ISO AI Data Life Cycle Framework
ISO/IEC 8183:2023 — Information technology — Artificial intelligence — Data life cycle framework
ISO
RAI-XS-GO-ISODATA-2023This ISO/IEC standard provides a 10-stage framework for managing data across the entire AI system life cycle, ensuring quality and compliance.
Summary
Read full text ↗Plain English
Overview
ISO/IEC 8183:2023, titled “Information technology — Artificial intelligence — Data life cycle framework,” is a pivotal international standard that defines the stages and associated actions for data processing throughout the artificial intelligence (AI) system life cycle. Published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) on July 26, 2023, this document provides a comprehensive framework applicable to all organizations, regardless of their type, size, or nature, that engage in the development and use of AI systems. Its primary purpose is to bring much-needed clarity, efficiency, and reliability to the complex task of handling data within AI contexts, thereby fostering trust and responsible innovation.
The standard is instrumental in ensuring data quality, security, and compliance across various stages of an AI system's existence. It addresses critical challenges in AI implementation by offering a structured approach to data lifecycle management, optimizing AI system performance, and facilitating alignment with existing and emerging regulations. Notably, ISO/IEC 8183:2023 adopts a technology-agnostic approach, meaning it does not prescribe specific services, platforms, or tools, offering organizations the flexibility to implement solutions best suited to their individual needs and technological environments. This flexibility ensures its broad applicability and enduring relevance in a rapidly evolving AI landscape, promoting global harmonization in AI data practices and mitigating data-related risks.
By establishing a common understanding and methodology for data management in AI, the standard helps organizations navigate the complexities of data governance, from initial data collection to its eventual decommissioning. It underscores the importance of considering data aspects at every phase of AI development and deployment, which is crucial for building robust, fair, and transparent AI systems. This foundational standard supports the broader goal of trustworthy AI by providing a structured backbone for data integrity and accountability.
Definitions
For the purposes of ISO/IEC 8183:2023, key terms and definitions are primarily drawn from ISO/IEC 22989, “Information technology — Artificial intelligence — Artificial intelligence concepts and terminology.” This normative reference ensures a consistent understanding of fundamental AI concepts across related international standards, thereby reducing ambiguity and promoting interoperability in the global AI ecosystem. The document itself provides an overarching data life cycle framework, which encompasses all the stages through which data can pass within any system that utilizes data of any kind. This framework is designed to support objectives related to system governance, system utility, data quality, and data security by ensuring that data processing receives due consideration throughout the planning, development, use, and decommissioning phases of an AI system.
The standard also explicitly defines and uses abbreviated terms essential for understanding its content. For instance, 'AI' refers to Artificial Intelligence, and 'DPIA' stands for Data Protection Impact Assessment, highlighting the standard's consideration for privacy and ethical implications in data handling. The data life cycle for AI systems, as conceptualized in this document, covers the entire journey of data from the initial idea conception of a new AI system to its eventual decommissioning. It recognizes that while each stage is a distinct part of the data life cycle for an AI system, their detailed purpose and timing can be influenced by a multitude of societal, commercial, organizational, and technical factors. This comprehensive definitional approach ensures that all stakeholders, from technical developers to policy makers, can engage with the standard on a common linguistic and conceptual ground.
Understanding these definitions is critical for effective implementation, as they form the bedrock upon which the entire data life cycle framework is built. The emphasis on drawing from established international standards like ISO/IEC 22989 reinforces the commitment to a globally harmonized approach to AI terminology, which is essential for cross-border collaboration and regulatory alignment in the rapidly evolving field of artificial intelligence.
Governance and Institutional Framework
ISO/IEC 8183:2023 was developed under the purview of ISO/IEC JTC 1/SC 42, the Joint Technical Committee 1, Subcommittee 42, dedicated to Artificial Intelligence. This subcommittee serves as the world's premier technical committee for artificial intelligence standardization, bringing together global expertise to create unified standards that address ethical and societal concerns, risk management, and technical robustness in AI systems. SC 42's comprehensive mandate covers a wide array of AI-related areas, including foundational AI standards, data standards, big data and analytics, AI trustworthiness, use cases, governance implications, computational approaches, testing, and ethical and societal concerns.
