Contact us
Illustration for ISO management-system services

ISO/IEC 23894

ISO/IEC 23894 AI risk management guidance

ISO/IEC 23894 consulting helps companies integrate AI risk management into development and use. Vosurein examines actual uses, data and human decisions to identify possible failures, controls and oversight responsibilities. Model performance alone cannot establish the risks of an entire use case.

Discuss ISO/IEC 23894 AI risk management consulting

For Your Business

Who this service is for and when to start

Suitable for organizations that develop, provide, deploy, or use AI. Before launching new applications, expanding usage scope, or changing models or data sources, existing controls should first be checked for relevance. Even when using purchased tools, it is necessary to understand the organization's own usage methods and responsibilities.

The Challenge

Common challenges faced by businesses

Testing a response for correctness does not mean it will not cause problems in real processes. Expired data, user misunderstanding, excessive permissions, or the absence of human intervention can all affect outcomes.

There may also be responsibility gaps between AI providers and enterprises. It is necessary to clearly distinguish between settings that can be controlled, evidence to be obtained from the provider, and limitations that cannot yet be assessed.

Our Approach

Methods and applicable requirements

ISO/IEC 23894:2023 is an AI risk management guideline that helps organizations integrate related risk processes into AI activities and functions, adjusting according to context. It can be used as a support method for AI governance work and is not equivalent to ISO/IEC 42001 management system certification.

The priorities below depend on the organisation’s context. Confirm the scope and level of supporting evidence at the start.

Scenarios and Roles

Define the tasks AI is to support, the users, and decision consequences, distinguishing development, supply, and usage responsibilities to avoid just registering the model name.

Risk Assessment

Organize possible failure scenarios from data, models, and usage processes, recording evidence and assumptions; both impacts on the enterprise and on others need to be appropriately discussed.

Controls and Supervision

Arrange data restrictions, permissions, human review, or stop conditions according to risks, confirming who can accept residual risks, rather than always leaving it to technical contacts.

Monitoring and Changes

Organize abnormal reports and re-evaluation triggers, such as usage expansion or model updates; post-launch, actual usage results still need to be checked.

Process

Consulting scope and process

  1. Review AI uses

    Confirm applications, data flows, and personnel roles, and select the scope for evaluation.

  2. Discuss Risk Scenarios

    Review errors, controls, and data gaps with business and technical departments to form evaluation records.

  3. Pilot risk treatments

    Test whether human review, access permissions and incident handling work in practice, then seek approval from the responsible people.

  4. Set reassessment triggers

    Integrate feedback and changes into the management process, tracking measures and remaining risks.

Preparation

What documents do companies need to prepare?

  • Purpose and Role: Application list, usage scenarios, and responsible departments.
  • Data and Supply: Sources, flow, suppliers, and contract summary.
  • Testing and Issues: Known limitations, test cases, and exception feedback.
  • Controls and Changes: Permissions, review, updates, and approval arrangements.

An index or summary is enough for an initial discussion. Before sharing personal data, confidential contract information or system records, agree on access authorisation, redaction and retention.

Project Planning

Estimating time and cost

We scope the work by AI use cases, data sensitivity, supplier relationships and assessment depth. Model testing, cybersecurity testing, legal assessment and system changes are agreed separately. A generic checklist does not constitute a complete assessment of every application.

FAQ

Frequently asked questions

Is it only applicable for self-built models?

No, organizations deploying or using AI can also adopt it; externally purchased services still need to verify their own usage, data, and controls.

Can I use one table to evaluate all AI?

The basic format can be shared, but questions and evidence need to be adjusted according to scenarios and consequences; you cannot just change the names.

Can human review eliminate risk?

It cannot directly guarantee; personnel capabilities, time, permissions, and whether they can actually intervene also need to be verified.

What is the difference from ISO/IEC 42005?

This item focuses on AI risk management processes; 42005 targets assessment of AI’s impact on individuals, groups, and society. Data can be shared but purposes must be clearly distinguished.

Do I have to use tools from specific brands?

No. Methods are arranged according to usage scenarios and data, not restricted to specific model or platform suppliers.

Do I need to re-evaluate after launch?

Reviews should be arranged according to changes and actual issues, particularly when usage, data, models, or usage scale changes.

Related

Related services and enquiries

Tell us your industry, the activities you want to improve, your existing system and your target completion date so we can define the scope together.

Content checked: . Applicable versions and requirements depend on the company’s circumstances.

Let's Talk

Start a conversation about your needs.

Tell us how the work is done today and when you hope to finish,
so we can agree the scope and way of working together.

Discuss your service needsBack to ISO management-system contents