Skip to main content
Praxikon
Back to the explorer
StandardGuidancev1.0.0

ISO/IEC 23894: guidance on risk management for AI

The international guidance for AI-specific risk management, usable as an interim structure while prEN 18228 remains in draft.

The official source remains authoritative. This is general information about obligations and not legal advice. See this object on the map

Address and citation

This object has an address of its own that is never renamed or reused. Store the identifier in your own file, not the title or the link.

Identifier
praxikon:eu:ai-act:standard:standard-iso-iec-23894-ai-risk-management-guidance
Payload hash (sha256)
97f89403e72d95ecd362a023a4bb4ee38d74bde7f30f7997125dfeb6f0e72c63

Citation line

Praxikon, "ISO/IEC 23894: guidance on risk management for AI", praxikon:eu:ai-act:standard:standard-iso-iec-23894-ai-risk-management-guidance@1.0.0, dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0 (schema 1.4.0), effective_at 2026-08-08T00:00:00.000Z, known_at 2026-08-14T00:00:00.000Z, sha256 97f89403e72d95ecd362a023a4bb4ee38d74bde7f30f7997125dfeb6f0e72c63
Version
1.0.0
Legal time (effective_at)
8 August 2026
Knowledge time (known_at)
8 August 2026
Closed on
Not closed
Topics
standards

Review status: Placed against the official source (8 August 2026). Next check due by 4 February 2027. The check date is the knowledge date of this version; no later recheck has been recorded.

What this object links to

Every relation appears below as a path: from the source with its locator, through the conditions and exceptions of the object carrying the relation, to the consequence. A locator belongs to a statement in the data and not to a relation, so the source is the source anchor of the carrying object.

The obligation this hangs off

1 of 1 shown

The object belongs to this obligation. The source line it hangs off sits there.

  1. Source

    Official fact on this object, with its locator.

    • CEN-CENELEC JTC 21: European standards under standardisation request M/613

      Locator: EN ISO/IEC 23894:2024, European adoption via CEN-CENELEC

      praxikon:eu:ai-act:source:cen-cenelec-jtc21

      Open official source
    • EU Artificial Intelligence Act 2024/1689

      Locator: Article 9

      praxikon:eu:ai-act:source:reg-eu-2024-1689

      Open official source

    Via

    No condition or exception recorded on this object.

    Consequence

What this object is about

2 of 2 shown

The object is about this role. Undifferentiated: it does not follow that the duty rests on this role.

  1. Source

    Official fact on this object, with its locator.

    • CEN-CENELEC JTC 21: European standards under standardisation request M/613

      Locator: EN ISO/IEC 23894:2024, European adoption via CEN-CENELEC

      praxikon:eu:ai-act:source:cen-cenelec-jtc21

      Open official source
    • EU Artificial Intelligence Act 2024/1689

      Locator: Article 9

      praxikon:eu:ai-act:source:reg-eu-2024-1689

      Open official source

    Via

    No condition or exception recorded on this object.

    Consequence

What this object states

Official fact

Attributable to a named primary source, with a locator. Where they differ, the official source prevails.

  • ISO/IEC 23894:2023 (Information technology: Artificial intelligence: Guidance on risk management) was published in February 2023 and is the first international standard dealing specifically with risk management for AI. It is non-prescriptive and built on the ISO 31000 structure. The text was adopted by CEN-CENELEC as EN ISO/IEC 23894:2024. It is not cited in the Official Journal and therefore confers no presumption of conformity under Article 40 of the AI Act. The deliverable intended to do so for Article 9 is prEN 18228.

    • Locator: EN ISO/IEC 23894:2024, European adoption via CEN-CENELECpraxikon:eu:ai-act:source:cen-cenelec-jtc21Open official source
    • Locator: Article 9praxikon:eu:ai-act:source:reg-eu-2024-1689Open official source

Our interpretation

Our own reading. It can change without the law changing, and it is not the position of a supervisory authority.

  • ISO/IEC 23894 gives you the vocabulary and process flow of AI risk management, and that is usable today. Where it falls short: it is guidance, not a requirements set, and it is written from organisational risk while Article 9 starts from risk to the health, safety and fundamental rights of others. A risk register built entirely along ISO/IEC 23894 therefore does not automatically cover Article 9. Use it as scaffolding, not as evidence.

