ISO/IEC 22989 — AI Concepts and Terminology

How to manage AI risk — the methodology behind ISO/IEC 42001's Clause 6.1

If ISO/IEC 42001 requires you to "manage AI risk," ISO/IEC 23894:2023 is the standard that answers "how." ISO/IEC 42001 (Clause 6.1) requires AI risk assessment and treatment but does not prescribe a method; ISO/IEC 23894 fills that gap. Read together, the requirement and the implementation method join up. This page explains what AI risk means in ISO/IEC 23894, how its risk management process runs, and what you actually look at to find risk.

Note that ISO/IEC 23894 is not itself certifiable. It is the methodology guidance an organization preparing for ISO/IEC 42001 certification draws on when it implements risk management.

Scope note

This overview is based on the published text of ISO/IEC 23894:2023, read alongside ISO 31000:2018 and ISO/IEC 42001:2023. Where a term could be ambiguous, the standard's wording is used. For formal citation or document submission, refer to the official standard text.

What is ISO/IEC 23894?

ISO/IEC 23894:2023 is the international standard for AI risk management guidance, published by ISO/IEC JTC 1/SC 42 in 2023. It applies to any organization that develops, provides, or uses AI, and is designed to be tailored to the organization and its context.

The standard is built on the structure of ISO 31000:2018, the generic risk management standard — its principles, framework, and process — with the additional considerations an AI system needs layered on top. So an organization that already runs a risk management system can reuse the skeleton and add only the AI-specific considerations. Internationally, ISO/IEC 23894 sits alongside the US NIST AI Risk Management Framework as one of the two main reference points for AI risk management; where the NIST AI RMF organizes the work into Govern, Map, Measure, and Manage functions, ISO/IEC 23894 frames it as principles, framework, and process inherited from ISO 31000. Both share the same risk-based logic that underpins the EU AI Act.

The standard has three main parts and three informative annexes:

  • Principles (Clause 4) — the eight principles risk management should follow, with the points that matter most for AI called out.
  • Framework (Clause 5) — the leadership, design, implementation, evaluation, and improvement structure for integrating risk management into the organization's activities.
  • Process (Clause 6) — the actual procedure: scope, context, and criteria; risk assessment and treatment; monitoring and review; recording and reporting — all underpinned by communication and consultation.
  • Annex A (objectives) — 11 AI-related objectives to examine when looking for risk.
  • Annex B (risk sources) — example lists across seven areas of risk source specific to AI.
  • Annex C (lifecycle) — an example mapping of risk management onto the stages of the AI system lifecycle.

Key point 1 — Risk includes opportunity, not just threat

Many organizations treat risk management as "stopping bad things from happening." The definition ISO/IEC 23894 works from is broader.

Following ISO 31000, it defines risk as the effect of uncertainty on objectives — and that effect can be negative or positive. Risk is the umbrella concept that spans both the downside (threat) and the upside (opportunity), often summarized as risk = threat + opportunity.

This definition is not just a statement; it shapes how treatment actually works. ISO/IEC 23894's risk-treatment options include "taking or increasing risk in order to pursue an opportunity." Reducing or removing harm is not the only valid move — deliberately accepting risk when the expected value is high is a legitimate strategy. The decision to adopt AI at all is itself an example.

One more distinction is worth fixing. When an event occurs it produces a consequence, and the degree to which that consequence affects the organization, individuals, and society is its impact. ISO/IEC 23894 asks you to evaluate consequences, and to do so across business impact, impact on individuals, and impact on society. The AI system impact assessment required by ISO/IEC 42001, Clause 6.1.4, develops exactly this individual-and-society axis into a separate, formal procedure.

Key point 2 — AI risk keeps changing after launch

Of ISO/IEC 23894's eight principles, the one that carries the most weight for AI is "dynamic." The standard notes that dynamic risk management matters especially for AI, for three reasons:

  • First, AI systems are dynamic by nature — continuous learning, refinement, and evaluation occur, and some systems adapt and generate change on their own.
  • Second, customer expectations of AI are high and shift as fast as the systems do.
  • Third, the legal and regulatory requirements around AI are updated frequently.

Traditional risk assessment leans toward a static model — assess once, review periodically. But because an AI system's model, data, and operating environment can change while it is in use, its risk profile can differ between launch and six months later. So ISO/IEC 23894 calls for structures and means to identify newly emerging risks and changes.

This "dynamic" mindset runs through the whole standard. The core message of ISO/IEC 23894 is that risk management is not a one-off activity before launch, but a process repeated across the lifecycle.

Key point 3 — The risk management process, one full loop

ISO/IEC 23894's process (Clause 6) runs as a flow — underpinned by communication and consultation — from setting scope, context, and criteria, to risk assessment (identification, analysis, evaluation), to risk treatment, to monitoring and review, to recording and reporting.

Setting context — start from an AI inventory

First, document the inventory of AI systems the organization develops and uses. The criteria for evaluating risk (what to look at, and how seriously) are also set here. Because AI changes quickly, the standard stresses checking continually that your measurement methods are still appropriate.

Risk assessment — what, to whom, and how much

In identification, you examine not only assets such as data, models, and systems, but also the tangible and intangible factors that bear on the risk judgment — reputation and trust, an individual's privacy, health, and safety, and societal values. The standard stresses that the group benefiting from the technology and the group experiencing its negative outcomes may not be the same.

In analysis, consequences are evaluated across business impact, impact on individuals, and impact on society. Likelihood is assessed too — but with a practical warning not to force numbers where likelihood is hard to compute or carries a large margin of error. The point is to beware the quantification trap in AI risk.

Treatment, monitoring, recording

Risk treatment is designed to reduce negative outcomes to an acceptable level while raising the likelihood of positive ones. The options include avoidance, taking risk to pursue an opportunity, removing the source, changing likelihood or consequences, sharing risk (contract, insurance), and informed retention.

