ISO/IEC
ISO/IEC 23894
Guidance on applying ISO 31000's general risk management principles specifically to AI — not certifiable on its own, but the reference most 42001 risk-assessment work actually leans on.
ISO/IEC 23894 is easy to confuse with ISO/IEC 42001 because they're published by the same committee and used together constantly — but they do different jobs. 42001 is the certifiable management-system standard; 23894 is guidance on the risk management process specifically, adapting the general-purpose ISO 31000 risk management standard to AI's particular risk characteristics. You don't get certified against 23894 — you use it to actually do the risk assessment work that 42001 (or any other framework) requires.
What it covers that general risk management guidance doesn't
ISO 31000 gives you a risk management process that works for any organizational risk — financial, operational, strategic. 23894 adapts that process specifically for AI risk characteristics that don't map cleanly onto traditional risk categories: risks that emerge from training data rather than a discrete failure event, risks that change as a model is retrained or fine-tuned after deployment, and risks — like a model producing subtly biased outputs — that can be real and material without any single identifiable "incident" triggering them.
How organizations actually use it
Most commonly, as the risk-assessment methodology underneath a broader governance effort — an organization building toward ISO/IEC 42001 certification uses 23894 as the concrete "how" for the risk assessment component 42001 requires, rather than inventing a bespoke AI risk methodology from scratch. It's also a reasonable reference independent of any certification goal, for teams that want a structured way to think through AI-specific risk without committing to a full management-system build.
Relationship to the NIST AI RMF's "Measure" function
23894's risk assessment guidance and the NIST AI RMF's Measure function cover substantially similar ground — organizations already using the NIST framework will find 23894 a natural, compatible addition for teams that want more procedural specificity than the RMF itself provides, rather than a competing approach requiring a choice between them.
Sources & references
Suggested next reading
frameworks