UNESCO vs OECD vs IMDA: Which AI Ethics Framework Should Your Singapore Business Follow?
There are at least four international AI ethics frameworks competing for the attention of Singapore businesses: the OECD AI Principles (2019, updated 2024), the UNESCO Recommendation on the Ethics of Artificial Intelligence (2021), IMDA's Model AI Governance Framework for Generative AI (2024), and ISO/IEC 42001:2023. Each was developed by a different body, for a different audience, at a different level of abstraction. No business can — or should — treat them as four separate implementation projects. This article maps exactly how they relate, what each one is for, and which ones deserve your operational attention.
Too many frameworks, not enough time
The proliferation of AI governance frameworks is a genuine problem. Organisations that want to act responsibly on AI are confronted with a landscape where every major international body has published its own guidance, each with its own vocabulary, scope, and level of prescriptiveness. The OECD published its AI Principles in 2019 and updated them in 2024. UNESCO adopted its universally applicable Recommendation on the Ethics of AI in November 2021. IMDA published its Model AI Governance Framework for Generative AI in May 2024. ISO published the 42001 standard for AI management systems in December 2023. Singapore adopted it as SS ISO/IEC 42001:2024, with SAC certification pathways opening in February 2025.
For a Singapore business trying to make practical governance decisions, the question is not which framework is theoretically superior. The question is: which ones create real obligations or real advantages in the Singapore market, and how do they connect to each other? The answer is that they form a layered stack, not competing alternatives. Understanding the stack is the first step to avoiding the trap of framework paralysis — where a business reads all four documents, feels overwhelmed, and implements none of them coherently.
OECD AI Principles: the G20 baseline
The OECD AI Principles, first published in May 2019, were the first intergovernmental AI ethics standard to be adopted at scale. More than 46 countries have endorsed them, and the G20 AI Principles — adopted by the world's largest economies — are based directly on the OECD text. This matters for Singapore businesses even though Singapore is not an OECD member. As a G20 partner economy with deep trade relationships across G20 markets, Singapore companies engaging with clients, regulators, or procurement processes in those markets will encounter OECD-aligned expectations.
The five OECD AI Principles are: (1) Inclusive growth and sustainable development — AI should benefit people broadly, not concentrate gains in ways that deepen inequality; (2) Human-centred values and fairness — AI systems should respect human rights, democratic values, and the rule of law, and should not discriminate; (3) Transparency and explainability — those developing or deploying AI should be open about AI systems and enable meaningful explanation of outcomes; (4) Robustness, security, and safety — AI systems should function reliably and securely throughout their lifecycle, with appropriate risk assessment; and (5) Accountability — those involved in AI should be held accountable for the proper functioning of AI systems and their outcomes.
The 2024 update to the OECD Principles strengthened the treatment of risks specific to advanced AI systems, including generative AI, and introduced clearer language on the responsibilities of different actors in the AI value chain — developers, deployers, and users. For Singapore businesses that are deployers of AI systems built on third-party models, this distinction is directly relevant: the Principles make clear that deployers carry accountability for the AI systems they put into use, not only the original developers.
UNESCO Recommendation on Ethics of AI: the broadest scope
The UNESCO Recommendation on the Ethics of Artificial Intelligence, adopted by all 193 UNESCO member states in November 2021, is the broadest of any AI governance instrument. Its scope deliberately extends beyond the information technology or business governance perspective. The Recommendation addresses AI's impact on human rights, environmental sustainability, democracy, gender equality, cultural diversity, education, health, the economy, and international peace. It operates at the level of civilisational values rather than operational controls.
The UNESCO framework is grounded in four core values: respect for human rights and fundamental freedoms, protection of human dignity, flourishing of environments and ecosystems, and the principle of living together in an interconnected world with shared responsibility. These values give the Recommendation its reach but also its distance from the day-to-day decisions a Singapore business makes when deploying an AI system for customer service, procurement, or content generation.
For Singapore businesses, the UNESCO Recommendation is most useful at two moments: when developing an organisation-wide AI ethics policy or set of principles — where it provides the conceptual vocabulary and ethical grounding — and when engaging with international stakeholders, NGOs, or public sector bodies that take human rights and environmental impacts seriously. It is the "why we govern AI" framework. It tells you what values a responsible AI approach should uphold. It does not tell you how to conduct an AI risk assessment, what to document, or how to demonstrate governance to an auditor. For those operational questions, you need the frameworks that sit above it in the stack.
UNESCO sets the ethical foundation: the values AI governance should protect. OECD translates those values into government policy principles. IMDA translates those principles into Singapore business practice. ISO 42001 gives you a certifiable management system to implement and evidence that practice. Each layer depends on the one below it.
IMDA's Model AI Governance Framework: Singapore's operational guide
IMDA's Model AI Governance Framework for Generative AI, published in May 2024, is the most operationally useful document for Singapore businesses. It was designed explicitly to translate the OECD AI Principles and broader international ethical commitments into guidance appropriate for the Singapore business context, specifically addressing the challenges posed by generative AI systems.
The framework organises responsible AI governance into nine dimensions: accountability, data, trusted development and deployment, incident reporting and response, testing and assurance, security, content provenance, safety and alignment, and model and system transparency. Each dimension comes with practical guidance on what businesses should do, not merely what they should aspire to. The framework also acknowledges the layered accountability between AI developers, AI deployers, and end users — a structure consistent with the 2024 OECD update.
IMDA supports the framework with the AI Verify initiative: a testing toolkit and methodology that organisations can use to assess their AI systems against the framework's dimensions. AI Verify has attracted collaboration from international technology companies and regulators, reinforcing IMDA's positioning as a global contributor to AI governance methodology.
