Skip to main content
Category: Validation & Testing

ISO/IEC 25059 (AI Quality Model)

Also known as: ISO/IEC 25059:2023, AI Quality Model (SQuaRE extension)
Simply put

ISO/IEC 25059 is an international standard published by ISO and IEC that describes a quality model for artificial intelligence systems. It sets out characteristics for assessing the quality of AI systems, taking into account traits such as their ability to learn, handle incomplete data, and produce probabilistic outputs. It builds on ISO/IEC's existing SQuaRE series of software quality standards rather than standing entirely on its own.

Formal definition

ISO/IEC 25059:2023 is an application-specific extension to the SQuaRE (Systems and software Quality Requirements and Evaluation) series that defines a quality model tailored to AI systems. According to the evidence, it outlines quality characteristics and sub-characteristics intended to support assessment of AI system quality, emphasizing attributes distinctive to AI such as learning behavior, handling of incomplete data, and probabilistic outputs. As a voluntary international standard, it provides a framework for evaluating AI system quality rather than a legally binding requirement, and it is distinct from AI governance instruments and from model risk management practices; it should be understood as a quality-model reference, not a compliance mandate. Note: the evidence provided does not enumerate the specific quality characteristics, sub-characteristics, or measurement methods, so the precise structure of the model is out of scope for this entry.

Why it matters

AI systems differ from traditional software in ways that complicate quality assessment: they can learn and change behavior over time, must often operate on incomplete data, and produce probabilistic rather than deterministic outputs. ISO/IEC 25059 matters because it extends an established software quality vocabulary (the SQuaRE series) to address these distinctive traits, giving organizations a shared reference for describing and evaluating AI system quality rather than improvising ad hoc criteria for each project.

For practitioners, a common quality model can support more consistent internal evaluation, procurement discussions, and communication between technical and non-technical stakeholders. Because it is a voluntary international standard rather than binding law, it does not by itself create legal obligations, and adopting it does not demonstrate compliance with any particular regulatory regime. Its value lies in providing structured language and characteristics for assessing quality, which organizations may choose to align with other governance or risk activities.

Who it's relevant to

AI quality and assurance teams
Teams responsible for evaluating AI system quality may use the standard as a shared reference vocabulary for characteristics such as learning behavior, handling of incomplete data, and probabilistic outputs. It offers structure for assessment discussions, though the specific measurement approaches would need to be drawn from the standard's own text.
Procurement and vendor management specialists
Those evaluating or acquiring AI systems from third parties may reference the quality model to frame expectations and comparison criteria. Alignment with a voluntary international standard can support due-diligence conversations, but it should not be treated as evidence of regulatory compliance.
AI governance professionals
Governance practitioners may find the standard useful as one input into broader oversight activities. It is important to note that ISO/IEC 25059 is a quality-model reference and is distinct from AI governance instruments; it addresses how to describe and assess AI quality, not organizational accountability structures or oversight mandates.
Model risk management practitioners
Those managing model risk may consider the quality characteristics as one perspective on model quality, but should recognize that this standard is distinct from model risk management practices such as those historically framed by SR 11-7. Model quality and model risk are related but not interchangeable, and adopting a quality model does not by itself satisfy model risk management expectations.

Inside ISO/IEC 25059 (AI Quality Model)

Quality model extension
ISO/IEC 25059 is positioned as an extension of the broader SQuaRE (Systems and software Quality Requirements and Evaluation) series, applying and adapting established software product quality concepts to AI systems rather than defining an entirely separate framework.
Quality characteristics for AI systems
The document is intended to describe quality characteristics and sub-characteristics relevant to AI systems, providing a structured vocabulary for specifying and evaluating aspects of AI quality. The specific set of characteristics should be confirmed against the standard text rather than assumed.
Basis for requirements and evaluation
As part of the SQuaRE lineage, it is meant to support the definition of quality requirements and the evaluation of whether an AI product meets them, connecting quality attributes to measurement and assessment activities.
Voluntary standard status
As an ISO/IEC standard, it functions as a voluntary consensus standard rather than binding law. Organizations may adopt it to structure quality practices, but it does not by itself impose legal obligations.
Scope focused on product quality
Its orientation is toward the quality of the AI system as a product, which is distinct from organizational AI governance structures and from model risk management processes, even where these areas may reference or interact with quality attributes.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 25059 (AI Quality Model).