The work of ISO/IEC JTC 1/SC 42 is crucial for fostering trust in AI technologies and ensuring that AI systems operate safely, ethically, and effectively across global markets. By providing guidance to other ISO and IEC committees developing AI applications, SC 42 acts as the focal point for AI standardization. ISO/IEC 8183:2023, as a product of this committee, inherently supports robust system governance, data quality, data security, and overall system utility. Its development process, involving national bodies from ISO and IEC member countries, ensures that the standard reflects a global consensus and is applicable in diverse cultural, regulatory, and technological contexts, thereby enhancing international cooperation in AI governance.
The collaborative nature of SC 42, involving experts from various countries and industries, ensures that the standard is not only technically sound but also addresses the practical challenges faced by organizations worldwide. This institutional framework provides the necessary credibility and authority for ISO/IEC 8183:2023 to be adopted as a benchmark for AI data lifecycle management globally, contributing significantly to the development of a coherent and responsible international AI landscape.
Key Provisions
The core of ISO/IEC 8183:2023 lies in its comprehensive ten-stage framework for the data life cycle within AI systems. This structured approach guides organizations through every phase of data processing, from the earliest conceptualization to the final decommissioning of both data and the AI system itself. The ten distinct stages outlined in the standard are:
- Idea conception: Initial phase where the need for an AI system and its potential data requirements are identified.
- Business requirements: Defining the specific objectives, functionalities, and performance criteria for the AI system, including data-related specifications.
- Data planning: Strategizing how data will be acquired, stored, processed, and managed throughout the AI system's lifecycle, considering ethical and legal aspects.
- Data acquisition: The process of collecting or generating the necessary data, ensuring its relevance, quality, and compliance with privacy regulations.
- Data preparation: Cleaning, transforming, and labeling data to make it suitable for training, validation, and testing AI models. This includes addressing biases and inconsistencies.
- Building model: Developing, training, and validating the AI model using the prepared data, iteratively refining its performance.
- System deployment: Integrating the trained AI model into its operational environment and making it accessible for its intended use.
- System operation: Ongoing monitoring, maintenance, and performance evaluation of the AI system in a live environment, including continuous data input and processing.
- Data decommissioning: Securely archiving or disposing of data that is no longer needed or relevant, adhering to retention policies and privacy requirements.
- System decommissioning: The final phase involving the retirement of the AI system and its associated infrastructure, ensuring all data and components are handled appropriately.
Each stage is accompanied by identified actions for data processing, ensuring a systematic and responsible approach to data management. This framework is designed to address the complexities of AI data lifecycles, providing detailed guidelines for their organization and management. It emphasizes the crucial role of appropriate data handling at every stage, aiming to bolster system governance, data quality, data security, and system utility. By standardizing how data is managed from its inception to its eventual retirement, the standard helps organizations ensure that their AI models are built on a foundation of integrity and reliability. This not only optimizes AI system performance but also aids in achieving compliance with various regulatory requirements, making it a fundamental tool for responsible AI implementation and fostering public trust.
Scope and Application
ISO/IEC 8183:2023 is broadly applicable to all organizations, irrespective of their size, type, or nature, that are involved in the development and utilization of AI systems. This wide scope ensures that the framework can be adopted by a diverse range of entities, from small startups to large multinational corporations, and across various sectors such as healthcare, finance, manufacturing, and public services. The standard specifically defines the stages and associated actions for data processing throughout the entire artificial intelligence (AI) system life cycle. This includes critical phases such as data acquisition, creation, development, deployment, maintenance, and eventual decommissioning, providing a holistic view of data management.
A key characteristic of this document is its technology-agnostic nature; it explicitly states that it does not define specific services, platforms, or tools. This design choice provides organizations with the flexibility to integrate the framework into their existing technological infrastructures and choose the most suitable solutions for their particular AI initiatives. By focusing on the overarching processes of data management rather than specific implementations, ISO/IEC 8183:2023 offers an adaptable structure that can be tailored to suit the diverse needs and operational contexts of different organizations, promoting consistency in data handling while allowing for innovation. This flexibility is crucial for its long-term relevance in a rapidly evolving technological landscape, ensuring that the standard remains applicable regardless of future advancements in AI technologies or specific vendor solutions. It empowers organizations to build robust data governance strategies that are both effective and future-proof.
