Skip to content

Evidence request lists

ISO/IEC 23894:2023

Evidence request list. 85 controls, 85 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

AI-Specific Risk Sources (Annex A)

ISO23894-A.1
Data Quality and Representativeness

Risks from poor data quality, biased training data, insufficient data volume, or unrepresentative datasets used in AI system development.

Artefacts an auditor will ask for
  • AI risk source catalog
  • Bias evaluation report
  • Robustness test results
  • Privacy impact assessment
Where this commonly fails
  • Risk sources incomplete
  • Bias unmeasured
  • Robustness untested
  • Privacy gaps unaddressed
ISO23894-A.2
Model Transparency and Explainability

Risks from lack of transparency and explainability in AI system decision-making processes, particularly for high-stakes applications.

Artefacts an auditor will ask for
  • AI risk source catalog
  • Bias evaluation report
  • Robustness test results
  • Privacy impact assessment
Where this commonly fails
  • Risk sources incomplete
  • Bias unmeasured
  • Robustness untested
  • Privacy gaps unaddressed
ISO23894-A.3
Algorithmic Bias and Fairness

Risks of unfair outcomes or discrimination resulting from biases in AI algorithms, training data, or system design.

Artefacts an auditor will ask for
  • AI risk source catalog
  • Bias evaluation report
  • Robustness test results
  • Privacy impact assessment
Where this commonly fails
  • Risk sources incomplete
  • Bias unmeasured
  • Robustness untested
  • Privacy gaps unaddressed
ISO23894-A.4
AI System Robustness

Risks from lack of robustness in AI systems including vulnerability to adversarial attacks, distribution shifts, and unexpected inputs.

Artefacts an auditor will ask for
  • AI risk source catalog
  • Bias evaluation report
  • Robustness test results
  • Privacy impact assessment
Where this commonly fails
  • Risk sources incomplete
  • Bias unmeasured
  • Robustness untested
  • Privacy gaps unaddressed
ISO23894-A.5
Privacy and Data Protection in AI

Risks to privacy from AI systems processing personal data, including risks of re-identification, inference attacks, and unauthorized profiling.

Artefacts an auditor will ask for
  • AI risk source catalog
  • Bias evaluation report
  • Robustness test results
  • Privacy impact assessment
Where this commonly fails
  • Risk sources incomplete
  • Bias unmeasured
  • Robustness untested
  • Privacy gaps unaddressed
ISO23894-A.6
AI System Security

Cybersecurity risks specific to AI systems including model extraction, data poisoning, evasion attacks, and supply chain compromises.

Artefacts an auditor will ask for
  • AI risk source catalog
  • Bias evaluation report
  • Robustness test results
  • Privacy impact assessment
Where this commonly fails
  • Risk sources incomplete
  • Bias unmeasured
  • Robustness untested
  • Privacy gaps unaddressed
ISO23894-A.7
Human Oversight of AI

Risks from inadequate human oversight of AI systems including automation bias, over-reliance on AI outputs, and insufficient human control mechanisms.

Artefacts an auditor will ask for
  • AI risk source catalog
  • Bias evaluation report
  • Robustness test results
  • Privacy impact assessment
Where this commonly fails
  • Risk sources incomplete
  • Bias unmeasured
  • Robustness untested
  • Privacy gaps unaddressed
ISO23894-A.8
AI Accountability and Governance

Risks from unclear accountability structures for AI system outcomes, including challenges in assigning responsibility across complex AI value chains.

Artefacts an auditor will ask for
  • AI risk source catalog
  • Bias evaluation report
  • Robustness test results
  • Privacy impact assessment
Where this commonly fails
  • Risk sources incomplete
  • Bias unmeasured
  • Robustness untested
  • Privacy gaps unaddressed

Annex Guidance

23894-A.2
AI Objectives and Risk Sources

Map AI system objectives to potential risk sources including data quality, transparency, fairness, robustness.

Artefacts an auditor will ask for
  • Objective-to-risk mapping
  • Source taxonomy
  • Mitigation library
Where this commonly fails
  • Fairness sources missing
  • Robustness not mapped
23894-A.3
Lifecycle Risk Considerations

Apply risk management across AI lifecycle stages: inception, design, data, build, verify, deploy, operate, decommission.

Artefacts an auditor will ask for
  • Lifecycle stage checklists
  • Stage-gate approvals
  • Decommission plan
Where this commonly fails
  • Decommission not planned
  • Stage gates skipped
23894-A.4
AI System Impact Assessment

Conduct impact assessments covering individuals, groups, society, environment, and organization.

Artefacts an auditor will ask for
  • AI impact assessment report
  • Affected-group analysis
  • Environmental footprint estimate
Where this commonly fails
  • No societal impact considered
  • Environmental impact ignored
23894-A.5
Human Oversight Controls

Implement controls enabling appropriate human oversight, intervention, and override of AI decisions.

Artefacts an auditor will ask for
  • Oversight procedures
  • Override logs
  • Operator training records
Where this commonly fails
  • No override mechanism
  • Operators untrained
23894-A.6
Transparency and Explainability

Provide stakeholders with appropriate explanations of AI decisions and system behaviour.

Artefacts an auditor will ask for
  • Explainability documentation
  • User-facing notices
  • Model cards
Where this commonly fails
  • No user notices
  • Model cards absent
23894-A.7
Data Quality and Provenance

Ensure training and operational data meet quality, representativeness, and provenance requirements.

Artefacts an auditor will ask for
  • Data quality reports
  • Data lineage records
  • Bias assessment
Where this commonly fails
  • No lineage
  • Representativeness untested
23894-A.8
Robustness and Resilience Testing

Test AI system robustness against adversarial inputs, distribution shift, and operational stresses.

Artefacts an auditor will ask for
  • Adversarial test reports
  • Drift test results
  • Stress test logs
Where this commonly fails
  • No adversarial testing
  • Drift untested
23894-A.9
Third-Party AI Components

Assess and manage risks from third-party AI models, datasets, and services used in the system.

Artefacts an auditor will ask for
  • Vendor assessment
  • Model provenance docs
  • Contractual clauses
Where this commonly fails
  • No vendor due diligence
  • Provenance unknown

Framework

23894-5.2
Leadership and Commitment

Top management demonstrates commitment to AI risk management through policy, resources, and accountability assignments.

Artefacts an auditor will ask for
  • AI risk policy signed by executive
  • Resource allocation records
  • Accountability matrix
Where this commonly fails
  • No executive sponsor named
  • Resources not budgeted
23894-5.3
Integration into Organizational Processes

Integrate AI risk management into governance, strategy, planning, reporting, policies, values, and culture.

Artefacts an auditor will ask for
  • Process maps showing AI risk touchpoints
  • Strategic plan referencing AI risk
  • Updated SDLC with AI risk gates
Where this commonly fails
  • AI risk siloed from enterprise risk
  • No SDLC integration
23894-5.4.1
Understanding Organization and Context

Examine external and internal context relevant to AI system purpose, stakeholders, and risk criteria.

Artefacts an auditor will ask for
  • Context analysis document
  • Stakeholder register
  • PESTLE analysis for AI use
Where this commonly fails
  • Stakeholders not identified
  • Context not refreshed
23894-5.4.2
AI Risk Management Policy

Establish documented AI risk policy stating objectives, scope, roles, criteria, and review cadence.

Artefacts an auditor will ask for
  • AI risk management policy
  • Policy review log
  • Distribution evidence
Where this commonly fails
  • Policy not approved
  • No review cadence defined
23894-5.4.3
Roles, Authorities, Responsibilities

Assign and communicate AI risk roles including model owner, risk owner, validator, and approver.

Artefacts an auditor will ask for
  • RACI matrix for AI risk
  • Role descriptions
  • Appointment letters
Where this commonly fails
  • Model validator not independent
  • Roles not documented
23894-5.4.4
Allocation of Resources

Allocate appropriate resources (people, skills, tools, budget) for AI risk management.

Artefacts an auditor will ask for
  • Budget allocation
  • Skills inventory
  • Tooling list
Where this commonly fails
  • No dedicated AI risk team
  • Tooling absent
23894-5.5
Communication and Consultation

Plan and execute internal and external communication on AI risks with stakeholders throughout lifecycle.

Artefacts an auditor will ask for
  • Communication plan
  • Stakeholder consultation records
  • External disclosure templates
Where this commonly fails
  • No affected-user channel
  • External comms ad hoc

Framework (Clause 5)

ISO23894-5.1
Leadership and Commitment

Top management and oversight bodies shall demonstrate leadership and commitment to AI risk management by ensuring integration into organizational governance.

Artefacts an auditor will ask for
  • Framework charter
  • Leadership endorsement
  • Implementation plan
  • Framework evaluation report
Where this commonly fails
  • Framework not endorsed
  • Implementation partial
  • Evaluation skipped
  • Integration with ISMS weak
ISO23894-5.2
AI Risk Management Integration

Integrating risk management into the organization depends on understanding the organizational structures and context of AI deployment.

Artefacts an auditor will ask for
  • Framework charter
  • Leadership endorsement
  • Implementation plan
  • Framework evaluation report
Where this commonly fails
  • Framework not endorsed
  • Implementation partial
  • Evaluation skipped
  • Integration with ISMS weak
ISO23894-5.3
AI Risk Management Design

Design the framework for managing AI risks by understanding the organization's AI context, articulating AI risk management commitment, and allocating resources.

Artefacts an auditor will ask for
  • Framework charter
  • Leadership endorsement
  • Implementation plan
  • Framework evaluation report
Where this commonly fails
  • Framework not endorsed
  • Implementation partial
  • Evaluation skipped
  • Integration with ISMS weak
ISO23894-5.4
AI Risk Management Implementation

Implement the AI risk management framework by developing appropriate plans, identifying decision-making pathways, and embedding risk management into AI lifecycle processes.

Artefacts an auditor will ask for
  • Framework charter
  • Leadership endorsement
  • Implementation plan
  • Framework evaluation report
Where this commonly fails
  • Framework not endorsed
  • Implementation partial
  • Evaluation skipped
  • Integration with ISMS weak
ISO23894-5.5
Framework Evaluation

Periodically measure AI risk management framework performance against its purpose, implementation plans, indicators, and expected behaviour.

Artefacts an auditor will ask for
  • Framework charter
  • Leadership endorsement
  • Implementation plan
  • Framework evaluation report
Where this commonly fails
  • Framework not endorsed
  • Implementation partial
  • Evaluation skipped
  • Integration with ISMS weak
ISO23894-5.6
Framework Improvement

Continually adapt and improve the AI risk management framework to address internal and external changes in AI technology and applications.

Artefacts an auditor will ask for
  • Framework charter
  • Leadership endorsement
  • Implementation plan
  • Framework evaluation report
Where this commonly fails
  • Framework not endorsed
  • Implementation partial
  • Evaluation skipped
  • Integration with ISMS weak

Framework – ISO/IEC 23894:2023

5.1
General
Artefacts an auditor will ask for
  • AI risk register
  • Treatment records
  • Integration
Where this commonly fails
  • AI risk register present but treatment effectiveness untested.
  • AI risks reported separately from enterprise risk, fragmenting board oversight.
5.2
Leadership and commitment
Artefacts an auditor will ask for
  • AI risk register
  • Treatment records
  • Integration
Where this commonly fails
  • AI risk register present but treatment effectiveness untested.
  • AI risks reported separately from enterprise risk, fragmenting board oversight.
5.3
Integration
Artefacts an auditor will ask for
  • AI risk register
  • Treatment records
  • Integration
Where this commonly fails
  • AI risk register present but treatment effectiveness untested.
  • AI risks reported separately from enterprise risk, fragmenting board oversight.
5.4
Design
Artefacts an auditor will ask for
  • AI risk register
  • Treatment records
  • Integration
Where this commonly fails
  • AI risk register present but treatment effectiveness untested.
  • AI risks reported separately from enterprise risk, fragmenting board oversight.
5.4.1
Understanding the organization and its context
Artefacts an auditor will ask for
  • AI risk register
  • Treatment records
  • Integration
Where this commonly fails
  • AI risk register present but treatment effectiveness untested.
  • AI risks reported separately from enterprise risk, fragmenting board oversight.
5.4.2
Articulating risk management commitment
Artefacts an auditor will ask for
  • AI risk register
  • Treatment records
  • Integration
Where this commonly fails
  • AI risk register present but treatment effectiveness untested.
  • AI risks reported separately from enterprise risk, fragmenting board oversight.
5.4.3
Assigning organizational roles, authorities, responsibilities and
Artefacts an auditor will ask for
  • AI risk register
  • Treatment records
  • Integration
Where this commonly fails
  • AI risk register present but treatment effectiveness untested.
  • AI risks reported separately from enterprise risk, fragmenting board oversight.
5.4.4
Allocating resources
Artefacts an auditor will ask for
  • AI risk register
  • Treatment records
  • Integration
Where this commonly fails
  • AI risk register present but treatment effectiveness untested.
  • AI risks reported separately from enterprise risk, fragmenting board oversight.
5.4.5
Establishing communication and consultation
Artefacts an auditor will ask for
  • AI risk register
  • Treatment records
  • Integration
Where this commonly fails
  • AI risk register present but treatment effectiveness untested.
  • AI risks reported separately from enterprise risk, fragmenting board oversight.
5.5
Implementation
Artefacts an auditor will ask for
  • AI risk register
  • Treatment records
  • Integration
Where this commonly fails
  • AI risk register present but treatment effectiveness untested.
  • AI risks reported separately from enterprise risk, fragmenting board oversight.
5.7.1
Adapting
Artefacts an auditor will ask for
  • AI risk register
  • Treatment records
  • Integration
Where this commonly fails
  • AI risk register present but treatment effectiveness untested.
  • AI risks reported separately from enterprise risk, fragmenting board oversight.
5.7.2
Continually improving
Artefacts an auditor will ask for
  • AI risk register
  • Treatment records
  • Integration
Where this commonly fails
  • AI risk register present but treatment effectiveness untested.
  • AI risks reported separately from enterprise risk, fragmenting board oversight.

Principles

23894-4.1
AI Risk Management Principles

Apply ISO 31000 principles adapted for AI: integrated, structured, customised, inclusive, dynamic, best available information, human and cultural factors, continual improvement.

Artefacts an auditor will ask for
  • AI risk management principles statement
  • Mapping to ISO 31000 principles
  • Board endorsement record
Where this commonly fails
  • Principles not tailored to AI specifics
  • No evidence of board endorsement

Principles (Clause 4)

ISO23894-4.1
Integrated AI Risk Management

AI risk management shall be an integral part of all organizational activities including governance, strategy, and operational processes.

Artefacts an auditor will ask for
  • Principles statement
  • Stakeholder register
  • Improvement plan
  • Cultural factors assessment
Where this commonly fails
  • Principles not applied
  • Stakeholders missed
  • No improvement cadence
  • Cultural factors ignored
ISO23894-4.2
Structured and Comprehensive Approach

A structured and comprehensive approach to AI risk management contributes to consistent and comparable results.

Artefacts an auditor will ask for
  • Principles statement
  • Stakeholder register
  • Improvement plan
  • Cultural factors assessment
Where this commonly fails
  • Principles not applied
  • Stakeholders missed
  • No improvement cadence
  • Cultural factors ignored
ISO23894-4.3
Customized to AI Context

The risk management framework and process shall be customized and proportionate to the organization's external and internal context related to AI objectives.

Artefacts an auditor will ask for
  • Principles statement
  • Stakeholder register
  • Improvement plan
  • Cultural factors assessment
Where this commonly fails
  • Principles not applied
  • Stakeholders missed
  • No improvement cadence
  • Cultural factors ignored
ISO23894-4.4
Inclusive Stakeholder Engagement

Appropriate and timely involvement of stakeholders enables their knowledge, views, and perceptions to be considered in AI risk management.

Artefacts an auditor will ask for
  • Principles statement
  • Stakeholder register
  • Improvement plan
  • Cultural factors assessment
Where this commonly fails
  • Principles not applied
  • Stakeholders missed
  • No improvement cadence
  • Cultural factors ignored
ISO23894-4.5
Dynamic and Responsive

Risks can emerge, change, or disappear as the AI system's external and internal context changes. Risk management anticipates, detects, acknowledges, and responds to those changes.

Artefacts an auditor will ask for
  • Principles statement
  • Stakeholder register
  • Improvement plan
  • Cultural factors assessment
Where this commonly fails
  • Principles not applied
  • Stakeholders missed
  • No improvement cadence
  • Cultural factors ignored
ISO23894-4.6
Best Available Information

Inputs to AI risk management shall be based on historical and current information, as well as future expectations considering limitations and uncertainties of AI systems.

