ISO AI Data Life Cycle Framework

ISO/IEC 8183:2023 - Information technology — Artificial intelligence — Data life cycle framework

ISO

RAI-XS-GO-ISOIEC8-2023

ISO/IEC 8183:2023

Effective: July 26, 2023
In Force(In Force)
StandardGovernance and OversightData Protection and PrivacyRisk Management
Export PDF

ISO/IEC 8183:2023 offers a comprehensive framework for managing data across the entire AI system life cycle, enhancing governance, quality, and security.

Overview

ISO/IEC 8183:2023, titled 'Information technology — Artificial intelligence — Data life cycle framework,' stands as a pivotal international standard providing a comprehensive structure for managing data throughout the entire life cycle of an Artificial Intelligence (AI) system. This document was developed by the Joint Technical Committee ISO/IEC JTC 1, Subcommittee SC 42, which is the leading global committee for AI standardization. Its primary purpose is to define the stages and associated actions for data processing, covering everything from the initial acquisition and creation of data to the development, deployment, maintenance, and eventual decommissioning of AI systems. The standard addresses the inherent complexity of AI data management by offering an overarching framework that aims to bring clarity, efficiency, and reliability to how organizations handle data, ensuring alignment with industry best practices.

The significance of ISO/IEC 8183:2023 lies in its foundational role for responsible AI development and operation. Data is the cornerstone of AI models, and its quality, quantity, and effective management directly influence an AI system's accuracy, reliability, and overall performance. By providing a structured approach to data processing, the standard helps organizations protect their data from loss, damage, and unauthorized access, while also mitigating risks such as breaches and data corruption. It emphasizes the crucial role of data processing at every stage of the AI system life cycle, thereby bolstering system governance, data quality, data security, and overall system utility. This framework is designed to be technology-agnostic, offering flexibility for diverse organizational needs and ensuring that data management considerations are integrated from conception to decommissioning.

Definitions

ISO/IEC 8183:2023 establishes a clear set of terms and definitions crucial for understanding the data life cycle within AI systems. While it refers to ISO/IEC 22989 for general AI concepts and terminology, the standard itself delineates specific terms central to its framework. A core concept is the 'AI system life cycle,' which encompasses the entire progression of an AI system from its earliest ideation to its eventual decommissioning, including all phases of data processing and system operation. Integral to this is the 'data life cycle framework,' which is the structured approach defining the distinct stages and associated actions that data undergoes within an AI system. This framework is designed to support objectives related to system governance, utility, data quality, and data security by ensuring data processing is duly considered at every phase.

Key stages within this framework are also implicitly defined through their described actions. For instance, 'data acquisition' refers to the process of obtaining or collecting data for use in an AI system, while 'data preparation' involves the crucial steps of cleaning, transforming, and organizing raw data into a usable format for the development, training, and testing of AI model development. Furthermore, 'data decommissioning' is a critical stage that addresses the secure and appropriate removal or archiving of data at the end of its useful life within an AI system, completing the circle of responsible data management. These definitions and the structured approach they underpin are vital for organizations to navigate the complexities of AI data management effectively, ensuring consistency and shared understanding across different contexts and applications.

Governance and Institutional Framework

The development of ISO/IEC 8183:2023 is a testament to the robust governance structure within the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). This standard was meticulously prepared by Joint Technical Committee ISO/IEC JTC 1, specifically its Subcommittee SC 42, which is dedicated to Artificial Intelligence. ISO/IEC JTC 1/SC 42 serves as the world's premier technical committee for AI standardization, with a comprehensive mandate covering the entire AI ecosystem. Its program of work includes foundational AI standards, data standards related to AI, big data and analytics, AI trustworthiness, use cases, applications, governance implications, computational approaches, testing, and ethical and societal concerns. This ensures that standards like ISO/IEC 8183 are developed with a holistic view of AI's impact and requirements.

The role of ISO/IEC JTC 1/SC 42 extends beyond mere document creation; it acts as the focal point for AI standardization within both ISO and IEC, providing guidance to other committees developing AI applications. The committee's collaborative efforts bring together global expertise from various fields, including technology, ethics, law, and business, ensuring a multidisciplinary approach to standard formulation. By establishing an overarching framework for AI data life cycles, ISO/IEC 8183:2023 directly contributes to the broader objective of sound AI governance. It helps organizations integrate responsible data management practices into their AI strategies, aligning with international best practices and fostering trust in AI technologies across global markets. This institutional framework ensures that AI standards are not only technically sound but also ethically and socially responsible.