Implementation Framework
The implementation framework provided by ISO/IEC 8183:2023 offers a practical and overarching guideline for organizing and managing the inherent complexities of AI data lifecycles. It is designed to be applicable to all AI processes, extending beyond just machine learning, thereby offering a holistic approach to data management within any AI system, including rule-based systems, expert systems, and other forms of artificial intelligence. Organizations adopting this standard can expect to benefit from enhanced data quality, improved compliance with international standards, and increased operational efficiency. The structured 10-stage lifecycle ensures that companies can maintain document traceability and transparency, which are essential for passing mandatory conformity assessments and demonstrating accountability.
By adhering to the guidelines set forth in ISO/IEC 8183:2023, companies can strategically address hurdles in AI implementation, such as data bias, privacy concerns, and security vulnerabilities. The standard serves as a technical roadmap for data governance, ensuring that training and validation datasets are representative, error-free, and handled responsibly and ethically from ideation to decommissioning. Its objective is to enable organizations to make better decisions by providing access to accurate and timely data, improving operational efficiency by reducing the time and cost associated with data management, and protecting data from loss, damage, and unauthorized access, thereby mitigating data risks. Furthermore, a robust implementation framework facilitates the integration of ethical considerations into data handling practices, aligning technical processes with broader societal values and regulatory expectations.
Monitoring and Evaluation
While ISO/IEC 8183:2023 primarily focuses on defining the stages and actions for data processing, its overarching goal of ensuring data quality, security, and compliance inherently supports robust monitoring and evaluation practices. The framework's emphasis on a structured, ten-stage data life cycle from conception to decommissioning establishes a foundation for continuous oversight. By outlining distinct phases such as data planning, acquisition, preparation, and decommissioning, the standard implicitly encourages organizations to track and assess data integrity and adherence to established protocols at each step. This systematic approach facilitates the identification of potential issues, allowing for timely corrective actions and continuous improvement in data management for AI systems.
The standard's contribution to traceability and transparency is also crucial for effective monitoring and evaluation. By providing detailed guidelines for managing the complexity of AI data lifecycles, it enables organizations to document their data handling processes thoroughly. This documentation is vital for internal reviews and external conformity assessments, where the ability to demonstrate adherence to the standard's provisions is paramount. Although the document does not explicitly detail specific monitoring mechanisms or reporting requirements, its framework is designed to support the achievement of objectives related to system governance, data quality, data security, and system utility, all of which necessitate ongoing evaluation to ensure their successful realization and maintenance. Regular audits and performance reviews, guided by the structured lifecycle, can help organizations ensure that their AI systems remain compliant, perform as expected, and continue to meet ethical and operational standards throughout their lifespan.
Relationship to Other Instruments
ISO/IEC 8183:2023 operates within a broader ecosystem of international AI governance instruments and is designed to complement several other key standards. It normatively references ISO/IEC 22989, “Information technology — Artificial intelligence — Artificial intelligence concepts and terminology,” ensuring a consistent vocabulary and conceptual foundation across related AI standards. This interconnectedness is vital for building a coherent and comprehensive framework for AI, preventing definitional inconsistencies and promoting clarity across different technical documents.
Furthermore, ISO/IEC 8183:2023 acts as a specialized data engine that significantly complements other prominent AI standards. It works in conjunction with ISO/IEC 42001, the international standard for Artificial Intelligence Management Systems (AIMS), which provides a certifiable framework for developing and deploying AI systems responsibly. While ISO/IEC 42001 focuses on the management system aspects, ISO/IEC 8183:2023 provides the detailed guidance for data handling, making them highly synergistic. It also supports ISO/IEC 23894, which focuses on risk management for AI, by ensuring that data-related risks are systematically identified and mitigated throughout the data lifecycle. By aligning with ISO 2023 and IEC directives and integrating with standards like ISO/IEC 5212 for data usage, ISO/IEC 8183:2023 enables organizations to create robust and integrated AI governance frameworks, ensuring seamless interoperability and consistent performance across various AI applications and regulatory landscapes. This layered approach to standardization ensures that all critical aspects of AI development and deployment, from data to management systems and risk, are comprehensively addressed.
