AI ethics, as something you can show.
Build responsible AI aligned with human values, from the UNESCO, IEEE and OECD principles to corporate best practice. Every organisation has an AI ethics statement; very few can produce evidence that anything in it changed a decision. The difference between those two positions is the entire subject, and it is testable.
What is AI ethics and governance?
A cross-cutting discipline that keeps AI systems aligned with human values, rights and societal benefit. Unlike a regulation it has no single text: it is the principles, frameworks, policies and practices that guide ethical AI decisions. As AI reaches decisions that affect people's lives, the pressure to demonstrate responsible practice comes from stakeholders, regulators and the public at once — and a demonstration needs evidence, not a statement.
- Reach Universal The principles apply across every AI system, not only the ones a regulation happens to name.
- Basis Value-driven Rooted in human rights and dignity rather than in a compliance threshold.
- Relationship Under the regimes Ethics is the foundation the EU AI Act, NIST AI RMF and ISO 42001 sit on. It complements them; it does not replace them.
Who needs an AI ethics programme?
Six populations, and what each one is usually trying to hold together. The common thread is a decision that reaches a person who had no say in how it was made.
- Global technology companies Managing ethical risk across diverse markets, regulators and stakeholder expectations at once.
- Financial services Demonstrating fairness in algorithmic lending, pricing and underwriting decisions.
- Healthcare organisations Protecting patient privacy while showing that care recommendations are equitable.
- Government agencies Maintaining public trust in AI-driven services, where the citizen cannot simply go elsewhere.
- HR technology providers Avoiding bias in hiring, promotion and workforce decisions, and being able to prove it.
- Consumer-facing AI Building trust through systems that are transparent about what they are and accountable when they are wrong.
Ethics work is the cheapest part of this subject to start and the most expensive to retrofit. A principle written after a system shipped has to argue with an architecture; the same principle written before it is a design constraint that costs nothing.
How iDharma supports AI ethics and governance
Practical work to put ethical principles into effect across an organisation — one workstream per pillar, each ending in something you can show rather than assert.
Fairness and bias assessment
Systematic evaluation across protected characteristics: demographic parity, disparate impact, equal opportunity — with the metric chosen before the result is seen, and the choice written down.
Transparency and explainability
Model cards, documented explainability methods and disclosure that is meaningful to the audience receiving it. A model card nobody outside the team can read is documentation, not transparency.
Accountability and oversight
Governance roles defined and mapped to named people, a review-board record with decisions and dissent, and an audit trail across the whole governance activity rather than its conclusions.
Privacy-enhancing controls
Privacy by design carried through development: data minimisation that is checked in the schema, consent that propagates, and an impact assessment done before deployment rather than beside it.
Safety and risk monitoring
Harm assessment before release and monitoring after it, with an incident route that produces a decision. The unintended consequence you find in month three is the one the process was for.
Human oversight mechanisms
Human-in-the-loop design tested rather than described: whether the reviewer has the time, the information and the authority to disagree, and whether anyone ever has.
Every ethics review is dated, attributed and carries its approval trail. That record is what separates systematic ethics governance from ad hoc consideration — and it is the first thing anyone auditing the programme will ask to see.
Complete ethics requirements coverage
The review tests against every core ethics requirement, grouped by pillar. Nothing in scope is left to a follow-up engagement.
- Fairness and bias Detection, mitigation, demographic parity and the metric choice behind each of them.
- 8 of 8 by the assessment
- Transparency Explainability method, model documentation and disclosure pitched at its audience.
- 7 of 7 by the assessment
- Accountability Oversight structures, audit mechanisms and responsibility that reaches a named person.
- 6 of 6 by the assessment
- Privacy Data protection, consent, minimisation and the impact assessment behind them.
- 5 of 5 by the assessment
Built for responsible AI from the ground up
Fairness testing
Bias assessment with demographic analysis, and the fairness metric fixed before the result is seen.
Transparency by default
Model cards and explainability documentation produced as the system is built, not after it ships.
Ethics committee workflow
A structured review with decisions tracked, including the ones that went against the build team.
Framework alignment
A crosswalk to the UNESCO, IEEE and OECD principles so one programme answers all three.
Core AI ethics pillars
Six foundational principles for responsible development and deployment. Each is stated here as something that produces evidence rather than something to agree with.
Fairness
Treat individuals and groups equitably, without discrimination or bias.
- Bias detection and mitigation
- Demographic parity analysis
- Equal opportunity metrics
- Disparate impact assessment
- Fairness-aware development
Transparency
Be open and understandable about what the system does and cannot do.
- Model cards and documentation
- Explainability methods
- Decision disclosure
- Algorithmic transparency
- Data provenance tracking
Accountability
Clear ownership of outcomes, held by a person rather than by a committee.
- Governance structures
- Responsibility assignment
- Audit mechanisms
- Redress procedures
- Performance monitoring
Privacy
Protect personal data and respect the rights attached to it.
- Data minimisation
- Privacy by design
- Consent management
- Anonymisation techniques
- Privacy impact assessments
Safety
Be safe and secure, and cause no avoidable harm to people or society.
