ISO/IEC 23894
ISO/IEC 23894 is an internationally published standard that offers guidance to organizations on managing the risks that come with using artificial intelligence. It is aimed at organizations that develop, produce, deploy, or use AI-enabled products, systems, and services, and it addresses risks across the AI life cycle. As a guidance standard, it describes recommended practices rather than imposing legally binding requirements.
ISO/IEC 23894:2023 is a guidance document providing recommendations for managing risks associated with artificial intelligence for organizations that develop, produce, deploy, or use AI-based products, systems, and services. According to the evidence, its guidance is adaptable and builds on the risk management principles and framework of ISO 31000:2018, applying them to the AI context. It is distinct from ISO/IEC 42001, which concerns AI management systems; ISO/IEC 23894 is focused specifically on AI risk management practices. As a voluntary international standard offering guidance, it is not itself binding law and should not be conflated with jurisdiction-specific regulatory instruments; the evidence provided does not detail its clause-level requirements or certifiability, which are out of scope for this entry.
Why it matters
As organizations increasingly develop and deploy AI systems, they face risks that are not always well captured by traditional software or operational risk practices. ISO/IEC 23894 matters because it offers a structured, internationally published reference point for managing AI-related risks across the AI life cycle, giving organizations a common vocabulary and set of recommended practices to draw on. For teams building governance and risk programs, adopting a recognized guidance standard can help demonstrate diligence and consistency, though it does not by itself satisfy any particular legal or regulatory obligation.
The standard is significant partly because of what it is anchored to. According to the evidence, its guidance builds on the risk management principles and framework of ISO 31000:2018, adapting general risk management concepts to the AI context. This lineage allows organizations that already use ISO 31000-based enterprise risk practices to extend familiar processes to AI rather than starting from scratch. It also situates AI risk management within a broader, established discipline rather than treating AI risk as wholly novel.
Professionals should be careful not to overstate the standard's role. As a voluntary international guidance document, ISO/IEC 23894 describes recommended practices rather than imposing binding requirements, and it is distinct from jurisdiction-specific regulatory instruments. It should also not be conflated with ISO/IEC 42001, which addresses AI management systems; ISO/IEC 23894 is focused specifically on AI risk management. The evidence provided does not detail its clause-level requirements or whether conformity can be certified, so those questions are out of scope here and should be confirmed against the source standard.
Who it's relevant to
Inside ISO/IEC 23894
Common questions
Answers to the questions practitioners most commonly ask about ISO/IEC 23894.