsibility for applying these ethical and societal considerations typically sit within an organization?
This varies by organization and is not prescribed uniformly. In many governance arrangements, ethical and societal considerations are surfaced through AI governance structures—such as policy owners, review committees, or a designated accountable function—rather than being confined to any single team. Under a lines-of-defense model, first-line teams may embed the considerations into design and development, second-line functions may set policy and challenge, and third-line assurance may review adherence, though the precise allocation depends on how the organization has structured its oversight. TR 24368 does not itself mandate a specific organizational placement.
How do the considerations in ISO/IEC TR 24368 relate to fairness and bias work in a model?
Ethical and societal considerations are broader than, and should not be reduced to, technical fairness or bias measurement. As commonly distinguished, bias refers to systematic error or skew in data or model outputs, while fairness concerns normative judgments about acceptable and equitable treatment; societal considerations may extend beyond both to include effects on affected communities, human rights, and wider impacts. In practice, teams often treat bias and fairness analysis as one component of a larger ethical and societal review rather than the whole of it, and the technical report's framing supports that broader lens.
At what point in the AI lifecycle should these considerations be addressed?
Ethical and societal considerations are typically most useful when introduced early and revisited throughout the lifecycle, rather than treated as a one-time check. In many implementations they inform problem framing and design, are reassessed during development and testing, and are monitored after deployment as context and use evolve. Because a technical report of this type is informative rather than prescriptive, it does not impose fixed gates or timing; organizations generally integrate the considerations into their existing governance and review cadences and document how and when they were addressed.

Common misconceptions

ISO/IEC TR 24368 can be certified against, like ISO/IEC 42001.
As commonly understood, a Technical Report (TR) is an informational deliverable and is not a certifiable management system standard. Organizations generally cannot obtain certification against a TR; certification pathways are associated with management system standards such as ISO/IEC 42001, which serve a different purpose.
Following this document satisfies legal or regulatory obligations for ethical AI.
The Technical Report is voluntary guidance issued by ISO/IEC and is not law. It does not replace jurisdiction-specific legal requirements, which vary by region and sector. Consulting it does not by itself demonstrate compliance with any statute or binding regulation.
Addressing ethical considerations under this guidance eliminates societal risk from AI.
Ethical and societal considerations, as described in guidance of this kind, are measures that help identify and reduce potential harms; they do not eliminate risk. Residual ethical and societal risks typically remain and require ongoing attention rather than one-time treatment.

Best practices

Treat ISO/IEC TR 24368 as an orienting reference for ethical and societal considerations, and pair it with a certifiable standard or a governance framework when auditable controls or formal assurance are needed.
Confirm and document which binding legal requirements apply in your jurisdiction and sector, rather than relying on the Technical Report to establish compliance obligations.
Distinguish organizational governance decisions from the broader societal impacts of an AI system when applying the report's concepts, so that both are addressed without conflating internal accountability with external effects.
Translate the ethical concepts discussed in the report into concrete, testable controls and responsibilities within your own governance program, since the report itself is descriptive rather than prescriptive.
Record ethical and societal considerations as ongoing items subject to monitoring, recognizing that identified measures reduce but do not eliminate residual risk.
Cross-reference the Technical Report against complementary instruments in your control environment, keeping clear which are voluntary guidance, which are certifiable standards, and which are legal requirements.