# ISO/IEC 23894:2023

> ISO/IEC 23894:2023 applies ISO 31000 risk-management practice to AI, and its hard part is the one every team hits first: naming the risks that actually apply to your system. Provael contributes to exactly that step - The EAI taxonomy as the mapped AI-risk context and the measured rate per risk as risk-assessment input to the AI risk-management process

Regulation/standard: ISO/IEC 23894:2023
Timing: Published 6 February 2023. Guidance on managing AI risk - it is not certifiable, and it does not tell you which risks to carry.

## What it is

- Guidance for organisations that develop, produce, deploy or use AI, on managing AI-specific risk and integrating it into existing risk processes.
- It is built on ISO 31000, so it describes a process - identify, analyse, evaluate, treat - rather than a checklist of controls.
- It is guidance, not a certifiable standard. ISO/IEC 42001:2023 is the certifiable management-system counterpart.
- It does not supply a domain risk catalogue. For a physical-AI system you have to bring one, which is the gap the Embodied AI Security Top 10 is written to fill.

## Where a red-team result fits

- **Risk identification & assessment** - AI risk management — risk identification & assessment input - a taxonomy gives the risk register its rows, and a measured rate per row turns qualitative likelihood into something with a denominator.

## What Provael maps to it

- The Embodied AI Security Top 10 as a ready risk context for a physical-AI system, so the register starts from a named set rather than a blank page.
- A measured rate per risk, with its interval and benign control, as risk-assessment input - evidence toward likelihood, not a determination of it.
- Honest nulls carried alongside: risks that were tested and did not transfer are reported as such, which is what stops a register recording only the risks that happened to fire.

## Dates (verified 26 Jul 2026)

- Published: 6 February 2023 (ISO/IEC JTC 1/SC 42; verified 10 Aug 2026)

## Sources

- ISO/IEC 23894:2023 (ISO): https://www.iso.org/standard/77304.html
- ISO/IEC 42001:2023 - the certifiable counterpart: https://www.iso.org/standard/81230.html

Canonical: https://www.provael.com/compliance/iso-23894

---
Provael · Prove it. Prevail. · Apache-2.0 · https://github.com/provael/provael
Not legal advice; verify regulatory dates against the primary source.