Key Provisions

ISO/IEC 8183:2023 outlines a comprehensive data life cycle framework comprising ten distinct stages, guiding organizations through the entire process of data handling within an AI system. These stages are designed to provide a clear roadmap for data processing, from the initial conceptualization to the final decommissioning. The framework begins with 'stage 1 – idea conception,' where the need for a new or revised AI system is recognized. This is followed by 'stage 2 – business requirements,' where the scope, goals, and necessary resources for system development are defined, alongside acceptance criteria and detailed documentation of functional and non-functional requirements. These initial stages set the strategic foundation for data planning and subsequent technical activities.

The subsequent stages delve into the practical aspects of data management. 'Stage 3 – data planning' involves outlining data needs, including sourcing strategies, security protocols, and storage requirements. This leads to 'stage 4 – data acquisition,' the process of collecting or generating the identified data, and 'stage 5 – data preparation,' which includes cleaning, transforming, and organizing the data for model development. The core AI development phases are addressed in 'stage 6 – building model,' where the AI model is constructed using the prepared data, and 'stage 7 – system deployment,' where the AI system is put into operation. Finally, 'stage 8 – system operation' covers the ongoing use and monitoring of the AI system, while 'stage 9 – data decommissioning' and 'stage 10 – system decommissioning' address the responsible and secure removal or archiving of data and the entire AI system at the end of their life cycles. This structured approach ensures that data processing is systematically managed throughout the AI system's existence.

Scope and Application

The scope of ISO/IEC 8183:2023 is broad and inclusive, making it a highly versatile instrument for organizations engaged with Artificial Intelligence. This document explicitly defines the stages and identifies associated actions for data processing throughout the entire AI system life cycle. This includes critical phases such as data acquisition, creation, development, deployment, maintenance, and eventual decommissioning. A key characteristic of its scope is that it does not define specific services, platforms, or tools, thereby promoting a technology-agnostic approach. This flexibility ensures that organizations are free to implement the solutions best suited to their diverse needs and existing technological infrastructures, rather than being constrained by prescriptive technical mandates. The standard focuses on the 'what' and 'when' of data processing within the AI life cycle, leaving the 'how' to the implementing organizations.

Furthermore, ISO/IEC 8183:2023 is universally applicable to all organizations, irrespective of their type, size, or nature, that utilize data in the development and use of AI systems. This wide applicability means that from small startups to large multinational corporations, and across various sectors like healthcare, finance, and manufacturing, any entity dealing with AI data can leverage this framework. By providing a common understanding and a structured approach to data management, the standard facilitates consistency and best practices across different contexts. It is particularly valuable for organizations seeking to enhance data quality, ensure data security, and establish robust governance mechanisms for their AI initiatives, fostering a more responsible and efficient AI ecosystem globally.

Implementation Framework

Implementing ISO/IEC 8183:2023 involves integrating its comprehensive data life cycle framework into an organization's existing AI development and operational processes. The standard provides a practical and overarching guideline for organizing and managing the inherent complexities of AI data life cycles, applicable to all AI processes, not exclusively machine learning. Organizations are encouraged to embed risk considerations and data management practices into every stage of AI development and deployment. This begins by aligning the standard's ten stages with internal project management methodologies, ensuring that data planning, acquisition, preparation, and decommissioning are treated as integral components of the AI system's journey from conception to obsolescence. The framework is designed to enhance, rather than replace, current data management systems, allowing for a gap analysis to identify areas where AI-specific data risks might fall through existing cracks.

Adopting ISO/IEC 8183:2023 yields numerous benefits, including significantly enhanced data quality, improved compliance with relevant regulations, and increased operational efficiency. By standardizing data handling from inception to decommissioning, organizations can ensure that their AI models are built on a foundation of integrity and reliability. This structured approach helps in making data more accessible, usable, and secure, thereby maximizing its value for AI systems. Effective implementation requires a commitment to continuous review and adaptation, as AI systems and their associated data evolve. Organizations can start by establishing AI data taxonomies tailored to their specific use cases and risk appetites, leveraging the standard's comprehensive categories to prioritize and customize their data management strategies. This proactive integration of the data life cycle framework is crucial for developing and operating AI systems that are both efficient and compliant.

Monitoring and Evaluation

While ISO/IEC 8183:2023 primarily focuses on defining the stages of the AI data life cycle, its effective implementation inherently supports robust monitoring and evaluation practices for data quality and process adherence. The very nature of a structured life cycle framework necessitates ongoing oversight to ensure that data processing actions are applied as intended and that objectives related to system governance, data quality, and data security are consistently met. Organizations adopting this standard would naturally integrate checkpoints and metrics at each of the ten data life cycle stages to assess the quality of data, the effectiveness of preparation methods, and the security of data handling procedures. This continuous assessment helps in identifying deviations, potential biases, or vulnerabilities early in the AI system's development and operation, allowing for timely corrective actions.

