ISO/IEC 23894
International guidance for integrating AI-specific risk management into organizations that develop, provide, deploy, or use AI systems. It complements ISO/IEC 42001 and is guidance, not a standalone certification.
2023 · ISO/IEC 23894:2023 · published 2023-02-06
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
ISO/IEC 23894 is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Licensed standard — purchase from ISO or a national member body and obtain software-use rights before verbatim ingestion.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- AI risk-management principles · AI risk-management process · Organizational integration · Monitoring and review
- Applies to
- AI · technology · all sectors · global
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-08-30
03Version ledger
| 2023 | Current edition | 2023-02-06 |
06Related frameworks
- ISO/IEC 420052025
Also applies to AI · International guidance for repeatable AI-system impact assessments across the system lifecycle. It complements ISO/IEC 42001, ISO/IEC 23894, and applicable AI laws; it is not an AI certification by itself.
- EU AI ActRegulation (EU) 2024/1689
Also applies to AI · The EU's risk-tiered regime for AI systems — prohibited practices, high-risk obligations, general-purpose model duties, and transparency requirements.
- ISO/IEC 420012023
Also applies to AI · The first certifiable management system standard for AI — the ISO 27001 shape applied to how an organization builds and operates AI systems.
- Shared Assessments SIG2026 annual release
Also applies to all sectors · The licensed Standardized Information Gathering questionnaire used for risk-based third-party due diligence across security, privacy, resilience, and operational domains. SIG responses are assessment inputs—not a certification, attestation, or independent assurance opinion.