ISO/IEC TR 24028:2020 · Trustworthy AI · Evidence & Implementation Kit
Make your AI trustworthy to ISO 24028, without turning the technical report into controls yourself.
Every trustworthiness concern handed to you as an adopt-ready control, from adversarial and poisoning threats through bias, robustness, privacy and human oversight, with the evidence of trustworthy AI.
Trustworthy AI in a weekend, not a quarter.
Here is the honest situation. AI systems fail in ways traditional software does not: adversarial and poisoning attacks, model theft, bias, opacity and automation bias. ISO/IEC TR 24028 is the international overview of what makes AI trustworthy, the characteristics, the threats and the mitigations. Turning that into controls your teams apply across the AI lifecycle, and evidencing that your models are robust, fair and overseen, is real work, and a model deployed without adversarial testing or human oversight is exactly where trust breaks down.
This Kit removes that translation. It is every ISO 24028 concern written as an adopt-ready control you personalize in a weekend, with the evidence of trustworthy AI.
What you get, the moment you buy
31
Concerns as adopt-ready controls. Every ISO 24028 trustworthiness concern, from the characteristics and AI-specific threats through bias, robustness, privacy and human oversight, written so you personalize and apply it.
31
Evidence-of-trust checklists. For each control, exactly the records that show trustworthy AI, plus where AI trust breaks down, so you build assurance not assumption.
1
AI Trustworthiness Control Matrix, pre-built. Every control in a working spreadsheet, ready to record status and evidence location across the AI lifecycle.
1
Gap & Readiness Assessment. Score each control and the workbook returns your AI trustworthiness as a single percentage, and exactly what to fix next.
Grounded in ISO/IEC TR 24028:2020, with the trustworthiness characteristics, the AI-specific threats (adversarial attacks, poisoning, bias, opacity) and the mitigation measures called out. Editable Word and Excel files.
AI has threats traditional security misses
Adversarial examples, data poisoning, model inversion and automation bias are not in a normal security program. ISO 24028 names them. This Kit builds the AI-specific threat controls and their mitigations, so the risks unique to machine learning are handled, not assumed away.
What one control looks like
This is defending against adversarial and evasion attacks, a threat unique to AI. All 31 are built to this depth.
AIT-6 Defend against adversarial and evasion attacks AI THREATS
Implement this control
[Organization] shall assess each AI system for susceptibility to adversarial and evasion attacks in which perturbed inputs induce misclassification or unsafe behaviour, and shall implement proportionate defences such as input validation, adversarial training, perturbation detection, and confidence thresholding, documenting the residual risk where a decision has safety, financial, or rights consequences for affected people.
Practitioner note.
Adversarial and evasion attacks are core AI-specific threats catalogued in the vulnerabilities and threats clause of the report.
Evidence of trustworthy AI
- Adversarial susceptibility assessment per model
- Description of implemented input validation and detection defences
- Adversarial robustness test results
- Residual risk statement for high-consequence decisions
Common finding they raise: Evasion resistance is seldom tested; models are shipped assuming benign inputs, leaving high-consequence decisions exploitable by crafted perturbations.
Why this is not another template pack
- The evidence is the point. Trustworthy AI you cannot evidence is a claim. This tells you the records that show trustworthy AI and where trust breaks down, for every concern.
- The AI-specific threats built in. Adversarial attacks, poisoning, model theft, bias and opacity are written into the controls, the risks a normal security program misses.
- Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
- It compounds. ISO 24028 underpins ISO 42001 AI management and the ISO 23894 AI risk work, so this feeds your whole AI governance program.
Who buys this
Teams building or deploying AI, the ML, data science and AI governance leads who own trustworthiness, and consultants standing up responsible AI. Whether it is a first model or an AI governance program, you save weeks and walk in with the controls and evidence structured.
By the end of the weekend you will have
✓ An adopt-ready control for all 31 concerns
✓ A completed AI trustworthiness control matrix
✓ The evidence of trustworthy AI
✓ Your adversarial and bias controls defined
✓ A trustworthiness percentage and a fix list
✓ The AI-specific failure modes designed out
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
Is ISO 24028 certifiable? No. It is a technical report, an overview of AI trustworthiness. This Kit operationalizes it into controls, and it feeds an ISO 42001 AI management system.
Does it cover adversarial attacks? Yes. Adversarial and evasion attacks, poisoning and model theft are their own control group, because they are the threats unique to AI.
Does it cover human oversight? Yes. Controllability, human oversight and AI governance are a full control group.
What if it is not for me? A 30-day money-back guarantee.
Do not deploy AI and hope it is trustworthy.
Every ISO 24028 concern is fast to adopt with the Kit. It is instant, and it is guaranteed.
Add it to your cart and make your AI trustworthy this weekend.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com