Finally, recording and reporting gathers information surfaced in operation, and information about similar systems in the market, to re-evaluate whether a previously unseen risk has appeared or a once-accepted risk is no longer acceptable — and feeds the result back into the risk management process. This feedback loop is what makes the "dynamic" principle actually operate.

Key point 4 — What you look at to find risk (Annexes A, B, C)

Looking for risk "in the abstract" is hard. ISO/IEC 23894 provides starting points in three annexes. All are informative (advisory), so they are not mandatory lists to apply wholesale, but checklists an organization selects from.

Annex A sets out 11 AI-related objectives to examine when looking for risk. For each objective, you ask "what situation would threaten this?" and check for risk that way: accountability; AI expertise; availability and quality of training and test data; environmental impact; fairness; maintainability; privacy; robustness; safety; security; and transparency and explainability.

Annex B shows examples across seven areas of risk source specific to AI. The standard notes the list is not exhaustive but is useful as a documented baseline for an organization assessing risk for the first time: complexity of the environment; lack of transparency and explainability; level of automation; machine-learning-related sources (data quality, acquisition, continuous learning); system hardware; lifecycle issues; and technology readiness.

Annex C shows how risk management applies across the AI system lifecycle, presented as a flow: inception → design and development → verification and validation → deployment → operation and monitoring → continuous validation → re-evaluation → retirement or replacement. At each stage, risk criteria and treatment plans are reviewed and adjusted again — reinforcing that risk management repeats rather than happening once. (The data and bias risks of machine learning are treated in more depth in our bias management guidance, forthcoming.)

How it connects to ISO/IEC 42001

In the context of this series, ISO/IEC 23894 is most valuable read as the method for implementing ISO/IEC 42001, Clause 6.1:

  • ISO/IEC 42001 6.1.2 (AI risk assessment) can be made concrete by reference to ISO/IEC 23894's assessment procedure.
  • ISO/IEC 42001 6.1.3 (AI risk treatment) can be designed using ISO/IEC 23894's treatment options and its approach to judging residual risk.
  • ISO/IEC 42001 6.1.4 (AI system impact assessment) connects closely to the individual-and-society impact analysis ISO/IEC 23894 covers.

A note on ordering: in the body of ISO/IEC 42001, impact assessment (6.1.4) comes after risk assessment (6.1.2), but a NOTE in 6.1.2 says the output of the impact assessment can be used as an input to the risk assessment. In practice it is natural to design the impact assessment to feed the risk assessment.

From an audit perspective — points to watch

Risk management is one of the areas practitioners find hardest, in AI governance as much as in information security (ISO/IEC 27001) or service management (ISO/IEC 20000) — and the dynamic nature of AI raises the difficulty another notch. The gaps that can surface include the following. (These are situations that can arise in practice, not assertions of frequency.)

  • Staying at a static assessment — a single pre-launch assessment exists, with no defined trigger to re-assess when the model, data, or environment changes.
  • Narrowing risk to threat only — taking risk to pursue an opportunity, or raising the likelihood of positive outcomes, is missing from the treatment strategy.
  • Seeing consequences only as organizational loss — only business impact is assessed; impact on individuals and society is not, so the link to the ISO/IEC 42001 impact assessment is broken.
  • Omitting AI-specific risk sources — sources such as data acquisition, continuous learning, level of automation, and the hand-off of control to a person are absent from the identification list.

In an audit, you would typically be asked to show not just the risk management procedure but the records that it has actually run, repeatedly, across the lifecycle — re-assessment history, impact-analysis outputs, and the rationale behind treatment decisions.

Putting it into practice — where to start

Starting points by situation:

  • An organization formalizing risk management for the first time — begin identification from the Annex B risk sources and the 11 Annex A objectives as a baseline, and use an AI risk management template as your starting document.
  • An organization preparing for ISO/IEC 42001 certification — implement 6.1.2 and 6.1.3 with ISO/IEC 23894's assessment and treatment procedure, and connect the 6.1.4 impact assessment to ISO/IEC 23894's individual-and-society impact analysis.

To see where this sits in the wider portfolio, the ISO/IEC AI Standards Map lays out the SC 42 standards by category on a single page.

Key terms at a glance

TermMeaning
riskThe effect of uncertainty on objectives. Spans both threat (negative) and opportunity (positive).
consequenceThe outcome an event brings about. Can be positive or negative.
impactThe degree to which a consequence affects the organization, individuals, and society. The basis for the ISO/IEC 42001 impact assessment.
risk sourceAn element with the potential to give rise to risk (see Annex B).
risk treatmentThe response: avoid, take, remove, change, share, or retain.

The bottom line

ISO/IEC 23894:2023 does not invent new risk management principles. It adds the characteristics of AI on top of a proven risk management structure and points out what is different about AI risk. Two things matter most. First, what we call "risk" includes opportunity, not just threat. Second, AI risk is not fixed at launch; it changes while the system is in use. Built on ISO 31000 and aligned with the NIST AI Risk Management Framework and the EU AI Act's risk-based approach, ISO/IEC 23894 is the method layer that makes ISO/IEC 42001's Clause 6.1 operational.

Next in this series: ISO/IEC 42005:2025 — AI System Impact Assessment, the standard that develops the individual-and-society impact axis into a formal procedure of its own.

 


📚 SC 42 AI Standards Series

← Previous: ISO/IEC 42001:2023 — The AI Management System Standard

📍 Current: ISO/IEC 23894:2023 — Guidance on AI Risk Management

→ Next: ISO/IEC 42005:2025 — AI System Impact Assessment (forthcoming)

Download the SC 42 AI Standards Map