Frameworks / ISO_23894
ISO/IEC 23894:2023 — AI Risk Management
ISO/IEC · International · effective 2023-02-01 · ISO_23894
Risk management guidance specific to AI, complementing ISO 31000. Process guidance rather than a conformity bar.
3 controls, mapped to the evidence that satisfies each
Every control links to the dimension whose evidence would satisfy it. That mapping is the working link between an obligation written in law or a standard and a document somebody has to produce. Each row has its own address: link to a single control.
| Control | Title | Requirement | Satisfied by |
|---|---|---|---|
| Clause 6 | Process | An AI risk management process is applied: establishing scope, context and criteria; identifying, analysing and evaluating risk; treating risk; and continually communicating, monitoring, reviewing, recording and reporting. | D2 |
| Clause 4 | Principles | AI-adapted risk management principles, based on ISO 31000, are established as the basis for the organization's approach. | D6 |
| Clause 5 | Framework | A risk management framework is established covering leadership and commitment, integration into organizational processes, design, implementation, evaluation and improvement. | D6 |
What this mapping is, and what it is not
It is a reading of a published instrument, with each control cited to its source, mapped to the kind of evidence that would satisfy it. It is not legal advice, not a certification, and not a statement that any organisation complies with anything. Where an instrument is not yet in force, this page says so rather than selling urgency.
Talk to the person who built this
If you assess clients against this instrument, the mapping is the part you can check line by line. There is no sales team: this is founder-led, so it reaches the founder directly. Tenant access is $500 a month, and free early access to the method, the corpus and the router is on offer first if that is useful. If it is not a fit, saying so costs you one reply.