The Integrity Gap

AI, ethics and another ISO

ISO standards, including those related to AI and ethics, play a significant role in risk management. In some areas (like risk management, ISO 30001 and the infosec heavy ISO 27001), these standards are widely adopted.

The Integrity GapAI, ethics and another ISO

ISO standards, including those related to AI and ethics, play a significant role in risk management. In some areas (like risk management, ISO 30001 and the infosec heavy ISO 27001), these standards are widely adopted. They provide a common framework for understanding and addressing risks. However, as risks have become more complex (political, regulatory, reputational, sustainability, etc.), these standards are showing their limitations. But that’s not the focus of this newsletter. We’re here to discuss ISO 42001.

What is that? Well, a very brief summary:

Risk Management: specifically around AI systems security, data quality, privacy, fairness, and transparency.

Risk Assessment: assessment and documenting the potential impacts of AI systems on people and groups throughout the system’s lifecycle (highlights data quality used in machine learning as a source of risk).

Ethics: same as risk management, but focusing on considering societal impacts and how to promote accountability and transparency in AI systems.

Compliance: cites the EU AI Act, supplier relationships, and integration with existing systems (enter ISO 27001).

So far, so uninspiring and vague. We may need to look at where 42001 deviates from 27001.

Risk Management: 27001 is broad (securing information assets from wide-ranging threats). 42001 picks out areas like biased decision-making, lack of transparency in algorithms, and the misuse of technology. More simply, 27001 is worried about harm (compromise) to the data, and 42001 is concerned about the impact caused by the system.

Risk Assessment: Errr, unclear. See below.

Ethics: Under 42001, we are supposed to implement AI that aligns with ethical standards, regulatory requirements, and societal expectations.

Compliance: 42001 required organisations to create specialised training programmes for AI project staff and implement “robust asset management strategies” to safeguard AI-related intellectual property and data. Furthermore, we must “establish clear criteria for AI procurement, emphasising transparency, fairness, and security.”

The vague risk assessment requirements under 42001 aren’t a bad thing entirely. It represents an opportunity to move from the classical risk management approach - probability and consequences - to something more fitting a dynamic and emerging technology. For instance, requiring analysis across the lifecycle could (if done well) allow us to integrate risk-based decision-making at each stage of the AI system development. How we do that is for a longer discussion.

Why should you care? People will start getting audited on AI this year. Infosys already has. Getting certified also fulfils regulatory requirements (EU AI Act). That’s important as I can guarantee we will soon (1-3 years) start seeing regulatory issues involving AI seeping into traditional integrity risk, sustainability, and compliance (fraud to human rights). If AI ethics aren’t already on your radar (or your remit), it’s time to ensure we’re part of a discussion that should not be led by information security (and HR) types alone!

Sharing is caring

The feedback is in. What you need from us is a place where those without significant risk resources (SMEs, mid-caps, impact investors) can come to learn, share, and get support.

We plan to build a hub with training, guidance, and walk-throughs on numerous risk topics supported by content. Over the past five years, we’ve built a library of tens of assessments and 240+ resources (guides, training, tracking tools, checklists, policies, etc.).

To bring this together, we need your help. Please share this newsletter so we can reach more people. The more inputs we get, the better the output.

Thank you!

More Ethics Insight writing

Is it worth a conversation?

Tell us what you are trying to decide. We will listen, ask a few questions and tell you whether we can help.

Start a conversation