Skip to main content
Category: Risk Assessment & Analysis

ISO/IEC 23894

Also known as: ISO/IEC 23894:2023, ISO 23894
Simply put

ISO/IEC 23894 is an internationally published standard that offers guidance to organizations on managing the risks that come with using artificial intelligence. It is aimed at organizations that develop, produce, deploy, or use AI-enabled products, systems, and services, and it addresses risks across the AI life cycle. As a guidance standard, it describes recommended practices rather than imposing legally binding requirements.

Formal definition

ISO/IEC 23894:2023 is a guidance document providing recommendations for managing risks associated with artificial intelligence for organizations that develop, produce, deploy, or use AI-based products, systems, and services. According to the evidence, its guidance is adaptable and builds on the risk management principles and framework of ISO 31000:2018, applying them to the AI context. It is distinct from ISO/IEC 42001, which concerns AI management systems; ISO/IEC 23894 is focused specifically on AI risk management practices. As a voluntary international standard offering guidance, it is not itself binding law and should not be conflated with jurisdiction-specific regulatory instruments; the evidence provided does not detail its clause-level requirements or certifiability, which are out of scope for this entry.

Why it matters

As organizations increasingly develop and deploy AI systems, they face risks that are not always well captured by traditional software or operational risk practices. ISO/IEC 23894 matters because it offers a structured, internationally published reference point for managing AI-related risks across the AI life cycle, giving organizations a common vocabulary and set of recommended practices to draw on. For teams building governance and risk programs, adopting a recognized guidance standard can help demonstrate diligence and consistency, though it does not by itself satisfy any particular legal or regulatory obligation.

The standard is significant partly because of what it is anchored to. According to the evidence, its guidance builds on the risk management principles and framework of ISO 31000:2018, adapting general risk management concepts to the AI context. This lineage allows organizations that already use ISO 31000-based enterprise risk practices to extend familiar processes to AI rather than starting from scratch. It also situates AI risk management within a broader, established discipline rather than treating AI risk as wholly novel.

Professionals should be careful not to overstate the standard's role. As a voluntary international guidance document, ISO/IEC 23894 describes recommended practices rather than imposing binding requirements, and it is distinct from jurisdiction-specific regulatory instruments. It should also not be conflated with ISO/IEC 42001, which addresses AI management systems; ISO/IEC 23894 is focused specifically on AI risk management. The evidence provided does not detail its clause-level requirements or whether conformity can be certified, so those questions are out of scope here and should be confirmed against the source standard.

Who it's relevant to

AI developers and producers
Organizations that develop or produce AI-based products, systems, and services can use ISO/IEC 23894 as a reference for identifying and managing risks that arise during design and build, applying its adaptable, life-cycle-oriented guidance to their own development context.
Organizations deploying or using AI
Entities that deploy or use AI-enabled products and services are within the standard's stated scope. They can draw on its recommendations to manage risks associated with putting AI systems into operation and using them over time, recognizing that it offers guidance rather than binding requirements.
Risk and model risk professionals
Practitioners responsible for enterprise or model risk management may find ISO/IEC 23894 useful because it adapts the ISO 31000:2018 risk management framework to AI, allowing existing risk processes to be extended to AI-specific concerns. It supports risk management practices but does not replace jurisdiction-specific regulatory obligations or independent validation.
Governance and compliance teams
Teams building AI governance and compliance programs can reference the standard as a recognized guidance document when structuring AI risk practices. They should distinguish it from ISO/IEC 42001, which addresses AI management systems, and should not treat adoption as a substitute for legal or regulatory compliance in any given jurisdiction.

Inside ISO/IEC 23894

AI-specific risk management guidance
ISO/IEC 23894 is an international standard published by ISO and IEC that provides guidance on managing risk specifically associated with the development and use of AI systems. It is guidance rather than a certifiable requirements specification.
Alignment with ISO 31000
The document is generally structured to be consistent with the ISO 31000 risk management framework and vocabulary, adapting its principles, framework, and process elements to the particular characteristics of AI systems.
Risk management principles for AI
It describes principles intended to inform how organizations approach AI-related risk, encouraging integration of risk management into organizational activities rather than treating it as a standalone exercise.
Risk management process elements
It addresses process components commonly associated with risk management such as establishing context, risk identification, analysis, evaluation, treatment, and monitoring, framed for AI-specific concerns.
Relationship to other AI standards
It is intended to complement other AI-related standards, and is frequently discussed alongside ISO/IEC 42001 (an AI management system standard); however, the two serve different purposes and should not be treated as identical.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 23894.

