Skip to content

Standard · ISO/IEC

Guidance on AI risk management

Guidance on applying the ISO 31000 risk-management principles and process to the specific context of AI.

ISO/IEC 23894:2023

What is it?

ISO/IEC 23894 is guidance (not certifiable requirements) on adapting the ISO 31000 risk process — identify, analyse, evaluate, treat, monitor and communicate — to AI characteristics such as data dependence, output uncertainty and model drift.

Why does it matter?

Organizations with enterprise risk management can extend it to AI instead of building a parallel system. It underpins the risk assessment part of ISO/IEC 42001.

Who needs it?

  • Enterprise risk managers
  • AI governance leads
  • Internal auditors

Key concepts

AI-specific risk sources

Data quality and bias, low transparency, complexity, environmental change and supplier dependence.

AI system lifecycle

Risks differ at each stage, from design and data to deployment and retirement.

Integration with ISO 31000

Uses the same principles, framework and process as enterprise risk management.

Requirements

  • Guidance only; no certifiable requirements.

Implementation

  1. 01Add AI risk categories to the enterprise taxonomy
  2. 02Define likelihood and impact criteria for AI use cases
  3. 03Create an AI risk register with owners
  4. 04Monitor continuously and report to management

Assessment

The “Risk & Incident Management” dimension of the readiness assessment measures maturity here.

Training

The “AI Risk Management” course and “AI Risk Register” workshop build on this approach.

Resources

This page is AI STANDARD's explanation and interpretation; it does not reproduce the official text. Obtain the full standard from its publisher.