ISO/IEC

ISO/IEC 23894

Guidance on applying ISO 31000's general risk management principles specifically to AI — not certifiable on its own, but the reference most 42001 risk-assessment work actually leans on.

Certifiable standard
Risk analysts mapping AI risk factors on a whiteboard during a working session
Photo: Walls.io via Unsplash
Governome Editorial Team2 min readHow we source and review this content.

ISO/IEC 23894 is easy to confuse with ISO/IEC 42001 because they're published by the same committee and used together constantly — but they do different jobs. 42001 is the certifiable management-system standard; 23894 is guidance on the risk management process specifically, adapting the general-purpose ISO 31000 risk management standard to AI's particular risk characteristics. You don't get certified against 23894 — you use it to actually do the risk assessment work that 42001 (or any other framework) requires.

What it covers that general risk management guidance doesn't

ISO 31000 gives you a risk management process that works for any organizational risk — financial, operational, strategic. 23894 adapts that process specifically for AI risk characteristics that don't map cleanly onto traditional risk categories: risks that emerge from training data rather than a discrete failure event, risks that change as a model is retrained or fine-tuned after deployment, and risks — like a model producing subtly biased outputs — that can be real and material without any single identifiable "incident" triggering them.

How organizations actually use it

Most commonly, as the risk-assessment methodology underneath a broader governance effort — an organization building toward ISO/IEC 42001 certification uses 23894 as the concrete "how" for the risk assessment component 42001 requires, rather than inventing a bespoke AI risk methodology from scratch. It's also a reasonable reference independent of any certification goal, for teams that want a structured way to think through AI-specific risk without committing to a full management-system build.

Relationship to the NIST AI RMF's "Measure" function

23894's risk assessment guidance and the NIST AI RMF's Measure function cover substantially similar ground — organizations already using the NIST framework will find 23894 a natural, compatible addition for teams that want more procedural specificity than the RMF itself provides, rather than a competing approach requiring a choice between them.

Sources & references

  1. ISO/IEC 23894:2023 — Information technology — Artificial intelligence — Guidance on risk management
Auditor reviewing AI management system documentation for certification
Photo: Zulfugar Karimov via Unsplash

frameworks

ISO/IEC 42001

ISO/IEC 42001 is a certifiable AI management system standard. Unlike the NIST AI RMF, an accredited body can actually audit you against it and issue a certificate.
Governome Editorial Team · 2 min read
Risk management team analyzing AI system risk factors in a meeting
Photo: Christina @ wocintechchat.com M via Unsplash
The NIST AI RMF is a voluntary, four-function framework for managing AI risk. It carries real legal weight in the US — Colorado's AI Act ties an affirmative defense directly to it.
Governome Editorial Team · 2 min read