ISO/IEC
Ver recurso originalThe ISO/IEC 25000 series, known as SQuaRE (Software product Quality Requirements and Evaluation), provides the most comprehensive international framework for evaluating software quality—and that includes AI systems. Published in 2014 but continuously updated, this standard series offers something many AI governance frameworks lack: concrete, measurable quality metrics. While other AI standards focus on high-level principles, ISO/IEC 25000 gets into the nuts and bolts of how to actually measure whether your AI software is reliable, usable, secure, and maintainable.
Most AI governance resources were written specifically for AI and focus on ethics, bias, and explainability. ISO/IEC 25000 takes a fundamentally different approach—it treats AI systems as software products first, then applies rigorous software engineering quality principles. This perspective is invaluable because AI systems, regardless of their sophistication, are ultimately software that must function reliably in production environments.
The standard provides eight quality characteristics: functional suitability, performance efficiency, compatibility, usability, reliability, security, maintainability, and portability. Each comes with specific sub-characteristics and measurable metrics. For AI systems, this translates to concrete evaluation criteria often missing from ethics-focused frameworks.
The ISO/IEC 25000 series consists of five divisions, each serving a specific purpose:
Start with the Quality Model Division (ISO/IEC 25010) to understand the eight quality characteristics and determine which are most critical for your AI system. Not all characteristics will be equally important—a batch processing AI system has different quality priorities than a real-time recommendation engine.
Use the Quality Requirements Division (ISO/IEC 25030) to translate business needs into specific, measurable quality requirements. Instead of vague requirements like "the AI should be reliable," you'll specify concrete metrics like "mean time between failures exceeding 720 hours" or "availability of 99.9% during business hours."
Implement measurement practices from the Quality Measurement Division using your existing monitoring and logging infrastructure. Many organizations discover they're already collecting data needed for ISO/IEC 25000 metrics—they just weren't organizing it systematically.
The evaluation processes can be integrated into existing code review, testing, and release procedures rather than implemented as separate governance overhead.
This isn't an AI ethics standard, and it won't directly address bias, fairness, or explainability concerns. It's a software quality standard that happens to apply to AI systems. You'll likely need to combine it with AI-specific governance frameworks for comprehensive coverage.
ISO/IEC 25000 doesn't prescribe specific quality levels or thresholds. It provides measurement frameworks, but you must determine appropriate targets based on your context, user needs, and regulatory requirements.
The standard series is comprehensive but can be overwhelming. Organizations often try to implement everything at once instead of focusing on the quality characteristics most relevant to their specific AI applications and risk profile.
Finally, while the standard is globally applicable, procurement requirements, regulatory expectations, and industry practices vary significantly by jurisdiction and sector. The framework provides consistency, but implementation details must be tailored to your specific operating environment.
Publicado
2014
JurisdicciĂłn
Global
CategorĂa
Assessment and evaluation
Acceso
Acceso de pago
VerifyWise le ayuda a implementar frameworks de gobernanza de IA, hacer seguimiento del cumplimiento y gestionar riesgos en sus sistemas de IA.