Skip to main content
v2026.11,858 entries · CC-BY 4.0

ISO/IEC 23894:2023: The AI Risk Management Guidance Nobody Cites

ISO/IEC 23894:2023 is the oldest SC 42 AI document and the most consistently skipped. It is guidance rather than requirements, an AI-specific application of ISO 31000 rather than a new framework, and it is not certifiable. Verified identity from the IEC catalogue, the ISO 31000 inheritance, the NIST crosswalk that was quietly revised in August 2025, and where 23894 sits between 42001, 42005 and 42006.

Written and maintained by CASRAI Editorial Board

Last updated

There is a document sitting in the middle of the AI governance stack that almost nobody cites. Teams reach for the NIST AI Risk Management Framework when they want structure, and for ISO/IEC 42001 when they want a certificate. The ISO/IEC document actually about AI risk management — ISO/IEC 23894:2023 — gets skipped, even by organisations that are already deep in both of its neighbours. NIKOLAI, CASRAI’s independent frontier-AI-safety dictionary, has a related vocabulary problem in its N4 track: the phrase “risk level” gets used for objects at completely different altitudes, and 23894 is a good illustration of why that matters.

This guide does two things. First, it states what ISO/IEC 23894:2023 verifiably is, from the publisher’s own catalogue record. Second — and this is the more useful half — it sets out what it is not, because nearly every misconception about this document is a category error rather than a factual mistake.

What ISO/IEC 23894:2023 actually is

The catalogue record on the IEC Webstore, the co-publisher’s own listing, gives the following verified identity:

Field Value
Designation ISO/IEC 23894:2023
Full title Information technology — Artificial intelligence — Guidance on risk management
Edition 1.0 (first edition)
Publication date 6 February 2023
Length 26 pages
Committee ISO/IEC JTC 1/SC 42, Artificial intelligence
ICS 35.020
Status Published

Two of those rows do most of the explanatory work. The title contains the word Guidance, not “Requirements” and not “Specification” — in ISO drafting conventions that word choice is load-bearing, not stylistic. And the document is 26 pages, which is short for a standard that people expect to carry a complete risk methodology.

The scope statement, as published in that catalogue record, describes a document that

provides guidance on how organizations that develop, produce, deploy or use products, systems and services that utilize artificial intelligence (AI) can manage risk specifically related to AI … The application of this guidance can be customized to any organization and its context.

Note the second sentence. “Can be customized to any organization and its context” is the language of an adaptable reference, not of a conformance target. You cannot audit an organisation against a document that explicitly invites each organisation to tailor it.

Three things ISO/IEC 23894 is not

1. It is not a set of requirements

This is the most common confusion, and it is entirely reasonable — people encounter 23894 next to ISO/IEC 42001, assume the ISO/IEC prefix means the same kind of obligation, and plan accordingly. It does not. Guidance documents in the ISO/IEC catalogue use recommendation language (“should”) rather than requirement language (“shall”). There is nothing in a guidance document for an auditor to raise a nonconformity against.

Practically: if a procurement questionnaire or a board paper asks whether you “comply with ISO/IEC 23894”, the honest answer is that compliance is not a state the document defines. You can say that your AI risk management process is informed by or aligned with 23894. You cannot say you comply with it, and you should be suspicious of a vendor who claims they do.

2. It is not a new framework

ISO/IEC 23894 does not invent a risk architecture. It takes the principles / framework / process structure of ISO 31000, the general risk management guidelines, and populates it with AI-specific content. This is not an outside interpretation — NIST states it directly in an explanatory note to its own crosswalk document:

ISO/IEC 23894 provides tailored guidance for AI systems based on the general risk management guidance in ISO 31000. The structure of ISO/IEC 23894 mirrors the structure of ISO 31000 to provide additional AI context and recommendations when needed.

That sentence explains the single most common complaint about the document, which is that it reads as thin. It reads thin to anyone who has not read ISO 31000 first, because it is deliberately not repeating ISO 31000. The clause numbering gives this away immediately: clause 5 covers leadership, integration, design, implementation, evaluation and improvement; clause 6 covers communication and consultation, scope and context and criteria, risk assessment, risk treatment, monitoring and review, and recording and reporting. Anyone who has worked with ISO 31000 will recognise that skeleton on sight, because it is the same skeleton.

So 23894 is best understood as a delta document. Its value is the AI-specific material layered onto an existing architecture — not a standalone methodology you can pick up cold.

3. It is not certifiable

Because 23894 is guidance, and because ISO 31000 — the document whose structure it inherits — is itself titled as guidelines rather than requirements, there is no accredited certification scheme against either one. There is no certificate to obtain, no certification body to engage, and no accreditation layer above such a body, because the lower layers of that stack do not exist.

