Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

trustworthy AI characteristics explained

Trustworthy AI Characteristics: A Clear Guide to NIST’s 7

The seven trustworthy AI characteristics in the NIST AI Risk Management Framework are the closest thing AI governance has to a shared vocabulary: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair with harmful bias managed. They appear in NIST’s Generative AI Profile as the tag on every risk, in the Playbook as the thing MEASURE 2 evaluates, and — under other names — in ISO/IEC 42001’s Annex C and the EU AI Act’s high-risk requirements.

This guide explains what each characteristic means in NIST’s own terms, how they relate to each other, the trade-offs the framework says you will face, and how to turn seven adjectives into things you can measure and evidence.

Trustworthy AI characteristics: the seven in the NIST AI RMF and how they relate
Valid and reliable is the base; accountable and transparent cuts across the rest.

The seven trustworthy AI characteristics

Characteristic What NIST means by it Typical evidence
Valid and reliable Validity: objective evidence the system meets the requirements of its intended use (drawing on ISO 9000). Reliability: performs as required, without failure, over time under given conditions (ISO/IEC TS 5723:2022). Accuracy, robustness and generalisation sit here Test results on held-out and out-of-distribution data; accuracy with false-positive and false-negative rates; drift monitoring
Safe Does not, under defined conditions, lead to a state in which human life, health, property or the environment is endangered (ISO/IEC TS 5723:2022). Risks of serious injury or death get the most urgent treatment Hazard analysis; safe-failure and human-intervention design; incident records; deployer guidance
Secure and resilient Resilient: withstands unexpected adverse events and returns to normal function. Secure: maintains confidentiality, integrity and availability, including against adversarial use, data poisoning and model or data exfiltration Threat model; adversarial test results; access controls on endpoints; recovery tests
Accountable and transparent Transparency: information about the system and its outputs is available to those interacting with it, tailored to lifecycle stage and role. Accountability presupposes transparency and rests on defined roles Model and system cards; disclosure at point of use; named owners; decision records
Explainable and interpretable Explainability: a representation of the mechanisms behind the system’s operation. Interpretability: the meaning of outputs in the context of their designed purpose Explanation methods and their limits; user-facing rationale; documentation of what cannot be explained
Privacy-enhanced Norms and practices safeguarding autonomy, identity and dignity — freedom from intrusion, limits on observation, agency over disclosure (the NIST Privacy Framework) DPIA or equivalent; data minimisation; privacy-enhancing techniques and their accuracy cost
Fair — with harmful bias managed Equality and equity concerns, addressed by managing harmful bias and discrimination. NIST names three bias categories: systemic, computational and statistical, and human-cognitive. Mitigating bias does not by itself make a system fair Disparity metrics across groups; bias testing across the three categories; review of decision thresholds

How the trustworthy AI characteristics relate to each other

The framework does not present the trustworthy AI characteristics as a flat list. In its figure of the characteristics, valid and reliable is drawn as the base — a necessary condition for trustworthiness — and accountable and transparent is drawn as a vertical box because it relates to all the others. The remaining five sit between. The reading is practical: a system that is not valid cannot be trusted regardless of its other properties, and no property can be assured without the transparency to see it and the accountability to answer for it.

Two further statements from NIST matter for how you use the set. Trustworthiness is a social concept that ranges across a spectrum and is only as strong as its weakest characteristic. And creating trustworthy AI requires balancing the characteristics based on the system’s context of use — rarely do all apply equally in every setting, and some will matter more than others in any given situation.

Trustworthy AI characteristics in tension: the trade-offs NIST expects you to make

The framework names the tensions between trustworthy AI characteristics rather than pretending they do not exist:

  • Interpretability versus privacy. Exposing how a model reasons can expose the data it reasons from.
  • Predictive accuracy versus interpretability. The most accurate model is often the least explainable.
  • Privacy-enhancing techniques versus accuracy. Under data sparsity, privacy protection can reduce accuracy, which in turn affects fairness and other characteristics.

The governance implication is that a trade-off decision is itself an artefact. Record which characteristic was favoured, for which system, why, who decided, and what the residual risk is. GOVERN 1.3’s risk-tolerance statement is what those decisions are judged against; MANAGE 1.4’s residual-risk documentation is where they land.

