Skip to content
23894:2023ISO/IEC 23894

Risk management,
applied to AI.

Run a proper risk process on real systems, with AI’s own risk sources named on each one.

Principles, framework, process
Clause 4Principleswhat it is for
Clause 5Frameworkhow it is run
Clause 6Processthe work, per system

Annex B · the risk sources the guidance adds for AI — environment complexity, transparency, level of automation, machine-learning-specific sources and technology maturity.

01Requirements

What the guidance asks you to work through.

ISO/IEC 23894 takes the classic ISO 31000 risk process and adapts it for AI. Each step is something you do per system — and write down.

Cl. 6.3

Scope, context and criteria

Where each system runs, and the yardstick its risks will be judged against.

Cl. 6.4.2

Risk identification

Name what could go wrong per system, including the risks unique to machine learning.

Cl. 6.4.3

Risk analysis

How likely each risk is, how bad it would be — worked out and recorded.

Cl. 6.4.4

Risk evaluation

Each risk compared against your criteria to decide whether it is acceptable.

Cl. 6.5

Risk treatment

What you decided to do about it, and a named person accepting what remains.

Cl. 6.6

Monitoring and review

Risks revisited as the system, its data and its context change.

The AI risk process

The ISO 31000 process, adapted for AI.

The guidance keeps the familiar risk process and changes what goes into it — the sources, the analysis and the review are all AI-specific.

6.3Scope, context, criteria
6.4.2Risk identification
6.4.3Risk analysis
6.4.4Risk evaluation
6.5Risk treatment
6.6Monitoring and review

Communication, consultation, recording and reporting run alongside every step rather than after them.

02In practice

From guidance to practice.

ISO/IEC 23894 describes how AI risk should be managed. Making it work means connecting that process to real systems and the evidence behind each risk.

FrameworkCoverage

A risk framework is real when every AI system you run sits inside it.

Risk listRisk sources

A risk becomes actionable when the thing that produces it is named.

AnalysisEvidence

An analysis holds up when what informed it is kept with it.

ReviewContinuous review

Risk stays current as systems, data and context change.

03Strai8 for ISO/IEC 23894

From risk guidance to live AI governance.

Strai8 connects the risk process to the systems, sources, treatments and evidence across your AI environment.

Discovery

Find the AI already in use.

Find every AI system before risk work begins — endpoints, apps, models, third-party services.

Risk sources

Name what actually produces risk.

Attach the guidance’s own risk sources to the systems and models that carry them.

Analysis

Analyse each risk on the record.

Record likelihood, impact and reasoning on the system itself, not in a spreadsheet.

Treatment

Track what you decided to do.

Treatment plans, owners and accepted residual risk, carried on the system itself.

Monitoring

Keep risk current.

Get told when a change to a system, model or dataset makes an analysis stale.

Reporting

Turn risk work into a record.

Generate one trail connecting risks, sources, decisions, treatments and evidence.

04Questions

Questions teams ask about ISO/IEC 23894.

ISO/IEC 23894

Run the risk process on real systems.

Thirty minutes on your own estate: which risks are named, analysed, treated and still current.