ISO/IEC 23894:2023
Evidence request list. 85 controls, 85 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
AI-Specific Risk Sources (Annex A)
Risks from poor data quality, biased training data, insufficient data volume, or unrepresentative datasets used in AI system development.
- AI risk source catalog
- Bias evaluation report
- Robustness test results
- Privacy impact assessment
- Risk sources incomplete
- Bias unmeasured
- Robustness untested
- Privacy gaps unaddressed
Risks from lack of transparency and explainability in AI system decision-making processes, particularly for high-stakes applications.
- AI risk source catalog
- Bias evaluation report
- Robustness test results
- Privacy impact assessment
- Risk sources incomplete
- Bias unmeasured
- Robustness untested
- Privacy gaps unaddressed
Risks of unfair outcomes or discrimination resulting from biases in AI algorithms, training data, or system design.
- AI risk source catalog
- Bias evaluation report
- Robustness test results
- Privacy impact assessment
- Risk sources incomplete
- Bias unmeasured
- Robustness untested
- Privacy gaps unaddressed
Risks from lack of robustness in AI systems including vulnerability to adversarial attacks, distribution shifts, and unexpected inputs.
- AI risk source catalog
- Bias evaluation report
- Robustness test results
- Privacy impact assessment
- Risk sources incomplete
- Bias unmeasured
- Robustness untested
- Privacy gaps unaddressed
Risks to privacy from AI systems processing personal data, including risks of re-identification, inference attacks, and unauthorized profiling.
- AI risk source catalog
- Bias evaluation report
- Robustness test results
- Privacy impact assessment
- Risk sources incomplete
- Bias unmeasured
- Robustness untested
- Privacy gaps unaddressed
Cybersecurity risks specific to AI systems including model extraction, data poisoning, evasion attacks, and supply chain compromises.
- AI risk source catalog
- Bias evaluation report
- Robustness test results
- Privacy impact assessment
- Risk sources incomplete
- Bias unmeasured
- Robustness untested
- Privacy gaps unaddressed
Risks from inadequate human oversight of AI systems including automation bias, over-reliance on AI outputs, and insufficient human control mechanisms.
- AI risk source catalog
- Bias evaluation report
- Robustness test results
- Privacy impact assessment
- Risk sources incomplete
- Bias unmeasured
- Robustness untested
- Privacy gaps unaddressed
Risks from unclear accountability structures for AI system outcomes, including challenges in assigning responsibility across complex AI value chains.
- AI risk source catalog
- Bias evaluation report
- Robustness test results
- Privacy impact assessment
- Risk sources incomplete
- Bias unmeasured
- Robustness untested
- Privacy gaps unaddressed
Annex Guidance
Map AI system objectives to potential risk sources including data quality, transparency, fairness, robustness.
- Objective-to-risk mapping
- Source taxonomy
- Mitigation library
- Fairness sources missing
- Robustness not mapped
Apply risk management across AI lifecycle stages: inception, design, data, build, verify, deploy, operate, decommission.
- Lifecycle stage checklists
- Stage-gate approvals
- Decommission plan
- Decommission not planned
- Stage gates skipped
Conduct impact assessments covering individuals, groups, society, environment, and organization.
- AI impact assessment report
- Affected-group analysis
- Environmental footprint estimate
- No societal impact considered
- Environmental impact ignored
Implement controls enabling appropriate human oversight, intervention, and override of AI decisions.
- Oversight procedures
- Override logs
- Operator training records
- No override mechanism
- Operators untrained
Provide stakeholders with appropriate explanations of AI decisions and system behaviour.
- Explainability documentation
- User-facing notices
- Model cards
- No user notices
- Model cards absent
Ensure training and operational data meet quality, representativeness, and provenance requirements.
- Data quality reports
- Data lineage records
- Bias assessment
- No lineage
- Representativeness untested
Test AI system robustness against adversarial inputs, distribution shift, and operational stresses.
