The OECD.AI Policy Navigator

Our policy navigator is a living repository from more than 80 jurisdictions and organisations. Use the filters to browse initiatives and find what you are looking for.

Information technology — Artificial intelligence — Guidance on risk management (ISO/IEC 23894)


Added by:   OECD analyst
Added on:   02 Jul 2026
Updated by:   OECD analyst
Updated on:   28 Jul 2026

ISO/IEC 23894 provides guidance on how organisations that develop, produce, deploy or use AI products, systems and services can manage risk specifically related to AI. It assists organisations in integrating risk management into AI-related activities and functions, and describes processes for effective implementation. The guidance can be customised to any organisation and its context, and is intended for use alongside ISO 31000:2018.

Initiative overview

ISO/IEC 23894 was prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology, Subcommittee SC 42, Artificial intelligence. It is intended to be used in connection with ISO 31000:2018, and whenever it extends the guidance given in that standard, an appropriate reference to the relevant clauses is made, followed by AI-specific guidance where applicable. The clause structure of ISO 31000:2018 is mirrored and amended by sub-clauses as needed, to make the relationship between the two more explicit.

The initiative addresses risk management, whose purpose is described as "the creation and protection of value," which "improves performance, encourages innovation and supports the achievement of objectives." It is structured in three main parts. Clause 4, Principles, describes the underlying principles of risk management, noting that the use of AI requires specific considerations with regard to some of these principles as set out in ISO 31000:2018, Clause 4. Clause 5, Framework, has the purpose of assisting "the organization in integrating risk management into significant activities and functions," with aspects specific to the development, provisioning, offering or use of AI systems described in relation to ISO 31000:2018, Clause 5. Clause 6, Processes, covers "the systematic application of policies, procedures and practices to the activities of communicating and consulting, establishing the context, and assessing, treating, monitoring, reviewing, recording and reporting risk," with a specialisation of these processes to AI described in relation to ISO 31000:2018, Clause 6.

Supporting content includes Annex A and Annex B, which provide "common AI-related objectives and risk sources," and Annex C, which provides "an example mapping between the risk management processes and an AI system life cycle." Terms and definitions are drawn from ISO 31000:2018, ISO/IEC 22989:2022 and ISO Guide 73:2009, with the ISO Online Browsing Platform and IEC Electropedia available as terminology databases. Normative references also include these three sources.

Stakeholders involved in development include national bodies that are members of ISO or IEC, which "participate in the development of International Standards through technical committees, as well as other international organizations, governmental and non-governmental, in liaison with ISO and IEC.

About the policy initiative