# AI standards and ISO norms: what they do and do not do

[Skip to content](#lm-inhoud)Network/[NL](/en/ai-standaarden-en-iso-normering)EN[Hubhub.llmnet.nlCompare models on task, language, cost and license.](https://hub.llmnet.nl/en/)[Communitycommunity.llmnet.nlPrompt techniques, patterns and system prompts.](https://community.llmnet.nl/en/)[APIapi.llmnet.nlLLMs in production: rate limits, routing, structured output.](https://api.llmnet.nl/en/)[Consultancyconsultancy.llmnet.nlRolling out AI in an organization, pilot to production.](https://consultancy.llmnet.nl/en/)[Newsnieuws.llmnet.nlAI developments, explained for the Netherlands.](https://nieuws.llmnet.nl/en/)[Benchmarkbenchmark.llmnet.nlMeasure AI quality yourself, on your own tasks.](https://benchmark.llmnet.nl/en/)[Careersvacatures.llmnet.nlAI roles, salaries and career paths in the Netherlands.](https://vacatures.llmnet.nl/en/)[Learnleren.llmnet.nlAI concepts in plain language, beginner to builder.](https://leren.llmnet.nl/en/)[Guidegids.llmnet.nlRun AI privately on your own Mac, PC, NAS or home server.](https://gids.llmnet.nl/en/)[Directorydirectory.llmnet.nlMapping the AI ecosystem: tools, models, companies.](https://directory.llmnet.nl/en/)[Radarradar.llmnet.nlSignals from X, research and communities for indie developers.](https://radar.llmnet.nl/en/)[Appsapps.llmnet.nlReviews of AI apps and open-source repos, with tips for builders.](https://apps.llmnet.nl/en/)[llmnet.nl — main site](https://llmnet.nl/en/)[](https://x.com/intent/post?url=https%3A%2F%2Fnieuws.llmnet.nl%2Fen%2Fai-standaarden-en-iso-normering&text=AI%20standards%20and%20ISO%20norms%3A%20what%20they%20do%20and%20do%20not%20do)[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fnieuws.llmnet.nl%2Fen%2Fai-standaarden-en-iso-normering)[](https://www.reddit.com/submit?url=https%3A%2F%2Fnieuws.llmnet.nl%2Fen%2Fai-standaarden-en-iso-normering&title=AI%20standards%20and%20ISO%20norms%3A%20what%20they%20do%20and%20do%20not%20do)[](#)[](https://x.com/intent/post?url=https%3A%2F%2Fnieuws.llmnet.nl%2Fen%2Fai-standaarden-en-iso-normering&text=AI%20standards%20and%20ISO%20norms%3A%20what%20they%20do%20and%20do%20not%20do)[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fnieuws.llmnet.nl%2Fen%2Fai-standaarden-en-iso-normering)[](https://www.reddit.com/submit?url=https%3A%2F%2Fnieuws.llmnet.nl%2Fen%2Fai-standaarden-en-iso-normering&title=AI%20standards%20and%20ISO%20norms%3A%20what%20they%20do%20and%20do%20not%20do)[](#)

# AI standards and norms: what they do and do not do

By Ivo Donker — compiled with AI support (Claude & Gemini) · Last updated: 6 August 2026

Framework legislation and legal guidelines are the fundamental starting point for market participants, but in daily practice laws leave room for interpretation. A law states in broad terms what is legally required, such as preventing unacceptable risks to fundamental rights or safety. Legislation, however, rarely gives a step-by-step manual for how an organization proves technologically or operationally that it meets those obligations. Standards and norms come into play at this interface.

In debates about governance and compliance, the terms law, standard and certificate are regularly conflated. This leads to misunderstandings about what an ISO standard or international standard actually achieves. A standard is not legislation, and a certificate is not proof of perfect quality. In this article we analyze how the standardization landscape is built, the mechanics of management system standards, the political charge of harmonized standards and the practical value for organizations.

Scope: This article covers the operational and governance workings of norms and standards. For the broader legal frameworks, see the [EU AI Act explained](https://nieuws.llmnet.nl/en/eu-ai-act-uitleg). For the supervisory and enforcement framework in the Netherlands, see the overview of [AI supervision in the Netherlands](https://nieuws.llmnet.nl/en/ai-toezicht-nederland).

## The distinction between law, standard and certificate

To understand how compliance works in practice, three core concepts have to be kept strictly apart:

- The law: This is a binding prescription from a government body. Legislation determines what is and is not permitted and attaches legal sanctions to violations. Laws generally address goals to be achieved and outcomes to be avoided.

- The standard: This is a voluntary, agreed convention or guideline drawn up by market parties, scientists and experts within a standardization institute. A standard describes 'how' to organize a particular process or 'what' a product has to meet technically. A standard only becomes binding when legislation refers to it or when two contracting parties agree to it.