This matters commercially. The certifiable document in this family is ISO/IEC 42001, the AI management system standard — and even there, a certificate is only meaningful if it came from a properly accredited body, which is a separate question covered in our guide to ISO/IEC 42006 and who is allowed to certify ISO 42001. If someone offers you a “23894 certification”, you are looking at an unaccredited product, not a recognised conformity assessment.

The NIST crosswalk — and an important correction

The single most useful artefact for anyone already working with the NIST AI RMF is NIST’s own published crosswalk between AI RMF 1.0 and ISO/IEC 23894:2023. It exists, it is free, and it is hosted on NIST’s AI Resource Center.

There is a version trap here worth flagging. A crosswalk to ISO/IEC 23894 was first published on 26 January 2023, and that file is labelled as a draft for comment against the FDIS (Final Draft International Standard) text rather than the published standard. NIST’s crosswalk listing now marks that January 2023 file as superseded, and points instead to a revised crosswalk dated 14 August 2025, prepared against the published 23894:2023. If you have the 2023 PDF saved, or if a search engine hands you that URL, you have the draft. Take the 2025 revision.

What the crosswalk maps, and at what resolution

The revised crosswalk is coarser than people often assume. It maps at the level of the four AI RMF functions — GOVERN, MAP, MEASURE, MANAGE — against clauses and sub-clauses of 23894. It is not a subcategory-by-subcategory table. Each function row lists the 23894 clauses that correspond to it, using an explicit notation the document defines: “all sub-clauses” means every sub-clause under that heading is in scope, while “specific sub-clauses” means only a named subset is.

The shape of the mapping, as published:

AI RMF 1.0 function Corresponding ISO/IEC 23894:2023 material
GOVERN — culture of risk management is cultivated and present 5.2 Leadership and commitment; 5.3 Integration; 5.4 Design (all sub-clauses); 5.6 Evaluation; 6.1 General
MAP — context is recognized and risks related to context are identified 5.4.1 Understanding the organization and its context; 6.3 Scope, context and criteria (specific); 6.4.2 Risk identification (specific); 6.4.3 Risk analysis (all); 6.7 Recording and reporting
MEASURE — identified risks are assessed, analyzed, or tracked 5.7 Improvement (all sub-clauses); 6.3.4 Defining risk criteria; 6.4.2.5 Identification of controls; 6.4.3 Risk analysis (specific); 6.4.4 Risk evaluation; 6.6 Monitoring and review
MANAGE — risks are prioritized and acted upon based on projected impact 5.5 Implementation; 5.6 Evaluation; 5.7 Improvement (all sub-clauses); 6.5 Risk treatment (specific); 6.6 Monitoring and review; 6.7 Recording and reporting

One asymmetry is called out explicitly in the crosswalk’s own notes, and it is the detail most worth carrying away: ISO/IEC 23894 contains additional material that does not map to the NIST AI RMF at all, and the note names exactly one such clause — 6.2, Communication and consultation. That is the concrete answer to “what would I gain from 23894 that the AI RMF does not already give me”, and it is a small answer. Anyone claiming a long list of gaps in either direction is going beyond what NIST actually published.

If you want the NIST side of this in detail first, see our walkthrough of the NIST Govern, Map, Measure and Manage functions.

Where 23894 sits in the SC 42 stack

The clearest way to place 23894 is by what each neighbouring document does, because the four are frequently treated as alternatives when they are actually layers.

Document What it is Certifiable?
ISO/IEC 23894:2023 AI risk management guidance; the risk content itself, inherited from ISO 31000’s architecture No — guidance
ISO/IEC 42001:2023 The AI management system standard; the certifiable wrapper that can contain a risk process Yes
ISO/IEC 42005 AI system impact assessment; the companion document about assessing effects on people and society. NIST published a separate crosswalk to it on 14 August 2025 Not a certification target
ISO/IEC 42006:2025 Requirements for the bodies that audit and certify AI management systems; the accreditation layer Not applicable — it governs the certifiers

Read as a stack rather than a menu, the relationship becomes obvious: 23894 is the substance of risk management, 42001 is the management system that can wrap it and be certified, 42005 is the impact-assessment companion, and 42006 is what makes a 42001 certificate mean anything. NIST publishes crosswalks to several of these, including a separate ISO/IEC 42005 crosswalk also dated 14 August 2025.

Our comparison of NIST AI RMF versus ISO/IEC 42001 covers the framework-versus-certificate choice in depth; 23894 is the document that sits between the two and is missing from most versions of that debate.

