IEEE 7000
Evidence request list. 9 controls, 9 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
IEEE 7000 Concept Exploration
Clause 5.1 establishes Concept Exploration - the foundational step where the system context + boundaries + operational environment are defined. Per public IEEE 7000-2021 abstract + Wikipedia + academic literature on Value-Based Engineering (full IEEE text NOT reproduced): system purpose + scope + use cases + operational environment + sociotechnical context; intended users + non-users + affected parties + power dynamics + market context; technology maturity + technical constraints + organisational constraints + regulatory environment + cultural setting; identifying potential ethical concerns at concept level + sociotechnical risks; differentiation between intended and unintended uses; emergent behaviours; lifecycle stages (development + deployment + operation + decommissioning + post-decommissioning effects). The concept exploration provides foundation for subsequent value elicitation + e
- System definition + scope + boundaries documented + ConOps + OCD
- Use case + operational environment + intended/unintended uses + market context
- Sociotechnical context + affected parties + power dynamics + cultural setting analysis
- Lifecycle stage identification + development + deployment + operation + decommissioning + post-decommissioning
- Initial ethical concern register + sociotechnical risk + emergent behaviour anticipation
- System scope too narrow (only technical, missing sociotechnical)
- Use cases optimistic (no unintended use anticipation)
- Affected parties missed (only paying customers)
- Lifecycle stops at deployment (no decommissioning consideration)
- Ethical concerns only at end (no upfront surfacing)
IEEE 7000 Ethical Requirements
Clauses 7 + 7.1 establish ethical requirements definition and traceability. Per public IEEE 7000-2021 abstract + Wikipedia + academic literature (full IEEE text NOT reproduced): translate prioritised ethical values + stakeholder concerns into system requirements; functional ethical requirements (e.g. consent mechanism + bias detection + explainability interface) + non-functional ethical requirements (e.g. fairness threshold + privacy guarantee + transparency level); requirements specified using INCOSE SE Vision + IEEE Std 29148 + INCOSE Guide for Writing Requirements; SMART criteria (Specific + Measurable + Achievable + Relevant + Time-bound) + verifiable + traceable; value-based requirements traceability matrix linking each ethical requirement to: source value + stakeholder + use case + risk + verification method + acceptance criteria. Integration with system engineering process: requir
- Ethical requirements specification + functional + non-functional + INCOSE/IEEE 29148 alignment
- Requirements per SMART + verifiable + traceable + acceptance criteria
- Value-based traceability matrix + source value + stakeholder + use case + risk + verification
- AI model validation + bias + fairness + explainability + robustness + adversarial + drift testing
- Iterative refinement throughout V-model/Agile/DevOps lifecycle + change control
- Ethical requirements aspirational (not SMART or verifiable)
- INCOSE/IEEE 29148 not applied (informal requirements)
- Traceability matrix absent (cannot link value to verification)
- AI validation only at deployment (no ongoing testing)
- Ethical requirements frozen at start (no iterative refinement)
IEEE 7000 Ethical Risk + Validation
Clauses 8 + 8.1 + 8.2 establish ethical risk management and Clause 10 establishes validation of ethical outcomes. Per public IEEE 7000-2021 abstract + Wikipedia + academic literature (full IEEE text NOT reproduced): ethical risk identification covering: harm to individuals + groups + communities + environment + future generations; ethical risk analysis (likelihood + severity + reversibility + scope + remediation availability); ethical risk treatment: avoid + mitigate + transfer + accept with informed consent + monitor + redesign; integration with ISO 31000 risk management + ISO/IEC 23894 AI risk management. AI risk identification and assessment: training data risks + algorithm risks + deployment risks + operational risks + monitoring risks; AI system categorization by risk level (EU AI Act prohibited + high-risk + limited risk + minimal risk; NIST AI RMF mapping); risk-tiered controls. V
- Ethical risk register + identification + analysis + ISO 31000 + ISO/IEC 23894 alignment
- AI risk categorisation per EU AI Act risk levels + NIST AI RMF risk profile
- Ethical risk treatment per risk + mitigation + monitoring + acceptance with informed consent
- Validation of ethical outcomes + post-deployment monitoring + ethical KPI + user feedback + impact assessment
- AI safety + adversarial training + uncertainty quantification + concept drift + safe deployment + red team report
- Ethical risk register IT-focused (no harm to communities/environment)
- AI risk categorisation static (no EU AI Act conformity)
- Risk treatment paper-only (no actual mitigation)
- Validation of outcomes one-time (no ongoing monitoring)
- AI safety only at training (no operational red teaming or drift monitoring)
IEEE 7000 Governance + Culture + Integration
