Skip to main content
Category: Trustworthy AI Principles

ISO/IEC TR 24368 (Ethical and Societal Concerns)

Also known as: ISO/IEC TR 24368, ISO/IEC TR 24368:2022, PD ISO/IEC TR 24368:2022, Information technology — Artificial intelligence — Overview of ethical and societal concerns
Simply put

ISO/IEC TR 24368 is a technical report published in 2022 that gives a high-level overview of the ethical and societal concerns raised by artificial intelligence, such as privacy and security breaches, discriminatory outcomes, and effects on human autonomy. It also points to other international standards that address these concerns. As a technical report rather than a certifiable management standard, it is informational in nature and does not set requirements that an organization can be audited or certified against.

Formal definition

ISO/IEC TR 24368:2022, titled in the AI (artificial intelligence) domain and published in 2022, is a technical report (TR) providing a high-level overview of AI-specific ethical and societal concerns, with examples spanning privacy and security breaches, discriminatory outcomes, and impacts on human autonomy. The document additionally includes an overview of International Standards that address issues arising from these ethical and societal concerns, functioning as an orienting reference rather than a specification. As an ISO/IEC technical report, it is a voluntary, informative deliverable and, unlike a management system standard such as ISO/IEC 42001, it does not establish certifiable or auditable requirements; practitioners should treat it as descriptive guidance rather than binding law or a conformity benchmark. The scope of contested definitional boundaries (for example, distinctions between bias and fairness) is addressed only at an overview level in this document and is not resolved by it.

Why it matters

As organizations expand their use of AI, they increasingly confront ethical and societal concerns—such as privacy and security breaches, discriminatory outcomes, and impacts on human autonomy—that do not map neatly onto traditional technical or compliance controls. ISO/IEC TR 24368 matters because it offers a consolidated, high-level overview of these concerns and points practitioners toward other International Standards that address them. For teams beginning to build an AI governance program, this kind of orienting reference can help establish a shared vocabulary and a map of the standards landscape before committing to more prescriptive frameworks.

Its significance, however, lies as much in what it is not as in what it is. Because ISO/IEC TR 24368 is a technical report rather than a management system standard, it is informational and voluntary. It does not establish requirements that an organization can be audited or certified against, unlike a management system standard such as ISO/IEC 42001. Professionals frequently err by treating any ISO/IEC deliverable as a certifiable benchmark; here that assumption would be mistaken, and mistaking a descriptive overview for a conformity target can lead to misplaced assurance in governance documentation.

The document is best understood as a starting point that raises awareness of contested and evolving issues rather than one that resolves them. For example, definitional boundaries such as the distinction between bias and fairness are addressed only at an overview level and are not settled by this report. Readers relying on it for operational risk controls or legal compliance should recognize these limits and pair it with binding law and, where certification is needed, with a management system standard.

Who it's relevant to

AI Governance and Policy Specialists
Those designing organizational governance programs can use ISO/IEC TR 24368 as an early-stage map of AI ethical and societal concerns and of the broader standards landscape. It is useful for establishing shared vocabulary and scoping, but because it is informational rather than certifiable, it should not be positioned as a conformity benchmark or as a substitute for a management system standard such as ISO/IEC 42001.
Model Risk and Compliance Officers
Practitioners assessing AI-related risks may find the report's overview of concerns—privacy and security breaches, discriminatory outcomes, and impacts on human autonomy—helpful for awareness and issue-spotting. They should note that the document does not establish auditable requirements and does not resolve contested distinctions such as bias versus fairness; it complements, rather than replaces, binding law and prescriptive controls.
Auditors and Assurance Professionals
Auditors should be aware that ISO/IEC TR 24368 is a technical report, not a management system standard, and therefore does not provide certifiable or auditable requirements. It can inform an auditor's understanding of ethical and societal concerns but cannot itself serve as the criteria against which conformity is evaluated.
Standards and Legal Professionals
Those tracking the AI standards environment can treat this report as a voluntary, informative reference that surveys other International Standards addressing ethical and societal concerns. It should not be represented as binding law or as settling evolving regulatory and definitional questions, which it addresses only at an overview level.

Inside ISO/IEC TR 24368

Overview document type
ISO/IEC TR 24368 is published as a Technical Report (TR) rather than a standard specifying requirements. As commonly understood, a TR is informative in nature—it conveys collected information and guidance rather than certifiable or auditable requirements—so it should not be treated as a conformance standard against which an organization can be certified.
Ethical and societal concerns scope
The document is oriented toward surveying ethical and societal considerations associated with AI systems. Its function is typically to provide an overview and context for these concerns rather than to prescribe a binding control framework.
Relationship to the broader ISO/IEC AI portfolio
It sits alongside other ISO/IEC deliverables addressing AI, and is distinct in role from a management system standard such as ISO/IEC 42001, which specifies requirements for an AI management system. The distinction between an informative overview and a requirements standard should be preserved.
Audience orientation
As an informative report, it is generally intended to help practitioners, developers, and organizational stakeholders understand and reason about ethical and societal issues, rather than to serve directly as an operational compliance checklist.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC TR 24368.

