Skip to content

Operationalizing IEEE 7003 in Modulos

This is the rollout playbook for IEEE Std 7003-2024 in Modulos. It assumes you are already oriented on the standard: the wanted/unwanted framing, the bias profile, and the lifecycle of activities (see the framework overview).

IEEE 7003 is a voluntary consensus standard, not a law. In the Modulos catalog its templates carry the Standard label, which reflects the instrument type. Its obligations bind only where an organization adopts the standard or commits to it contractually; where it is adopted, the bias-consideration process is auditable through the bias profile.

Most rollouts use the following structure:

  • One organization project with the OFF-25 framework template attached. This holds the organization-level foundations set once and consumed by every AI system: the conformance route and governance interface, the competency and advocacy resourcing, and the organizational values and bias policies that feed each system's values statement.
  • One AI-application project per in-scope AI system with the MFF-25 framework template attached. Each application project holds that system's bias-consideration process: the bias profile, the stakeholder reference set, the data provenance and mapping records, the risk and impact register, the evaluation record, and the ongoing-monitoring program.

OFF-25 carries 3 requirements (ORF-465ORF-467); MFF-25 carries 8 requirements (MRF-440MRF-447) — 11 in total. The two templates operate together: each system's values statement and boundaries of acceptability (app side) draw on the organizational values and policies (org side), and the governance interface (org side) is where each system's accountability structure connects.

Primary source

IEEE Std 7003-2024, IEEE Standard for Algorithmic Bias Considerations, Institute of Electrical and Electronics Engineers (IEEE). The standard is licensed; these pages paraphrase it and cite clauses by number and name, and reproduce no text from it.

The 11 requirements mapped to clauses

ClauseOrg requirements (OFF-25)App requirements (MFF-25)
Clause 1 / 4 — adoption, conformance, governanceORF-465 (adoption, conformance, and governance interface)
Clause 4 — bias-consideration setupMRF-440 (setup and boundaries of acceptability)
Clause 5 — the bias profileMRF-441 (the bias profile)
Clause 6 — stakeholder identificationORF-466 (competency, diversity, and advocacy resourcing)MRF-442 (stakeholder identification)
Clause 7 — data representationMRF-443 (data provenance and representation metadata), MRF-444 (data-stakeholder mapping and exploration)
Clause 8 — risk and impact assessmentMRF-445 (bias risk and impact assessment)
Clause 9.2 — design and output evaluationMRF-446 (design and output bias evaluation)
Clause 9.3 — ongoing evaluationMRF-447 (ongoing bias evaluation and drift monitoring)
Clause 4.2 — organizational inputsORF-467 (organizational values and bias policies)

The ORF-466 and ORF-467 org requirements feed several app activities rather than a single clause: competency and advocacy resourcing (ORF-466) supports stakeholder identification and the assessment teams, and the organizational values and policies (ORF-467) feed each system's values statement and boundaries of acceptability.

The organization layer (OFF-25)

The org layer is deliberately thin — three requirements — because IEEE 7003 is a per-system standard. What sits at the organization level is the material that would otherwise be re-derived for every system:

  • ORF-465 — Adoption, conformance, and governance interface. Explains the conformance routes IEEE 7003 permits — claiming conformance, a contractual supplier commitment, or in-house adoption (Clause 1.8) — which are optional, not a duty. Its one mandatory per-system duty is at the governance level: choosing an accountability structure and defining the interface between the bias-consideration process and the organizational governance framework (Clause 4). The new control OCF-369 evidences that governance interface; it is not a conformance declaration.
  • ORF-466 — Bias competency, diversity, and advocacy resourcing. Where sensitive attributes need representation, the organization checks whether they are present among the people assigned to bias consideration and brings in external advocates where they are not (Clause 4.4); and the diversity, competency, and cultural context of the people performing stakeholder identification are given consideration (Clauses 6.4–6.5). New control: OCF-370.
  • ORF-467 — Organizational values and bias policies. The organization identifies and uses the governance inputs it already has — diversity and inclusion policies, organizational values, documentation standards, and an inventory of responsible-innovation procedures (Clause 4.2 c) — which feed each system's values statement (Clause 4.4 f) and boundaries of acceptability (Clause 4.4 g). The standard treats these as inputs to draw on where they exist, not artifacts every organization must create, so this requirement reuses documentation-management controls rather than inventing a creation duty.