Governance + Culture + Integration cover organisational elements supporting IEEE 7000 implementation. Per public IEEE 7000-2021 abstract + Wikipedia + academic literature (full IEEE text NOT reproduced): governance + roles including: AI Ethics Officer + Ethics Review Board + Responsible AI Steering Committee + cross-functional team (engineering + legal + policy + UX + domain expert); accountability framework for AI systems per NIST AI RMF GOVERN + EU AI Act Article 17 quality management system + ISO/IEC 42001 management system; senior management commitment + Board ESG/AI oversight + reporting lines. Organisational culture and training: ethics in technology training + responsible AI training + role-based curriculum + onboarding + ongoing CPD; psychological safety + speaking-up culture + ethical concern reporting + whistleblower protection; ethical maturity assessment + cultural change man
- AI Ethics Governance + Ethics Officer + Review Board + Steering Committee + accountability framework
- Ethics training + role-based curriculum + onboarding + CPD + psychological safety + whistleblower protection
- System engineering integration + V-model + Agile + DevOps + MLOps + ethics gates + decision points
- Ethical KPI dashboard + responsible AI metrics + maturity model assessment + continuous improvement
- AI incident register + AIID reporting + regulatory compliance tracking + EU AI Act + national AI laws
- AI Ethics Officer nominal (no real authority or budget)
- Ethics training one-off (no role-based or ongoing)
- Integration siloed (ethics separate from engineering)
- KPIs financial-only (no ethical or responsible AI)
- Incident reporting absent (AI incidents not tracked or shared)
IEEE 7000 Operations + Lifecycle
Operations + Lifecycle cover IEEE 7000 in deployed system operation. Per public IEEE 7000-2021 abstract + Wikipedia + academic literature (full IEEE text NOT reproduced): monitoring in operation including: ethical KPIs continuous tracking + drift monitoring (concept drift + data drift + model performance degradation + ethical performance degradation) + complaint and grievance mechanism + user feedback channels + community engagement; threshold alerts when ethical performance breaches; ongoing AI risk monitoring + emerging risk identification + horizon scanning. Data governance throughout AI lifecycle: data provenance and lineage tracking (where data came from + transformations + access) per CDISC standards + Datasheets for Datasets + Data Catalogs (Apache Atlas + DataHub + Collibra); privacy protection in AI training data + differential privacy + federated learning + synthetic data + k-a
- Ethical KPI monitoring + drift detection + threshold alerts + user feedback + community engagement
- Data provenance + lineage tracking + Datasheets for Datasets + Apache Atlas + DataHub + Collibra
- Privacy protection + differential privacy + federated learning + synthetic data + GDPR + IEEE 7002
- Safe deployment + canary + blue-green + feature flags + kill-switch + monitoring + rollback procedure
- Decommissioning procedure + secure deletion + cryptographic erasure + sunset notification + alternative provision
- Ethical KPI monitoring at deployment only (no drift detection)
- Data provenance only at acquisition (no lineage through transformations)
- Privacy protection generic (no differential privacy or federated learning for high-risk)
- Deployment without canary/kill-switch (high blast radius on failure)
- Decommissioning without secure deletion + post-decommissioning monitoring
IEEE 7000 Scope + Family + Coordination
IEEE 7000-2021 IEEE Standard Model Process for Addressing Ethical Concerns During System Design - copyrighted IEEE standard published September 2021 by IEEE Standards Association (IEEE SA). First-of-its-kind standard providing engineers + technologists + organisations with a systematic methodology to translate ethical values into system design through a Value-Based Engineering (VBE) process. Outcome of IEEE Global Initiative on Ethics of Autonomous and Intelligent Systems (founded 2016) + IEEE Ethically Aligned Design (EAD) initiative. Part of IEEE 7000 family of standards: IEEE 7000-2021 (Model Process - parent standard) + IEEE 7001-2021 (Transparency of Autonomous Systems) + IEEE 7002-2022 (Data Privacy Process) + IEEE 7003 (Algorithmic Bias Considerations) + IEEE 7004 (Child and Student Data Governance) + IEEE 7005 (Employer Data Governance) + IEEE 7006 (Personal Data AI Agent Working
- IEEE 7000-2021 applicability assessment + system scope + ethical concern relevance per project
- Value-Based Engineering process adoption + organisational charter + integration with system engineering
- IEEE 7000 family alignment matrix + 7001 Transparency + 7002 Privacy + 7003 Bias + 7010 Wellbeing applicable
- Coordination with EU AI Act + NIST AI RMF + ISO/IEC 42001 + ISO/IEC 23894 risk + OECD AI Principles
- Adoption record of OECD AI Principles + UNESCO Ethics + Council of Europe + UN HRC + Singapore Model AI Governance
- IEEE 7000 referenced but VBE process not actually adopted
- Family standards not coordinated (using 7000 without 7001/7002/7003 where applicable)
- EU AI Act + NIST AI RMF + ISO 42001 treated as separate (no integration)
- OECD/UNESCO principles signed but not operationalised
- Coordination static (no update with 2024-2025 regulatory pipeline)
IEEE 7000 Stakeholders + Engagement
Clauses 5.2 + 5.3 establish stakeholder identification and engagement. Per public IEEE 7000-2021 abstract + Wikipedia + academic literature (full IEEE text NOT reproduced): stakeholder identification including: direct users (purchasers + operators); indirect users (affected by system use); marginalised + vulnerable + underrepresented populations (children + elderly + persons with disabilities + ethnic minorities + LGBTQ+ + low-income + migrant + indigenous + linguistic minorities); affected non-users (those whose lives are shaped without using the system); future generations + environment + non-human stakeholders; regulators + civil society + academic + media + investors; competitors + supply chain. Stakeholder engagement methods: workshops + interviews + focus groups + ethnographic study + design thinking sprints + participatory design + co-design + value-sensitive design (VSD) methods
- Stakeholder map + direct + indirect + marginalised + non-user + future + environment + non-human
- Marginalised + vulnerable stakeholder identification + engagement + accessibility + compensation
- Engagement methods + workshops + interviews + ethnographic + design thinking + advisory boards
- Human oversight mechanism per EU AI Act Article 14 + decision review + override capability + accountability
- Co-design + VSD application + value scenarios + iterative engagement + feedback loops
- Stakeholder mapping limited to paying customers (no indirect/marginalised)
- Marginalised engagement token only (no real influence on design)
- Engagement single-event (no iteration or follow-up)
- Human oversight nominal (no real override + accountability)
- Co-design + VSD methods not used (top-down design instead)
IEEE 7000 Transparency + Documentation + Audit
Clause 9 establishes transparency and communication. Per public IEEE 7000-2021 abstract + Wikipedia + academic literature (full IEEE text NOT reproduced): transparency throughout VBE process + transparency artifacts including: system documentation (purpose + scope + values + stakeholders + risks + design rationale + verification) + decision logs + value trade-off documentation + ethical requirement traceability + risk treatment evidence + validation evidence; communication to stakeholders + users + regulators + civil society in plain language adapted to audience. Process Documentation: VBE artifacts + meeting minutes + workshop outputs + ethical review board records + change history + version control. External Review and Assurance: independent ethics review + ethics board + community advisory board + academic review + third-party audit + certification per emerging standards (ISO/IEC 4200
- VBE process documentation + decision logs + value trade-offs + ethical requirements traceability + version control
- AI system documentation per EU AI Act Annex IV + Model Cards + Datasheets + IBM FactSheets
- Algorithmic transparency + SHAP + LIME + counterfactual explanations + feature importance + decision rules
- External ethics review + ethics board + community advisory + third-party audit + certification readiness
- User notification per EU AI Act Article 50 + watermarking (C2PA + SynthID) + GDPR Article 22
- VBE process not documented (no audit trail)
- AI documentation generic (no EU AI Act Annex IV compliance)
- Algorithmic transparency post-hoc explanations only (no SHAP/LIME)
- External ethics review absent (internal-only)
- User notification missing for AI interactions (deceptive UX)
IEEE 7000 Values + Ethical Concerns
Clauses 6 + 6.1 establish ethical values elicitation and prioritisation. Per public IEEE 7000-2021 abstract + Wikipedia + academic literature (full IEEE text NOT reproduced): elicit values from stakeholders covering categories: human autonomy + beneficence + non-maleficence + justice + dignity + privacy + transparency + accountability + fairness + sustainability + wellbeing + cultural sensitivity + human rights. Value prioritisation: multi-criteria decision analysis + analytic hierarchy process (AHP) + value-focused thinking + trade-off analysis when values conflict; precedence rules; ethical frameworks (consequentialism + deontology + virtue ethics + care ethics + capability approach) selection per context. IEEE 7000 family integration: IEEE 7001 Transparency (transparency levels per stakeholder type + technical means + user interfaces); IEEE 7002 Data Privacy Process (privacy by design
- Value elicitation + categories + stakeholder mapping + workshops + value scenarios
- Value prioritisation + AHP + MCDA + trade-off analysis + ethical framework selection per context
- IEEE 7001 transparency levels per stakeholder + technical means + UI/UX evidence
- IEEE 7002 privacy by design + 7003 bias considerations + bias measurement (Aequitas/Fairlearn/AIF360)
- IEEE 7010 wellbeing metrics + measurement + monitoring + impact
- Value elicitation theoretical (no real stakeholder workshops)
- Prioritisation arbitrary (no MCDA or AHP methodology)
- IEEE 7001 transparency not differentiated by stakeholder
- Privacy + bias considered separately (not integrated)
- Wellbeing metrics ignored (only financial KPIs)
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the IEEE 7000 framework page.