For Singapore businesses, IMDA's framework is the primary reference for what "responsible AI" looks like locally. It is the standard most likely to be referenced in government procurement requirements, MAS or sector-specific regulatory guidance, and enterprise client due diligence processes. Businesses that want to demonstrate responsible AI practice in Singapore should be able to map their governance activities against IMDA's nine dimensions.
ISO 42001: the certifiable management system
ISO/IEC 42001:2023 is structurally different from the frameworks above. It is not a set of ethical principles or policy guidance. It is a management system standard — the AI governance equivalent of ISO 27001 for information security or ISO 9001 for quality management. Singapore adopted it as SS ISO/IEC 42001:2024, and the Singapore Accreditation Council (SAC) opened certification pathways in February 2025.
The standard's design is risk-based: organisations identify the AI systems they develop or deploy, assess the risks and impacts associated with those systems, and implement controls appropriate to those risks. Its Statement of Applicability covers 65 controls spanning areas including AI risk management, data governance, transparency, human oversight, incident management, and supplier relationships. The controls are designed to be implementable across organisations of different sizes and sectors.
The critical difference from every other framework in this discussion: ISO 42001 produces something an auditor can verify. A third-party certification body, accredited by SAC, can assess your AI management system against the standard and issue a certificate of conformity. That certificate is a credible, independently verified signal that your organisation has implemented systematic AI governance — not merely declared it. This matters increasingly in enterprise procurement, financial services regulation, government contracting, and for businesses positioning themselves for international expansion.
ISO 42001 incorporates the substance of OECD AI Principles and broader ethical considerations as inputs to its risk-based design. Organisations implementing ISO 42001 systematically are, in effect, operationalising the ethical commitments articulated by OECD and UNESCO — but within a management system that generates documented evidence and is subject to external audit.
How they stack: a layered view
The relationship between these four frameworks becomes much clearer when you view them as a stack rather than alternatives. Each layer serves a distinct function, and each layer builds on the one below it.
At the foundation sits the UNESCO Recommendation: the global ethical consensus on what AI should protect and respect — human rights, dignity, democracy, environmental sustainability, cultural diversity. This layer answers the question: why do we govern AI at all?
Above it sits the OECD AI Principles: the government-level policy framework that translates those ethical values into principles that should guide how both governments and businesses approach AI development and deployment. This layer answers the question: what should responsible actors in the AI ecosystem commit to? Because the G20 AI Principles are based directly on OECD, and because Singapore operates closely with G20 economies, this layer also defines the baseline expected in international business contexts.
Above that sits IMDA's Model AI Governance Framework: the Singapore operational translation of those international principles into a practical governance structure for businesses deploying AI in Singapore. This layer answers the question: what specifically should a Singapore business do?
At the top sits ISO/IEC 42001: the certifiable management system that operationalises all of the above within a structured, documented, auditable framework. This layer answers the question: how do we systematically implement governance and prove it to external parties?
The frameworks do not conflict. The areas IMDA covers in its nine dimensions are substantially consistent with the OECD principles. ISO 42001's controls address the same concerns. A business that implements ISO 42001 properly and maps its outputs to IMDA's nine dimensions will have addressed the substantive requirements of the OECD principles and the operational intent of UNESCO's recommendation. The stack is additive upward, not contradictory across.
Practical recommendation for Singapore businesses
Given the layered relationship between these frameworks, the practical approach for most Singapore businesses is straightforward. You do not need four parallel governance workstreams.
Start with IMDA's nine dimensions as your operational checklist. The framework is Singapore-specific, covers generative AI explicitly, is the reference point most likely to appear in local regulatory and procurement contexts, and is supported by IMDA's own AI Verify testing methodology. If you can articulate how your AI governance activities map to IMDA's nine dimensions, you are already addressing the substance of the OECD principles and much of what UNESCO's recommendation calls for.
Use ISO 42001 as your management system if you want structured, auditable governance. ISO 42001 gives you the process discipline — risk assessments, documented controls, internal audits, management reviews — that turns good governance intent into verifiable practice. If you are in a regulated sector, serve enterprise clients with supply chain governance requirements, or want to differentiate your AI credibility with a third-party-certified credential, ISO 42001 certification is the most concrete investment you can make. SS ISO/IEC 42001:2024 is the local standard; SAC-accredited certification has been available since early 2025.
Reference OECD when working with international clients or partners in G20 markets. If you are pitching to a European enterprise, a Japanese partner, or a US government-adjacent agency, OECD alignment is the common language. Being able to say your AI governance approach is consistent with OECD AI Principles and ISO 42001 translates across borders in a way that IMDA-specific language alone may not.
Reference UNESCO when developing your top-level AI ethics principles. If you are writing an organisational AI policy, a board-level statement on responsible AI, or stakeholder communications about your AI commitments, UNESCO's framework gives you the broadest and most universally recognised ethical foundation. It also provides the vocabulary for addressing concerns about AI's societal impacts that go beyond operational risk management.
The most important practical conclusion is that you do not need to track four frameworks separately. ISO 42001's management system approach naturally incorporates the substantive requirements of the others. A business implementing ISO 42001 with IMDA's nine dimensions as a supplementary reference will have addressed the operational substance of OECD and UNESCO without needing parallel workstreams for each. The goal is a single, coherent governance system with clear documentation — not four separate compliance exercises.
Frequently Asked Questions
Stop Framework-Hopping. Start Governing.
VerityOS maps all major AI governance frameworks — IMDA's 9 dimensions, ISO 42001's 65 controls, and the principles underlying OECD and UNESCO guidance — into a single evidence vault. Instead of maintaining four separate tracking documents and wondering whether your controls address the right requirements, your Singapore business has one place to manage AI governance, collect evidence, and demonstrate responsible AI practice to clients, regulators, and auditors. No framework paralysis. No duplicated effort. Governed, evidenced, and audit-ready.