- Adversarial test reports
- Drift test results
- Stress test logs
- No adversarial testing
- Drift untested
Assess and manage risks from third-party AI models, datasets, and services used in the system.
- Vendor assessment
- Model provenance docs
- Contractual clauses
- No vendor due diligence
- Provenance unknown
Framework
Top management demonstrates commitment to AI risk management through policy, resources, and accountability assignments.
- AI risk policy signed by executive
- Resource allocation records
- Accountability matrix
- No executive sponsor named
- Resources not budgeted
Integrate AI risk management into governance, strategy, planning, reporting, policies, values, and culture.
- Process maps showing AI risk touchpoints
- Strategic plan referencing AI risk
- Updated SDLC with AI risk gates
- AI risk siloed from enterprise risk
- No SDLC integration
Examine external and internal context relevant to AI system purpose, stakeholders, and risk criteria.
- Context analysis document
- Stakeholder register
- PESTLE analysis for AI use
- Stakeholders not identified
- Context not refreshed
Establish documented AI risk policy stating objectives, scope, roles, criteria, and review cadence.
- AI risk management policy
- Policy review log
- Distribution evidence
- Policy not approved
- No review cadence defined
Assign and communicate AI risk roles including model owner, risk owner, validator, and approver.
- RACI matrix for AI risk
- Role descriptions
- Appointment letters
- Model validator not independent
- Roles not documented
Allocate appropriate resources (people, skills, tools, budget) for AI risk management.
- Budget allocation
- Skills inventory
- Tooling list
- No dedicated AI risk team
- Tooling absent
Plan and execute internal and external communication on AI risks with stakeholders throughout lifecycle.
- Communication plan
- Stakeholder consultation records
- External disclosure templates
- No affected-user channel
- External comms ad hoc
Framework (Clause 5)
Top management and oversight bodies shall demonstrate leadership and commitment to AI risk management by ensuring integration into organizational governance.
- Framework charter
- Leadership endorsement
- Implementation plan
- Framework evaluation report
- Framework not endorsed
- Implementation partial
- Evaluation skipped
- Integration with ISMS weak
Integrating risk management into the organization depends on understanding the organizational structures and context of AI deployment.
- Framework charter
- Leadership endorsement
- Implementation plan
- Framework evaluation report
- Framework not endorsed
- Implementation partial
- Evaluation skipped
- Integration with ISMS weak
Design the framework for managing AI risks by understanding the organization's AI context, articulating AI risk management commitment, and allocating resources.
- Framework charter
- Leadership endorsement
- Implementation plan
- Framework evaluation report
- Framework not endorsed
- Implementation partial
- Evaluation skipped
- Integration with ISMS weak
Implement the AI risk management framework by developing appropriate plans, identifying decision-making pathways, and embedding risk management into AI lifecycle processes.
- Framework charter
- Leadership endorsement
- Implementation plan
- Framework evaluation report
- Framework not endorsed
- Implementation partial
- Evaluation skipped
- Integration with ISMS weak
Periodically measure AI risk management framework performance against its purpose, implementation plans, indicators, and expected behaviour.
- Framework charter
- Leadership endorsement
- Implementation plan
- Framework evaluation report
- Framework not endorsed
- Implementation partial
- Evaluation skipped
- Integration with ISMS weak
Continually adapt and improve the AI risk management framework to address internal and external changes in AI technology and applications.
- Framework charter
- Leadership endorsement
- Implementation plan
- Framework evaluation report
- Framework not endorsed
- Implementation partial
- Evaluation skipped
- Integration with ISMS weak
Framework – ISO/IEC 23894:2023
- AI risk register
- Treatment records
- Integration
- AI risk register present but treatment effectiveness untested.
- AI risks reported separately from enterprise risk, fragmenting board oversight.
- AI risk register
- Treatment records
- Integration
- AI risk register present but treatment effectiveness untested.
- AI risks reported separately from enterprise risk, fragmenting board oversight.
