ISO/IEC 23894 (AI Risk Management)
ISO/IEC 23894 is an internationally published standard that offers guidance to organizations on how to manage the risks that come with developing, deploying, or using artificial intelligence. Rather than treating AI as a one-off experiment, it helps organizations approach AI as a source of risk that can be identified, assessed, and controlled across the AI system's lifecycle. It provides guidance and processes that an organization can adapt to its own context, rather than a rigid checklist.
ISO/IEC 23894:2023 is a standard, published under the ISO/IEC information technology framework, that provides guidance on risk management for organizations that develop, produce, deploy, or use AI-based products, systems, and services. It describes processes for the effective implementation and integration of AI risk management, and its application is intended to be customizable to an organization's specific context and needs. As commonly characterized, it functions as guidance for treating AI as a managed risk source across the AI system lifecycle; readers should note that this entry does not establish whether the standard is binding in any given jurisdiction, and it is distinct from other instruments such as the NIST AI Risk Management Framework issued by NIST. The evidence provided does not detail the standard's specific clauses, control requirements, or relationship to certification, so those aspects are out of scope here.
Why it matters
As organizations move AI from pilot projects into production, they face a recurring problem: AI systems introduce risks that traditional risk management processes were not designed to capture. ISO/IEC 23894 matters because it offers a structured way to treat AI as a managed source of risk that can be identified, assessed, and controlled across the system lifecycle, rather than as a one-off experiment. This framing helps organizations bring AI-related risk under the kind of disciplined oversight already applied to other operational and technology risks.
The standard's emphasis on customization is significant for practitioners. Because it provides guidance and processes intended to be adapted to an organization's specific context and needs, it can serve as a reference point across sectors and jurisdictions without prescribing a single rigid checklist. This flexibility is useful for organizations seeking to align internal governance and risk practices with an internationally recognized reference, but it also means that the depth and rigor of implementation depend heavily on how each organization applies it.
Readers should note the limits of what this entry can establish. The evidence provided does not detail the standard's specific clauses, control requirements, or its relationship to certification, and it does not determine whether the standard is binding in any particular jurisdiction. ISO/IEC 23894 is also distinct from other instruments such as the NIST AI Risk Management Framework issued by NIST; the two address AI risk but are separate documents from different bodies and should not be treated as interchangeable.
Who it's relevant to
Inside ISO/IEC 23894 (AI Risk Management)
Common questions
Answers to the questions practitioners most commonly ask about ISO/IEC 23894 (AI Risk Management).