
ISO/IEC 23894
ISO/IEC 23894 AI risk management guidance
ISO/IEC 23894 consulting helps companies integrate AI risk management into development and use. Vosurein examines actual uses, data and human decisions to identify possible failures, controls and oversight responsibilities. Model performance alone cannot establish the risks of an entire use case.
For Your Business
Who this service is for and when to start
Suitable for organizations that develop, provide, deploy, or use AI. Before launching new applications, expanding usage scope, or changing models or data sources, existing controls should first be checked for relevance. Even when using purchased tools, it is necessary to understand the organization's own usage methods and responsibilities.
The Challenge
Common challenges faced by businesses
Testing a response for correctness does not mean it will not cause problems in real processes. Expired data, user misunderstanding, excessive permissions, or the absence of human intervention can all affect outcomes.
There may also be responsibility gaps between AI providers and enterprises. It is necessary to clearly distinguish between settings that can be controlled, evidence to be obtained from the provider, and limitations that cannot yet be assessed.
Our Approach
Methods and applicable requirements
ISO/IEC 23894:2023 is an AI risk management guideline that helps organizations integrate related risk processes into AI activities and functions, adjusting according to context. It can be used as a support method for AI governance work and is not equivalent to ISO/IEC 42001 management system certification.
The priorities below depend on the organisation’s context. Confirm the scope and level of supporting evidence at the start.
Scenarios and Roles
Define the tasks AI is to support, the users, and decision consequences, distinguishing development, supply, and usage responsibilities to avoid just registering the model name.
Risk Assessment
Organize possible failure scenarios from data, models, and usage processes, recording evidence and assumptions; both impacts on the enterprise and on others need to be appropriately discussed.
Controls and Supervision
Arrange data restrictions, permissions, human review, or stop conditions according to risks, confirming who can accept residual risks, rather than always leaving it to technical contacts.
Monitoring and Changes
Organize abnormal reports and re-evaluation triggers, such as usage expansion or model updates; post-launch, actual usage results still need to be checked.
Process
Consulting scope and process
Review AI uses
Confirm applications, data flows, and personnel roles, and select the scope for evaluation.
Discuss Risk Scenarios
Review errors, controls, and data gaps with business and technical departments to form evaluation records.
Pilot risk treatments
Test whether human review, access permissions and incident handling work in practice, then seek approval from the responsible people.
Set reassessment triggers
Integrate feedback and changes into the management process, tracking measures and remaining risks.
Preparation
What documents do companies need to prepare?
- Purpose and Role: Application list, usage scenarios, and responsible departments.
- Data and Supply: Sources, flow, suppliers, and contract summary.
- Testing and Issues: Known limitations, test cases, and exception feedback.
- Controls and Changes: Permissions, review, updates, and approval arrangements.
An index or summary is enough for an initial discussion. Before sharing personal data, confidential contract information or system records, agree on access authorisation, redaction and retention.
Project Planning
Estimating time and cost
We scope the work by AI use cases, data sensitivity, supplier relationships and assessment depth. Model testing, cybersecurity testing, legal assessment and system changes are agreed separately. A generic checklist does not constitute a complete assessment of every application.
FAQ
Frequently asked questions
Is it only applicable for self-built models?
No, organizations deploying or using AI can also adopt it; externally purchased services still need to verify their own usage, data, and controls.
Can I use one table to evaluate all AI?
The basic format can be shared, but questions and evidence need to be adjusted according to scenarios and consequences; you cannot just change the names.
Can human review eliminate risk?
It cannot directly guarantee; personnel capabilities, time, permissions, and whether they can actually intervene also need to be verified.
What is the difference from ISO/IEC 42005?
This item focuses on AI risk management processes; 42005 targets assessment of AI’s impact on individuals, groups, and society. Data can be shared but purposes must be clearly distinguished.
Do I have to use tools from specific brands?
No. Methods are arranged according to usage scenarios and data, not restricted to specific model or platform suppliers.
Do I need to re-evaluate after launch?
Reviews should be arranged according to changes and actual issues, particularly when usage, data, models, or usage scale changes.
Related
Related services and enquiries
Tell us your industry, the activities you want to improve, your existing system and your target completion date so we can define the scope together.
Content checked: . Applicable versions and requirements depend on the company’s circumstances.
Let's Talk
Start a conversation about your needs.
Tell us how the work is done today and when you hope to finish,
so we can agree the scope and way of working together.
Blog
Sustainability and AI insights
Start with understanding,
and see where change can lead.