Artefacts an auditor will ask for
  • Principles statement
  • Stakeholder register
  • Improvement plan
  • Cultural factors assessment
Where this commonly fails
  • Principles not applied
  • Stakeholders missed
  • No improvement cadence
  • Cultural factors ignored
ISO23894-4.7
Human and Cultural Factors

Human behaviour and culture significantly influence all aspects of AI risk management at each level and stage.

Artefacts an auditor will ask for
  • Principles statement
  • Stakeholder register
  • Improvement plan
  • Cultural factors assessment
Where this commonly fails
  • Principles not applied
  • Stakeholders missed
  • No improvement cadence
  • Cultural factors ignored
ISO23894-4.8
Continual Improvement

AI risk management is continually improved through learning and experience as AI technologies and their applications evolve.

Artefacts an auditor will ask for
  • Principles statement
  • Stakeholder register
  • Improvement plan
  • Cultural factors assessment
Where this commonly fails
  • Principles not applied
  • Stakeholders missed
  • No improvement cadence
  • Cultural factors ignored

Process

23894-6.3
AI Risk Assessment Scope and Criteria

Define scope, context, and criteria for assessing AI-specific risks including likelihood and consequence measures.

Artefacts an auditor will ask for
  • Risk criteria document
  • AI use case inventory
  • Risk appetite statement
Where this commonly fails
  • Criteria copied from enterprise risk
  • Use cases not inventoried
23894-6.4.2
AI Risk Identification

Identify sources of AI risk including data, model, system, deployment, and societal factors.

Artefacts an auditor will ask for
  • AI risk register
  • Risk taxonomy
  • Identification workshop records
Where this commonly fails
  • Societal risks omitted
  • Data-source risks missed
23894-6.4.3
AI Risk Analysis

Analyse identified AI risks considering causes, consequences, controls, uncertainty, and AI-specific characteristics.

Artefacts an auditor will ask for
  • Risk analysis worksheets
  • Scenario analysis
  • Model card excerpts
Where this commonly fails
  • Uncertainty not quantified
  • Cascading effects ignored
23894-6.4.4
AI Risk Evaluation

Compare analysis results against criteria to decide on risk treatment priorities.

Artefacts an auditor will ask for
  • Risk evaluation matrix
  • Treatment priority list
  • Approval records
Where this commonly fails
  • No formal evaluation step
  • Priorities not justified
23894-6.5
AI Risk Treatment

Select and implement treatment options for AI risks including avoidance, mitigation, transfer, or acceptance.

Artefacts an auditor will ask for
  • Risk treatment plan
  • Control implementation evidence
  • Residual risk acceptance
Where this commonly fails
  • Treatments not tracked to closure
  • Residual risk unsigned
23894-6.6
Monitoring and Review

Continuously monitor AI risks, controls, performance, and external changes; review at planned intervals.

Artefacts an auditor will ask for
  • Monitoring KPIs
  • Drift detection reports
  • Periodic review minutes
Where this commonly fails
  • No drift monitoring
  • Reviews skipped
23894-6.7
Recording and Reporting

Record AI risk management activities and report outcomes to relevant stakeholders.

Artefacts an auditor will ask for
  • Risk reports to board
  • Audit trail
  • Decision logs
Where this commonly fails
  • No audit trail for model decisions
  • Reports omit AI risk

Process (Clause 6)

ISO23894-6.1
Communication and Consultation

Communication and consultation with appropriate external and internal stakeholders shall take place within and throughout all steps of the AI risk management process.

Artefacts an auditor will ask for
  • Risk assessment process
  • Risk register
  • Treatment plan
  • Monitoring report
Where this commonly fails
  • Process not followed
  • Treatments deferred
  • Monitoring inconsistent
  • Reporting late
ISO23894-6.2
Scope, Context and Criteria

Define the scope of AI risk management activities, understand external/internal context of AI deployment, and establish risk criteria specific to AI systems.