- The certificate: This is a written declaration from an independent assessing body. The certificate confirms that a specific process, product or management system meets, at a given moment, the requirements laid down in a selected standard.

In practice, policymakers and executives sometimes assume that obtaining a certificate automatically means an organization complies fully with all relevant legislation. That is incorrect. A standard can help substantiate legal presumptions of conformity, but holding a certificate does not replace legal responsibility.

Concept | 
Origin | 
Legal status | 
Core questions | 

Law | 
Legislator / government | 
Binding | 
What is absolutely required or forbidden? | 

Standard | 
Standardization institutes (experts/market) | 
Voluntary (unless tied to law/contract) | 
How do you carry out the process in a standardized way? | 

Certificate | 
Independent audit party | 
Evidence / assessment | 
Has it been verified that the process works as agreed? | 

## What a management system standard amounts to at its core

Many of the widely discussed international standards around technology are built as management system standards. It is essential to understand that a management system standard sets no direct requirements for the computational accuracy of an algorithm or the architecture of a neural network. A management system standard sets requirements for how an organization structures decision-making, maps risks, documents measures and reviews processes repeatedly.

At its core, a management system follows the familiar cycle of plan, do, check and act. Applied to developing or implementing artificial intelligence, a management system requires an organization to record in documented form:

- Which goals and risks have been identified for the specific application.

- Which roles and responsibilities have been assigned to staff and management.

- Which monitoring and testing mechanisms are applied throughout the software's life cycle.

- How incidents and deviations are recorded, evaluated and corrected.

To outsiders and technicians, this emphasis on procedures and record-keeping can feel disappointing. Applying a management system does not guarantee that a trained model is free of errors, hallucinations or bias. What it does guarantee is that a demonstrable and verifiable process exists in which choices were made deliberately and recorded traceably. If something goes wrong, the organization can show which considerations were weighed in advance and how the risk was monitored.

## Relation to information security and privacy

Standards for artificial intelligence do not stand alone. They build on existing and well-established structures for information security and data protection. Organizations already experienced with well-known information security frameworks (such as the ISO/IEC 27001 series) or the General Data Protection Regulation (GDPR) quickly discover that the basic requirements resemble each other closely.

An organization with a mature information security management system already has a risk register, access management, incident procedures and internal audit cycles. Extending to AI-specific norms does not require building a completely new administrative apparatus, but adding specific risk categories to the existing framework.

AI-specific additions include:

- Explicitly monitoring the data quality and provenance of training and test data.

- Setting up human oversight (human-in-the-loop) in operational processes.

- Safeguarding transparency and explainability of automated decisions.

- Managing the specific vulnerabilities of AI models, such as data poisoning or deviations in model performance over time (model drift).

For an organization with no experience of structured norms at all, the entry threshold is high. Organizations with a solid basis in information security and IT governance, by contrast, have less new work to do than it first appears. They can extend existing audit mechanisms with AI-specific control points.

## The different types of standards side by side

The standards landscape is diverse and consists of several complementary layers. To keep an overview, standards are generally divided into three categories:

### 1. Governance and organizational standards

These are the management system standards already mentioned. They determine how the board and management steer the application of technology across the whole organization. One example is the international standard for AI management systems, ISO/IEC 42001. This standard provides the overarching organizational structure.

### 2. Standards for terminology and concepts

In a fast-developing field, confusion arises when market parties, lawyers and technicians do not speak the same language. Terminology standards such as ISO/IEC 22989 fix definitions of terms such as 'autonomy', 'machine learning', 'bias' and 'explainability'. These standards ensure a contractual agreement or a legal obligation is interpreted the same way by all parties involved.

### 3. Technical guidelines and process standards

These standards offer specific, operational handles for developers and engineers. Examples are guidelines for assessing data quality for analytics and AI (such as the ISO/IEC 5259 series), technical frameworks for risk management (such as the NIST AI Risk Management Framework) or standards for testing model robustness. These documents describe concrete measurement methods and test protocols.

## Harmonized standards: why standardization has become political

A crucial link in European regulation is the concept of the 'harmonized standard'. This is a standard developed at the European Commission's request by European standardization organizations (such as CEN and CENELEC) and whose reference has been published in the Official Journal of the European Union.

When an organization applies a harmonized standard in full, a so-called 'presumption of conformity' arises. This means the supervisory authority assumes as a matter of law that the product or service meets the specific legal requirements the standard covers. This mechanism considerably lowers the administrative burden of proof for organizations.

Because harmonized standards directly affect how a European law is enforced in practice, drawing up these standards is no longer a purely technical matter. In recent years, standardization committees have become the playing field of international political and economic interests. Large technology companies, national governments and civil society organizations try to anchor their own definitions, protocols and market interests in these standards. Whoever sets the standard, after all, sets the requirements for market access.

