ISO/IEC 23894: AI risk management guide and how it relates to ISO 42001
ISO/IEC 23894 is the standard that explains how to manage AI-specific risks. It cannot be certified: it is guidance. Here is what it offers, how it fits with ISO 42001 and the AI Act, and how to apply it without turning it into bureaucracy.
What it is and what it is not
ISO/IEC 23894:2023 is guidance on managing AI-related risk. It builds on ISO 31000 (the general risk management standard) and proposes how to apply it when models, training data and automated decisions are involved. Think of it as the method manual; ISO 42001 is the management system (with auditable requirements) where that method lives.
Note: the standard is paid and its text is protected; here we only summarise general ideas. Consult the official standard for detail.
The risk process in five steps
- Establish context: what the system is for, who is affected and which risk criteria the organisation accepts.
- Identify risks: bias, errors, opacity, model drift, supplier dependence, security, impact on people’s rights.
- Analyse and evaluate: likelihood and impact, with consistent criteria across teams.
- Treat: technical and organisational measures, human oversight, testing, usage limits.
- Monitor and review: ongoing follow-up, incidents and improvement; AI changes, and so does risk.
Around those steps sit communication and consultation with those involved, and a record of what was decided.
How it fits with ISO 42001, the AI Act and NIST
- ISO 42001: requires a management system including AI risk assessment; ISO 23894 guides how to do it. Compare both in ISO 42001 vs ISO 27001.
- AI Act (Art. 9): for high-risk systems requires a continuous risk management system across the lifecycle; voluntary guidance can be a useful methodological aid without replacing legal requirements.
- NIST AI RMF: a voluntary framework with a different approach (govern, map, measure, manage); read the practical guide and the comparison ISO 42001 vs NIST.
How to apply it without bureaucracy
- Start from the inventory: you cannot manage risks of systems you do not know (see AI inventory).
- Use one risk-record template for all teams.
- Scale the effort: more analysis for systems that affect people or significant decisions.
- Connect to audit and review: risks are reviewed in the internal audit cycle.
Frequently asked questions
Can you be certified against ISO 23894?
No: it is guidance. Certification of AI management systems falls under ISO/IEC 42001.
Does it replace the AI Act risk system?
No; it can help, but does not by itself give a presumption of conformity.
Informational and indicative content; it is not legal advice. Review your case with a qualified professional.
What's your Data Governance maturity?
Free assessment with your priority gaps, plus the self-assessment quiz and savings calculator on the Data Governance path.