Risk management,
applied to AI.
Run a proper risk process on real systems, with AI’s own risk sources named on each one.
Annex B · the risk sources the guidance adds for AI — environment complexity, transparency, level of automation, machine-learning-specific sources and technology maturity.
What the guidance asks you to work through.
ISO/IEC 23894 takes the classic ISO 31000 risk process and adapts it for AI. Each step is something you do per system — and write down.
Scope, context and criteria
Where each system runs, and the yardstick its risks will be judged against.
Risk identification
Name what could go wrong per system, including the risks unique to machine learning.
Risk analysis
How likely each risk is, how bad it would be — worked out and recorded.
Risk evaluation
Each risk compared against your criteria to decide whether it is acceptable.
Risk treatment
What you decided to do about it, and a named person accepting what remains.
Monitoring and review
Risks revisited as the system, its data and its context change.
The AI risk process
The ISO 31000 process, adapted for AI.
The guidance keeps the familiar risk process and changes what goes into it — the sources, the analysis and the review are all AI-specific.
Communication, consultation, recording and reporting run alongside every step rather than after them.
From guidance to practice.
ISO/IEC 23894 describes how AI risk should be managed. Making it work means connecting that process to real systems and the evidence behind each risk.
A risk framework is real when every AI system you run sits inside it.
A risk becomes actionable when the thing that produces it is named.
An analysis holds up when what informed it is kept with it.
Risk stays current as systems, data and context change.
From risk guidance to live AI governance.
Strai8 connects the risk process to the systems, sources, treatments and evidence across your AI environment.
Discovery
Find the AI already in use.
Find every AI system before risk work begins — endpoints, apps, models, third-party services.
Risk sources
Name what actually produces risk.
Attach the guidance’s own risk sources to the systems and models that carry them.
Analysis
Analyse each risk on the record.
Record likelihood, impact and reasoning on the system itself, not in a spreadsheet.
Treatment
Track what you decided to do.
Treatment plans, owners and accepted residual risk, carried on the system itself.
Monitoring
Keep risk current.
Get told when a change to a system, model or dataset makes an analysis stale.
Reporting
Turn risk work into a record.
Generate one trail connecting risks, sources, decisions, treatments and evidence.
Questions teams ask about ISO/IEC 23894.
Run the risk process on real systems.
Thirty minutes on your own estate: which risks are named, analysed, treated and still current.