## What certification involves in practice

Obtaining a certificate against a standard is a formal process carried out by an external, independent party (a certification body). This process generally follows a fixed pattern:

- Stage 1 audit (document review): The auditor checks whether the required policy documents, risk analyses, register overviews and process descriptions exist on paper and meet the standard's requirements.

- Stage 2 audit (practical assessment): The auditor speaks with staff, examines concrete projects and tests whether the recorded processes are actually followed in daily practice and demonstrably work.

- Issuing the certificate: On a positive recommendation the certificate is issued, usually with a clearly delimited scope and a limited period of validity (often three years).

- Periodic reassessment: Certification is not a one-off snapshot. An interim surveillance audit takes place annually to establish whether the management system remains operational. After the period of validity expires, a full reassessment is required.

## When does certification deliver value and when does it mostly cost money?

A certification process demands a substantial investment in time, resources and external audit costs. It is therefore essential for organizations to determine in advance what the concrete purpose of a formal certificate is.

Formal certification adds clear value in situations where external trust is necessary. In large public tenders or business processes in chains with strict risk profiles, clients increasingly demand proof of a certified management system up front. In those cases the certificate functions as a ticket to the market. It saves time because the organization does not have to undergo a lengthy supplier audit with every individual customer.

For a small organization with a single internal application with a low risk profile, scaling up to formal certification is often out of proportion to the benefits. The financial resources and overhead needed to have a certification body audit you annually are in that case better spent on direct quality testing and substantive risk management. More on the trade-offs for smaller organizations can be found in the article on [AI governance for SMEs](https://consultancy.llmnet.nl/en/ai-governance-mkb).

## Sharp criticism of process standardization

There is fundamental and justified criticism of the strong emphasis on management system standards within the technology sector. The main criticism is that process standards tend to degenerate into a bureaucratic box-ticking exercise. An organization can have a perfectly documented management system in which every risk analysis is neatly archived while the eventual model still generates biased or harmful results in practice.

With physical products such as a crane or a medical device, the physical properties and wear are directly measurable against clear safety margins. With AI systems those boundaries are more complicated. The behavior of a probabilistic model depends heavily on context, user input and a changing environment. The illusion of safety projected by a management system that is correct on paper is therefore a greater risk in software and AI applications than in traditional industrial standards.

Standards should therefore be seen as an organizational foundation, and never as a guarantee of ethical or factual correctness at system level.

## Getting value without a formal certificate

The good news for organizations is that applying a standard and obtaining a formal certificate are two separate decisions. An organization can perfectly well acquire an international standard, study it and use it as an internal guideline without ever letting an external auditor through the door.

The structure that standardization offers helps organizations set up useful internal instruments, such as:

- The AI register: A central overview of all algorithms, models, vendors and purposes used within the organization.

- A clear risk classification: A method for classifying applications by impact on the organization and the user, so that oversight and control are applied proportionately.

- Fixed review moments: Building in periodic evaluations that test whether a model in production still performs to the original specifications.

Incorporating these elements into operations produces a mature form of governance. This can be shaped in part by drawing up a structured [AI policy](https://consultancy.llmnet.nl/en/ai-beleid-opstellen) that matches actual working processes. Should a market or legislative obligation to certify arise in future, the foundation is already there and the formal audit can be completed with minimal extra effort.

## Dynamics and movement in the field

The field of AI standards moves fast. New guidelines appear regularly, draft standards are revised and sector-specific guidelines emerge. This means claims about 'the definitive AI standard' should be read with due caution.

There is no single overarching standard covering all aspects of AI development, data management and societal impact. Organizations are wise to follow international and European developments closely while keeping their focus on the essentials: mapping their own risks, determining responsibilities transparently and continuously checking the systems in use.

The rise of specialized tools supports organizations in keeping these processes manageable. An overview of software that helps with documentation and risk monitoring can be found in the overview of [AI governance and compliance platforms](https://directory.llmnet.nl/en/ai-governance-en-compliance-platforms). The rising demand for structured compliance has also created new roles within organizations. More information on the job profile of the specialist leading these processes can be found in the description of the [AI compliance officer role](https://vacatures.llmnet.nl/en/ai-compliance-officer-rol).

## Further reading

- [EU AI Act explained](https://nieuws.llmnet.nl/en/eu-ai-act-uitleg)

- [AI supervision in the Netherlands](https://nieuws.llmnet.nl/en/ai-toezicht-nederland)

- [AI legislation outside the EU](https://nieuws.llmnet.nl/en/ai-wetgeving-buiten-de-eu)

- [AI governance for SMEs](https://consultancy.llmnet.nl/en/ai-governance-mkb)

- [Drawing up an AI policy](https://consultancy.llmnet.nl/en/ai-beleid-opstellen)

- [AI governance and compliance platforms](https://directory.llmnet.nl/en/ai-governance-en-compliance-platforms)

- [AI compliance officer role](https://vacatures.llmnet.nl/en/ai-compliance-officer-rol)

llmnet.nl - AI news and research
