International

ISO/IEC 23894:2023

110 controls. 331 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

110 controls 331 frameworks share controls with it International verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

ISO/IEC 23894:2023 AI Risk Management Evidence & Implementation Kit

110 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
23894-4.1AI Risk Management Principles1
23894-5.2Leadership and Commitment33
23894-5.3Integration into Organizational Processes3
23894-5.4.1Understanding Organization and Context26
23894-5.4.2AI Risk Management Policy4
23894-5.4.3Roles, Authorities, Responsibilities25
23894-5.4.4Allocation of Resources1
23894-5.5Communication and Consultation33
23894-6.3AI Risk Assessment Scope and Criteria0
23894-6.4.2AI Risk Identification4
23894-6.4.3AI Risk Analysis2
23894-6.4.4AI Risk Evaluation3
23894-6.5AI Risk Treatment3
23894-6.6Monitoring and Review6
23894-6.7Recording and Reporting3
23894-A.2AI Objectives and Risk Sources0
23894-A.3Lifecycle Risk Considerations0
23894-A.4AI System Impact Assessment1
23894-A.5Human Oversight Controls2
23894-A.6Transparency and Explainability5
23894-A.7Data Quality and Provenance1
23894-A.8Robustness and Resilience Testing0
23894-A.9Third-Party AI Components1
ISO23894-1Scope of AI Risk Management140
ISO23894-3AI-Specific Terminology135
ISO23894-4.1Integrated AI Risk Management0
ISO23894-4.2Structured and Comprehensive Approach0
ISO23894-4.3Customized to AI Context0
ISO23894-4.4Inclusive Stakeholder Engagement0
ISO23894-4.5Dynamic and Responsive0
ISO23894-4.6Best Available Information1
ISO23894-4.7Human and Cultural Factors2
ISO23894-4.8Continual Improvement34
ISO23894-5.1Leadership and Commitment108
ISO23894-5.2AI Risk Management Integration81
ISO23894-5.3AI Risk Management Design0
ISO23894-5.4AI Risk Management Implementation0
ISO23894-5.5Framework Evaluation81
ISO23894-5.6Framework Improvement0
ISO23894-6.1Communication and Consultation33
ISO23894-6.2Scope, Context and Criteria140
ISO23894-6.3AI Risk Assessment133
ISO23894-6.3.1AI Risk Identification133
ISO23894-6.3.2AI Risk Analysis2
ISO23894-6.3.3AI Risk Evaluation124
ISO23894-6.4AI Risk Treatment3
ISO23894-6.5Monitoring and Review6
ISO23894-6.6Recording and Reporting3
ISO23894-A.1Data Quality and Representativeness48
ISO23894-A.2Model Transparency and Explainability0
ISO23894-A.3Algorithmic Bias and Fairness0
ISO23894-A.4AI System Robustness0
ISO23894-A.5Privacy and Data Protection in AI125
ISO23894-A.6AI System Security60
ISO23894-A.7Human Oversight of AI2
ISO23894-A.8AI Accountability and Governance1
4Principles of AI risk management0
5.2Leadership and commitment33
5.3Integration1
5.4Design4
5.4.1Understanding the organization and its context26
5.4.2Articulating risk management commitment1
5.4.3Assigning organizational roles, authorities, responsibilities and accountabilities18
5.4.4Allocating resources2
5.4.5Establishing communication and consultation2
5.5Implementation13
5.6Evaluation0
5.7Improvement0
5.7.1Adapting1
5.7.2Continually improving1
6.2Communication and consultation33
6.3Scope, context and criteria0
6.3.2Defining the scope2
6.3.3External and internal context1
6.3.4Defining risk criteria2
6.4Risk assessment36
6.4.2Risk identification10
6.4.2.2Identification of assets and their value0
6.4.2.3Identification of risk sources0
6.4.2.4Identification of potential events and outcomes0
6.4.2.5Identification of controls0
6.4.2.6Identification of consequences0
6.4.3Risk analysis6
6.4.3.2Assessment of consequences0
6.4.3.3Assessment of likelihood0
6.4.4Risk evaluation5
6.5Risk treatment8
6.5.2Selection of risk treatment options4
6.5.3Preparing and implementing risk treatment plans1
6.6Monitoring and review7
6.7Recording and reporting5
A.10Safety0
A.11Security0
A.12Transparency and explainability0
A.2Accountability0
A.3AI expertise0
A.4Availability and quality of training and test data0
A.5Environmental impact0
A.6Fairness0
A.7Maintainability0
A.8Privacy0
A.9Robustness0
B.2Complexity of environment0
B.3Lack of transparency and explainability0
B.4Level of automation0
B.5Machine learning0
B.6System hardware issues0
B.7System life cycle issues0
B.8Technology readiness0
CRisk management and AI system life cycle0

Tell me when ISO/IEC 23894:2023 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • ISMS scope statement
  • Statement of applicability
  • ISMS policy
  • Management review minutes
  • Design documents
  • Build standards
  • Monitoring KPIs
  • Drift detection reports
  • Periodic review minutes
  • Drift reports

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for ISO/IEC 23894:2023, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition