IBM AI Ethics: The Real Framework (3 Principles, 5 Pillars)

IBM governs AI through two linked things: a centralised AI Ethics Board that reviews real use cases, and a published framework of three Principles for Trust and Transparency backed by five Pillars of Trust. The principles have guided IBM since 2018, and the model is one of the few from big tech built to be run day to day, not just announced in a press release.
If you came here asking which approach sits at the foundation of IBM's ethical AI governance, here's the short answer: the Principles for Trust and Transparency, operationalised by the Pillars of Trust and enforced by the AI Ethics Board. Not a list of "seven requirements." That seven-point list belongs to the EU's High-Level Expert Group, and people mix the two up constantly. We'll clear that up below.
What is IBM's AI Ethics Board?
The AI Ethics Board is a central, cross-company body that reviews how IBM builds and uses AI, and decides hard cases against IBM's principles. It pulls in a mix of stakeholders from across the business: technical, legal, research, policy, and product. IBM describes it as the centre of its AI ethics governance framework, the place where principles turn into actual decisions about products and partnerships.
What makes it work isn't the org chart. It's that the board has teeth. Projects get escalated to it, it can say no, and it feeds policy back down into how teams build. Plenty of companies wrote AI principles and stopped there. IBM built the body that has to live by them.
What are IBM's three Principles for Trust and Transparency?
These three principles, in place since 2018, are the foundation everything else hangs off:
- The purpose of AI is to augment human intelligence, not replace it. AI serves people; it doesn't make them redundant by design.
- Data and the insights from it belong to their creator. A client's data, and what you learn from it, stays the client's.
- Technology must be transparent and explainable, and it must work to reduce harmful or inappropriate bias.
Read them again and notice how concrete they are. Each one is a position you can be held to, not a vague aspiration.
What are the five Pillars of Trust?
The principles set the direction. The Pillars of Trust are the properties IBM engineers into systems to get there. They came out of IBM Research, and there are five:
| Pillar | What it means |
|---|---|
| Explainability | The system can give a human-readable reason for its outputs |
| Fairness | The system treats individuals and groups equitably for its context |
| Transparency | How the system was designed, trained, and tested is documented and shareable |
| Privacy | The system protects people's data and privacy rights |
| Robustness | The system handles edge cases and attacks without falling over |
Three principles, five pillars. That's the structure. If you see IBM's framework described as "seven core requirements," it's been confused with the EU High-Level Expert Group's seven requirements for trustworthy AI, which is a separate piece of work from a separate body. Getting this right matters, because procurement and audit teams check it.
How does IBM put the framework into practice?
This is the part most frameworks skip. IBM open-sourced the tooling that makes the pillars real, so teams aren't left to invent everything themselves:
- AI Fairness 360 - bias metrics and mitigation algorithms for testing models across groups.
- AI Explainability 360 - a set of methods for explaining model decisions to different audiences.
- Adversarial Robustness Toolbox - tooling to test and defend models against adversarial attacks.
- AI FactSheets - a documentation template, like a nutrition label for a model, covering how it was built, tested, and intended to be used.
The point of releasing these openly is that "trustworthy" becomes something you can measure and show, not just claim. That's the bar your own governance should aim for.
How does IBM's framework compare to other standards?
IBM's model isn't a rival to the main governance standards. It slots alongside them:
- Microsoft's Responsible AI Standard - similar principles, different in-house tooling.
- Google's Responsible AI Practices - heavier on developer guidance; IBM leans more on the central board.
- NIST AI Risk Management Framework - IBM's pillars give you concrete controls that feed NIST's govern-map-measure-manage cycle.
- ISO/IEC 42001 - IBM's board and documentation map cleanly onto ISO's management-system requirements.
The practical move is to pick your standard of record (often NIST or ISO 42001) and borrow IBM's board structure and tooling to actually deliver against it.
What does IBM's framework mean for your organisation?
You don't need IBM's budget to copy what matters. The transferable parts are the shape, not the brand:
- A standing body with the authority to review and stop AI projects.
- A short set of principles people can actually be held to.
- Measurable properties (the five pillars) wired into how you test and document systems.
- Honest documentation, so claims about a model can be checked.
Most organisations get the principles written and then stall on the board and the measurement. That gap, between a published policy and a system you can prove is fair and explainable, is where the risk lives. It's also where independent review earns its keep.
Frequently asked questions
Does IBM's framework have three principles or seven?
Three Principles for Trust and Transparency, supported by five Pillars of Trust. The "seven requirements for trustworthy AI" come from the EU's High-Level Expert Group, not IBM. They're often confused.
When was IBM's AI Ethics Board established?
IBM's Principles for Trust and Transparency date to 2018, and the AI Ethics Board is the central governance body that puts them into practice across the company.
Are IBM's trustworthy-AI tools free to use?
Yes. IBM open-sourced AI Fairness 360, AI Explainability 360, the Adversarial Robustness Toolbox, and the AI FactSheets approach, so any team can adopt them.
Can a smaller company copy IBM's model?
Yes, and it should copy the structure rather than the scale: a cross-functional review body, a few enforceable principles, and measurable controls for fairness, explainability, and robustness.
The bottom line
IBM's approach works because it joins three things most programmes keep apart: principles people are accountable to, a board with the authority to enforce them, and open tooling that turns "trustworthy" into something measurable. Adopt that chain and the framework does real work. Adopt only the principles, and you've got a policy nobody has to follow.
Want a Responsible AI governance model that holds up to a buyer's or regulator's scrutiny? That's the work we do at VerityAI. Start a conversation.
For hands-on help, see VerityAI's AI risk and compliance advisory.

Sotiris Spyrou
Sotiris Spyrou is the founder of VerityAI, a Responsible AI advisory for boards and AI-deploying businesses. With 27 years across agencies, global in-house roles, and the C-suite, he advises leaders on AI governance and risk, and on answer-engine visibility engineered without the dark patterns the rest of the industry is getting penalised for. He is the author of TRANSFORM, AI Moats, and Ethical AI.
Founder at VerityAI
Areas of Expertise: