Overview
ISO/IEC 23894:2023 - "Information technology - Artificial intelligence - Guidance on risk management" provides targeted guidance for organizations that develop, produce, deploy or use AI products, systems and services. Mirroring the structure of ISO 31000:2018, this standard helps integrate AI-specific risk management into existing organizational governance, processes and the AI system life cycle. It is customizable to any organization and covers principles, a risk management framework and detailed processes for assessment, treatment, monitoring and improvement.
Keywords: ISO/IEC 23894:2023, AI risk management, ISO 31000, AI governance, risk assessment, AI lifecycle
Key topics and technical guidance
The standard focuses on practical, AI-specific guidance rather than prescriptive technical specifications. Main topics include:
- Principles of AI risk management
- Integrating risk management into all organizational activities
- Inclusiveness, customization and a structured approach tailored to AI
- Risk management framework (leadership to improvement)
- Leadership and commitment, assigning roles and accountability
- Integration with organizational objectives, design, implementation, evaluation and continual improvement
- Risk management process
- Communication and consultation with stakeholders
- Defining scope, context and risk criteria for AI use cases
- Risk assessment steps: identification, analysis and evaluation
- Risk treatment: selecting and implementing mitigation options
- Monitoring, review, recording and reporting of AI risks
- Annexes and practical aids
- Annex A: common AI-related objectives
- Annex B: AI risk sources (e.g., data, model, system and operational aspects)
- Annex C: mapping risk management activities to an AI system life cycle
Note: ISO/IEC 23894:2023 provides guidance that complements ISO 31000:2018 and other AI standards; it does not replace organizational policies or industry-specific regulatory requirements.
Practical applications and who should use it
ISO/IEC 23894:2023 is relevant to a wide range of stakeholders involved in AI risk and governance:
- AI developers, ML engineers and system architects - to embed risk controls into design and development
- Product managers and program leads - to align AI features with organizational risk appetite
- Risk managers, compliance and internal audit teams - to assess AI-specific threats and track mitigation
- Procurement and vendor management - to evaluate third-party AI suppliers against risk criteria
- Regulators and policy teams - to understand structured, standards-based approaches to AI risk
- Cross-functional teams (legal, privacy, security, ethics) - for stakeholder consultation and lifecycle oversight
Related standards
- ISO 31000:2018 - Risk management - Guidelines (framework alignment)
- ISO/IEC 22989:2022 - AI concepts and terminology
- ISO Guide 73:2009 - Risk management vocabulary
ISO/IEC 23894:2023 helps organizations operationalize AI risk management: aligning governance, technical controls, stakeholder engagement and continuous monitoring across the AI lifecycle.