The first intergovernmental standard on AI, and the quiet common denominator under the EU AI Act, the NIST AI Risk Management Framework and the G20 principles. Five value-based principles for everyone who builds or deploys one, and five recommendations for governments.
The OECD principles every other AI regime borrows from.
Five principles, forty-seven adherents, no certificate - and the definition the EU AI Act runs on.
Our promise
“Principles are a position. Practice is evidence.”
Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $6,500, and nothing is charged until you approve it.
- Each additional tool
- $1,500
- Re-audit, same scope
- $4,200
- Renewal, every twelve months
- $5,500 locked
This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.
Request this auditThe Recommendation, in three chapters
Adherence is a political commitment made by forty-seven governments, not a certificate anybody can issue you. What organisations actually publish is a claim — on a policy page, in an RFP answer, in an investor deck — and a claim with nothing dated behind it is what a buyer can test.
Our review is the independent read. We take every system through all five principles, record what is evidenced, what is merely asserted and what is absent, and map each finding onward to the EU AI Act, the NIST AI RMF and ISO/IEC 42001 — so a finding can be checked against its source.
Two halves. Only one is yours.
It asks everyone for five things, and governments for five more.
- Inclusive growth - sustainable development and well-being
- Human rights - democratic values, fairness and privacy
- Transparency - and explainability, for its audience
- Robustness and accountability - safety, and an owner
- Investment - in AI research and development
- Ecosystem - an inclusive digital one, and its data
- Governance - an agile, interoperable policy environment
- Capacity and co-operation - skills, and across borders
The principle is theirs. The evidence is yours.
The organisation making the claim
Nothing in the Recommendation binds you directly. What can be held against you is the statement you have already published about it - on a policy page, in an RFP answer, in a vendor questionnaire, in an investor deck. That is a representation about your AI, and anybody can test it.
The adherent that actually signed
Forty-seven adherents, the European Union among them, made a political commitment to promote these principles. That commitment sits with the state and is discharged by legislating - which is why the text keeps turning up inside laws that do bind you, and never as a duty filed by you.
When a principle turns into a rule
The OECD definition of an AI system was adopted near-verbatim into the EU AI Act, and the NIST AI RMF's trustworthiness characteristics track the five principles closely. Ignore the Recommendation and you are still being measured against its vocabulary, in instruments that bind.
“We’ve adopted the OECD principles, so we’re aligned.”
Adoption is a claim. Evidence is what answers it.
It is the most common finding we write up.
- Who it is for
- AI product teams
- SaaS & platform vendors
- Public-sector suppliers
- Legal & compliance
- Investor & board reporting
The EU AI Act carries the OECD definition of an AI system almost word for word, so scoping under that Act already applies this text - with real penalties behind it.
Enterprise questionnaires, public-sector tenders and investor diligence ask about these principles by name, and answers get compared across bidders.
Nothing about a commitment being voluntary makes it exempt from being accurate. A published claim is checkable from outside, by anyone.
Three questions. Then you’ll know.
No email, no signup. A starting point, not a determination.
Your alignment check
Four moments, and the text kept moving.
Two of these are history and two are still doing work today - so a commitment written against the 2019 text is a commitment to a document that has changed.
-
Agreed
Adopted May 2019The first intergovernmental standard on AI, adopted by the OECD Council on 22 May 2019 as OECD/LEGAL/0449.
-
Echoed
Endorsed June 2019Weeks later the G20 endorsed AI principles drawn from the same text, taking its reach well past the OECD.
-
Rewritten
Revised May 2024Generative AI forced a revision: safety sharpened, and IP, privacy and information integrity written in.
-
Binding
Borrowed sinceIts definition of an AI system now sits inside the EU AI Act, where the same words carry real penalties.
Teams cite “the OECD AI Principles” and mean the 2019 ones. The May 2024 revision added information integrity, intellectual property and privacy - three things a statement written before it does not cover at all.
What the principles ask, what we ship
12 things to hold, and the artefact that evidences each one. Paired, so every claim on this page can be checked against the requirement beside it.
- The claim you already publish Policy pages, RFP answers, investor decks
- Every place you assert OECD alignment, collected - and what actually stands behind each one.
- Whose commitment it is A Recommendation binds governments, not you
- A written determination of what adherence means here, so a political commitment is never sold as a certificate.
- Inclusive growth and well-being Principle 1.1 - the purpose, examined
- Whether the purpose of each system was ever assessed for who it benefits and who it costs.
- Human rights and democratic values Principle 1.2 - broadened in the 2024 revision
- Rule-of-law, fairness, privacy and diversity safeguards traced across the lifecycle, with human intervention where appropriate.
- Transparency Principle 1.3 - meaningful to the audience
- Whether the people who meet a system know it is AI, tested on the disclosure they actually receive.
- Explainability Principle 1.3 - the basis of an outcome
- Whether someone on the receiving end of an AI-informed decision can understand the basis of it.
- Robustness, security and safety Principle 1.4 - normal use, misuse, adverse conditions
- Behaviour under foreseeable misuse and adverse conditions, tested against the claim rather than assumed from it.
- Traceability Principle 1.4 - datasets, processes and decisions
- Traceability of data, processes and decisions, with override, repair and decommission paths that actually exist.
- Information integrity New in May 2024 - synthetic content and disinformation
- Marking, provenance and the misinformation exposure the 2019 text never anticipated, per system.
- Intellectual property and privacy New in May 2024 - named explicitly
- What your training data and your deployments do to third-party IP and to personal data, recorded.
- Accountability Principle 1.5 - it requires a named owner
- An identifiable owner per system, a risk-management approach across its lifecycle, and escalation that functions.