International Alignment
As a joint publication of the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), ISO/IEC 8183:2023 is inherently designed for international alignment and global applicability. These two organizations form the specialized system for worldwide standardization, and their technical committees, including ISO/IEC JTC 1/SC 42, collaborate to develop International Standards. National bodies that are members of ISO or IEC actively participate in the development process, ensuring that the standards reflect a broad consensus and address diverse global needs and perspectives.
The standard's objective is to bring clarity, efficiency, and reliability to how organizations handle their data in AI systems, ensuring they are aligned with international industry best practices and compliance standards. This global harmonization reduces technical barriers to trade, facilitates cross-border data flows for AI development, and promotes a common understanding of responsible AI data practices. ISO/IEC JTC 1/SC 42, the committee responsible for this standard, actively collaborates with organizations worldwide, including national standards bodies, to ensure that the standards address diverse cultural, regulatory, and technological contexts while maintaining universal applicability. The adoption of ISO/IEC 8183:2023 by CEN as EN ISO/IEC 8183:2024 further underscores its international recognition and integration into regional standardization efforts, promoting global compatibility and reducing implementation costs for organizations operating across different markets. This widespread adoption signifies a collective commitment to establishing a unified and trustworthy framework for AI data management on a global scale.
Implementation Timeline
| Milestone | Date | Status |
|---|---|---|
| Publication of ISO/IEC 8183:2023 | 2023-07-26 | In Force |
Adoption and Endorsement
| Entity | Date | Status |
|---|---|---|
| ISO/IEC JTC 1/SC 42 | 2023-07-26 | Adopted |
| CEN (as EN ISO/IEC 8183:2024) | 2024 | Adopted |
Sources and References
| Source | Type |
|---|---|
| ISO/IEC 8183:2023 — Artificial intelligence — Data life cycle framework | official |
| Essential guidance on AI data lifecycle management - IEC | official |
| ISO/IEC JTC 1/SC 42 - Artificial intelligence | official |
| ISO/IEC 8183:2023 - EVS standard evs.ee | official |
| EN ISO/IEC 8183:2024 - AI Data Life Cycle Framework & Governance - iTeh Standards | official |
This international standard offers a 10-stage framework for managing data throughout the entire lifecycle of artificial intelligence (AI) systems, applying to all organizations that develop or use AI, regardless of their size or sector.
Published on July 26, 2023, this standard provides a comprehensive guide for handling data from the initial idea of an AI system to its eventual retirement. Its main goal is to ensure data quality, security, and compliance, helping organizations build trustworthy and effective AI.
Organizations in scope include any entity involved in creating, deploying, or operating AI systems. The standard outlines a ten-stage data management process, covering everything from initial concept and business requirements to building the AI model, system deployment, operation, and finally, data and system decommissioning. Key obligations for organizations include: - Systematically planning data handling, considering ethical and legal aspects. - Acquiring data ethically and compliantly, ensuring its relevance and quality. - Thoroughly preparing data, including cleaning, transforming, and actively addressing potential biases. - Securely decommissioning data when it is no longer needed, adhering to retention policies and privacy requirements.
This standard took effect on July 26, 2023. While ISO standards are generally voluntary and do not carry direct legal penalties, adopting this framework is crucial for demonstrating responsible AI practices. Failure to follow these guidelines can lead to poor AI system performance, increased operational risks, difficulty achieving other certifications (like ISO/IEC 42001 for AI Management Systems), and challenges in meeting regulatory expectations from bodies like the EU AI Act or data protection authorities.
