GovernanceCore
Voluntary frameworkInternational (ISO/IEC)

ISO/IEC 23894: AI Risk Management Guidance

Guidance that maps general ISO 31000 risk management to AI, giving organisations a common vocabulary and process for identifying, analysing and treating AI risks across the lifecycle.

Status
Voluntary framework
Jurisdiction
International (ISO/IEC) · Standard
Adopted
Feb 1, 2023
In force
Feb 1, 2023
Enforcement date
Regulator / body
ISO/IEC (guidance)
Sectors
Cross-sector
Extraterritorial
No

Key dates

  • Feb 1, 2023
    Published

Risk areas addressed

Safety & robustnessGovernance & accountability

Who it applies to

Organisations developing, deploying or using AI seeking structured guidance on managing AI-specific risk (aligned to ISO 31000).

Penalties & enforcement

None (guidance standard).

Enforced by: ISO/IEC (guidance)

Getting ready

ISO/IEC 23894 carries no direct penalty today, so its value is evidential: teams adopt it to show a named standard behind their controls for safety & robustness and governance & accountability. Mapping an existing AI inventory against it is usually enough to surface the gaps, and that same evidence tends to carry over to the binding regimes that follow.

Official source

ISO/IEC 23894:2023

Related regulations

← All regulations