- Mapping onward EU AI Act, NIST AI RMF, ISO/IEC 42001
- Each finding mapped to the binding regime it also answers, so one assessment feeds several conversations.
Your AI estate, read against the five
From model providers to everyday deployers.
-
Inventory
Which AI systems you run, and which of the five principles each one touches.
-
Assess
Each system read against all five - evidenced, asserted, or absent.
-
Sign off and file
You see the draft first. Then the report and the regime mapping - dated.
Why teams choose iDharma to read the principles with them
Genuinely independent
We build, resell and operate no AI systems of our own, and take no fee tied to what we find.
Written to the principle
Every finding names the principle it answers, so a reader can check it against the source.
One reading, several regimes
Findings map onward to the EU AI Act, NIST AI RMF and ISO 42001, so nothing is read twice.
Evidence, not adherence
We report what is evidenced, what is only asserted, and what is absent - never one score.
Four marks, struck on every report.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
Principle-by-principle report
The full assessment in one document: every system read against all five value-based principles, each finding marked as evidenced, asserted without support, or absent, every one of them mapped onward to the EU AI Act, the NIST AI RMF and ISO/IEC 42001, and written in plain language rather than the OECD's.
AI system register
Every system, its purpose, its owner and its principle-by-principle standing, in a workbook your team can keep current after hand-over.
Alignment statement pack
Wording you can actually publish about your OECD standing, drafted to say only what the assessment found and dated so it can be checked.
Principle evidence index
The record broken into the five principles, showing what you already hold, what is thin, and what is missing altogether from each.
Scope memo
Which systems were in scope, which were not, and why each call was made - the written record behind your AI inventory.
Remediation shortlist
Where the gaps sit, what to do first, and why each one is where it is. Ranked by consequence to the people affected, not by ease of fixing.
Regime mapping memo
What each finding also answers under the EU AI Act, the NIST AI RMF and ISO/IEC 42001, so one reading feeds three conversations.
Real numbers, upfront.
- Scope
- Set by the Recommendation, not by us
- Input
- Your systems and what exists on them
- Re-read
- Annually, or on material change - $5,500 against your known baseline
The Recommendation fixed the scope, so the fee is flat - nothing to meter, and nothing charged until you approve.
Request your review- Independent principle-by-principle report
- System register, principle by principle
- Alignment wording, ready to publish
- Regime mapping memo included
Four things you have to be able to produce
A Recommendation is not graded on intent. Each of these is either in your hand on the day somebody asks, or it is not.
The purpose,
examined
A written account of what each system is for, who it benefits and who carries its cost. Principle 1.1 asks about purpose, and most estates have never been asked it.
The record,
assembled
What was examined against each of the five principles, what held, what did not, and on what date - the difference between a stated position and a press release.
The notice,
up front
The people who meet the system told that it is AI, and those affected by an outcome able to understand its basis. Principle 1.3 sets that test as meaningful to them, not to you.
The owner,
named
A person answerable for each system working as intended, with a risk-management approach across its whole lifecycle. Principle 1.5 turns the other four into work.
Four cards, and the date on each one is part of the card.
We already say we follow the OECD AI Principles. Is that a problem?
Only if nothing stands behind it. A published commitment is a representation about your AI, and the gap that hurts is not non-adherence - it is a public claim with no dated assessment underneath it.
Are the OECD AI Principles legally binding?
No. They are a Recommendation of the OECD Council: adherent governments make a political commitment, but no direct legal obligation lands on companies and there are no penalties. Their force is indirect.
What changed in the 2024 revision?
It answered generative AI: safety strengthened, intellectual property and privacy named explicitly, and information integrity added - synthetic content, misinformation and disinformation, which the 2019 text did not anticipate.
How do they relate to the EU AI Act and NIST AI RMF?
They are the shared ancestor. The EU AI Act adopted the OECD definition of an AI system almost verbatim, and the NIST AI RMF trustworthiness characteristics map closely onto the five principles.
How long does it take?
Typically two to four weeks from hand-over for a first reading, longer where the system count turns out to be bigger than expected - which it usually does. Scope is agreed before anything is charged.
Request your alignment review
Tell us about your AI systems and we come back with a scoping call within one business day.
What we need from you
Nothing you do not already have. Most of this is a folder someone can assemble in an afternoon, and we name every document first, in writing, before you commit.
- Which AI systems you build or use, and what each decides
- Where you already claim alignment with the principles
- Any documentation - model cards, DPIAs, minutes
- Whether you built the system, bought it, or modified one
- Your target date for publishing the claim, if you have one
What happens next
- You send the five items we need.
- You get a scoping call within one business day.
- Nothing is charged until you approve the scope.
Where this page gets its facts
Where the claims on this page come from, and what they are worth - stated, not assumed.
What it is drawn from
- OECD/LEGAL/0449 - Recommendation on AI
- The OECD May 2024 revision of that text
- Adopted
- 22 May 2019
- Revised
- May 2024
What it means
- General information about what the Recommendation asks for — not legal advice, and no professional relationship arises from reading it. It determines nothing about your own systems.
- Where a reading is arguable, our reports say so rather than the convenient one.
Scope & limitation
- The Recommendation is non-binding and confers no certification on anyone.
- It covers the OECD principles alone - the EU AI Act and GDPR reach the same systems.
- Use it as a starting point for a scoping conversation, not as your final word.
Something on this page out of date?
Tell usFrom Insights
Before you commission one
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
ISO/IEC 42001, SOC 2 and NIST AI RMF: Which One Your Buyer Is Actually Asking For
One certifies an organisation, one is an opinion about controls over a window, one is a method with nothing to issue. What each covers — and what none of them answers.