← All guidesISO/IEC 23894 — AI Risk Management

ISO/IEC 23894 – A new standard for risk management of AI

Source
AI Standards Hub (The Alan Turing Institute); author Tim McGarr, Sector Lead (Digital), BSI
URL
https://aistandardshub.org/a-new-standard-for-ai-risk-management
Type
blog post
Retrieved
2026-08-17
License note
Summary and analysis by On The Ground (OTG). Original article © source_organization. This is an original summary, not a reproduction of the source text — see source_url for the complete original.

What ISO/IEC 23894 covers

ISO/IEC 23894, published in February 2023, sets out strategic guidance for organizations of any size or sector on managing the risks that come with developing and using AI. Its aim is to help organizations weave risk management into their AI-related activities and business functions rather than treating it as a bolt-on exercise.

Two features of the standard stand out. First, it does not stop at abstract principles — it gives worked examples of how risk management can actually be implemented and integrated across the AI development lifecycle. Second, it goes into detail on the risk sources that are specific to AI, rather than only restating generic technology risk. Because the guidance is written to be adaptable, organizations are expected to tailor it to their own business context rather than apply it as a fixed checklist.

Relationship to existing risk management standards

Risk management, at its core, exists to help organizations create and protect value, and ISO 31000:2018 is the established international standard that guides how organizations do this across every sector. Rather than inventing a separate, bespoke risk methodology for AI, the drafters of ISO/IEC 23894 chose to build directly on ISO 31000's existing principles, framework, and process. The reasoning was that generic risk management principles already travel well across domains, so AI did not need its own from-scratch system — it needed an AI-specific layer on top of the existing one.

ISO/IEC 23894 also draws on two companion documents: ISO Guide 73:2009 (Risk Management — Vocabulary), which supplies the shared risk terminology, and ISO/IEC 22989 (Information technology — Artificial intelligence — Concepts and terminology), which supplies the AI-specific concepts and the AI system life-cycle model that the risk standard maps onto.

Why AI risk needs specific treatment

AI systems are more complex than most other technologies an organization deploys, and that complexity multiplies the number of places risk can originate. AI introduces risks that are genuinely new to an organization, or that were not previously on its radar, with effects that can be positive or negative for strategic objectives — and it can also shift the likelihood or shape of risks the organization already had. That combination is why generic risk management principles, while still valid, need AI-specific elaboration to be applied well.

Annex C: mapping risk management to the AI life cycle

The article singles out Annex C as the standard's most practically important contribution. Annex C provides a functional mapping between risk management processes and the stages of the AI system life cycle (using the life-cycle model defined in ISO/IEC 22989). It lays out both "vertical" and "horizontal" pathways — that is, how risk management principles, frameworks, and processes connect to each life-cycle stage, and how they connect to each other — in a way that can be adapted to any organization's circumstances. The article treats Annex C as the primary practical tool the standard offers for actually operationalizing AI risk management, rather than the principles or process clauses considered in isolation.