- AI risk register
- Treatment records
- Integration
- AI risk register present but treatment effectiveness untested.
- AI risks reported separately from enterprise risk, fragmenting board oversight.
- AI risk register
- Treatment records
- Integration
- AI risk register present but treatment effectiveness untested.
- AI risks reported separately from enterprise risk, fragmenting board oversight.
- AI risk register
- Treatment records
- Integration
- AI risk register present but treatment effectiveness untested.
- AI risks reported separately from enterprise risk, fragmenting board oversight.
- AI risk register
- Treatment records
- Integration
- AI risk register present but treatment effectiveness untested.
- AI risks reported separately from enterprise risk, fragmenting board oversight.
- AI risk register
- Treatment records
- Integration
- AI risk register present but treatment effectiveness untested.
- AI risks reported separately from enterprise risk, fragmenting board oversight.
- AI risk register
- Treatment records
- Integration
- AI risk register present but treatment effectiveness untested.
- AI risks reported separately from enterprise risk, fragmenting board oversight.
- AI risk register
- Treatment records
- Integration
- AI risk register present but treatment effectiveness untested.
- AI risks reported separately from enterprise risk, fragmenting board oversight.
- AI risk register
- Treatment records
- Integration
- AI risk register present but treatment effectiveness untested.
- AI risks reported separately from enterprise risk, fragmenting board oversight.
- AI risk register
- Treatment records
- Integration
- AI risk register present but treatment effectiveness untested.
- AI risks reported separately from enterprise risk, fragmenting board oversight.
- AI risk register
- Treatment records
- Integration
- AI risk register present but treatment effectiveness untested.
- AI risks reported separately from enterprise risk, fragmenting board oversight.
Principles
Apply ISO 31000 principles adapted for AI: integrated, structured, customised, inclusive, dynamic, best available information, human and cultural factors, continual improvement.
- AI risk management principles statement
- Mapping to ISO 31000 principles
- Board endorsement record
- Principles not tailored to AI specifics
- No evidence of board endorsement
Principles (Clause 4)
AI risk management shall be an integral part of all organizational activities including governance, strategy, and operational processes.
- Principles statement
- Stakeholder register
- Improvement plan
- Cultural factors assessment
- Principles not applied
- Stakeholders missed
- No improvement cadence
- Cultural factors ignored
A structured and comprehensive approach to AI risk management contributes to consistent and comparable results.
- Principles statement
- Stakeholder register
- Improvement plan
- Cultural factors assessment
- Principles not applied
- Stakeholders missed
- No improvement cadence
- Cultural factors ignored
The risk management framework and process shall be customized and proportionate to the organization's external and internal context related to AI objectives.
- Principles statement
- Stakeholder register
- Improvement plan
- Cultural factors assessment
- Principles not applied
- Stakeholders missed
- No improvement cadence
- Cultural factors ignored
Appropriate and timely involvement of stakeholders enables their knowledge, views, and perceptions to be considered in AI risk management.
- Principles statement
- Stakeholder register
- Improvement plan
- Cultural factors assessment
- Principles not applied
- Stakeholders missed
- No improvement cadence
- Cultural factors ignored
Risks can emerge, change, or disappear as the AI system's external and internal context changes. Risk management anticipates, detects, acknowledges, and responds to those changes.
- Principles statement
- Stakeholder register
- Improvement plan
- Cultural factors assessment
- Principles not applied
- Stakeholders missed
- No improvement cadence
- Cultural factors ignored
Inputs to AI risk management shall be based on historical and current information, as well as future expectations considering limitations and uncertainties of AI systems.
- Principles statement
- Stakeholder register
- Improvement plan
- Cultural factors assessment
- Principles not applied
- Stakeholders missed
- No improvement cadence
- Cultural factors ignored
Human behaviour and culture significantly influence all aspects of AI risk management at each level and stage.
