Skip to main content
Category: Management System Governance

ISO/IEC 22989 (Concepts and Terminology)

Also known as: ISO/IEC 22989:2022, ISO/IEC 22989 Artificial Intelligence Concepts and Terminology
Simply put

ISO/IEC 22989 is an international standard that provides a common vocabulary and set of concepts for artificial intelligence. Its purpose is to help a broad range of stakeholders understand and communicate about AI in a consistent way. It defines terminology rather than setting operational requirements, and is intended to support the development of other AI-related standards.

Formal definition

ISO/IEC 22989:2022 is a foundational terminology standard, published jointly by ISO and IEC, that establishes standardized concepts and terminology for artificial intelligence. As commonly described, it is intended to make AI technology more readily understood and used across a broad set of stakeholders and to serve as a reference vocabulary in the development of other AI standards. It should be understood as a concepts-and-terminology document rather than a management system standard or a set of certifiable requirements; practitioners frequently conflate it with a management system standard (a distinct instrument), which the evidence here does not support. This entry does not address the standard's specific defined terms, clause structure, or how individual definitions map to particular regulatory or model risk management frameworks, which are out of scope for this definition.

Why it matters

Consistent terminology is a precondition for effective AI governance and model risk management. When compliance officers, data scientists, auditors, and legal professionals use the same words to mean different things, gaps and misunderstandings emerge in policies, controls, and documentation. ISO/IEC 22989 addresses this problem by providing a shared vocabulary and set of concepts for artificial intelligence, intended to help a broad set of stakeholders understand and communicate about AI more consistently. As commonly described, it can be used as a reference in the development of other AI standards, which gives it a foundational role even though it does not itself impose operational requirements.

Who it's relevant to

Standards developers and policy specialists
Because the standard is described as usable in the development of other standards, those drafting AI-related standards, internal policies, or governance frameworks may reference it to align on terminology. This does not mean adopting it satisfies any particular regulatory or certification requirement; it is a terminology reference, not a management system standard or a set of certifiable requirements.
Compliance officers and legal professionals
Practitioners who must interpret AI-related obligations across documents may find a common vocabulary useful for reducing ambiguity in policies and contracts. Note, however, that this entry does not map the standard's individual defined terms to any specific regulatory framework, and how those definitions relate to particular legal or model risk management requirements is out of scope here.
Model risk and data science teams
Teams documenting AI systems can use shared terminology to communicate more precisely about their models across functions. A common vocabulary supports clearer documentation but does not, by itself, establish validation, monitoring, or control requirements, which are addressed by other instruments and internal practices.
Auditors and reviewers
Consistent terminology can help reviewers assess documentation against a shared conceptual baseline. Auditors should be aware that ISO/IEC 22989 is a concepts-and-terminology document rather than a certifiable management system standard, and practitioners sometimes conflate the two; the evidence here does not support treating it as a set of auditable operational requirements.

Inside ISO/IEC 22989 (Concepts and Terminology)

Foundational AI terminology
ISO/IEC 22989 is published by ISO and IEC as an international standard establishing standardized concepts and terminology for artificial intelligence. It aims to provide a common vocabulary so that practitioners, standards bodies, and stakeholders can communicate about AI consistently. It is a voluntary consensus standard, not binding law or regulation.
AI system concepts
The standard describes core concepts associated with AI systems, including how such systems are characterized and the elements commonly used to describe them. It is intended to be referenced by other AI standards that build on a shared conceptual base rather than to prescribe specific technical controls.
Machine learning and related concepts
It addresses terminology relevant to machine learning and other approaches within the broader AI field, providing definitions intended to support consistent usage across documents and disciplines. The precise breadth of terms is defined within the standard text itself.
Role as a terminology base for other standards
As a concepts-and-terminology standard, its primary function is to serve as a reference vocabulary that supporting standards (such as management-system or risk-oriented standards) can draw upon, promoting alignment of language across the AI standards landscape.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 22989 (Concepts and Terminology).

