Voluntary frameworkInternational (ISO/IEC)
ISO/IEC 23894: AI Risk Management Guidance
Guidance that maps general ISO 31000 risk management to AI, giving organisations a common vocabulary and process for identifying, analysing and treating AI risks across the lifecycle.
Status
Voluntary framework
Jurisdiction
International (ISO/IEC) · Standard
Adopted
Feb 1, 2023
In force
Feb 1, 2023
Enforcement date
—
Regulator / body
ISO/IEC (guidance)
Sectors
Cross-sector
Extraterritorial
No
Key dates
- Feb 1, 2023Published
Risk areas addressed
Safety & robustnessGovernance & accountability
Who it applies to
Organisations developing, deploying or using AI seeking structured guidance on managing AI-specific risk (aligned to ISO 31000).
Penalties & enforcement
None (guidance standard).
Enforced by: ISO/IEC (guidance)
Getting ready
ISO/IEC 23894 carries no direct penalty today, so its value is evidential: teams adopt it to show a named standard behind their controls for safety & robustness and governance & accountability. Mapping an existing AI inventory against it is usually enough to surface the gaps, and that same evidence tends to carry over to the binding regimes that follow.