Where in Modulos (requirements, controls, evidence, comments)

SurfaceUse
Project dashboard Add FrameworkAttach OFF-25 to the organization project; attach MFF-25 to each in-scope AI-system project
Project → Settings → FrameworksManage attached frameworks — list, freeze, and update
Project → RequirementsTrack the OFF-25 / MFF-25 requirements; the owner reviews and attests fulfillment, moving status from Not fulfilled to Fulfilled
Project → ControlsDocument implemented measures — the bias profile, the stakeholder reference set, the provenance metadata, the mapping records, the risk register, the evaluation record, and the monitoring program — against the controls the template maps to each requirement
Project → EvidenceStore supporting artifacts (the versioned bias profile, stakeholder and attribute registers, dataset metadata, mapping and imbalance analyses, evaluation records, monitoring dashboards) and link them to the relevant control components
Comments and logs on each requirementCapture the rationale for fulfillment attestation, accepted-risk decisions, and the wanted/unwanted determinations

The bias profile is not a separate Modulos surface: it is realized as control-level evidence on MCF-661, with the underlying artifacts linked from each contributing requirement.

The control library: 10 new, 25 reused

The framework pair was built reuse-first: the setup, testing, monitoring, and governance duties map largely onto controls the platform already carries, while the artifacts unique to IEEE 7003 — the bias profile, the stakeholder reference set, the data-to-stakeholder mapping, the collection-condition metadata, the integrated evaluation record, and the drift program — needed new controls.

New controls. 10 controls were minted for this framework: 8 app-side (MCF-660MCF-667) and 2 org-side (OCF-369, OCF-370).

ControlNameAnchored requirementLevel
MCF-660Bias requirements, values statement, and boundaries of acceptabilityMRF-440App
MCF-661The bias profile (flagship)MRF-441App
MCF-662Stakeholder identification and attribute reference setMRF-442App
MCF-663Dataset collection-condition and proxy metadataMRF-443App
MCF-664Data-to-stakeholder representativeness mappingMRF-444App
MCF-665Design and output bias evaluation recordMRF-446App
MCF-666Ongoing bias evaluation programMRF-447App
MCF-667Bias risk and impact register with owner acceptanceMRF-445App
OCF-369Bias-process governance interfaceORF-465Org
OCF-370Sensitive-attribute representation and external advocacyORF-466Org

Reused controls. Beyond the new controls, MFF-25 reuses 17 shared controls and OFF-25 reuses 8, drawn from the platform's ISO 42001, NIST AI RMF, and EU AI Act estates — requirements documentation, data documentation, testing and evaluation, monitoring, feedback loops, and governance and policy controls.

Widened controls. Two existing controls were generalized so this framework could reuse them while keeping their EU-specific substance intact as named branches:

  • MCF-45 (bias feedback loops) — a neutral feedback-loop core, plus a named EU AI Act Article 15(4) branch for high-risk continuously-learning systems.
  • MCF-152 (accessibility) — a neutral accessible-design core, plus a named EU AI Act high-risk branch for the specified Union accessibility duties.

Foundations first, then the per-system lifecycle in the standard's own order:

  1. Org foundations. Make the available organizational values and policies usable (ORF-467), define the mandatory governance interface and note the applicable conformance route (ORF-465), and resource competency and advocacy (ORF-466).
  2. Per system — set the footing. Run the setup activity and open the bias profile (MRF-440, MRF-441).
  3. Per system — who and what data. Identify stakeholders and their attributes (MRF-442), document data provenance and proxies (MRF-443), and map data to impacted stakeholders (MRF-444).
  4. Per system — assess, evaluate, monitor. Run the risk and impact assessment (MRF-445), the design and output evaluation (MRF-446), and stand up the ongoing evaluation program (MRF-447).

The lifecycle is iterative: later findings feed back into earlier records through the bias profile, so the sequence is a first pass, not a one-time march.

Source attribution

The authoritative source is IEEE Std 7003-2024, IEEE Standard for Algorithmic Bias Considerations, published by IEEE. This page paraphrases the standard and references its clauses by number and name; no text from the standard is reproduced, per IEEE licensing. Requirement and control codes (MFF-25, OFF-25, MRF-, ORF-, MCF-, OCF-) are Modulos template identifiers, not IEEE references.

Disclaimer

This page is for general informational purposes and does not constitute legal advice. IEEE 7003 is a voluntary standard; conformance is not a legal obligation. Verify against the current published edition of IEEE Std 7003-2024.