Implementing ISO standards? Don't overlook GDPR. Try Cookiebot free →

ISO 23894

Artificial Intelligence - Risk Management

Technology & Innovation Published: 2023

ISO 23894:2023 at a glance

Current edition
ISO/IEC 23894:2023 - Information technology — Artificial intelligence — Guidance on risk management
Published
2023
Status
Published
Type of standard
Guidance
Certifiable
No — used for reference and implementation, not certification
Official ISO page
View ISO 23894:2023 on iso.org
Last verified

Overview

Guidance on managing risk specific to artificial intelligence, applying the ISO 31000 risk management model to AI development and use; guidance only, not certifiable

ISO/IEC 23894:2023 provides guidance on how organizations that develop, produce, deploy or use products, systems and services that utilize artificial intelligence can manage risk specifically related to AI. It was published in February 2023 by ISO/IEC JTC 1/SC 42, the subcommittee responsible for artificial intelligence, and it is the reference document that most AI governance programmes use for the risk half of their work.

It is important to be clear about its status: ISO/IEC 23894 is a guidance document, not a requirements standard. It contains no auditable requirements and no organization can be certified against it. Any claim of "ISO 23894 certification" for an organization should be treated as a misdescription; what exists are personal training certificates. The certifiable standard for AI governance is ISO/IEC 42001, the AI management system standard, and ISO/IEC 23894 is the natural companion to it: 42001 requires an AI risk assessment and treatment process, and 23894 explains how to build and run one.

The document is intended to be used in connection with ISO 31000:2018, and its structure mirrors it deliberately. Clause 4 adapts the ISO 31000 principles to AI, clause 5 adapts the framework — leadership and commitment, integration, design, implementation, evaluation and improvement — and clause 6 adapts the process: establishing scope, context and criteria; risk identification, analysis and evaluation; risk treatment; and the continuing activities of communication and consultation, monitoring and review, and recording and reporting. The value added is not a new process but the AI-specific content poured into each step.

Three informative annexes carry much of that content. Annex A sets out common AI-related objectives — the things an organization may be trying to achieve or protect, such as fairness, transparency and explainability, robustness, reliability, safety, security, privacy, accountability, maintainability and control of environmental impact. Because ISO 31000 defines risk as the effect of uncertainty on objectives, naming the objectives properly is what makes AI risk assessment coherent rather than a list of generic worries.

Annex B catalogues common AI-related risk sources. These are the properties of AI systems that generate risk in ways conventional software does not: the complexity of the operating environment; lack of transparency and explainability in models; the level of automation and the reduction of human oversight; machine learning specifics such as training data quality, representativeness and bias, data drift and model drift; system hardware and compute dependencies; system life cycle issues including retraining and versioning; technology readiness; and security and privacy exposure particular to models and training data.

Annex C provides an example mapping between risk management processes and the AI system life cycle. This is the part that turns the guidance into practice: it shows which risk activities belong at inception, design and development, verification and validation, deployment, operation and monitoring, re-evaluation and retirement — reflecting that AI risk is not settled at release but changes as data, usage and the environment change.

In an operating governance programme, ISO/IEC 23894 is typically used to define risk criteria for AI, to structure risk workshops around named objectives and risk sources, and to feed the risk register that an ISO/IEC 42001 management system requires. It sits alongside ISO/IEC 42005 (AI system impact assessment), ISO/IEC 22989 (AI concepts and terminology), ISO/IEC 23053 (framework for AI systems using machine learning), ISO/IEC TR 24027 (bias in AI systems and AI aided decision making), ISO/IEC TR 24028 (overview of trustworthiness in AI) and the ISO/IEC 5259 series on data quality for analytics and machine learning.

It is also widely used as a bridge to regulatory and voluntary frameworks. Its objectives and risk sources map readily onto the risk management, data governance, transparency and human oversight themes of the EU AI Act and onto the functions of the NIST AI Risk Management Framework. Using ISO/IEC 23894 does not establish legal compliance with any of them, but it produces the analysis and documentation those frameworks expect an organization to be able to show.

Purpose

To give organizations that develop, provide or use AI systems practical guidance on identifying, analysing, evaluating, treating and monitoring AI-specific risks, and on integrating that work into existing risk management and into an ISO/IEC 42001 AI management system.

Key Benefits

  • Applies the established ISO 31000 risk model to AI without inventing a parallel process
  • Supplies AI-specific objectives (Annex A) so risk is assessed against what actually matters for the system
  • Catalogues AI-specific risk sources (Annex B) including data quality, bias, drift, opacity and automation level
  • Maps risk activities to the AI system life cycle (Annex C), covering post-deployment risk as well as design
  • Provides the risk methodology that ISO/IEC 42001 requires but does not itself describe in detail
  • Gives a common vocabulary for technical, legal, compliance and executive stakeholders discussing AI risk
  • Supports the analysis and documentation expected by the EU AI Act and the NIST AI Risk Management Framework
  • Applicable to developers, providers and deployers of AI, including organizations using third-party models
  • Integrates with existing enterprise risk management rather than replacing it
  • Freely usable as guidance, with no certification programme or audit overhead

Key Requirements

  • Note: ISO/IEC 23894 is guidance — it contains no auditable requirements, and organizations cannot be certified against it
  • Use the standard in connection with ISO 31000:2018, whose principles, framework and process it adapts to AI
  • Establish leadership commitment and integrate AI risk management into existing governance and risk structures
  • Define the scope, context and risk criteria for AI risk management, including risk acceptance criteria
  • Identify the AI-related objectives that matter for each system, using Annex A as a starting point
  • Identify AI-specific risk sources using Annex B, including data, model, automation, transparency and environment factors
  • Analyse identified risks considering consequences, likelihood and the effectiveness of existing controls
  • Evaluate risks against the defined criteria and prioritise them for treatment
  • Select and implement risk treatments, and document residual risk and its acceptance
  • Map risk management activities to the AI system life cycle stages, following the example in Annex C
  • Monitor and review risks continually, including data drift, model drift and changes in the operating environment
  • Communicate and consult with internal and external interested parties affected by the AI system
  • Record and report AI risk management activities so they can feed an ISO/IEC 42001 management system
  • Reassess risk after retraining, significant change of use, or changes in the deployment context

Who Needs This Standard?

Organizations building or deploying AI systems — AI and software vendors, enterprises embedding third-party models, and regulated firms in finance, healthcare, HR, insurance and public services — and the risk, compliance, data science and audit functions that need a defensible AI risk methodology, particularly those implementing ISO/IEC 42001.

Where to get ISO 23894

The full text of ISO 23894 is copyrighted and is sold by ISO and its national member bodies — buy the official edition on iso.org, or order the same document from your national standards body, often at a member price. Sites offering a free PDF of the complete standard are not authorised to distribute it, and the files circulating there are frequently superseded editions, partial scans or altered copies, with no way to tell which. What is legitimately free is the standard's page on iso.org: the abstract, the current edition and status, the table of contents, and a preview of the opening sections. This page summarises the scope and requirements of ISO 23894 in our own words; it does not reproduce the standard's text and is not a substitute for the published document.

Get our free implementation resources

Our AI Risk Assessment Workbook is a set of blank, printable templates for running an AI risk process: an AI system inventory, a risk register with worked example rows, a likelihood and impact scoring matrix, a treatment plan and a monitoring log. Free, no account needed.

We'll only email you about this standard. Unsubscribe anytime.

Related Standards