Is ISO/IEC TR 24368 a certifiable management system standard like ISO/IEC 42001?
No. As commonly understood, ISO/IEC TR 24368 is a Technical Report (TR), which is an informative document providing an overview and guidance on ethical and societal concerns related to AI. It is not a requirements standard and, unlike a management system standard such as ISO/IEC 42001, it is not intended as a basis against which an organization can be audited or certified. Treating it as a conformance benchmark is a common error; it typically functions as a reference and awareness-building resource rather than a set of auditable controls.
Does following ISO/IEC TR 24368 make an organization compliant with the EU AI Act or other binding regulation?
No, and conflating the two is a frequent misconception. ISO/IEC TR 24368 is issued through the international standards process and is voluntary in nature; it does not carry the force of law. The EU AI Act is binding legislation within its own jurisdiction and scope. Consulting a Technical Report may help inform an organization's thinking about ethical and societal issues, but it does not substitute for a legal compliance assessment against applicable regulations, which should be scoped and evaluated separately.
How does ISO/IEC TR 24368 relate to an organization's AI governance program versus its model risk management function?
As a resource addressing ethical and societal concerns, the document tends to inform the AI governance side of the house—organizational policies, oversight structures, and accountability for how AI systems affect people and society. It is generally less focused on the quantitative identification, measurement, monitoring, and control of model risk that model risk management functions handle. The two areas overlap where ethical concerns translate into concrete model risks (for example, risks tied to biased outputs), but a Technical Report of this kind typically does not provide the validation, monitoring, or control procedures that a model risk framework requires. Organizations usually need to map any relevant guidance into their existing governance and risk structures rather than expecting it to serve both roles.
Where does a document like ISO/IEC TR 24368 fit alongside other standards and frameworks an organization already uses?
It is typically used as a complementary, informative reference rather than a replacement for other instruments. Organizations may position it alongside a management system standard, a voluntary risk framework, and applicable binding regulation, each of which serves a distinct purpose and jurisdiction. Because it is a Technical Report rather than a requirements standard, professionals should be careful not to cite it as a source of mandatory controls when integrating it into an existing policy landscape.
Can an organization use ISO/IEC TR 24368 as the basis for internal ethical review of AI systems?
It can serve as input to internal deliberation on ethical and societal concerns, but organizations should treat it as one reference among several rather than a definitive checklist. Because the document is informative in nature, any internal review process built around it typically still needs organization-specific criteria, defined ownership, and clear escalation paths. The Technical Report may help frame the issues worth considering; the decision procedures, thresholds, and accountability structures generally have to be defined by the organization itself.
What are the limitations to keep in mind when relying on ISO/IEC TR 24368?
Several limitations warrant attention. As a Technical Report it is informative rather than normative, so it does not establish auditable requirements. It does not confer legal compliance or certification. Its treatment of ethical and societal concepts may be high-level, and terminology in this area is still evolving and sometimes contested. It is also not a substitute for sector-specific requirements, and users should verify the current status and scope of the document rather than assuming universal applicability across jurisdictions or industries.

Common misconceptions

ISO/IEC TR 24368 is a certifiable standard an organization can be audited against.
As a Technical Report, it is typically informative and does not specify auditable requirements. Certification against a Technical Report is generally not how such deliverables function; organizations seeking certifiable AI management requirements would look to a requirements standard rather than a TR.
Following this Technical Report satisfies AI governance or model risk management obligations.
Addressing ethical and societal concerns is related to, but not a substitute for, AI governance (organizational oversight, accountability, and policy) or model risk management (identification, measurement, monitoring, and control of model-related risk). Guidance on societal concerns does not by itself discharge legal, regulatory, or model validation obligations, which may arise from separate frameworks and jurisdictions.
The Technical Report is legally binding.
ISO/IEC deliverables are voluntary international documents and are not law in themselves. A Technical Report becomes relevant to obligations only if a jurisdiction, contract, or internal policy references it; otherwise it carries no independent legal force.

Best practices

Treat ISO/IEC TR 24368 as an informative reference for reasoning about ethical and societal concerns, and confirm its current status and content directly from the published document before relying on it.
Do not equate use of this Technical Report with certification; if certifiable AI management requirements are needed, identify and apply an appropriate requirements standard separately.
Map ethical and societal considerations surfaced by the report to your own AI governance structures and model risk management processes, keeping the two functions distinct rather than collapsing them into a single control.
Verify whether any applicable law, regulation, contract, or internal policy actually references or requires the Technical Report before treating it as an obligation, since it is voluntary unless incorporated.
Document how you use the report as one input among several, and avoid representing adherence to it as eliminating ethical, societal, legal, or model-related risk—describe it as one measure that helps identify and manage such concerns.
Coordinate use of the report with legal, compliance, and model risk stakeholders so that jurisdiction-specific requirements are addressed through the appropriate binding instruments rather than through an informative overview.