International
ISO 23894
ISO/IEC 23894 provides guidance on managing risk specific to AI, aligning the ISO 31000 risk management process with the particular challenges of developing and using artificial intelligence.
5 clauses
Risk management principles for AI
AI risk management should be integrated, structured, customised, inclusive, dynamic and based on the best available information, creating and protecting value.
Leadership and commitment
Top management should ensure AI risk management is integrated into all organisational activities and demonstrate leadership and commitment.
Risk assessment (identification, analysis, evaluation)
The AI risk assessment process comprises risk identification, risk analysis and risk evaluation, tailored to AI-specific risk sources.
Risk treatment
The organisation should select and implement options for addressing AI risk and formulate risk treatment plans.
Monitoring, review, recording and reporting
The organisation should continually monitor and review AI risks and controls, and record and report the risk management process and outcomes.
Turn ISO 23894 into tracked tasks
eurocompliant maps these obligations to checklists and evidence, so you can prove compliance instead of re-reading the text.
Start free trial