- Risk assessment
- Safety constraints
- Reliability testing
- Harm prevention
- Incident response
Human oversight
Meaningful human control over decisions, tested rather than asserted.
- Human-in-the-loop design
- Override mechanisms
- Review workflows
- Human judgement integration
- Escalation procedures
Building an AI governance programme
The six components of a working ethics structure. The last line of each card is what "mature" looks like for that component — the target, not the starting point.
Board oversight
Executive engagement and strategic direction for AI ethics.
- A board-level AI committee
- Strategic risk oversight
- Ethics policy approval
- Resource allocation
- Mature: regular board reporting on AI ethics
AI ethics committee
A cross-functional body reviewing systems for ethical concerns.
- Genuinely diverse membership
- Authority to stop a release
- Ethics case evaluation
- Guidance development
- Mature: a formal review process with clear escalation
Policies and standards
Documented principles, policies and operating procedures.
- An AI ethics policy
- Development standards
- Deployment criteria
- Use-case restrictions
- Mature: a complete framework aligned to the principles
Risk assessment
Systematic evaluation of ethical risk before and during deployment.
- Ethics impact assessments
- Harm identification
- Risk mitigation
- Ongoing monitoring
- Mature: mandatory assessment for every high-risk system
Monitoring and auditing
Continuous tracking of behaviour, plus periodic ethics audits.
- Performance metrics
- Bias monitoring
- Compliance audits
- Stakeholder feedback
- Mature: automated monitoring with human review cycles
Transparency practices
External communication about AI use, capability and limitation.
- Public disclosure
- Model documentation
- Impact reporting
- Stakeholder engagement
- Mature: proactive transparency with clear disclosures
AI ethics frameworks
The leading international frameworks guiding responsible AI. They overlap heavily, which is useful: a programme built against one is most of the way to the other two.
Recommendation on the Ethics of AI
Global AI ethics principles, adopted by member states.
- Human rights and dignity
- Environmental sustainability
- Transparency and explainability
- Responsibility and accountability
Ethically Aligned Design
Technical standards for ethical AI, written for engineers.
- Human well-being as the metric
- Accountability
- Transparency
- Awareness of misuse
OECD AI Principles
An international policy framework, and the basis for much that followed.
- Inclusive growth and well-being
- Human-centred values
- Transparency and explainability
- Robustness and safety
Corporate AI ethics programmes
Three published programmes, useful mainly as worked examples of how a principle set gets turned into something operational.
Google AI Principles
Seven principles guiding AI development, published following internal pressure.
- Social benefit
- Fairness
- Safety
- Privacy
Microsoft Responsible AI
Six principles, notable for shipping with implementation tooling rather than alone.
- Fairness
- Reliability and safety
- Privacy and security
- Inclusiveness
IBM AI Ethics Board
A trust and transparency framework, with an external advisory board attached.
- Explainability
- Fairness
- Robustness
- Transparency
These are listed for reference and are not endorsements. The useful lesson from all three is structural rather than textual: a principle set only starts working once something in the organisation has the authority to apply it against a shipping deadline.
Implementation roadmap
A practical 36-week path to a working AI ethics programme. The weeks are indicative — the variable is how many AI systems already exist and how many of them anyone can currently name.
-
Weeks 1-6
Foundation
Decide what you believe, and find out what you actually run.
- Define the organisation's AI ethics principles
- Establish the AI ethics committee
- Build the AI system inventory
- Assess current ethics maturity honestly
-
Weeks 7-14
Framework development
Turn the principles into things a team can follow.
- Write the ethics policies and procedures
- Create the ethics impact assessment template
- Define fairness and bias standards
- Set the transparency requirements
-
Weeks 15-24
Implementation
Where the framework stops being a document and starts blocking things.
- Integrate ethics review into development
- Put bias assessment into the pipeline
- Train teams on the framework they now work under
- Stand up the monitoring that feeds review
-
Weeks 25-36
Maturity and scale
From one team doing it well to the whole estate doing it consistently.
- Run the first ethics audits
- Refine on what the audits found
- Extend coverage to every AI system
- Build external transparency reporting
Responsible AI maturity model
Five levels to place your organisation against. Read down until a row stops flattering you — that one is where you are.
| Level | What it looks like, and the test that decides it |
|---|---|
| Level 1 · Ad hoc | No documented principles, decisions taken case by case, limited awareness and no accountability structure. The test: ethics concerns are addressed only once a problem has already arrived. |
| Level 2 · Defined | Written principles, some training, informal reviews and basic documentation. The test: the framework exists, and it is not yet integrated into how anything actually gets built. |
| Level 3 · Managed | Mandatory reviews, a standing ethics committee, standardised assessment and a tracking system behind it. The test: an ethics review is required before deployment, and it has stopped something. |
| Level 4 · Optimised | Automated monitoring, regular audits, stakeholder engagement and metrics that are read. The test: ethics improvements are driven by data coming back from live systems. |
| Level 5 · Leading | Public transparency, external validation, research contribution and ecosystem influence. The test: other organisations use what you publish. |
Most organisations sit at level 1 or 2. Reaching level 3 usually takes twelve to eighteen months, and it is the level worth aiming at: it is the first one where the programme changes outcomes rather than describing them.