Who should actually read it

An honest recommendation, rather than a blanket one:

  • Organisations already running ISO 31000. This is the clearest case. You have the architecture; 23894 is the AI delta, and 26 pages is a short read for an existing risk function.
  • Organisations pursuing ISO/IEC 42001 certification. 42001 expects a risk process. 23894 is the SC 42 committee’s own view of what an AI risk process should contain, which makes it the natural source to build that process from.
  • Teams standardised on the NIST AI RMF who need an international reference point. Use the 14 August 2025 crosswalk rather than re-reading both documents in parallel.
  • Teams with no existing risk management architecture at all. This is the group that will be disappointed. 23894 assumes ISO 31000 and will not fill the gap on its own. Start with the architecture, or start with the AI RMF, which is self-contained and free.

If the practical task in front of you is building the register rather than choosing the standard, our guide to an AI risk assessment framework and risk register is the more directly usable starting point.

Where NIKOLAI fits

NIKOLAI is CASRAI’s own independent frontier-AI-safety dictionary. It is unendorsed: its crosswalk rows are shadow mappings — CASRAI’s reading of how an organisation’s published vocabulary lines up with a NIKOLAI element — unless that organisation has filed a Mapping Declaration. Nothing here is an official position of ISO, IEC or NIST.

The relevant element is N4 risk-level, in NIKOLAI’s Claims and Argument track. It proposes “risk level” for the overall graded risk assigned to a model, domain or company activity as a whole, and flags a labelling collision: frontier labs use identical words — “High”, “Critical” — sometimes for capability thresholds and sometimes for net risk after mitigations.

That element illuminates a distinction ISO/IEC 23894 readers run into immediately. A frontier lab’s “risk level” is a small, fixed, published ordinal scale applied to a model. A 23894 risk assessment is an organisational process producing risk criteria that each organisation defines for its own context, per the standard’s own “can be customized to any organization” scope. They are different objects at different altitudes, and a governance document that treats a lab’s tier label as though it were the output of a 23894 assessment has conflated the two.

Frequently asked questions

Can my organisation be certified to ISO/IEC 23894?

No. It is a guidance document, and guidance documents contain recommendations rather than auditable requirements. The certifiable standard in this family is ISO/IEC 42001. Treat any offer of “ISO/IEC 23894 certification” as a red flag.

Is ISO/IEC 23894 a replacement for the NIST AI RMF?

No, and they are not really competitors. The AI RMF is a self-contained framework you can adopt from a standing start. 23894 is an AI-specific layer on top of ISO 31000’s architecture and assumes you have that architecture. NIST publishes a crosswalk precisely because organisations are expected to use both.

Which NIST crosswalk should I use?

The revision dated 14 August 2025. The earlier file dated 26 January 2023 was prepared against the FDIS draft and is now marked superseded on NIST’s own crosswalk listing.

Do I need to buy ISO 31000 as well?

If you do not already have an ISO 31000-based risk architecture, then realistically yes — 23894 mirrors ISO 31000’s structure and adds AI context to it rather than restating the underlying method. Reading 23894 alone tends to produce the impression that it is unhelpfully brief, which is a symptom of reading a delta without its base.

How long is ISO/IEC 23894:2023?

26 pages, first edition, published 6 February 2023 by ISO/IEC JTC 1/SC 42.

What does 23894 cover that the NIST AI RMF does not?

NIST’s own crosswalk note identifies one clause of 23894 as having no counterpart in the AI RMF: 6.2, Communication and consultation. That is the extent of what NIST documents as unmapped, and we would not claim more than that without reading both documents in full.

Sources

  • IEC Webstore catalogue record for ISO/IEC 23894:2023 — designation, title, edition, publication date, page count, committee, ICS classification and scope text.
  • NIST AI Resource Center crosswalk listing — “Crosswalk ISO/IEC 23894 and NIST AI RMF (Revised)”, 14 August 2025, and the superseded “ISO/IEC 23894 FDIS” crosswalk, 26 January 2023.
  • The revised NIST crosswalk document itself — function-level mapping table and explanatory notes 1 to 3, including the ISO 31000 statement and the unmapped clause 6.2.
  • OECD.AI catalogue of tools and metrics — entry for ISO/IEC 23894:2023.

This page describes publicly available documents. CASRAI is not affiliated with ISO, IEC or NIST, and NIKOLAI is an independent, unendorsed dictionary.

Related reading

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Ask CASRAI · free to try

Ask about ISO/IEC 23894:2023: The AI Risk Management Guidance Nobody Cites

Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.

An AI assistant specialized in research administration. It cites the sources behind every answer, labels web answers and says when it can't answer.

Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.

Works on this site and inside Claude, Cursor and the AI tools you already use.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Ask CASRAI · Regulatory Radar

AI policy question? Get an answer citing the framework.

An AI assistant specialized in research administration. Every answer links its sources to check before you act. 2 questions free, no account. $29/month after.

  • Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.
  • Every answer numbers its sources and links each one, so you can check the source yourself.