- Principles statement
- Stakeholder register
- Improvement plan
- Cultural factors assessment
- Principles not applied
- Stakeholders missed
- No improvement cadence
- Cultural factors ignored
AI risk management is continually improved through learning and experience as AI technologies and their applications evolve.
- Principles statement
- Stakeholder register
- Improvement plan
- Cultural factors assessment
- Principles not applied
- Stakeholders missed
- No improvement cadence
- Cultural factors ignored
Process
Define scope, context, and criteria for assessing AI-specific risks including likelihood and consequence measures.
- Risk criteria document
- AI use case inventory
- Risk appetite statement
- Criteria copied from enterprise risk
- Use cases not inventoried
Identify sources of AI risk including data, model, system, deployment, and societal factors.
- AI risk register
- Risk taxonomy
- Identification workshop records
- Societal risks omitted
- Data-source risks missed
Analyse identified AI risks considering causes, consequences, controls, uncertainty, and AI-specific characteristics.
- Risk analysis worksheets
- Scenario analysis
- Model card excerpts
- Uncertainty not quantified
- Cascading effects ignored
Compare analysis results against criteria to decide on risk treatment priorities.
- Risk evaluation matrix
- Treatment priority list
- Approval records
- No formal evaluation step
- Priorities not justified
Select and implement treatment options for AI risks including avoidance, mitigation, transfer, or acceptance.
- Risk treatment plan
- Control implementation evidence
- Residual risk acceptance
- Treatments not tracked to closure
- Residual risk unsigned
Continuously monitor AI risks, controls, performance, and external changes; review at planned intervals.
- Monitoring KPIs
- Drift detection reports
- Periodic review minutes
- No drift monitoring
- Reviews skipped
Record AI risk management activities and report outcomes to relevant stakeholders.
- Risk reports to board
- Audit trail
- Decision logs
- No audit trail for model decisions
- Reports omit AI risk
Process (Clause 6)
Communication and consultation with appropriate external and internal stakeholders shall take place within and throughout all steps of the AI risk management process.
- Risk assessment process
- Risk register
- Treatment plan
- Monitoring report
- Process not followed
- Treatments deferred
- Monitoring inconsistent
- Reporting late
Define the scope of AI risk management activities, understand external/internal context of AI deployment, and establish risk criteria specific to AI systems.
- Scope statement
- Glossary
- Reference document
- Context diagram
- Scope drifts
- Inconsistent terms
- References stale
- Stakeholders not mapped
The overall process of risk identification, risk analysis, and risk evaluation for AI systems considering AI-specific sources of risk.
- Risk assessment process
- Risk register
- Treatment plan
- Monitoring report
- Process not followed
- Treatments deferred
- Monitoring inconsistent
- Reporting late
Find, recognize, and describe risks related to AI systems including risks from data quality, algorithmic bias, lack of explainability, and unintended AI behaviours.
- Risk assessment process
- Risk register
- Treatment plan
- Monitoring report
- Process not followed
- Treatments deferred
- Monitoring inconsistent
- Reporting late
Comprehend the nature of AI risk and its characteristics including the level of risk, considering likelihood and consequences of AI-specific risks.
- Risk assessment process
- Risk register
- Treatment plan
- Monitoring report
- Process not followed
- Treatments deferred
- Monitoring inconsistent
- Reporting late
Compare the results of AI risk analysis with the established risk criteria to determine whether additional action is required.
- Risk assessment process
- Risk register
- Treatment plan
- Monitoring report
- Process not followed
- Treatments deferred
- Monitoring inconsistent
- Reporting late
Select and implement options for addressing AI-specific risks including risk avoidance, acceptance, mitigation through controls, or risk transfer.
- Risk assessment process
- Risk register
- Treatment plan
- Monitoring report
- Process not followed
- Treatments deferred
- Monitoring inconsistent
- Reporting late
Monitor and review the AI risk management process, its outputs, and ongoing changes in the AI system and its operating environment.
