Microsoft Responsible AI Standard: Six Principles, Made Enforceable

Microsoft's Responsible AI Standard is the company's internal rulebook for building and deploying AI. The public version, Standard v2, was released on 21 June 2022 and turns six principles, fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability, into concrete requirements teams have to meet before a system ships.
Most published AI ethics material stops at the principle. Microsoft's contribution is that it doesn't. The Standard takes each value, breaks it into goals, and then attaches specific requirements to each goal. That structure is what makes it worth reading, even if you never plan to use Microsoft's stack.
A note on what this is and isn't. We advise boards and regulated businesses on AI governance, and we use Microsoft's Standard as one reference point when we do. We don't sell software, and nothing here is a product pitch. It's a read of a public framework and how to borrow from it.
What is the Microsoft Responsible AI Standard?
The Standard is the framework Microsoft's own teams follow when they design, build, and release AI systems. Version 2 was published openly in June 2022 after roughly a year of work by a cross-functional working group of researchers, lawyers, designers, and engineers, per Microsoft's launch post.
Two things make it useful outside Microsoft. First, it covers the full lifecycle, from the first design conversation through deployment and ongoing monitoring. Second, it's written as obligations, not aspirations. Microsoft calls it a living document, and it gets revised as research, technology, and law move on.
What are Microsoft's six responsible AI principles?
The Standard rests on six principles, named exactly this way on Microsoft's principles page:
| Principle | What it asks of a system |
|---|---|
| Fairness | Treat people equitably; check for quality-of-service gaps and stereotyping across groups |
| Reliability and safety | Perform consistently and safely, including under conditions the team didn't anticipate |
| Privacy and security | Protect data through the lifecycle; guard against leakage and misuse |
| Inclusiveness | Design so a broad range of people, including those with disabilities, can use the system |
| Transparency | Make systems understandable; disclose capabilities and limitations |
| Accountability | Keep humans answerable for how systems behave; no system is the final word on decisions about people |
Worth flagging one detail, because a sibling framework write-up got this wrong elsewhere on this blog. Microsoft has six principles. Not seven. The seven-requirement structure people sometimes attach to Microsoft actually belongs to the EU's Ethics Guidelines for Trustworthy AI, a separate document from a separate body. If you see Microsoft credited with seven, someone has crossed the wires.
How does the Standard turn principles into requirements?
This is the part that earns the Standard its reputation. Microsoft doesn't leave "accountability" as a word on a slide. It uses a three-layer structure described in the launch post:
- Principle. The enduring value, for example accountability.
- Goal. What that value means in practice. For accountability, goals include impact assessments, oversight of significant adverse impacts, and human oversight and control.
- Requirement. The specific steps a team must take to meet the goal.
So accountability isn't a sentiment. It's a set of actions a team has to complete and evidence. That mapping, principle to goal to requirement, is the thing most worth copying if you're building your own governance.
What tools does Microsoft provide?
Microsoft pairs the Standard with practical resources. The ones that are real and documented:
- Impact Assessment template and guide. A structured way to map a system's stakeholders, intended benefits, and potential harms at the earliest design stage. Microsoft built this alongside Standard v2.
- Transparency Notes. Documentation that tells customers what a building-block technology can and can't do, so they don't deploy it for something it was never meant to handle.
- Responsible AI Toolbox. An open-source set of tools, including Fairlearn for assessing fairness and InterpretML for model interpretability, that engineers can run against their own models.
Microsoft's 2025 Responsible AI Transparency Report states the company has released 30 responsible AI tools carrying more than 155 features. Treat that as Microsoft's own count, not an independent audit.
Who governs responsible AI inside Microsoft?
The Standard only works because there's a structure enforcing it. Microsoft names three bodies, described in its 2025 Transparency Report and earlier governance posts:
- Office of Responsible AI. Set up in 2019 to coordinate governance centrally and own the Standard and Impact Assessment.
- Responsible AI Council. A regular forum bringing together research, policy, and engineering leaders with the senior business owners accountable for putting the rules into practice.
- Aether Committee. The research-led group (AI, Ethics and Effects in Engineering and Research), established in 2017, that keeps the Standard current.
The lesson for any board: a standard without an owner and an enforcement route is a document, not a control. Microsoft pairs the rulebook with named accountability. That pairing is the actual governance.
Where does the Standard fit with other frameworks?
Microsoft's Standard isn't a rival to the other big frameworks. It sits at a different layer.
- NIST AI Risk Management Framework. NIST gives you the risk-management loop (govern, map, measure, manage). Microsoft's requirements are the kind of concrete controls that loop calls for. In fact Microsoft now describes its own programme around that loop in its 2025 report.
- Google's Responsible AI Practices. Google leans toward developer-facing techniques and tooling. Microsoft leans toward enterprise process and documentation. They overlap, but the emphasis differs.
- IBM's AI ethics framework. IBM runs governance through its AI Ethics Board. Useful to compare against Microsoft's three-body model when you're deciding how to structure your own oversight.
How can a board borrow from the Standard?
You don't need Microsoft's scale to use its logic. The transferable parts:
- Name your principles, then refuse to stop there. Pick your values, then force each one down to a goal and a checkable requirement. A principle you can't audit isn't a control.
- Run an impact assessment before the build, not after. The cheapest time to spot a harm is in design. Borrow the structure of Microsoft's template: stakeholders, intended benefits, potential harms.
- Write transparency notes for systems you deploy. Even a one-page "what this does, what it can't do, where it shouldn't be used" cuts misuse.
- Give governance an owner. Decide who holds the equivalent of the Office of Responsible AI, who sits on the council, and who escalates. No owner, no enforcement.
Frequently asked questions
How many principles does the Microsoft Responsible AI Standard have?
Six. Fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability. Anyone citing seven is likely confusing it with the EU's Ethics Guidelines for Trustworthy AI, which is a different framework from a different organisation.
When was the Microsoft Responsible AI Standard v2 released?
21 June 2022. It replaced an earlier internal version after about a year of revision by a cross-functional working group. Microsoft treats it as a living document and continues to update its surrounding programme, most recently in its 2025 Responsible AI Transparency Report.
Is the Microsoft Responsible AI Standard free to use?
Yes. The General Requirements document for v2 is published openly, as is the Impact Assessment guide. You can read it, adapt its structure, and apply its logic to your own systems without using any Microsoft product.
What's the difference between the Standard and the Transparency Report?
The Standard is the internal rulebook teams must follow. The Transparency Report, published annually since 2024, is Microsoft's public account of how it applied that rulebook over the year, including tooling, red-teaming, and governance changes. One sets the rules; the other reports on them.
The bottom line
The strongest thing about Microsoft's Standard isn't any single principle. It's the discipline of pushing every principle down to a requirement a team has to meet and evidence. That's where most corporate AI ethics falls apart, the values get published and the requirements never get written. Copy the structure, not the brand. Map your principles to goals, your goals to checkable requirements, and put a named owner behind the lot. Do that and you've built a control, not a poster.
This is the kind of work our AI governance handles.

Sotiris Spyrou
Sotiris Spyrou is the founder of VerityAI, a Responsible AI advisory for boards and AI-deploying businesses. With 27 years across agencies, global in-house roles, and the C-suite, he advises leaders on AI governance and risk, and on answer-engine visibility engineered without the dark patterns the rest of the industry is getting penalised for. He is the author of TRANSFORM, AI Moats, and Ethical AI.
Founder at VerityAI
Areas of Expertise: