Skip to main content
Category: Fairness & Bias

ISO/IEC TR 24027 (Bias in AI Systems)

Also known as: ISO/IEC TR 24027, ISO/IEC TR 24027:2021, Bias in AI systems and AI aided decision making, CEN/CLC ISO/IEC/TR 24027:2023
Simply put

ISO/IEC TR 24027 is a technical report published by ISO and IEC that addresses bias in artificial intelligence systems, particularly where those systems support or make decisions. It describes ways to assess and reduce bias that can arise across the AI lifecycle, including bias stemming from system design, human cognitive bias, or data. As a technical report rather than a requirements standard, it is intended to be informative and does not, on its own, constitute a binding legal obligation.

Formal definition

ISO/IEC TR 24027 is a technical report (TR) issued by ISO and IEC that addresses bias in relation to AI systems, with particular focus on AI-aided decision-making. According to the evidence, it covers measurement techniques and methods for assessing and mitigating bias throughout the AI system lifecycle, and recognizes that bias may be introduced through structural deficiencies in system design, human cognitive bias held by stakeholders, or data- and engineering-related sources. As a technical report it is typically informative and descriptive rather than a certifiable management-system or conformity-assessment standard; practitioners should not treat it as imposing auditable requirements in the way a Type 1 requirements standard (or applicable law) would. The evidence indicates a 2021 ISO/IEC edition and a 2023 CEN/CLC adoption; version and edition applicability should be confirmed against the relevant catalog entry for a given jurisdiction or context. Note that this report addresses bias as a technical property and does not by itself define or resolve fairness, which is a distinct, often normative and context-dependent concept beyond the scope stated in the evidence.

Why it matters

Bias in AI systems is a recurring concern for organizations that deploy models to support or automate decisions, and ISO/IEC TR 24027 matters because it offers a structured, internationally recognized reference for thinking about where bias originates and how it can be assessed and mitigated. The report is notable for treating bias as arising from more than one source: structural deficiencies in system design, human cognitive bias held by stakeholders, and data- or engineering-related factors. This multi-source framing helps practitioners avoid the common error of treating bias as purely a data problem, when design choices and human judgment can introduce or amplify it across the AI lifecycle.

Who it's relevant to

Data scientists and ML engineers
Teams building and testing models can use the report's framing of bias sources, spanning design, human cognitive, and data or engineering factors, to structure bias assessment and mitigation activities across the development lifecycle. It is a reference for methods and vocabulary rather than a prescriptive checklist, so technical judgment remains necessary.
Model risk managers and validators
Second-line functions may reference TR 24027 when designing bias-related testing and documentation expectations. Because it is a technical report and not a requirements standard, it should inform control design rather than serve as an audit criterion on its own, and it does not replace obligations under applicable binding frameworks.
AI governance and policy specialists
Those setting internal standards can draw on the report's lifecycle and source-based treatment of bias to align terminology and expectations across teams. Governance owners should be clear that the document addresses bias as a technical property and does not resolve fairness, which typically requires separate, context-specific determination.
Auditors and compliance officers
Practitioners assessing AI systems should note the report's informative status and confirm which edition or regional adoption (for example, the 2021 ISO/IEC edition versus the 2023 CEN/CLC adoption) is relevant to their context. Alignment with the report is not, by itself, evidence of legal compliance in any particular jurisdiction.
Legal professionals advising on AI deployment
Counsel evaluating bias-related risk can treat TR 24027 as a descriptive reference on measurement and mitigation methods, while advising clients that a technical report does not create binding obligations on its own and that fairness and non-discrimination requirements may be governed by separate applicable law.

Inside ISO/IEC TR 24027

Technical report scope
ISO/IEC TR 24027 is a technical report (a TR, not a certifiable management system standard like ISO/IEC 42001) published under the ISO/IEC JTC 1/SC 42 work on artificial intelligence. As a technical report, it is informative and descriptive in nature rather than establishing auditable requirements, and it is a voluntary international standard rather than binding law in any jurisdiction.
Sources of bias across the AI lifecycle
The report addresses bias as it can arise at different stages, including data collection and preparation, model design and training, and deployment and use. It frames bias as something that can be introduced by data, by algorithmic choices, and by human decisions, rather than treating it as a single-origin problem.
Bias categories and terminology
It provides descriptive treatment of types of bias relevant to AI systems, which may include data-related bias, human cognitive bias, and bias that emerges from system engineering choices. Its aim is to help practitioners identify and describe bias in a structured way rather than to mandate a specific taxonomy.
Assessment and measurement considerations
The report discusses how bias may be identified and assessed in AI systems, including considerations relevant to measuring differential outcomes across groups. It treats measurement as context-dependent rather than prescribing a single metric.
Relationship to fairness
The report distinguishes bias, understood as a systematic difference in treatment or outcome, from fairness, which is a broader normative and context-specific judgment about whether such differences are acceptable. Reducing measured bias does not automatically establish fairness, and the two are treated as related but distinct.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC TR 24027.