- Risk assessment process
- Risk register
- Treatment plan
- Monitoring report
- Process not followed
- Treatments deferred
- Monitoring inconsistent
- Reporting late
Document the AI risk management process and its outcomes, and report to relevant stakeholders.
- Risk assessment process
- Risk register
- Treatment plan
- Monitoring report
- Process not followed
- Treatments deferred
- Monitoring inconsistent
- Reporting late
Risk management process – ISO/IEC 23894:2023
- AI risk register
- Treatment records
- Integration
- AI risk register present but treatment effectiveness untested.
- AI risks reported separately from enterprise risk, fragmenting board oversight.
- AI risk register
- Treatment records
- Integration
- AI risk register present but treatment effectiveness untested.
- AI risks reported separately from enterprise risk, fragmenting board oversight.
- AI risk register
- Treatment records
- Integration
- AI risk register present but treatment effectiveness untested.
- AI risks reported separately from enterprise risk, fragmenting board oversight.
- AI risk register
- Treatment records
- Integration
- AI risk register present but treatment effectiveness untested.
- AI risks reported separately from enterprise risk, fragmenting board oversight.
- AI risk register
- Treatment records
- Integration
- AI risk register present but treatment effectiveness untested.
- AI risks reported separately from enterprise risk, fragmenting board oversight.
- AI risk register
- Treatment records
- Integration
- AI risk register present but treatment effectiveness untested.
- AI risks reported separately from enterprise risk, fragmenting board oversight.
- AI risk register
- Treatment records
- Integration
- AI risk register present but treatment effectiveness untested.
- AI risks reported separately from enterprise risk, fragmenting board oversight.
- AI risk register
- Treatment records
- Integration
- AI risk register present but treatment effectiveness untested.
- AI risks reported separately from enterprise risk, fragmenting board oversight.
- AI risk register
- Treatment records
- Integration
- AI risk register present but treatment effectiveness untested.
- AI risks reported separately from enterprise risk, fragmenting board oversight.
- AI risk register
- Treatment records
- Integration
- AI risk register present but treatment effectiveness untested.
- AI risks reported separately from enterprise risk, fragmenting board oversight.
- AI risk register
- Treatment records
- Integration
- AI risk register present but treatment effectiveness untested.
- AI risks reported separately from enterprise risk, fragmenting board oversight.
- AI risk register
- Treatment records
- Integration
- AI risk register present but treatment effectiveness untested.
- AI risks reported separately from enterprise risk, fragmenting board oversight.
- AI risk register
- Treatment records
- Integration
- AI risk register present but treatment effectiveness untested.
- AI risks reported separately from enterprise risk, fragmenting board oversight.
- AI risk register
- Treatment records
- Integration
- AI risk register present but treatment effectiveness untested.
- AI risks reported separately from enterprise risk, fragmenting board oversight.
- AI risk register
- Treatment records
- Integration
- AI risk register present but treatment effectiveness untested.
- AI risks reported separately from enterprise risk, fragmenting board oversight.
- AI risk register
- Treatment records
- Integration
- AI risk register present but treatment effectiveness untested.
- AI risks reported separately from enterprise risk, fragmenting board oversight.
- AI risk register
- Treatment records
- Integration
- AI risk register present but treatment effectiveness untested.
- AI risks reported separately from enterprise risk, fragmenting board oversight.
Scope, Terms and References (Clauses 1-3)
Defines the scope of risk management guidance for AI systems covering the entire AI system lifecycle from design through decommissioning.
- Scope statement
- Glossary
- Reference document
- Context diagram
- Scope drifts
- Inconsistent terms
- References stale
- Stakeholders not mapped
Terms and definitions specific to AI risk management building on ISO 31000, ISO/IEC 22989 (AI concepts), and ISO/IEC 23053 (AI framework).
- Scope statement
- Glossary
- Reference document
- Context diagram
- Scope drifts
- Inconsistent terms
- References stale
- Stakeholders not mapped
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO/IEC 23894:2023 framework page.