23894-4.1 | AI Risk Management Principles | 1 |
23894-5.2 | Leadership and Commitment | 33 |
23894-5.3 | Integration into Organizational Processes | 3 |
23894-5.4.1 | Understanding Organization and Context | 26 |
23894-5.4.2 | AI Risk Management Policy | 4 |
23894-5.4.3 | Roles, Authorities, Responsibilities | 25 |
23894-5.4.4 | Allocation of Resources | 1 |
23894-5.5 | Communication and Consultation | 33 |
23894-6.3 | AI Risk Assessment Scope and Criteria | 0 |
23894-6.4.2 | AI Risk Identification | 4 |
23894-6.4.3 | AI Risk Analysis | 2 |
23894-6.4.4 | AI Risk Evaluation | 3 |
23894-6.5 | AI Risk Treatment | 3 |
23894-6.6 | Monitoring and Review | 6 |
23894-6.7 | Recording and Reporting | 3 |
23894-A.2 | AI Objectives and Risk Sources | 0 |
23894-A.3 | Lifecycle Risk Considerations | 0 |
23894-A.4 | AI System Impact Assessment | 1 |
23894-A.5 | Human Oversight Controls | 2 |
23894-A.6 | Transparency and Explainability | 5 |
23894-A.7 | Data Quality and Provenance | 1 |
23894-A.8 | Robustness and Resilience Testing | 0 |
23894-A.9 | Third-Party AI Components | 1 |
ISO23894-1 | Scope of AI Risk Management | 140 |
ISO23894-3 | AI-Specific Terminology | 135 |
ISO23894-4.1 | Integrated AI Risk Management | 0 |
ISO23894-4.2 | Structured and Comprehensive Approach | 0 |
ISO23894-4.3 | Customized to AI Context | 0 |
ISO23894-4.4 | Inclusive Stakeholder Engagement | 0 |
ISO23894-4.5 | Dynamic and Responsive | 0 |
ISO23894-4.6 | Best Available Information | 1 |
ISO23894-4.7 | Human and Cultural Factors | 2 |
ISO23894-4.8 | Continual Improvement | 34 |
ISO23894-5.1 | Leadership and Commitment | 108 |
ISO23894-5.2 | AI Risk Management Integration | 81 |
ISO23894-5.3 | AI Risk Management Design | 0 |
ISO23894-5.4 | AI Risk Management Implementation | 0 |
ISO23894-5.5 | Framework Evaluation | 81 |
ISO23894-5.6 | Framework Improvement | 0 |
ISO23894-6.1 | Communication and Consultation | 33 |
ISO23894-6.2 | Scope, Context and Criteria | 140 |
ISO23894-6.3 | AI Risk Assessment | 133 |
ISO23894-6.3.1 | AI Risk Identification | 133 |
ISO23894-6.3.2 | AI Risk Analysis | 2 |
ISO23894-6.3.3 | AI Risk Evaluation | 124 |
ISO23894-6.4 | AI Risk Treatment | 3 |
ISO23894-6.5 | Monitoring and Review | 6 |
ISO23894-6.6 | Recording and Reporting | 3 |
ISO23894-A.1 | Data Quality and Representativeness | 48 |
ISO23894-A.2 | Model Transparency and Explainability | 0 |
ISO23894-A.3 | Algorithmic Bias and Fairness | 0 |
ISO23894-A.4 | AI System Robustness | 0 |
ISO23894-A.5 | Privacy and Data Protection in AI | 125 |
ISO23894-A.6 | AI System Security | 60 |
ISO23894-A.7 | Human Oversight of AI | 2 |
ISO23894-A.8 | AI Accountability and Governance | 1 |
4 | Principles of AI risk management | 0 |
5.2 | Leadership and commitment | 33 |
5.3 | Integration | 1 |
5.4 | Design | 4 |
5.4.1 | Understanding the organization and its context | 26 |
5.4.2 | Articulating risk management commitment | 1 |
5.4.3 | Assigning organizational roles, authorities, responsibilities and accountabilities | 18 |
5.4.4 | Allocating resources | 2 |
5.4.5 | Establishing communication and consultation | 2 |
5.5 | Implementation | 13 |
5.6 | Evaluation | 0 |
5.7 | Improvement | 0 |
5.7.1 | Adapting | 1 |
5.7.2 | Continually improving | 1 |
6.2 | Communication and consultation | 33 |
6.3 | Scope, context and criteria | 0 |
6.3.2 | Defining the scope | 2 |
6.3.3 | External and internal context | 1 |
6.3.4 | Defining risk criteria | 2 |
6.4 | Risk assessment | 36 |
6.4.2 | Risk identification | 10 |
6.4.2.2 | Identification of assets and their value | 0 |
6.4.2.3 | Identification of risk sources | 0 |
6.4.2.4 | Identification of potential events and outcomes | 0 |
6.4.2.5 | Identification of controls | 0 |
6.4.2.6 | Identification of consequences | 0 |
6.4.3 | Risk analysis | 6 |
6.4.3.2 | Assessment of consequences | 0 |
6.4.3.3 | Assessment of likelihood | 0 |
6.4.4 | Risk evaluation | 5 |
6.5 | Risk treatment | 8 |
6.5.2 | Selection of risk treatment options | 4 |
6.5.3 | Preparing and implementing risk treatment plans | 1 |
6.6 | Monitoring and review | 7 |
6.7 | Recording and reporting | 5 |
A.10 | Safety | 0 |
A.11 | Security | 0 |
A.12 | Transparency and explainability | 0 |
A.2 | Accountability | 0 |
A.3 | AI expertise | 0 |
A.4 | Availability and quality of training and test data | 0 |
A.5 | Environmental impact | 0 |
A.6 | Fairness | 0 |
A.7 | Maintainability | 0 |
A.8 | Privacy | 0 |
A.9 | Robustness | 0 |
B.2 | Complexity of environment | 0 |
B.3 | Lack of transparency and explainability | 0 |
B.4 | Level of automation | 0 |
B.5 | Machine learning | 0 |
B.6 | System hardware issues | 0 |
B.7 | System life cycle issues | 0 |
B.8 | Technology readiness | 0 |
C | Risk management and AI system life cycle | 0 |