GovernanceCore
Voluntary frameworkInternational (ISO/IEC)

ISO/IEC 23894 — AI Risk Management Guidance

Guidance that maps general ISO 31000 risk management to AI, giving organisations a common vocabulary and process for identifying, analysing and treating AI risks across the lifecycle.

Status
Voluntary framework
Jurisdiction
International (ISO/IEC) · Standard
Adopted
Feb 1, 2023
In force
Feb 1, 2023
Enforcement date
Regulator / body
ISO/IEC (guidance)
Sectors
Cross-sector
Extraterritorial
No

Overview

Guidance that maps general ISO 31000 risk management to AI, giving organisations a common vocabulary and process for identifying, analysing and treating AI risks across the lifecycle.

Key dates

  • Feb 1, 2023
    Published

Risk areas addressed

Safety & robustnessGovernance & accountability

Who it applies to

Organisations developing, deploying or using AI seeking structured guidance on managing AI-specific risk (aligned to ISO 31000).

Penalties & enforcement

None — guidance standard.

Enforced by: ISO/IEC (guidance)

Getting ready

Whatever your exposure to ISO/IEC 23894, the practical work is the same: inventory the AI systems in scope, map them to concrete obligations, and keep the evidence to show it. A structured AI governance programme — risk assessments, documentation and continuous monitoring — turns a moving regulatory target into a repeatable process.

Official source

ISO/IEC 23894:2023

Related regulations

← All regulations