ISO/IEC 23894 — AI Risk Management Guidance
Guidance that maps general ISO 31000 risk management to AI, giving organisations a common vocabulary and process for identifying, analysing and treating AI risks across the lifecycle.
Overview
Guidance that maps general ISO 31000 risk management to AI, giving organisations a common vocabulary and process for identifying, analysing and treating AI risks across the lifecycle.
Key dates
- Feb 1, 2023Published
Risk areas addressed
Who it applies to
Organisations developing, deploying or using AI seeking structured guidance on managing AI-specific risk (aligned to ISO 31000).
Penalties & enforcement
None — guidance standard.
Enforced by: ISO/IEC (guidance)
Whatever your exposure to ISO/IEC 23894, the practical work is the same: inventory the AI systems in scope, map them to concrete obligations, and keep the evidence to show it. A structured AI governance programme — risk assessments, documentation and continuous monitoring — turns a moving regulatory target into a repeatable process.