Is ISO/IEC 22989 a certifiable standard that an organization can be audited against for compliance?
No. ISO/IEC 22989 is a concepts and terminology standard; its purpose is to establish shared definitions and foundational vocabulary for AI, not to specify management-system requirements. Certification is typically associated with requirements standards such as ISO/IEC 42001, not with a terminology document. Treating 22989 as a compliance benchmark is a common category error—it supports interpretation of other standards rather than serving as an auditable control set itself.
Does adopting the terminology in ISO/IEC 22989 satisfy AI governance or model risk management obligations?
No. Using consistent terminology does not, on its own, discharge governance or model risk management obligations. ISO/IEC 22989 provides definitions that can improve communication across teams and align documentation, but governance structures, accountability, validation, and risk controls are addressed by other frameworks and, where applicable, by law or supervisory guidance. Vocabulary alignment is a foundational aid, not a substitute for substantive controls.
How can we use ISO/IEC 22989 when implementing another AI framework such as an AI management system?
The standard is commonly used as a reference vocabulary to interpret and apply other AI standards and internal policies consistently. In practice, teams may map the terms they use in policies, model documentation, and risk assessments to the definitions in 22989 so that concepts like 'AI system' or 'stakeholder' are understood uniformly. Note that where another framework or a regulator defines a term differently, that authoritative definition typically governs for that context; 22989 does not override binding or sector-specific definitions.
Should we replace our existing internal glossary with ISO/IEC 22989 definitions?
Not necessarily as a wholesale replacement. Many organizations treat it as a baseline reference and reconcile their existing terminology against it, noting where internal, legal, or sector-specific meanings intentionally differ. Blindly substituting definitions can create conflicts if your operating context—such as banking model risk—uses established terms with different scope. A reconciliation and documented rationale for any divergence is generally more workable than substitution.
Who within an organization typically benefits from referencing ISO/IEC 22989?
It is generally useful to roles that must communicate across disciplines—data scientists, model risk managers, compliance officers, auditors, and legal specialists—where inconsistent use of terms can cause misunderstanding. Its value is primarily in supporting shared understanding and clearer documentation. It does not assign roles, responsibilities, or lines of defense; those are defined by governance frameworks and internal policy rather than by a terminology standard.
How does referencing ISO/IEC 22989 fit alongside jurisdiction-specific requirements?
It can serve as a neutral vocabulary layer beneath jurisdiction-specific instruments, but it does not determine legal or regulatory scope. Where a binding regulation or supervisory guidance defines a term for a specific jurisdiction or sector, that definition applies for that purpose regardless of the standard's wording. Practically, teams should document where regulatory definitions differ from the standard and ensure the applicable authoritative meaning is used in each context.

Common misconceptions

ISO/IEC 22989 is a compliance or certification requirement that organizations must adopt.
It is a voluntary international standard focused on concepts and terminology. It does not impose binding legal obligations and is not, by itself, a certifiable management system; certification is more commonly associated with management-system standards rather than a terminology standard.
It defines governance controls or risk management processes for AI.
Its scope is concepts and terminology, not the prescription of AI governance structures or model risk management procedures. It may support those disciplines by supplying shared vocabulary, but it should not be treated as a substitute for governance frameworks or risk management guidance.
The definitions in ISO/IEC 22989 are the single authoritative meanings used across all regulations and frameworks.
Its terminology is one widely referenced source, but other frameworks and jurisdictions may define terms differently. Practitioners should confirm how a given term is defined within the specific regulatory or organizational context they are operating in, rather than assuming universal interchangeability.

Best practices

Consult the official published standard text for exact definitions rather than relying on paraphrased summaries, since terminology precision is the standard's core purpose.
Use ISO/IEC 22989 as a shared vocabulary baseline when coordinating across teams, but map its terms explicitly to the definitions used in any applicable regulation or internal policy to avoid conflating differing meanings.
Distinguish this terminology standard from governance frameworks and risk management guidance; adopt it to align language, not to satisfy governance or model risk management obligations.
Document, in internal glossaries and model documentation, which terminology source is being applied so that reviewers and auditors can trace the intended meaning.
Verify current version and status of the standard before citing it, as standards are periodically revised and terminology may be updated.
Where a term carries sector-specific or contested meaning, note the divergence explicitly rather than assuming the ISO/IEC 22989 definition governs all contexts.