Standards Comparison
ISO/IEC 23894 vs. ISO 42001: AI Risk Management Standards Compared
ISO/IEC 23894 is non-certifiable guidance that adapts ISO 31000 risk management principles to AI-specific contexts. ISO/IEC 42001 is a certifiable AI management system (AIMS) standard that requires an operational risk assessment and treatment process but does not mandate a single methodology. In practice, 23894 provides the process detail that satisfies 42001's risk-related clauses and Annex A controls.
Scope and Purpose: Guidance vs. Certifiable Requirements
ISO/IEC 23894:2023 and ISO/IEC 42001:2023 were both developed under ISO/IEC JTC 1/SC 42, the joint technical committee responsible for AI standardization, but they serve different functions in an enterprise governance program. ISO/IEC 23894 is a guidance document. It adapts the risk management principles and process defined in ISO 31000 to AI-specific contexts, covering context establishment, risk assessment, risk treatment, monitoring, and communication. Organizations cannot be certified against it; it exists to inform how an organization thinks about and structures AI risk. ISO/IEC 42001, by contrast, specifies requirements for establishing, implementing, maintaining, and improving an AI management system (AIMS), and it is certifiable through accredited bodies. It follows the ISO Harmonized Structure used by standards such as ISO/IEC 27001, meaning its clauses cover context, leadership, planning, support, operation, performance evaluation, and improvement. Within that structure, 42001 requires organizations to operate an AI risk assessment process and an AI risk treatment process, but it does not itself define the methodology in detail.
Key Structural Differences
The two standards are best understood as two functions of the same governance effort: one defines how to think about AI risk, the other defines what a management system must demonstrate.
| Aspect | ISO/IEC 23894 | ISO/IEC 42001 |
|---|---|---|
| Function | Guidance on AI risk management process | Certifiable AI management system requirements |
| Certifiability | Not certifiable | Certifiable through accredited bodies |
| Relationship | Can serve as the defined risk methodology | Requires a risk process, but does not mandate which one |
How the Two Standards Interrelate
ISO/IEC 42001's core clauses require that risk management activity be operational and evidenced, but the standard deliberately does not prescribe a single mandatory methodology. This is where ISO/IEC 23894 most directly applies. Its process steps (establishing context, conducting risk assessment, selecting risk treatment, and monitoring outcomes) map onto 42001's risk assessment and risk treatment clauses, and onto the Annex A controls covering AI system impact assessment and risk assessment. Organizations are free to use ISO 31000 directly, an internal methodology, or ISO/IEC 23894 as the basis for this work. In practice, because 23894 was written specifically for AI contexts rather than general enterprise risk, it tends to be the more direct fit for satisfying 42001's risk-related requirements without significant adaptation.
Where Documentation Gaps Emerge
A common failure pattern is treating ISO/IEC 42001 as a checklist exercise rather than building the underlying risk process that 23894 describes. Certification audits assess whether risk management is operational and evidenced, not whether a specific external guidance document was consulted. Organizations that skip a structured risk methodology and attempt to satisfy 42001's clauses retroactively often find gaps in risk assessment and treatment documentation that surface during internal audit or certification review. Mapping 23894's process steps explicitly to 42001 clause numbers and Annex A controls reduces duplication between a risk register and management system documentation. Existing ISO 31000-based enterprise risk programs do not need to be replaced; they can typically be extended to incorporate AI-specific considerations from 23894 rather than run as a parallel process.
Governance Practices for Combined Implementation
- Certification requires ongoing internal audit and management review of the AI risk process, not a one-time assessment.
- Clarify whether 23894 is the organization's chosen risk methodology reference, since 42001 does not mandate this pairing.
- Reconcile overlap between 23894-based risk registers and 42001 Annex A control evidence to avoid duplicate governance artifacts.
- Scope certification statements explicitly by AI system and risk process, since 23894 guidance is broader than any single certified AIMS boundary.
Questions to Resolve Before Implementation
- Does the organization need certification (42001), internal guidance adoption (23894), or both?
- How will the existing enterprise risk management framework map to 42001's risk assessment and treatment clauses?
- Which Annex A controls in 42001 depend on a documented AI risk process, and is that process currently defined?
- Is 23894 being used as the explicit basis for the AI risk methodology, and is that decision documented for audit purposes?
- What evidence will an external auditor expect to see linking the risk assessment process to 42001 management system requirements?
Frequently Asked Questions
Can an organization be certified against ISO/IEC 23894?
No. ISO/IEC 23894 is a guidance document adapted from ISO 31000 principles. It informs how AI risk is assessed and treated but is not a certifiable standard. Certification applies to ISO/IEC 42001, which specifies management system requirements an organization can be audited against.
Does ISO/IEC 42001 require the use of ISO/IEC 23894?
No. ISO/IEC 42001 requires an operational AI risk assessment and treatment process but does not mandate a specific methodology. Organizations may use ISO/IEC 23894, ISO 31000, or another approach, provided the process is documented and evidenced during audit.
Can an existing ISO 31000-based risk program satisfy ISO/IEC 42001 requirements?
Often yes, with extension. ISO/IEC 42001 does not require replacing an existing enterprise risk framework. Many organizations extend an ISO 31000-based program with AI-specific considerations from ISO/IEC 23894 rather than building a separate parallel process.
Operationalizing AI Risk Management Beyond Documentation
Standards define the required process and evidence. Runtime governance addresses how AI agent behavior, tool access, and policy enforcement are monitored and controlled once systems are in production.
Explore Runtime Governance