What is it?
ISO/IEC 23894 is guidance (not certifiable requirements) on adapting the ISO 31000 risk process — identify, analyse, evaluate, treat, monitor and communicate — to AI characteristics such as data dependence, output uncertainty and model drift.
Why does it matter?
Organizations with enterprise risk management can extend it to AI instead of building a parallel system. It underpins the risk assessment part of ISO/IEC 42001.
Who needs it?
- Enterprise risk managers
- AI governance leads
- Internal auditors
Key concepts
AI-specific risk sources
Data quality and bias, low transparency, complexity, environmental change and supplier dependence.
AI system lifecycle
Risks differ at each stage, from design and data to deployment and retirement.
Integration with ISO 31000
Uses the same principles, framework and process as enterprise risk management.
Requirements
- Guidance only; no certifiable requirements.
Implementation
- 01Add AI risk categories to the enterprise taxonomy
- 02Define likelihood and impact criteria for AI use cases
- 03Create an AI risk register with owners
- 04Monitor continuously and report to management
Assessment
The “Risk & Incident Management” dimension of the readiness assessment measures maturity here.
Training
The “AI Risk Management” course and “AI Risk Register” workshop build on this approach.
Resources
This page is AI STANDARD's explanation and interpretation; it does not reproduce the official text. Obtain the full standard from its publisher.