In May 2019 the OECD adopted the first intergovernmental standard on AI: five values-based principles, revised again in May 2024 for generative systems. Adhering countries commit to reflect them in national policy, and that is the only enforcement mechanism the instrument has ever had.
Nobody enforces them. Everybody drafts from them.
Five principles, revised in 2024 - and already the vocabulary of the diligence packs, board papers and questionnaires you already answer.
Our promise
“Principles are a position. Practice is evidence.”
Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $6,500, and nothing is charged until you approve it.
- Each additional tool
- $1,500
- Re-audit, same scope
- $4,200
- Renewal, every twelve months
- $5,500 locked
This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.
Request this auditA recommendation that binds nobody, in three chapters
Most organisations hold a responsible-AI page, a policy restating each principle in slightly different words, and a list of the data team’s models. Each is the right subject and the wrong artefact — alignment that cannot be evidenced is only a sentence written on a page that nobody checks.
Our review builds the position a careful reader can check. We inventory every AI system you build, buy or embed, answer the five principles in your own words with the gaps named, and tag each finding to the NIST, ISO 42001 and EU AI Act clause behind it, so it can be checked later.
Five principles, one written position.
Nobody checks that you agree with them. They check whether you can show it.
- Inclusive growth — benefit for the people affected
- Human rights and democratic values — fairness, privacy
- Transparency and explainability — one you can act on
- Robustness and accountability — a stop, and an owner
- Anyone selling to a buyer whose policy came from this text
- Multinationals needing one story across jurisdictions
- Vendors answering a customer’s diligence pack
- Boards, investors, and teams adopting NIST or ISO 42001
The commitment is theirs. The question is yours.
The organisation running the system
The Principles address "AI actors" - anyone who develops, deploys or operates an AI system - but they address you through a government rather than directly. Nobody fines you under them and no regulator examines you against them. What reaches you is everything drafted from them.
The governments who actually signed
The commitment is theirs. Adhering countries undertake to promote and implement the Principles in their own policy, which is why the same five headings keep reappearing in national AI strategies and regulator guidance that had no contact with each other. The OECD keeps the record of who has signed.
Non-binding is not unasked
The EU AI Act took its definition of an AI system from this text. Procurement questionnaires, diligence packs and board papers are written in its vocabulary whether or not they name it. You will be asked these five questions - by someone who can walk away - long before a regulator asks them.
“Nothing binds us, so there is nothing to show.”
Your questionnaire was drafted from these five.
A buyer who can walk away asks earlier than a regulator does.
- Who it is for
- Chief risk & compliance
- AI & data science
- General counsel
- Procurement & vendors
- Investor relations & ESG
- Public-sector bid teams
The EU AI Act’s definition of an “AI system” was drawn directly from this text. Scope your inventory to the one and you have scoped both.
Procurement questionnaires and diligence packs use this vocabulary whether or not they name it, and unlike the text they arrive with a deadline.
It was revised in May 2024 for generative systems. A statement written against the 2019 text describes an instrument that has moved.
Three questions. Then you’ll know.
No email, no signup. A starting point, not a determination.
Your scope check
Four moments, and only one is yours.
Three of these already happened, none of them asked you anything, and the fourth is the only one you can be ready for.
-
Adoption
May 2019The first intergovernmental standard on AI: five values-based principles and five policy recommendations.
-
Diffusion
The years afterThe same five headings turn up in national strategies, in regulator guidance and eventually in statute.
-
Revision
May 2024Updated for generative systems - the AI-system definition, information integrity and safety reworked.
-
Production
When you are askedA customer, an investor or a public buyer asks for your position on all five principles. That date is not yours.
Nothing here falls due, so nothing prompts anybody — and the first prompt is usually a procurement deadline. The answers are then written in a fortnight by whoever is free, which is how an organisation ends up publishing a claim it has never once tested.
What the Principles ask, what we ship
12 expectations, and the artefact that answers each one. Principle headings unverified.
- Inclusive growth and well-being Principle 1.1 - who benefits, and who does not
- A record that benefit and harm were weighed for the people affected, not only for the operator.
- Human rights and democratic values Principle 1.2 - fairness and privacy sit inside it
- Discrimination testing, and evidence that rights reached the design stage rather than the launch review.
- Transparency and explainability Principle 1.3 - meaningful, not merely available
- What is disclosed, to whom, and whether the explanation would mean anything to the person receiving it.
- Robustness, security and safety Principle 1.4 - across the whole life of a system
- Testing and monitoring evidence, plus a demonstrated ability to override, roll back or withdraw a system.
- Accountability Principle 1.5 - somebody answers for the outcome
- Named owners with real authority, and a traceable route from a finding to the change it actually caused.
- The definition of an AI system The wording other instruments borrowed
- Your inventory scoped to that definition, so one register answers this and the EU AI Act at the same time.
- Recommendations for policy makers The second half - addressed to governments, not you
- Named as out of scope in writing, so nobody spends a quarter building against somebody else's commitment.
- A written position per principle Most hold a responsible-AI page on the website
- Five positions in your own words, with the gaps named on the face of the document rather than smoothed over.
- Evidence rather than restatement Most hold a policy that repeats the principle back
- Test results, decisions and records - the artefacts a principle produces when it is actually operating.
- A complete AI inventory Most hold the models the data team owns
- Every system you build, buy or embed, including the generative tools that arrived through business teams.
- A map to what binds you Most hold four assessments that do not reconcile
- Each finding tagged to its NIST AI RMF category, ISO 42001 clause and EU AI Act article. One body of evidence.
- Something that survives a questionnaire Most hold answers assembled the week they were asked
- A standing answer pack that is true on the day it is sent, and dated so you know when it stops being true.