Turning trustworthy AI characteristics into measurements

MEASURE 2 of the Core asks that AI systems are evaluated for trustworthy AI characteristics, and its subcategories follow the seven in order — accuracy and reliability, safety, security and resilience, transparency and accountability, explainability, privacy, fairness and bias. The working method:

  1. Decide which characteristics apply to this system, and how much. A back-office document classifier has a low safety weighting and a high validity one; a triage tool inverts that. Write the weighting down — it is the first thing an assessor asks about.
  2. Pick one or two metrics per applicable characteristic that you can compute with the data you have. MEASURE 1.1 asks you to start with the most significant risks and to document what will not or cannot be measured.
  3. Set the threshold from the tolerance statement, not from the metric’s convenience.
  4. Test before deployment and monitor after it (MANAGE 4.1), because validity and fairness both degrade as the world moves away from the training data.
  5. Record limits. A fairness metric computed on one protected attribute is not a fairness result; say so.

Our guide to NIST AI RMF implementation places this inside the eight-step programme.

Where the same trustworthy AI characteristics appear elsewhere

NIST characteristic ISO/IEC 42001 Annex C objective EU AI Act high-risk requirement
Valid and reliable Robustness; availability and quality of training and test data Art 15 accuracy and robustness; Art 10 data governance
Safe Safety Art 9 risk management (risks to health and safety); Annex I product safety law
Secure and resilient Security Art 15 cybersecurity and resilience
Accountable and transparent Accountability; transparency and explainability Art 13 transparency to deployers; Art 50 transparency to people; Art 17 QMS
Explainable and interpretable Transparency and explainability Art 13 instructions for use; Art 14 human oversight (understanding outputs)
Privacy-enhanced Privacy Art 4a (which replaced Art 10(5) in July 2026) — bias-detection processing of special-category data, within GDPR
Fair — with harmful bias managed Fairness Art 10 examination for possible biases; Art 27 fundamental rights impact assessment (where required)

The mapping is why the seven trustworthy AI characteristics are a good spine for a multi-framework programme: measure each one once and cite the measurement to whichever regime is asking. See ISO 42001 vs NIST AI RMF for the management-system side.

The trustworthy AI characteristics and the revision

NIST states that AI RMF 1.0 is being revised as part of the White House AI Action Plan, which directed the removal of references to misinformation, diversity, equity and inclusion, and climate change. No revised framework had been published as of September 2026, so the seven characteristics above remain the current text. Whatever the revision changes, the underlying properties — a model that works, does not hurt people, cannot be trivially attacked, can be explained and answered for — are the ones customers and regulators will keep asking about, so measuring them now is not wasted work.

Frequently asked questions

How many trustworthy AI characteristics does NIST define?
Seven: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair with harmful bias managed.

Do all seven apply to every AI system?
No. NIST says trade-offs are usually involved and that rarely do all characteristics apply in every setting. Decide the weighting per system and record it.

Which characteristic matters most?
Valid and reliable is described as the necessary condition and drawn as the base of the others. Beyond that, context decides — safety dominates where life or health is at stake.

Is ‘fair’ the same as ‘unbiased’?
No. NIST states that systems in which harmful biases are mitigated are not necessarily fair. Bias management is one input to fairness, which also depends on context and on decisions about equality and equity.

How do the trustworthy AI characteristics relate to the EU AI Act?
The Act does not use the list, but its high-risk requirements — accuracy, robustness, cybersecurity, transparency, human oversight, data governance — cover the same properties. Measurements made against the seven characteristics are reusable evidence for those articles.

Where this leaves you

Use the seven trustworthy AI characteristics as the axes of every AI evaluation you run: decide the weighting per system, pick metrics you can compute, set thresholds from your tolerance statement, record the trade-offs and the limits, and monitor after deployment. Validity is the floor, transparency is the frame, and the rest is a balance you have to justify — which is exactly what an assessor, a customer or a regulator will ask you to do.

References

More on AI governance

Evaluation templates built around the seven characteristics, with model and system card formats, are in the NIST AI RMF Toolkit (36 templates), or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.