Skip to main content
Framework library
Framework module · iso-23894-2023

ISO/IEC 23894

International guidance for integrating AI-specific risk management into organizations that develop, provide, deploy, or use AI systems. It complements ISO/IEC 42001 and is guidance, not a standalone certification.

2023 · ISO/IEC 23894:2023 · published 2023-02-06

Standing today
Directory entry

00Answer

from the registry record
What is ISO/IEC 23894?
International guidance for integrating AI-specific risk management into organizations that develop, provide, deploy, or use AI systems. It complements ISO/IEC 42001 and is guidance, not a standalone certification.
Who does ISO/IEC 23894 apply to?
ISO/IEC 23894 applies to AI, technology, all sectors, global, per ISO/IEC 23894:2023.
What is the current version of ISO/IEC 23894?
The current edition is 2023, issued by ISO/IEC 23894:2023 and published 2023-02-06. Source: https://www.iso.org/standard/77304.html.
What does an assessment under ISO/IEC 23894 require?
No control catalog has been ingested for ISO/IEC 23894 yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

ISO/IEC 23894 is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Licensed standard — purchase from ISO or a national member body and obtain software-use rights before verbatim ingestion.

02Registry record

checked 2026-08-30
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
AI risk-management principles · AI risk-management process · Organizational integration · Monitoring and review
Applies to
AI · technology · all sectors · global
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-30

03Version ledger

1 edition
2023Current edition2023-02-06

06Related frameworks

scored from registry facts
  1. Also applies to AI · International guidance for repeatable AI-system impact assessments across the system lifecycle. It complements ISO/IEC 42001, ISO/IEC 23894, and applicable AI laws; it is not an AI certification by itself.

  2. EU AI ActRegulation (EU) 2024/1689

    Also applies to AI · The EU's risk-tiered regime for AI systems — prohibited practices, high-risk obligations, general-purpose model duties, and transparency requirements.

  3. Also applies to AI · The first certifiable management system standard for AI — the ISO 27001 shape applied to how an organization builds and operates AI systems.

  4. Shared Assessments SIG2026 annual release

    Also applies to all sectors · The licensed Standardized Information Gathering questionnaire used for risk-based third-party due diligence across security, privacy, resilience, and operational domains. SIG responses are assessment inputs—not a certification, attestation, or independent assurance opinion.

ISO/IEC 23894 | ControlFrame