Moreover, the principles embedded within ISO/IEC 8183:2023 align with broader AI governance and risk management standards that explicitly emphasize monitoring and review. For instance, related standards like ISO/IEC 23894:2023, which provides guidance on risk management for AI, underscore the importance of continuous monitoring and periodic reviews to ensure that risk management practices remain effective throughout the AI system lifecycle. By establishing clear data processing stages, ISO/IEC 8183:2023 provides the foundational structure upon which such monitoring and evaluation mechanisms can be built. This ensures that as AI systems evolve, their associated data risks and quality aspects are continuously tracked, enabling organizations to maintain alignment with organizational objectives, ethical expectations, and regulatory requirements, thus fostering trustworthy and sustainable AI deployment.

Relationship to Other Instruments

ISO/IEC 8183:2023 is an integral part of a growing ecosystem of international standards developed by ISO/IEC JTC 1/SC 42, designed to address various facets of Artificial Intelligence. It complements other key documents by focusing specifically on the data life cycle, while other standards tackle broader management systems, risk, or terminology. For instance, it works in conjunction with ISO/IEC 22989:2022 – Artificial intelligence — Concepts and terminology, which provides a common vocabulary for AI, ensuring consistent understanding of terms used within the data life cycle framework. Another closely related standard is ISO/IEC 23053:2022 – Information technology — Artificial intelligence — Framework for AI systems using machine learning, which offers a framework for AI systems more broadly, with ISO/IEC 8183 providing the detailed data management component within that larger system context.

Furthermore, ISO/IEC 8183:2023 is crucial for organizations implementing comprehensive AI governance strategies, particularly in relation to ISO/IEC 42001:2023 – Information technology — Artificial intelligence — Management system. While ISO/IEC 42001 sets the requirements for an Artificial Intelligence Management System (AIMS), covering governance, risk management, and impact assessments, ISO/IEC 8183 provides the specific guidance on managing the data that underpins these systems. Similarly, it supports the objectives of ISO/IEC 23894:2023 – Information technology — Artificial intelligence — Guidance on risk management, by ensuring data integrity and quality throughout the life cycle, which are critical factors in mitigating AI-specific risks like bias and data drift. The synergistic relationship among these standards allows organizations to build robust, trustworthy, and compliant AI systems by addressing data management as a fundamental element of responsible AI.

International Alignment

ISO/IEC 8183:2023, as an international standard developed by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), inherently promotes global alignment in Artificial Intelligence data governance. The collaborative development process, involving experts from numerous member countries through ISO/IEC JTC 1/SC 42, ensures that the framework reflects diverse cultural, regulatory, and technological contexts while maintaining universal applicability. This global consensus-building approach is fundamental to creating standards that can be adopted and recognized worldwide, fostering a common understanding and consistent practices for managing data in AI systems across different jurisdictions.

By providing a unified framework for the AI data life cycle, ISO/IEC 8183:2023 facilitates cross-border cooperation and reduces barriers to the international deployment of AI technologies. Organizations operating in multiple countries can leverage this standard to ensure their data management practices for AI are consistent and meet globally recognized benchmarks, thereby simplifying compliance efforts and enhancing trust among international stakeholders. The standard's technology-agnostic nature further supports international alignment by allowing various technological solutions to conform to the same foundational data life cycle principles. This global harmonization is critical for fostering responsible innovation and ensuring that AI development and deployment proceed with a shared commitment to data quality, security, and ethical considerations on a worldwide scale.

Implementation Timeline

MilestoneDateStatus
Standard Adoption2023-07-26Adopted
Standard In Force2023-07-26In Force
Organizational ImplementationOngoingUnderway by various organizations

Adoption and Endorsement

EntityDateStatus
International Organization for Standardization (ISO)2023-07-26Adopted
International Electrotechnical Commission (IEC)2023-07-26Adopted
ISO/IEC JTC 1/SC 42 (Artificial Intelligence)2023-07-26Developed and Adopted

Sources and References

SourceType
ISO/IEC 8183:2023 - Information technology — Artificial intelligence — Data life cycle frameworkofficial
ISO/IEC JTC 1/SC 42 (Artificial Intelligence)official
BS ISO/IEC 8183:2023 | 31 Oct 2023 - BSI Knowledgeofficial
SC 42 – Artificial Intelligence - JTC 1official
SIST EN ISO/IEC 8183:2024 - Information technology - Artificial intelligenceofficial
Plain English

ISO/IEC 8183:2023 provides a comprehensive framework for managing data throughout the entire lifecycle of an Artificial Intelligence (AI) system, applying to any organization that develops or uses AI.

