Skip to main content

ISO/IEC 23894:2023 — AI Risk Management

standard

ISO/IEC 23894:2023 is an international standard providing guidance on managing risks faced by organisations that develop, provide, deploy, or use AI systems.

Status: published
Last reviewed: 2026-09-12

Technical explanation

The standard adapts risk-management principles to AI by addressing organisational context, lifecycle activities, stakeholders, sources of risk, assessment, treatment, communication, monitoring, and review. It is guidance rather than a certifiable requirements standard and is intended to integrate with broader risk-management practices.

Business relevance

ISO/IEC 23894 gives organisations a common structure for connecting AI-specific technical and societal concerns with enterprise risk governance and accountable decisions.

Implementation example

A provider uses the standard to identify risks across data, model, integration, user interaction, and post-deployment monitoring, then assigns treatments and residual-risk owners.

Limitations and common misconceptions

The standard does not prescribe universal controls or establish that residual risk is acceptable. It must be adapted to the system, stakeholders, legal context, and organisational risk criteria.

Discuss your systems

Need help implementing or evaluating this concept? Keenfunnel designs connected AI, automation, and data systems.

Book a discovery session