Artefacts an auditor will ask for
  • Scope statement
  • Glossary
  • Reference document
  • Context diagram
Where this commonly fails
  • Scope drifts
  • Inconsistent terms
  • References stale
  • Stakeholders not mapped
ISO23894-6.3
AI Risk Assessment

The overall process of risk identification, risk analysis, and risk evaluation for AI systems considering AI-specific sources of risk.

Artefacts an auditor will ask for
  • Risk assessment process
  • Risk register
  • Treatment plan
  • Monitoring report
Where this commonly fails
  • Process not followed
  • Treatments deferred
  • Monitoring inconsistent
  • Reporting late
ISO23894-6.3.1
AI Risk Identification

Find, recognize, and describe risks related to AI systems including risks from data quality, algorithmic bias, lack of explainability, and unintended AI behaviours.

Artefacts an auditor will ask for
  • Risk assessment process
  • Risk register
  • Treatment plan
  • Monitoring report
Where this commonly fails
  • Process not followed
  • Treatments deferred
  • Monitoring inconsistent
  • Reporting late
ISO23894-6.3.2
AI Risk Analysis

Comprehend the nature of AI risk and its characteristics including the level of risk, considering likelihood and consequences of AI-specific risks.

Artefacts an auditor will ask for
  • Risk assessment process
  • Risk register
  • Treatment plan
  • Monitoring report
Where this commonly fails
  • Process not followed
  • Treatments deferred
  • Monitoring inconsistent
  • Reporting late
ISO23894-6.3.3
AI Risk Evaluation

Compare the results of AI risk analysis with the established risk criteria to determine whether additional action is required.

Artefacts an auditor will ask for
  • Risk assessment process
  • Risk register
  • Treatment plan
  • Monitoring report
Where this commonly fails
  • Process not followed
  • Treatments deferred
  • Monitoring inconsistent
  • Reporting late
ISO23894-6.4
AI Risk Treatment

Select and implement options for addressing AI-specific risks including risk avoidance, acceptance, mitigation through controls, or risk transfer.

Artefacts an auditor will ask for
  • Risk assessment process
  • Risk register
  • Treatment plan
  • Monitoring report
Where this commonly fails
  • Process not followed
  • Treatments deferred
  • Monitoring inconsistent
  • Reporting late
ISO23894-6.5
Monitoring and Review

Monitor and review the AI risk management process, its outputs, and ongoing changes in the AI system and its operating environment.

Artefacts an auditor will ask for
  • Risk assessment process
  • Risk register
  • Treatment plan
  • Monitoring report
Where this commonly fails
  • Process not followed
  • Treatments deferred
  • Monitoring inconsistent
  • Reporting late
ISO23894-6.6
Recording and Reporting

Document the AI risk management process and its outcomes, and report to relevant stakeholders.

Artefacts an auditor will ask for
  • Risk assessment process
  • Risk register
  • Treatment plan
  • Monitoring report
Where this commonly fails
  • Process not followed
  • Treatments deferred
  • Monitoring inconsistent
  • Reporting late