Is ISO/IEC 23894 a certifiable standard like ISO/IEC 42001?
No. ISO/IEC 23894 is commonly understood as guidance on AI-related risk management rather than a management system standard against which organizations are typically certified. Certification schemes are generally associated with management system standards such as ISO/IEC 42001. Treating ISO/IEC 23894 as a certifiable requirement conflates guidance with a certifiable management system, which are distinct in purpose and structure.
Does following ISO/IEC 23894 make an organization compliant with the EU AI Act?
Not by itself. ISO/IEC 23894 is a voluntary international standard issued through ISO/IEC, whereas the EU AI Act is binding law within its jurisdiction. Applying the standard may support certain risk management practices, but conformity with a voluntary standard should not be equated with legal compliance under any specific regulation. The two are scoped differently and issued by different bodies, and legal obligations must be assessed against the applicable law itself.
How does ISO/IEC 23894 relate to ISO 31000?
ISO/IEC 23894 is commonly described as applying general risk management principles, in the spirit of ISO 31000, to the specific context of AI. In practice, organizations that already use an ISO 31000-aligned risk framework often use ISO/IEC 23894 to address AI-specific considerations within that existing structure rather than as a wholly separate process. Confirm the precise relationship and scope against the current text of each standard before relying on it.
Where does ISO/IEC 23894 fit alongside model risk management practices such as those framed by SR 11-7?
They operate at different levels and in different contexts. ISO/IEC 23894 offers general AI risk management guidance intended for broad applicability, while SR 11-7 is supervisory guidance historically applied to model risk in U.S. banking. The two can overlap where AI models are in scope, but they are not interchangeable, and one does not substitute for the other. Organizations in regulated sectors should map the standard's guidance to their applicable regulatory obligations rather than assume equivalence.
Can ISO/IEC 23894 be used together with ISO/IEC 42001?
They are often positioned as complementary, with the management system standard providing organizational structure and governance and the risk management guidance informing how AI-related risks are identified, assessed, and treated within that system. Because the exact interfaces depend on the current text of each document and an organization's own arrangements, verify how the two are intended to be used together before designing controls around that assumption.
Who within an organization typically applies ISO/IEC 23894?
As commonly used, its guidance is relevant to those responsible for identifying, assessing, and managing AI-related risk, which may span risk management, compliance, model development, and oversight functions. It does not by itself assign a specific line-of-defense structure; organizations generally map its guidance onto their existing roles and accountability arrangements. Applying it does not eliminate AI-related risk but is intended to help manage and reduce it.

Common misconceptions

ISO/IEC 23894 is a certifiable standard that organizations can be audited against for compliance.
As commonly characterized, ISO/IEC 23894 provides guidance on AI risk management rather than auditable requirements. Certification is typically associated with management system standards structured around requirements, and readers should verify current certification treatment rather than assume it applies here.
ISO/IEC 23894 is a legally binding regulation that AI providers must follow.
It is a voluntary international standard issued by ISO and IEC, not law. It does not carry the binding legal force of instruments such as regional AI legislation, and adopting it does not by itself demonstrate compliance with any specific jurisdiction's legal requirements.
ISO/IEC 23894 and ISO/IEC 42001 are interchangeable.
They are distinct standards addressing different scopes. One is oriented toward guidance on AI risk management while the other concerns an AI management system; using one does not substitute for the other, and organizations should treat them as complementary rather than equivalent.

Best practices

Treat ISO/IEC 23894 as guidance to inform your AI risk management approach, and confirm its current status and scope directly from the published standard rather than relying on secondary summaries.
Align use of the standard with your existing ISO 31000-based risk management framework where one exists, so that AI-specific risk activities integrate with broader organizational risk processes.
Distinguish the role of ISO/IEC 23894 (risk management guidance) from that of ISO/IEC 42001 (AI management system) and map how each supports your objectives without conflating them.
Do not rely on adoption of this voluntary standard alone to satisfy binding legal obligations; assess applicable laws in each relevant jurisdiction separately.
Document how the standard's process elements—context establishment, identification, analysis, evaluation, treatment, and monitoring—are operationalized for specific AI systems, recognizing these measures manage rather than eliminate risk.
Coordinate application of the standard across governance functions and applicable lines of defense so that risk management guidance is embedded in ongoing oversight rather than treated as a one-time exercise.