    • Locator: EN ISO/IEC 23894:2024, European adoption via CEN-CENELECpraxikon:eu:ai-act:source:cen-cenelec-jtc21Open official source
    • Locator: Article 9praxikon:eu:ai-act:source:reg-eu-2024-1689Open official source

Recommended step

A practical step we consider appropriate. Not an obligation following from the Regulation.

  • Adopt the ISO/IEC 23894 process flow (context, identification, analysis, evaluation, treatment, monitoring, recording) and add two AI Act-specific fields per risk: who outside your organisation can be affected, and what residual risk you deem acceptable on what justification. That lets you connect the register to the final EN 18228 without rebuilding it.

    • Locator: EN ISO/IEC 23894:2024, European adoption via CEN-CENELECpraxikon:eu:ai-act:source:cen-cenelec-jtc21Open official source
    • Locator: Article 9praxikon:eu:ai-act:source:reg-eu-2024-1689Open official source

When this applies

No condition recorded on this object.

When this does not apply

No exception recorded on this object.

Referring to this object

Citation block

Copy this reference into your advice, article or file. The identifier, the version and the hash keep the statement findable later, even once the dataset has moved on.

Reference

Praxikon, "ISO/IEC 23894: guidance on risk management for AI",
praxikon:eu:ai-act:standard:standard-iso-iec-23894-ai-risk-management-guidance@1.0.0,
dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0 (schema 1.4.0),
effective_at 2026-08-08T00:00:00.000Z, known_at 2026-08-08T00:00:00.000Z,
sha256 97f89403e72d95ecd362a023a4bb4ee38d74bde7f30f7997125dfeb6f0e72c63,
https://www.praxikon.com/en/verkenner/standard/standard-iso-iec-23894-ai-risk-management-guidance
(https://www.praxikon.com/api/v1/entities?id=praxikon%3Aeu%3Aai-act%3Astandard%3Astandard-iso-iec-23894-ai-risk-management-guidance&effective_at=2026-08-08&known_at=2026-08-08&lang=en, accessed 2026-08-25)

Short form

praxikon:eu:ai-act:standard:standard-iso-iec-23894-ai-risk-management-guidance@1.0.0 (sha256 97f89403)

BibTeX

@misc{praxikon-eu-ai-act-standard-standard-iso-iec-23894-ai-risk-management-guidance-1-0-0,
  author       = {{Praxikon}},
  title        = {ISO/IEC 23894: guidance on risk management for AI},
  year         = {2026},
  version      = {1.0.0},
  number       = {praxikon:eu:ai-act:standard:standard-iso-iec-23894-ai-risk-management-guidance},
  howpublished = {AI Act Change \& Evidence Graph, dataset 2.1.0, schema 1.4.0},
  note         = {effective_at 2026-08-08T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 97f89403e72d95ecd362a023a4bb4ee38d74bde7f30f7997125dfeb6f0e72c63},
  url          = {https://www.praxikon.com/en/verkenner/standard/standard-iso-iec-23894-ai-risk-management-guidance},
  urldate      = {2026-08-25},
  language     = {en}
}

CSL JSON

[
  {
    "id": "praxikon:eu:ai-act:standard:standard-iso-iec-23894-ai-risk-management-guidance@1.0.0",
    "type": "dataset",
    "title": "ISO/IEC 23894: guidance on risk management for AI",
    "container-title": "AI Act Change & Evidence Graph",
    "publisher": "Praxikon",
    "version": "1.0.0",
    "number": "praxikon:eu:ai-act:standard:standard-iso-iec-23894-ai-risk-management-guidance",
    "URL": "https://www.praxikon.com/en/verkenner/standard/standard-iso-iec-23894-ai-risk-management-guidance",
    "language": "en",
    "issued": {
      "date-parts": [
        [
          2026,
          8,
          8
        ]
      ]
    },
    "accessed": {
      "date-parts": [
        [
          2026,
          8,
          25
        ]
      ]
    },
    "note": "dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0; schema 1.4.0; effective_at 2026-08-08T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 97f89403e72d95ecd362a023a4bb4ee38d74bde7f30f7997125dfeb6f0e72c63; retrieved_from https://www.praxikon.com/api/v1/entities?id=praxikon%3Aeu%3Aai-act%3Astandard%3Astandard-iso-iec-23894-ai-risk-management-guidance&effective_at=2026-08-08&known_at=2026-08-08&lang=en; licence https://www.praxikon.com/nl/legal/terms"
  }
]

How to verify a reference later is set out in the methodology. Terms

For agents and integrations

This page and the machine output come from the same object and the same two time axes.