ISO/IEC 23894
ISO/IEC 23894:2023 — AI Risk Management Guidance
International guidance for managing AI-specific risk across the lifecycle — the bridge between enterprise risk management and day-to-day AI governance.
26 individual requirements seeded and assessable in AIXYRA.
ISO/IEC 23894 adapts the ISO 31000 risk management framework to AI: it walks through how AI-specific risk sources — data quality, model opacity, autonomy, third-party components — should be identified, analyzed, evaluated, and treated across the AI lifecycle. It is guidance rather than a certifiable standard, and pairs naturally with ISO/IEC 42001, which requires risk management an AIMS can point to.
Its practical value is vocabulary and structure: it gives risk teams and AI teams a shared, auditable way to talk about AI risk. The gap it leaves is tooling — a documented process still needs an inventory, scoring, and records to operate at scale.
Who it applies to
Risk management and AI governance teams in any organization that develops or deploys AI — particularly those building toward ISO/IEC 42001 or aligning AI risk with an existing ISO 31000-based ERM program.
Key requirement themes
AI-specific risk sources
Data quality, drift, opacity, autonomy, and supply-chain components — risks classical ERM frameworks don't enumerate.
Lifecycle integration
Risk management woven through design, development, deployment, and operation rather than a one-time gate.
Risk treatment & monitoring
Documented treatment decisions and continuous monitoring, feeding back into assessment.
ERM alignment
AI risk expressed in ISO 31000 terms, so it rolls up into the enterprise risk picture.
Orientation for evaluators — not legal advice. Consult counsel for obligations specific to your organization.
How AIXYRA helps
- Six-dimension risk scoring — data sensitivity, use case, deployment scope, regulatory reach, concentration, technology risk — gives AI-specific risk sources a measurable form
- Dependency-propagated scores capture supply-chain and third-party risk that isolated assessments miss
- Monitoring triggers reassessment when runtime behavior drifts, making lifecycle risk management continuous
- Assessments map to seeded ISO/IEC 23894 articles, with the audit trail as the documented record
ISO/IEC 23894 FAQ
Is ISO/IEC 23894 certifiable?
No — it is guidance, not a management system standard. Organizations typically use it to structure AI risk management practice, often alongside ISO/IEC 42001 (which is certifiable) and an ISO 31000-based enterprise risk program.
How does AIXYRA's risk model relate to ISO/IEC 23894?
AIXYRA scores each entity across six risk dimensions aligned to recognized AI risk categories, propagates risk through dependency chains, and re-triggers assessment on monitored drift — an operational implementation of the lifecycle risk management the guidance describes, with seeded articles to assess against.
Assess your AI systems against ISO/IEC 23894
ISO/IEC 23894 ships built into AIXYRA — and the same assessment maps to every other enabled framework at once.