AI risk guidance, applied to a live AI inventory.
ISO/IEC 23894 is AI risk management guidance — the method, not the requirement. It takes the general risk process of ISO 31000 and works through what each step means when the thing at risk is an AI system: what counts as context, which sources of risk are specific to machine learning, how consequence looks when a model is wrong in ways a conventional system cannot be. It is not certifiable on its own. It is what you use to do the risk part of ISO 42001 properly.
The relationship is the same one 27005 has to 27001, and it fails the same way. Guidance gets read during design and abandoned in operation; a risk assessment is written for the audit and then photographed; the AI systems keep changing — new model version, new training data, new use nobody told the risk owner about — and the assessment describes something that no longer exists.
Who it applies to
Anyone managing AI risk with any rigour — which, once an organization is in scope for ISO 42001 or the EU AI Act, is no longer optional. It is also the natural reference for teams who need a defensible AI risk method before they have decided whether to pursue a certificate at all.
Risk against a live inventory
23894 is only as good as the inventory it runs on. The method asks you to establish context per system — purpose, data, affected people, degree of autonomy — before identifying what could go wrong, and every one of those context facts changes over a system's life. Run against a static list compiled for the assessment, the method produces a document. Run against the same AI system inventory that 42001, the AI Act and the NIST AI RMF read, it produces a register that moves when the system does: a new model version re-opens the risk, a new use case adds a context row, a vendor change re-triggers review. That is what guidance looks like when it is operated rather than filed.
What it asks, in operating terms
Read as an operating requirement rather than a guidance document, 23894 reduces to a handful of standing asks — each answerable from a live register, not a file from the last audit.
| What 23894 asks | Where it is answered |
|---|---|
| Establish context per AI system, and keep it current | AI system inventory · purpose, data, autonomy held per system |
| Identify AI-specific sources of risk | Risk entries · AI risk sources as a first-class category |
| Analyze consequence for the people affected, not just the business | Impact assessment · affected parties recorded per risk |
| Treat, and tie the treatment to a control | Control library · 42001 Annex A control linked per treatment |
| Re-assess when the system changes | Review triggers · model version, data, use-case events |
What you'd actually look at
In the dashboard, every figure opens on click to the system, the risk and the person behind it. This excerpt is what an AI risk register is made of:
- Systems assessed
- 12/12 · context current
- Risks open
- 9 · each tied to a system and an owner
- Affected parties recorded
- 9/9
- Last review trigger
- model version change · 3 days ago
- Export
- sealed · sha256:27a4...d9e8
Where teams usually start
With a demo walked through by TruSecure — a single AI system opened to its context, its risks and the control that treats each one, and the review that fires when the model changes rather than when the audit is due. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
ISO/IEC 23894 provides AI-specific risk management guidance supporting ISO 42001, in the same relationship 27005 has to 27001. It is not certifiable on its own.