The increasing use of artificial intelligence (AI) within Canadian organizations reveals the need to balance the use of AI's innovative capabilities with stakeholder expectations for responsible AI use. At the same time, with the continued growth and use of AI, government agencies, regulators and standard organizations are attempting to establish laws and voluntary codes for organizations that use and develop AI.
in Previous Insights, We discussed the Canadian government's voluntary code of conduct for the responsible development and management of advanced generator AI systems. Currently, this companion article highlights some of the other voluntary standards aimed at helping organizations implement AI to responsibly implement the AI risk management framework, primarily ISO/IEC 42001:2023 and NIST.
Overview of ISO/IEC 42001:2023
The International Organization for Standardization (ISO) ISO/IEC 42001 is an international standard that helps organizations of all sizes, including nonprofits, establish a structured framework for managing AI projects, AI models and data governance practices. Rather than looking at specific AI applications, you manage AI-related risks and opportunities for a wide range of applications used throughout your organization, providing value for every business. This standard follows a structured plan-Do-Check-ACT system that helps organizations implement, monitor, improve and adapt AI models.
The main pillars of the ISO/IEC 42001 framework include:
- Responsible AI – Organizations must ensure ethical and responsible use of AI by adopting robust governance systems and regulations
- Reputation Management – Strengthen public and stakeholder trust in AI applications through transparency, fairness and accountability
- AI Governance – Supports compliance with legal and regulatory standards that clearly outline the roles and responsibilities of all organizations
- Practical guidance – Effectively identify and manage AI-related risks, including bias, accountability, transparency, and data protection.
- Identify opportunities – Encourage innovation and growth within a structured framework, including AI performance assessment, internal audits, and administrative reviews
ISOs also have other AI-related standards, including, but not limited to:
- 23053 – AI and machine learning frameworks to explain common AI systems
- 23894 – Provides guidance on AI-related risk management for organizations
- 5339 – AI Application Guidance
- 24027 – Addressing AI system bias and AI decisions
The ISO 42001 certification shows that an independent third party has confirmed completion of the framework and governance tools needed to effectively manage the risks and opportunities associated with AI use and development. This provides stakeholders with additional assurance that the organization is committed to responsible use of AI and takes data privacy seriously.
NIST AI Risk Management Framework
The National Institute of Standards and Technology (NIST) AI Risk Management Framework is a resource for designing, developing, deploying, or actively using AI systems to manage AI risks and fostering the reliable and responsible development of AI systems. This framework is a voluntary system for organizations of all sizes and for all sectors considering implementing effective AI governance.
The framework is divided into two parts.
Part 1 outlines the risks of AI and how to ensure stakeholder trust through safe, transparent and fair use of AI, while Part 2 outlines the systems that an organization can use to control the risks outlined in Part 1, which are explained in four main stages:
- map – Contexts are established and risks related to the context are identified taking into account the intended purpose, beneficial use, laws, norms and expectations.
- measurement – Identified risks will be assessed, analyzed and tracked through appropriate methods and metrics
- management – AI risks based on assessments and other analytical outputs from maps and measurement functions are prioritized, responded and managed
- Regulation – Organization-wide policies, procedures and practices related to mapping, measuring and managing AI risks have been implemented, transparent and effectively implemented
Many public sector entities in Canada, including the federal government, require that contractors be required to comply with NIST. Therefore, organizations dealing with federal and state governments may want to consider implementing AI use along the NIST framework.
Organizational Considerations
Organizations using AI in every part of their business should consider following one or more of the voluntary standards or codes that exist today, especially considering there are no legislation on issues. It can provide opportunities to improve the business and outcomes generated from AI systems according to voluntary standards or code, creating more value for your organization. It also improves risk management, accountability, and stakeholder trust to the organization, and may better position it for the inevitable implementation of laws and regulations regarding the use of AI.
Note: This article is of general nature only and does not cover all possible legal rights or remedies. Furthermore, these materials are not intended to be dependent on or adopted legal advice or opinions, as laws may change over time and should be interpreted only in the context of a particular situation. Readers should consult a legal expert about specific advice in certain circumstances.
