Questions & Answers
What is ISO/IEC TR 24028?▼
ISO/IEC TR 24028 is a technical report providing guidance on AI system trustworthiness and security, including threat modeling, attack surface analysis, and risk assessment methodologies. It complements ISO 42001 by offering technical depth for AI-specific risks like adversarial attacks and data poisoning. For enterprises, this means moving beyond general IT security to address AI-unique vulnerabilities, ensuring compliance with the EU AI Act's stringent security requirements and the Taiwan AI Basic Law's emerging principles. It serves as a bridge between high-level AI governance and low-level technical controls, enabling a risk-based approach to AI deployment. This standard is critical for companies using large language models (LLMs) or autonomous decision-making systems where AI-specific risks are most prevalent.
How is ISO/IEC TR 24028 applied in enterprise risk management?▼
Implementation typically follows three phases: (1) AI Use Case Definition: Aligning with ISO 42001 to define the AI system's scope and intended purpose. (2) AI-Specific Threat Modeling: Using TR 24028 to identify threats like model inversion, membership inference, and evasion attacks, then mapping them against the NIST AI RTO framework. (3) Control Implementation & Verification: Deploying technical safeguards such as differential privacy, adversarial training, and input/output-level-sanitization. In a recent Taiwan manufacturing pilot, companies implementing these steps saw a 40% reduction in AI-related security incidents within the first six months. The key is integrating these AI risks into the existing enterprise risk management (ERM)-based on ISO 31000, ensuring that AI risks are not treated in isolation from traditional IT risks.
What challenges do Taiwan enterprises face when implementing ISO/IEC TR 24028? How to overcome them?▼
Taiwan enterprises face three primary challenges: (1) Talent Scarcity: AI security requires dual expertise in data science and cybersecurity. The solution is to invest in upskilling existing IT staff or partnering with specialized consultants like Winners Consulting Services Co., Ltd. (2) Tooling Gaps: Standardized tools for AI threat modeling are still emerging. Companies should adopt a hybrid approach, combining open-source tools (like G-SAIF or Adversarial Robustness Toolbox) with customized frameworks. (3) Regulatory Ambiguity: The EU AI Act and Taiwan's AI Basic Law are evolving at different speeds. The best strategy is to adopt the EU AI Act's higher compliance standard as the baseline, which future-proofs operations for both EU market access and local compliance. Effective implementation requires a phased approach: starting with high-impact AI systems before scaling to lower-risk applications.
Why choose Winners Consulting for ISO/IEC TR 24028?▼
Winners Consulting Services Co., Ltd. specializes in ISO/IEC TR 24028 for Taiwan enterprises, delivering compliant management systems within 90 days. Our team of experts provides end-to-turn assistance, from AI risk assessment to EU AI Act compliance certification. We have successfully guided over 100 companies through the complexities of AI governance and risk management. For a free mechanism diagnosis and to own your AI advantage, contact us at: https://winners.com.tw/contact
Related Services
Need help with compliance implementation?
Request Free Assessment