Risk management process – ISO/IEC 23894:2023

6.1
General
Artefacts an auditor will ask for
  • AI risk register
  • Treatment records
  • Integration
Where this commonly fails
  • AI risk register present but treatment effectiveness untested.
  • AI risks reported separately from enterprise risk, fragmenting board oversight.
6.2
Communication and consultation
Artefacts an auditor will ask for
  • AI risk register
  • Treatment records
  • Integration
Where this commonly fails
  • AI risk register present but treatment effectiveness untested.
  • AI risks reported separately from enterprise risk, fragmenting board oversight.
6.3.1
General
Artefacts an auditor will ask for
  • AI risk register
  • Treatment records
  • Integration
Where this commonly fails
  • AI risk register present but treatment effectiveness untested.
  • AI risks reported separately from enterprise risk, fragmenting board oversight.
6.3.2
Defining the scope
Artefacts an auditor will ask for
  • AI risk register
  • Treatment records
  • Integration
Where this commonly fails
  • AI risk register present but treatment effectiveness untested.
  • AI risks reported separately from enterprise risk, fragmenting board oversight.
6.3.3
External and internal context
Artefacts an auditor will ask for
  • AI risk register
  • Treatment records
  • Integration
Where this commonly fails
  • AI risk register present but treatment effectiveness untested.
  • AI risks reported separately from enterprise risk, fragmenting board oversight.
6.3.4
Defining risk criteria
Artefacts an auditor will ask for
  • AI risk register
  • Treatment records
  • Integration
Where this commonly fails
  • AI risk register present but treatment effectiveness untested.
  • AI risks reported separately from enterprise risk, fragmenting board oversight.
6.4
Risk assessment
Artefacts an auditor will ask for
  • AI risk register
  • Treatment records
  • Integration
Where this commonly fails
  • AI risk register present but treatment effectiveness untested.
  • AI risks reported separately from enterprise risk, fragmenting board oversight.
6.4.1
General
Artefacts an auditor will ask for
  • AI risk register
  • Treatment records
  • Integration
Where this commonly fails
  • AI risk register present but treatment effectiveness untested.
  • AI risks reported separately from enterprise risk, fragmenting board oversight.
6.4.2
Risk identification
Artefacts an auditor will ask for
  • AI risk register
  • Treatment records
  • Integration
Where this commonly fails
  • AI risk register present but treatment effectiveness untested.
  • AI risks reported separately from enterprise risk, fragmenting board oversight.
6.4.3
Risk analysis
Artefacts an auditor will ask for
  • AI risk register
  • Treatment records
  • Integration
Where this commonly fails
  • AI risk register present but treatment effectiveness untested.
  • AI risks reported separately from enterprise risk, fragmenting board oversight.
6.4.4
Risk evaluation
Artefacts an auditor will ask for
  • AI risk register
  • Treatment records
  • Integration
Where this commonly fails
  • AI risk register present but treatment effectiveness untested.
  • AI risks reported separately from enterprise risk, fragmenting board oversight.
6.5
Risk treatment
Artefacts an auditor will ask for
  • AI risk register
  • Treatment records
  • Integration
Where this commonly fails
  • AI risk register present but treatment effectiveness untested.
  • AI risks reported separately from enterprise risk, fragmenting board oversight.
6.5.1
General
Artefacts an auditor will ask for
  • AI risk register
  • Treatment records
  • Integration
Where this commonly fails
  • AI risk register present but treatment effectiveness untested.
  • AI risks reported separately from enterprise risk, fragmenting board oversight.
6.5.2
Selection of risk treatment options
Artefacts an auditor will ask for
  • AI risk register
  • Treatment records
  • Integration
Where this commonly fails
  • AI risk register present but treatment effectiveness untested.
  • AI risks reported separately from enterprise risk, fragmenting board oversight.
6.5.3
Preparing and implementing risk treatment plans
Artefacts an auditor will ask for
  • AI risk register
  • Treatment records
  • Integration
Where this commonly fails
  • AI risk register present but treatment effectiveness untested.
  • AI risks reported separately from enterprise risk, fragmenting board oversight.
6.6
Monitoring and review
Artefacts an auditor will ask for
  • AI risk register
  • Treatment records
  • Integration
Where this commonly fails
  • AI risk register present but treatment effectiveness untested.
  • AI risks reported separately from enterprise risk, fragmenting board oversight.
6.7
Recording and reporting
Artefacts an auditor will ask for
  • AI risk register
  • Treatment records
  • Integration
Where this commonly fails
  • AI risk register present but treatment effectiveness untested.
  • AI risks reported separately from enterprise risk, fragmenting board oversight.

Scope, Terms and References (Clauses 1-3)

ISO23894-1
Scope of AI Risk Management

Defines the scope of risk management guidance for AI systems covering the entire AI system lifecycle from design through decommissioning.

Artefacts an auditor will ask for
  • Scope statement
  • Glossary
  • Reference document
  • Context diagram
Where this commonly fails
  • Scope drifts
  • Inconsistent terms
  • References stale
  • Stakeholders not mapped
ISO23894-3
AI-Specific Terminology

Terms and definitions specific to AI risk management building on ISO 31000, ISO/IEC 22989 (AI concepts), and ISO/IEC 23053 (AI framework).

Artefacts an auditor will ask for
  • Scope statement
  • Glossary
  • Reference document
  • Context diagram
Where this commonly fails
  • Scope drifts
  • Inconsistent terms
  • References stale
  • Stakeholders not mapped
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO/IEC 23894:2023 framework page.