Standard / soft law
AI-specific risk management should follow a documented identify-analyse-evaluate-treat-monitor process (ISO/IEC 23894)
ISO/IEC 23894:2023 is international guidance for AI risk management. In our own words from its public scope: it guides organizations that develop, produce, deploy, or use AI-enabled products, systems, and services in managing AI-specific risk and integrating that risk management into their existing activities and functions. It adapts ISO 31000:2018 concepts to AI-related objectives, risk sources, and life-cycle activities, including post-deployment as well as design. It can complement an ISO/IEC 42001 AI management system but is not itself certifiable. Detect an AI system with no documented AI-specific risk-management process for identifying, analysing, evaluating, treating, and monitoring risks across the life cycle. [TIER C: own-words summary of public scope; licensed normative text not stored.]
iso-23894.ai-risk-management-process · ISO/IEC 23894:2023 (AI risk management process; Annexes A/B/C) · official source · jurisdictions: INTL