web analytics
AI Governance

ISO/IEC 22989

AI Vocabulary Standard

The one-paragraph answer

ISO/IEC 22989 is the international vocabulary standard for artificial intelligence. It does not tell you what to do. It tells you what to call things. Every other AI standard from ISO/IEC, including ISO/IEC 42001, references ISO/IEC 22989 to define its terms. Alignment happens implicitly: if you use ISO/IEC 42001, you are using ISO/IEC 22989.

The pain ISO/IEC 22989 is solving for our customers

Ask ten people in your organization what "AI system" means. You will get ten answers. Some will mean a large language model. Some will mean a machine-learning pipeline. Some will mean the app they use every day. Some will mean anything a vendor labeled "AI." The confusion is not academic. It shows up in policies that cover things nobody meant to include, in incident reports that miss things everyone meant to include, and in audit findings that argue for months about scope.

ISO/IEC 22989 ends that argument. It defines the terms that every other AI standard uses. AI system, AI actor, machine learning, deep learning, agent, stakeholder, risk, transparency. Adopting the vocabulary means every artifact, every policy, and every audit line uses the same words to mean the same things. The pain of scope confusion is what this standard was built to remove.

What ISO/IEC 22989 actually is

ISO/IEC 22989 is an international standard published by the joint technical committee of ISO (International Organization for Standardization) and IEC (International Electrotechnical Commission). The full title is "Information technology, Artificial intelligence, Artificial intelligence concepts and terminology." It was published in July 2022, ahead of ISO/IEC 42001, because the community needed a shared vocabulary before the operating standard could be written.

This is not a certification target. Nobody gets audited against ISO/IEC 22989. It is a reference. When ISO/IEC 42001 uses the term "AI actor," the normative reference at the front of the standard says "as defined in ISO/IEC 22989." When ISO/IEC 23894 (risk management) talks about "AI system life cycle stages," it points at ISO/IEC 22989 for the definitions. This makes ISO/IEC 22989 the shared dictionary for the entire AI standards family.

What ISO/IEC 22989 covers

The standard defines terms across several categories.

Core AI concepts

What an AI system is. What machine learning is (a subset of AI). What deep learning is (a subset of machine learning). What an autonomous system is. What generative AI is. What an agent is. What a foundation model is. Precise definitions that let policies and contracts refer to specific technology categories without ambiguity.

AI system life cycle

The stages an AI system passes through: inception, design and development, verification and validation, deployment, operation and monitoring, continuous validation, re-evaluation, and retirement. Governance obligations attach to specific stages, so the life cycle vocabulary matters for audit trails.

AI actors and stakeholders

Who does what in an AI ecosystem. AI provider, AI producer, AI customer, AI subject, AI partner, AI evaluator. The definitions matter because obligations differ by role. A "deployer" in the EU AI Act corresponds to specific ISO/IEC 22989 actor categories.

Trustworthiness characteristics

Definitions of the properties that make AI trustworthy: transparency, explainability, controllability, reliability, robustness, resilience, security, privacy, fairness, safety, accountability. These are also used by NIST AI RMF (with slightly different names but similar meanings).

Why ISO/IEC 22989 matters to you

You do not adopt ISO/IEC 22989 directly. You adopt it by proxy when you align to ISO/IEC 42001, NIST AI RMF, or any credible governance framework that references it. But the value of adopting it consciously is disambiguation.

When your policies say "AI system," a reader knows which definition applies. When your contracts say "AI actor," a court has an accepted definition to interpret. When your risk register references "AI life cycle stages," an auditor knows what you mean. Without ISO/IEC 22989, every document becomes an argument about terminology. With it, arguments about scope end and the substantive work begins.

For SRJ engagements, ISO/IEC 22989 is the vocabulary layer underneath every artifact. The Accountability Matrix identifies roles using ISO/IEC 22989 AI actor definitions. The AI Usage Policy uses ISO/IEC 22989 to distinguish AI systems from adjacent technologies. The dossiers describe AI systems using the standard's life cycle stages. The book crosswalk in Appendix L of Volume III maps every artifact to the exact ISO/IEC 22989 terms it depends on.

What the research says about ISO 22989

The academic literature on ISO 22989 is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.

“AI governance is a system of rules, practices and processes employed to ensure an organization's use of AI aligns with its strategies, objectives, and values.”

That is the gap between having AI and governing it. The second finding is the one that tends to change the room.

“all those who are involved in the research, development and maintenance of AI systems have social and ethical responsibilities”

Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about ISO 22989 arrives from the board, the buyer, or the regulator.

How to get compliant with ISO/IEC 22989: a 5-step path

This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.

  1. Inventory the AI in scope. List every AI system that could fall under ISO 22989. Record what it does, what decision it influences, what data it touches, and who owns it. You cannot govern AI you cannot name, and almost every organisation we assess is running more AI than its leadership believes.
  2. Determine whether you are actually in scope. Work out precisely which of your AI systems and activities ISO 22989 reaches, and write the determination down with its reasoning. Do this in writing. A documented scope determination, right or wrong, is defensible. An undocumented assumption is not.
  3. Assign one accountable owner. Name a person, not a committee, with the authority to stop a deployment. Governance without someone who can say no is documentation, not control.
  4. Build the evidence file. Assemble the documentation ISO 22989 expects: the scope, the risk assessment, the controls, the testing evidence, and the incident record. Assemble it before anyone asks. Reconstructing it under a regulator's deadline costs several times more and looks exactly like what it is.
  5. Set a review cadence and hold it. Re-run the assessment on a schedule and after any material change to the model, the data, or the use case. Alignment decays. A control tested once is a snapshot, not a control.

Done in this order, ISO 22989 becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.

Frequently asked questions about ISO/IEC 22989

Do we get certified against ISO/IEC 22989?

No. It is a terminology standard, not a management-system standard. Certification is available for management-system standards (like ISO/IEC 42001, ISO 9001, ISO 27001), not for vocabulary references.

If we align to ISO/IEC 42001, do we need to know ISO/IEC 22989 separately?

Alignment to ISO/IEC 42001 automatically incorporates ISO/IEC 22989 definitions. But knowing the vocabulary consciously (rather than by accident) helps in negotiations, audits, and cross-framework mapping.

How does ISO/IEC 22989 compare to NIST's AI vocabulary?

They overlap heavily and were coordinated during drafting. NIST AI RMF uses similar categories with slightly different terminology. ISO/IEC 22989 is more comprehensive on life cycle stages; NIST is more comprehensive on trustworthiness characteristics.

Where does ISO/IEC 22989 show up in The Operating Discipline for AI Library™?

Vocabulary from ISO/IEC 22989 is used throughout Volume III, The AI Risk & Governance Review™, especially in chapters describing the AI system life cycle, the AI Governance Framework Crosswalk™ (Appendix L), and the Accountability Matrix chapter. The book adopts ISO/IEC 22989 definitions verbatim wherever the standard specifies one.

Primary sources on ISO 22989

The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning ISO 22989 that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.

Ready to see where you stand?

The AI Business Enablement Audit™ measures your organization against every framework in this library, including ISO/IEC 22989, and delivers a defensible governance dossier. Start or finish your audit below.

Start or finish your AI Audit →
Schedule a Free AI Consultation