Does ISO/IEC TR 24027 set mandatory requirements for eliminating bias in AI systems?
No. As a Technical Report (TR), ISO/IEC TR 24027 is informative rather than normative—it does not establish certifiable requirements or conformity obligations the way a management system standard might. It provides technical information and analysis about bias in AI systems and AI-aided decision-making rather than binding controls. Treating it as a compliance checklist misreads its nature; it is better understood as reference material that can inform, but does not by itself satisfy, any regulatory or contractual obligation.
Does addressing bias under this document mean the resulting AI system is fair?
Not necessarily. Bias and fairness are distinct concepts that professionals are careful not to blur. Bias generally refers to systematic differences in data, measurement, or model behavior, whereas fairness is a normative judgment about what outcomes are acceptable in a given context. Analyzing and mitigating identified biases—the focus of this technical report—can inform a fairness assessment but does not, on its own, determine whether a system is fair, since fairness depends on context, chosen criteria, and stakeholder values that lie outside the scope of a single technical document.
How does ISO/IEC TR 24027 relate to model risk management practices?
The document addresses bias as a technical characteristic of AI systems, which can be one input into broader risk activities, but it is not itself a model risk management framework. Where model risk management focuses on identifying, measuring, monitoring, and controlling risks from model use, this technical report supplies concepts and considerations about bias that a risk function might draw on. Organizations typically need to map its content into their own control processes rather than expecting it to prescribe those processes.
Can this technical report be used as the basis for certification or audit?
A Technical Report of this type is generally not a certifiable standard, so it does not provide auditable requirements on its own. Teams seeking assurance often pair its bias-related concepts with a management system standard or internal control framework that does contain auditable requirements. Using the report to structure documentation and analysis is reasonable, but presenting it as a certification basis would overstate its status.
At what stage of the AI lifecycle is this document most useful?
Because bias can arise from data, model design, and deployment context, the concepts in the report can be relevant across the lifecycle—during data understanding, model development, validation, and ongoing monitoring. Practitioners commonly use it to prompt consideration of potential sources of bias early and to structure later checks, rather than confining its use to a single phase. Its usefulness depends on integration with an organization's existing lifecycle and governance processes.
How should teams document their use of the concepts in this technical report?
A common practice is to record which sources and types of bias were considered, what analysis was performed, and what limitations remain, so that reviewers can understand the reasoning. Because the document is informative, teams generally translate its considerations into their own artifacts—such as model documentation, risk assessments, or governance records—rather than treating adherence as self-evident. Clear documentation of scope and residual concerns helps distinguish what was analyzed from what was left out of scope.

Common misconceptions

ISO/IEC TR 24027 is a certifiable standard that organizations can be audited or certified against.
As a technical report, it is informative guidance rather than a requirements standard. Certification of an AI management system is associated with a management system standard such as ISO/IEC 42001, not with a TR. TR 24027 supports understanding and assessment of bias but does not by itself provide auditable conformity criteria.
Addressing bias as described in the report makes an AI system fair or eliminates discrimination risk.
Bias and fairness are distinct concepts. The report treats bias as a systematic difference that can be measured, while fairness is a broader, context- and value-dependent judgment. Managing identified bias reduces certain risks but does not eliminate them, and does not on its own guarantee a fair or legally compliant outcome.
The report imposes legal obligations comparable to a regulation such as the EU AI Act.
TR 24027 is a voluntary international standard issued through ISO/IEC and is not law. It may inform practice and be referenced by organizations, but it does not carry the binding force of statutory or regulatory instruments, which are issued by legislative or regulatory bodies within their own jurisdictions.

Best practices

Treat TR 24027 as a reference for identifying and describing bias across the AI lifecycle, and pair it with a management system standard or governance framework where auditable requirements are needed.
Examine potential bias at multiple lifecycle stages, including data collection and preparation, model design and training, and deployment, rather than assuming bias originates from a single source.
Keep the distinction between bias and fairness explicit in documentation, so that measured differences in outcomes are not conflated with normative fairness conclusions.
Select bias assessment metrics based on the specific context and use case, and document why a given measurement approach was chosen and what its limitations are.
Record what the bias analysis does and does not cover, noting that reducing measured bias mitigates but does not eliminate discrimination or fairness risk.
Verify jurisdiction-specific legal and regulatory obligations separately, since adherence to a voluntary technical report does not establish legal compliance.