AI ethics policy repository
Ready-to-use AI ethics policy templates aligned to the UNESCO, IEEE and OECD principles, and mapped across to the EU AI Act, NIST AI RMF and ISO 42001.
Foundational policies
- AI Ethics Principles Statement
- Responsible AI Policy
- AI Ethics Committee Charter
- Ethical AI Development Standards
- AI Use Case Assessment
+ 3 more policies
Operational policies
- Fairness and Bias Policy
- AI Transparency Standards
- Privacy-Enhancing AI Policy
- Human Oversight Requirements
- Ethics Impact Assessment Procedure
+ 4 more policies
Governance policies
- AI Accountability Framework
- Ethics Review Board Procedures
- AI Incident Response Policy
- Stakeholder Engagement Plan
- Ethics Audit Protocol
+ 3 more policies
Frequently asked questions
What the subject is, how it sits against the regulations, and the questions that come up once a programme is actually being built.
What is AI ethics and governance?
A cross-cutting discipline that keeps AI systems developed and deployed responsibly, aligned with human values and accountable to the people they affect. Unlike a regulation it has no single text: it is the principles, frameworks, policies and practices that guide ethical decisions across an organisation.
How does AI ethics relate to regulations like the EU AI Act?
Ethics supplies the principles that most AI regulation was built from. The EU AI Act sets mandatory requirements; ethics frameworks are how an organisation goes past the minimum and builds something defensible. Fairness, transparency and accountability started as ethical claims and are now written into law, which is the direction of travel worth planning for.
What are the key AI ethics frameworks?
The UNESCO Recommendation on the Ethics of Artificial Intelligence, IEEE Ethically Aligned Design and the OECD AI Principles are the main international reference points. Corporate frameworks from Google, Microsoft and IBM are useful as worked examples of turning a principle set into something operational.
How does this relate to ISO 42001 and other standards?
Ethics supplies the principles and the values; ISO 42001 supplies the management system that carries them. Ethics decides what controls belong in your AI management system, and the standard decides how they are run and evidenced. Most organisations use one to guide the other rather than choosing between them.
How does ethics governance differ from AI risk management?
Ethics governance is about value alignment and responsible practice; risk management, in the NIST AI RMF sense, is about identifying and mitigating specific risks. Ethics supplies the why, risk management supplies the how. Run one without the other and you get either a statement nobody can act on or a control set nobody can justify.
Who should be on an AI ethics committee?
Technical people who understand what the system does, domain people from legal, compliance and privacy, business stakeholders from product and operations, and voices from outside the build — ethicists, civil society, or the community the system affects. Diversity of background is not decoration here; homogeneous committees reliably fail to see the harm that lands on people unlike them.
What is an ethics impact assessment?
A structured evaluation of the ethical risks and benefits of a system before it is deployed: fairness, privacy, transparency, accountability, safety and wider societal impact. It is close in shape to a privacy impact assessment and wider in scope, and its value comes from being done early enough that the answer can still change the design.
How long does it take to build an AI ethics programme?
Six to twelve months to establish the foundations — principles, governance structure, policies, training and the first processes. Real maturity takes longer; two to three years is normal before a managed level is applied consistently across every AI system rather than the flagship ones.
How do we measure whether ethics governance is working?
Quantitatively: the share of AI systems that have had an ethics review, concerns raised and closed, audit findings, time to resolve an issue. Qualitatively, and more usefully: whether people feel able to raise a concern, and whether a review has ever changed or stopped a release. A programme that has never blocked anything has not been tested.
How do we assess AI systems for fairness and bias?
Statistical parity across demographic groups, disparate impact testing, formal fairness metrics such as demographic parity, equalised odds and predictive parity, qualitative review of the training data, and monitoring of live outputs. The metrics conflict with each other by construction, so the important step is choosing which one matters for your use case, and recording the choice before you see what it produces.
What transparency should we actually provide?
It depends who is asking. Users need clear disclosure that AI is involved, an explanation they can act on, and information about data use. Regulators need technical documentation, risk assessments and compliance evidence. Internal teams need model cards, performance metrics and honest limitation documentation. Transparency that is not usable by its audience is not transparency.
How do we ensure meaningful human oversight?
Human-in-the-loop design for high-stakes decisions, explicit authority to override, training for reviewers, and enough time and information to form a judgement. The failure mode to design against is automation bias: a reviewer who approves every recommendation is evidence of a rubber stamp, not of oversight, and the override rate is the number that tells you which one you have.
What does an iDharma ethics review cover, and how long does it take?
It is scoped before you are charged. The variables are how many AI systems are in the estate, whether an inventory exists, and whether any governance structure is already running. We tell you the shape of all three after a short scoping call.
Ready to build a responsible AI programme?
Start with a review against the six pillars — the principles you have published, the structures meant to carry them, and whether either has ever changed a decision.
This page is guidance on how we scope an assessment, not legal advice. AI ethics has no single authoritative text; the UNESCO, IEEE and OECD documents are published in full, and where a scoping call turns on the wording, go to them rather than to this page.