Is ISO/IEC 25059 a certifiable standard that proves my AI system meets a required quality level?
Not in the way certification is often assumed to work. ISO/IEC 25059 is typically understood as a quality model that extends the SQuaRE series (the ISO/IEC 25000 family) to AI systems, providing a structured set of quality characteristics rather than a pass/fail conformity threshold. It offers a vocabulary and framework for describing and evaluating quality attributes, but on its own it does not establish a universally required quality level or a binding certification regime. Professionals should not conflate using a quality model with holding a certification, and should verify separately what, if any, conformity mechanisms apply in their context.
Does ISO/IEC 25059 satisfy my AI governance or model risk management obligations?
It should not be treated as interchangeable with governance or model risk management obligations. As commonly positioned, ISO/IEC 25059 addresses product quality characteristics of AI systems, which is a different focus from the organizational accountability and oversight structures associated with AI governance, or the identification, measurement, monitoring, and control activities associated with model risk management. A quality model can inform inputs to those functions, but it does not by itself discharge governance responsibilities or the risk-control activities framed by guidance such as SR 11-7 in banking contexts. Treat it as one component that may complement, not replace, those programs.
How does ISO/IEC 25059 relate to the broader ISO/IEC 25000 (SQuaRE) series we may already use?
ISO/IEC 25059 is commonly described as an extension of the SQuaRE quality model concepts to AI systems. Organizations already familiar with the 25000 family's quality characteristics can generally approach 25059 as building on that established structure to account for characteristics relevant to AI. Where teams have existing SQuaRE-based evaluation practices, mapping AI-specific quality considerations onto that foundation is a natural starting point, though the specific characteristics and their applicability should be confirmed against the standard's own text rather than assumed from the general series.
How can a quality model like this fit alongside a risk-based framework such as the NIST AI RMF or ISO/IEC 42001?
A quality model and a risk or management-system framework serve different but potentially complementary purposes, and they should be kept scoped correctly. The NIST AI Risk Management Framework is a voluntary framework issued in the U.S., and ISO/IEC 42001 is positioned as an AI management system standard; neither is interchangeable with a quality characteristics model. In practice, teams may use quality characteristics to give concrete, measurable substance to attributes that a risk framework asks them to consider, while relying on the risk or management-system framework for the surrounding process. The mapping should be documented explicitly rather than assumed, since the instruments have distinct scopes and issuing bodies.
Where does ISO/IEC 25059 fit in evaluation and testing activities across the model lifecycle?
A quality model typically informs what you evaluate rather than prescribing a full test methodology. It can help teams articulate which quality characteristics matter for a given AI system and structure evaluation criteria accordingly. When integrating it, it is useful to keep the distinction between verification and validation in view: defining quality characteristics supports both, but the standard's role is generally to frame the characteristics to be assessed, not to specify every measurement procedure. Confirm the applicable measures and their intended use against the standard itself before building test plans around them.
What are the limits of relying on ISO/IEC 25059, and what falls outside its scope?
As a quality model, it is generally out of scope for organizational accountability structures, legally binding compliance obligations, and the control activities of a model risk management program; those must be addressed through other instruments and functions. It also does not eliminate risk, and applying it does not guarantee that an AI system is fit for a particular regulated use. Sector-specific expectations, such as those in banking model risk contexts, are governed by their own guidance and are not superseded by a quality model. Teams should treat it as one input that helps describe and evaluate quality, while confirming its precise contents and applicability against the standard's own text.

Common misconceptions

ISO/IEC 25059 is a legal requirement that organizations must comply with.
It is a voluntary consensus standard published under the ISO/IEC framework, not binding law. Adoption is typically a business or governance choice, and it does not carry regulatory force on its own, though a regulator or contract could reference standards separately.
An AI quality model like ISO/IEC 25059 is the same thing as a model risk management framework or a governance framework.
A quality model provides characteristics and vocabulary for evaluating an AI system as a product. Model risk management concerns identifying, measuring, monitoring, and controlling risks arising from model use, and AI governance concerns organizational accountability and oversight. These areas can overlap in practice but address different objectives and should not be treated as interchangeable.
Meeting the quality characteristics in the standard guarantees the AI system is safe, fair, or free of risk.
A quality model helps structure and evaluate quality attributes but does not eliminate risk. Conformance to described characteristics is a measure that can help manage certain concerns; it does not by itself establish safety, fairness, or the absence of residual risk.

Best practices

Confirm the specific quality characteristics and sub-characteristics against the actual published text of ISO/IEC 25059 before relying on any particular list, since the standard's precise content should not be assumed from its title.
Treat the standard as an extension of the SQuaRE series and align its use with existing software quality practices rather than deploying it in isolation.
Use the quality model to structure product-level evaluation, and keep it distinct from, though connected to, separate model risk management and AI governance processes.
Document where you rely on the standard voluntarily versus where legal or regulatory obligations apply, so that voluntary quality practices are not mistaken for compliance with binding requirements.
Pair quality characteristic definitions with concrete measurement and evaluation methods so that quality requirements are testable rather than aspirational.
Frame conformance to the quality model as a risk-reducing measure rather than a guarantee, and continue to assess residual risk through appropriate monitoring and controls.