An international guidance standard that helps organisations apply risk management principles to AI — addressing the unique risks that come from AI's non-determinism, opacity, and emergent behaviour.
An international guidance standard that helps organisations apply risk management principles to AI — addressing the unique risks that come from AI's non-determinism, opacity, and emergent behaviour.
ISO/IEC 23894:2023 (Information technology — Artificial intelligence — Guidance on risk management) provides practical guidance for integrating AI risk management into existing enterprise risk management frameworks. It covers AI risk identification (cataloguing AI-specific risk sources including data quality, model behaviour, deployment context, and societal impact), risk assessment, treatment, and monitoring. The standard references ISO 31000 for foundational risk management concepts and extends them with AI-specific guidance aligned with ISO/IEC 22989 and ISO/IEC 42001. It is complementary to the NIST AI RMF.
Risk managers and AI governance teams can use ISO/IEC 23894 to structure their AI risk management activities against an internationally recognised framework — supporting both internal governance and external audit readiness.
Like ISO 14971 for medical device risk management — it applies general risk management principles (from ISO 31000) to the specific hazard profile of the technology in question.
An international guidance standard that helps organisations apply risk management principles to AI — addressing the unique risks that come from AI's non-determinism, opacity, and emergent behaviour.
ISO/IEC 23894:2023 (Information technology — Artificial intelligence — Guidance on risk management) provides practical guidance for integrating AI risk management into existing enterprise risk management frameworks. It covers AI risk identification (cataloguing AI-specific risk sources including data quality, model behaviour, deployment context, and societal impact), risk assessment, treatment, and monitoring. The standard references ISO 31000 for foundational risk management concepts and extends them with AI-specific guidance aligned with ISO/IEC 22989 and ISO/IEC 42001. It is complementary to the NIST AI RMF.
Risk managers and AI governance teams can use ISO/IEC 23894 to structure their AI risk management activities against an internationally recognised framework — supporting both internal governance and external audit readiness.