Overview
EN ISO/IEC 23894:2024 (identical to ISO/IEC 23894:2023) provides practical guidance for organizations that develop, produce, deploy or use products, systems and services that utilize artificial intelligence (AI). The standard explains how to manage risks specifically related to AI, how to integrate risk management into AI activities and functions, and how to implement and adapt an AI risk management program to any organizational context. It aligns with and mirrors the structure of ISO 31000:2018 while adding AI-specific considerations.
Key topics
The standard is structured around principles, a risk management framework and detailed processes. Major technical topics and requirements include:
- Principles of AI risk management - foundational concepts to guide decision‑making and value protection when using AI.
- Framework elements - leadership and commitment; integration into organizational processes; design considerations such as:
- understanding organizational context,
- articulating risk management commitment,
- assigning roles, authorities and accountabilities,
- allocating resources,
- establishing communication and consultation.
- Risk management process - systematic steps for:
- communication and consultation,
- defining scope, context and risk criteria,
- risk assessment (identification, analysis, evaluation),
- risk treatment (selection of options, preparing and implementing treatment plans),
- monitoring, review, recording and reporting.
- AI-specific guidance - mapping risk activities to the AI system life cycle and describing common AI risk sources and objectives (see Annexes A–C).
- Documentation and continual improvement - ensuring decisions, controls and monitoring are recorded and updated as AI systems evolve.
Applications and users
EN ISO/IEC 23894:2024 is aimed at organizations across sectors that build, deploy or procure AI-enabled systems. Typical users include:
- AI/ML engineers, data scientists and system architects
- Product managers and software development teams
- Risk managers, compliance and governance teams
- C-suite (CIO, CTO) and program owners responsible for AI adoption
- Procurement and third‑party risk teams evaluating AI suppliers
- Regulators and auditors seeking conformity with recognized AI risk practices
Practical applications include establishing AI governance, performing AI risk assessments, developing treatment plans (technical and organizational controls), and integrating risk processes into AI system life cycles.
Related standards
- ISO/IEC 23894:2023 (International edition)
- EN ISO/IEC 23894:2024 (European adoption)
- ISO 31000:2018 (Risk management - guidance; referenced and extended for AI-specific concerns)
For organizations implementing AI, EN ISO/IEC 23894:2024 offers a structured, adaptable approach to identify, evaluate and treat AI risks while supporting governance and continuous improvement.