This international standard, which came into force on July 26, 2023, is designed for all organizations, regardless of their type, size, or sector—from small startups to large multinational corporations in fields like healthcare, finance, or manufacturing. Its primary goal is to enhance governance, data quality, and security for AI systems by offering a structured approach to data handling.

The core of the standard is a ten-stage data lifecycle framework, guiding organizations from the initial idea conception of an AI system to its eventual decommissioning. Key actions it outlines include: - Thorough data planning, which involves outlining data needs, sourcing strategies, and security protocols. - Careful data acquisition and preparation, encompassing the cleaning, transforming, and organizing of raw data for model development. - Responsible data decommissioning, ensuring the secure removal or archiving of data at the end of its useful life within an AI system. The standard emphasizes integrating data management considerations at every phase to protect data from loss, damage, and unauthorized access, thereby mitigating risks like breaches and data corruption.

As an ISO standard, it does not carry direct legal penalties. However, adhering to this framework helps organizations align with international best practices for responsible AI development and operation. A practical point to note is that while the standard defines the "what" and "when" of data processing, it remains technology-agnostic. This means it doesn't prescribe specific services, platforms, or tools. Organizations are therefore responsible for determining the "how" of implementation, tailoring solutions to their unique technological infrastructure and needs. This flexibility can be both a benefit and a challenge, requiring internal expertise to translate the framework into concrete operational procedures.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 12 marked complete

Plain-English obligations under ISO AI Data Life Cycle Framework. Not legal advice — verify against the official text before relying on it.

  1. #1ImportantStage 2 – business requirementsBefore data planning

    Applies to: Organizations developing AI systems.

    'stage 2 – business requirements,' where the scope, goals, and necessary resources for system development are defined, alongside acceptance criteria and detailed documentation of functional and non-functional requirements.
  2. #2ImportantStage 3 – data planningBefore data acquisition

    Applies to: Organizations developing and using AI systems.

    'Stage 3 – data planning' involves outlining data needs, including sourcing strategies, security protocols, and storage requirements.
  3. #3ImportantStage 4 – data acquisitionBefore data preparation

    Applies to: Organizations developing and using AI systems.

    'stage 4 – data acquisition,' the process of collecting or generating the identified data
  4. #4ImportantStage 5 – data preparationBefore building AI models

    Applies to: Organizations developing and using AI systems.

    'stage 5 – data preparation,' which includes cleaning, transforming, and organizing the data for model development.
  5. #5ImportantStage 6 – building modelDuring model construction

    Applies to: Organizations developing and using AI systems.

    'stage 6 – building model,' where the AI model is constructed using the prepared data
  6. #6ImportantStage 8 – system operationDuring system operation

    Applies to: Organizations operating AI systems.

    'stage 8 – system operation' covers the ongoing use and monitoring of the AI system
  7. #7ImportantStage 9 – data decommissioningAt the end of data's useful life

    Applies to: Organizations operating AI systems.

    'stage 9 – data decommissioning' ... address the responsible and secure removal or archiving of data
  8. #8ImportantImplementation FrameworkOngoing

    Applies to: Organizations developing and deploying AI systems.

    Organizations are encouraged to embed risk considerations and data management practices into every stage of AI development and deployment.
  9. #9ImportantImplementation FrameworkOngoing

    Applies to: Organizations implementing the standard.

    aligning the standard's ten stages with internal project management methodologies, ensuring that data planning, acquisition, preparation, and decommissioning are treated as integral components
  10. #10ImportantMonitoring and EvaluationOngoing

    Applies to: Organizations adopting the standard.

    Organizations adopting this standard would naturally integrate checkpoints and metrics at each of the ten data life cycle stages to assess the quality of data, the effectiveness of preparation methods, and the security of data handling procedures.
  11. #11RecommendedImplementation FrameworkOngoing

    Applies to: Organizations implementing the standard.

    allowing for a gap analysis to identify areas where AI-specific data risks might fall through existing cracks.
  12. #12RecommendedImplementation FrameworkOngoing

    Applies to: Organizations implementing the standard.

    Organizations can start by establishing AI data taxonomies tailored to their specific use cases and risk appetites

© Regulations.AI — created on 12-Jun-2026 using Gemini 2.5 Flash