ISO/IEC 23894:2023 PDF
Information technology — Artificial intelligence — Guidance on risk management
Information technology — Artificial intelligence — Guidance on risk management
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 26
- Дата публикации:
- 6 февраля 2023 г.
- Издание:
- ISO/IEC IS 23894 edition 1 version 1
- ICS:
- 35.020
This document provides guidance on how organizations that develop, produce, deploy or use products, systems and services that utilize artificial intelligence (AI) can manage risk specifically related to AI. The guidance also aims to assist organizations to integrate risk management into their AI-related activities and functions. It moreover describes processes for the effective implementation and integration of AI risk management. The application of this guidance can be customized to any organization and its context.
Abstract
Overview
ISO/IEC 23894:2023 - "Information technology - Artificial intelligence - Guidance on risk management" provides targeted guidance for organizations that develop, produce, deploy or use AI products, systems and services. Mirroring the structure of ISO 31000:2018, this standard helps integrate AI-specific risk management into existing organizational governance, processes and the AI system life cycle. It is customizable to any organization and covers principles, a risk management framework and detailed processes for assessment, treatment, monitoring and improvement.
Keywords: ISO/IEC 23894:2023, AI risk management, ISO 31000, AI governance, risk assessment, AI lifecycle
Key topics and technical guidance
The standard focuses on practical, AI-specific guidance rather than prescriptive technical specifications. Main topics include:
- Principles of AI risk management
- Integrating risk management into all organizational activities
- Inclusiveness, customization and a structured approach tailored to AI
- Risk management framework (leadership to improvement)
- Leadership and commitment, assigning roles and accountability
- Integration with organizational objectives, design, implementation, evaluation and continual improvement
- Risk management process
- Communication and consultation with stakeholders
- Defining scope, context and risk criteria for AI use cases
- Risk assessment steps: identification, analysis and evaluation
- Risk treatment: selecting and implementing mitigation options
- Monitoring, review, recording and reporting of AI risks
- Annexes and practical aids
- Annex A: common AI-related objectives
- Annex B: AI risk sources (e.g., data, model, system and operational aspects)
- Annex C: mapping risk management activities to an AI system life cycle
Note: ISO/IEC 23894:2023 provides guidance that complements ISO 31000:2018 and other AI standards; it does not replace organizational policies or industry-specific regulatory requirements.
Practical applications and who should use it
ISO/IEC 23894:2023 is relevant to a wide range of stakeholders involved in AI risk and governance:
- AI developers, ML engineers and system architects - to embed risk controls into design and development
- Product managers and program leads - to align AI features with organizational risk appetite
- Risk managers, compliance and internal audit teams - to assess AI-specific threats and track mitigation
- Procurement and vendor management - to evaluate third-party AI suppliers against risk criteria
- Regulators and policy teams - to understand structured, standards-based approaches to AI risk
- Cross-functional teams (legal, privacy, security, ethics) - for stakeholder consultation and lifecycle oversight
Related standards
- ISO 31000:2018 - Risk management - Guidelines (framework alignment)
- ISO/IEC 22989:2022 - AI concepts and terminology
- ISO Guide 73:2009 - Risk management vocabulary
ISO/IEC 23894:2023 helps organizations operationalize AI risk management: aligning governance, technical controls, stakeholder engagement and continuous monitoring across the AI lifecycle.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 42 - Artificial intelligence
- SKU
- ISO/IEC 23894:2023
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO 31000:2018
ДействующийRisk management — Guidelines
Overview ISO 31000:2018 - Risk management - Guidelines provides a unified, organization‑wide approach to managing risk. It offers adaptable guidance that can be customized to any organization, sector…
BS ISO/IEC 27557:2022
ДействующийInformation security, cybersecurity and privacy protection. Application of ISO 31000:2018 for organizational…
ISO 8689-1:2000
ДействующийWater quality — Biological classification of rivers — Part 1: Guidance on the interpretation of biological qu…
Overview ISO 8689-1:2000, titled Water quality - Biological classification of rivers - Part 1: Guidance on the interpretation of biological quality data from surveys of benthic macroinvertebrates, is…
ISO/ASTM51540-04(2012)
ОтменёнStandard Practice for Use of a Radiochromic Liquid Dosimetry System (Withdrawn 2020)
Significance and Use4.1 The radiochromic liquid dosimetry system provides a means of measuring absorbed dose in materials (5-7). Under the influence of ionizing radiation, chemical reactions take pla…
ISO/ASTM51204-04
ДействующийStandard Practice for Dosimetry in Gamma Irradiation Facilities for Food Processing (Withdrawn 2013)
Significance and Use4.1 Food products may be treated with ionizing radiation, such as gamma-rays from 60Co or 137Cs sources, for numerous purposes, including control of parasites and pathogenic micro…
ISO/ASTM51431-05
ОтменёнStandard Practice for Dosimetry in Electron Beam and X-Ray (Bremsstrahlung) Irradiation Facilities for Food P…
Significance and Use4.1 Food products may be treated with acceleratorgenerated radiation (electrons and X-rays) for numerous purposes, including control of parasites and pathogenic microorganisms, in…
ISO/ASTM52628-20e1
ДействующийStandard Practice for Dosimetry in Radiation Processing
1.1 This practice describes the basic requirements that apply when making absorbed dose measurements in accordance with the ASTM E61 series of dosimetry standards. In addition, it provides guidance o…
ISO/ASTM52921-13(2019)
ДействующийStandard Terminology for Additive Manufacturing—Coordinate Systems and Test Methodologies
Significance and Use 3.1 Although many additive manufacturing systems are based heavily upon the principles of Computer Numerical Control (CNC), the coordinate systems and nomenclature specific to CN…