A practical surprise for many might be that the standard is "technology-agnostic." It doesn't tell you which specific tools, platforms, or services to use. Instead, it provides the overarching process, leaving organizations to select and integrate the best technological solutions for their unique needs. This flexibility is powerful but also means organizations must invest in tailoring the framework to their specific environment.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 14 marked completePlain-English obligations under ISO AI Data Life Cycle Framework. Not legal advice — verify against the official text before relying on it.
- #1Important⏰ Throughout AI system lifecycle
Applies to: Organizations developing and using AI systems.
“This document provides a comprehensive framework applicable to all organizations... that engage in the development and use of AI systems.”
- #2Important⏰ Throughout AI system lifecycle
Applies to: Organizations developing and using AI systems.
“The standard is instrumental in ensuring data quality, security, and compliance across various stages of an AI system's existence.”
- #3Important⏰ Throughout AI system lifecycle
Applies to: Organizations developing and using AI systems.
“The structured 10-stage lifecycle ensures that companies can maintain document traceability and transparency.”
- #4Important⏰ Throughout AI system lifecycle
Applies to: Organizations developing and using AI systems.
“companies can strategically address hurdles in AI implementation, such as data bias, privacy concerns, and security vulnerabilities.”
- #5ImportantIdea conception (Stage 1)⏰ Before system development
Applies to: Organizations developing AI systems.
“Idea conception: Initial phase where the need for an AI system and its potential data requirements are identified.”
- #6ImportantBusiness requirements (Stage 2)⏰ Before system development
Applies to: Organizations developing AI systems.
“Business requirements: Defining the specific objectives, functionalities, and performance criteria for the AI system, including data-related specifications.”
- #7ImportantData planning (Stage 3)⏰ Before data acquisition
Applies to: Organizations developing AI systems.
“Data planning: Strategizing how data will be acquired, stored, processed, and managed throughout the AI system's lifecycle, considering ethical and legal aspects.”
- #8ImportantData acquisition (Stage 4)⏰ Before data preparation
Applies to: Organizations developing AI systems.
“Data acquisition: The process of collecting or generating the necessary data, ensuring its relevance, quality, and compliance with privacy regulations.”
- #9ImportantData preparation (Stage 5)⏰ Before model building
Applies to: Organizations developing AI systems.
“Data preparation: Cleaning, transforming, and labeling data... This includes addressing biases and inconsistencies.”
- #10ImportantBuilding model (Stage 6)⏰ Before system deployment
Applies to: Organizations developing AI systems.
“Building model: Developing, training, and validating the AI model using the prepared data, iteratively refining its performance.”
- #11ImportantSystem operation (Stage 8)⏰ Throughout system operation
Applies to: Organizations operating AI systems.
“System operation: Ongoing monitoring, maintenance, and performance evaluation of the AI system in a live environment.”
- #12ImportantData decommissioning (Stage 9)⏰ Upon data no longer being needed
Applies to: Organizations operating AI systems.
“Data decommissioning: Securely archiving or disposing of data that is no longer needed or relevant, adhering to retention policies and privacy requirements.”
- #13ImportantSystem decommissioning (Stage 10)⏰ Upon system retirement
Applies to: Organizations operating AI systems.
“System decommissioning: The final phase involving the retirement of the AI system and its associated infrastructure, ensuring all data and components are handled appropriately.”
- #14Recommended⏰ Throughout AI system lifecycle
Applies to: Organizations developing and using AI systems.
“a robust implementation framework facilitates the integration of ethical considerations into data handling practices.”
Related Regulations
ISO/IEC 8183:2023 - Information technology — Artificial intelligence — Data life cycle framework
ISO99% similar
ISO/IEC 5338:2023 — Information technology — Artificial intelligence — AI system life cycle processes
ISO93% similar
ISO/IEC 23894:2023 - Information technology — Artificial intelligence — Guidance on risk management
ISO89% similar
ISO/IEC 42006:2025 — Information technology — Artificial intelligence — Requirements for bodies providing audit and certification of artificial intelligence management systems
ISO88% similar
ISO/IEC 5259-1:2024 - Artificial intelligence — Data quality for analytics and machine learning (ML) — Part 1: Overview, terminology, and examples
ISO88% similar
© Regulations.AI — created on 12-Jun-2026 using Gemini 2.5 Flash