Your AI estate, independently read
From a ranking model to the assistant somebody expensed.
-
Inventory
Every AI system you build, buy or embed, and the decision each one reaches.
-
Assess and evidence
A position per principle, and the record that stands behind it rather than restates it.
-
Map and hand over
You see the draft first. Then the position, tagged to what actually binds you.
Why organisations choose iDharma for this
Genuinely independent
We build and resell no AI systems, and take no fee tied to what the review concludes here.
Written to the text
Every finding maps to the principle it answers, so a reader can check it against the source.
Mapped, not just scored
Findings carry their AI RMF, ISO 42001 and EU AI Act tags in the base scope, not as an extra.
A position, not a policy
What lands says what you do and where you fall short - which is what a serious asker reads for.
Four marks, struck on every position we write.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
OECD alignment position
The written position, drafted to the five principles in order: each one answered in your own words, with the gaps named on the face of the document rather than buried behind it, and every finding tagged to the NIST, ISO and EU AI Act clause that stands behind it, so a procurement reviewer can check the answer without asking you for it.
AI system register
Every AI system, the decision it reaches, who owns it, and whether it was built, bought, or arrived embedded in something else.
Evidence file per principle
What stands behind each of the five claims - tests, decisions and records, with the method stated so it still reads a year later.
Cross-framework map
Each finding tagged to its NIST AI RMF category, ISO 42001 clause and EU AI Act article, so one assessment answers several askers.
Questionnaire answer pack
Standing answers to the responsible-AI questions buyers and investors actually ask, dated so you know when they stop being true.
Escalation route
How a finding becomes a change: escalation, decision, remediation and re-test, with a named owner at each step of it.
Board and disclosure memo
What can be said publicly, what cannot be said yet, and the difference between them - written so it survives being quoted back at you.
Real numbers, upfront.
- Scope
- Five principles, not five opinions
- Input
- Your systems and your records
- Re-review
- On material change — $5,500 against your known baseline
The text fixed the scope, not us, so the fee is flat - nothing to meter, and nothing charged until you approve.
Request this review- The written alignment position
- AI system register across the estate
- Evidence per principle, method stated
- Cross-framework map and the answer pack
Four things you have to be able to produce
The Principles prescribe no format. Each of these is either in your hand on the day a reader asks, or it is not.
The register,
whole
Every AI system you build, buy or embed, with its owner and the decision it reaches. A published position cannot cover a use that nobody has written down.
The position,
stated
Five principles answered in your own words, dated and approved, with the gaps named on the face of the document rather than left to be inferred from what is missing.
The evidence,
behind it
Test results, decisions and records rather than a policy that repeats the principle back in its own words. This is the limb almost every alignment claim is missing.
The map,
across
How each finding lands against the frameworks that do bind you, so one body of evidence answers four askers instead of four separate exercises run four times over.
Four cards, and the date on each one is part of the card.
Plain answers
Binding, certification, and what it maps to. Answered straight.
Request this reviewAre the OECD AI Principles legally binding?
Not on you. They are an intergovernmental recommendation that adhering governments commit to reflect in their own policy. Where they bite is indirectly - through the national frameworks, regulator guidance and procurement terms drafted from them.
Can we be certified against them?
No. There is no certification scheme and no conformity assessment. What you can do is state a position, evidence it, and have that evidence stand up - which is the useful version of the same thing.
How do they relate to NIST AI RMF, ISO 42001 and the EU AI Act?
They sit underneath all three. AI RMF gives you a structure for the risk work, ISO 42001 a certifiable management system, the EU AI Act a binding obligation - and the Principles describe what all three are for. Findings map cleanly between them, which is why we tag them.
Is this worth doing if the EU AI Act already applies to us?
Build to the Act - it binds you and the Principles do not. This earns its place explaining to a board, a customer or a regulator in another jurisdiction how the pieces fit together, from one body of evidence rather than four.
What changed in the 2024 revision?
It was updated for generative AI - the definition of an AI system, information integrity, and parts of the safety principle. An alignment statement written against the 2019 text is describing an instrument that has since moved.
Request an alignment review
Tell us where AI reaches a decision and we come back within one business day.
What we need from you
Nothing you do not already have. Most of it comes out of your existing governance records in an afternoon, and we name exactly which extracts before you commit.
- The jurisdictions you operate and sell in
- Which decisions your AI systems reach, and whose
- Your AI inventory, if you already have one
- Anything you have already published about responsible AI
- Whether a questionnaire or tender is in front of you
What happens next
- We agree the scope with you first.
- Three to six weeks, longer for a large inventory.
- Nothing is charged until you approve the scope.
Where this page gets its facts
Where the claims on this page come from, and what they are worth - stated, not assumed.
What it is drawn from
- OECD Recommendation of the Council on AI
- The OECD.AI Policy Observatory record
- Adopted
- May 2019
- Revised
- May 2024
What it means
- General information about what the Principles ask for — not legal advice, and no professional relationship.
- Nothing here is a certification, because none exists. Where a scope question is genuinely arguable, our reports say so rather than pick the convenient answer.
Scope & limitation
- Written from general knowledge of the Recommendation, not line-checked against the text. The principle headings in the ledger are the least certain part, and no count of adhering countries appears anywhere on this page.
- It covers the Principles alone - the frameworks drafted from them bind you separately.
- On an engagement we work from the current text. Use this as a starting point for a scoping conversation, not as your final word.
Something on this page out of date?
Tell usFrom Insights
Before you commission one
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
ISO/IEC 42001, SOC 2 and NIST AI RMF: Which One Your Buyer Is Actually Asking For
One certifies an organisation, one is an opinion about controls over a window, one is a method with nothing to issue. What each covers — and what none of them answers.