ISO/IEC 42001:2023 specifies requirements for a certifiable AI management system; ISO/IEC 23894:2023 provides guidance on managing AI risk and is not itself a certifiable management-system requirements standard.
Use ISO/IEC 23894 to deepen risk methods inside an AIMS while keeping ISO/IEC 42001's clauses, impact assessment, control selection, documented information, audit, review, and improvement requirements authoritative for AIMS conformance.
The standards are complementary, not substitutes. ISO/IEC 42001:2023 establishes requirements for an AIMS; :2023 gives organisations guidance for managing AI-specific risk and integrating that work into their activities and functions. Both are voluntary standards unless a law, contract, policy, or other commitment makes one applicable. A risk method can support the AIMS without satisfying the rest of ISO/IEC 42001 Clauses 4-10.
Side-by-side comparison
ISO/IEC 42001 vs ISO/IEC 23894: requirements, risk guidance, and evidence
Use ISO/IEC 42001 for AIMS requirements and conformity; use as supporting AI risk-management guidance. The comparison shows how to integrate them without claiming equivalence.
Requirements standard for establishing, implementing, maintaining, and continually improving an AIMS; suitable for conformity assessment and certification.
Second framework
ISO/IEC 23894
Guidance standard for managing AI-related risk; useful inside an AIMS but not a replacement for the AIMS requirements or a standalone certification basis.
ISO/IEC 42001 vs ISO/IEC 23894: requirements, risk guidance, and evidence
ISO/IEC 42001:2023 specifies requirements for establishing, implementing, maintaining, and continually improving an AIMS within a defined organisational scope.
:2023 guides organisations that develop, produce, deploy, or use AI products, systems, and services in managing AI-specific risk and integrating risk management into related activities and functions.
ISO/IEC 42001 ownership should sit with the team that can operate the relevant management system, control process, risk method, supplier relationship, incident process, privacy process, or AI governance scope.
risk ownership should be integrated into the organisation's activities and functions, with responsibilities suited to its AI lifecycle, context, stakeholders, and risk process.
ISO/IEC 42001 work is triggered by scope definition, implementation, certification readiness, customer assurance, control gaps, incidents, supplier changes, or management review.
Use to shape the risk method where helpful, but trigger and document ISO/IEC 42001 risk assessment, treatment, impact assessment, operational control and management-system review under their own requirements.
guides the design and integration of AI risk management, including context, assessment, treatment, communication and consultation, monitoring, and review. Its application can be customised to the organisation and context.
ISO/IEC 42001 evidence should show the process operating: owners, decisions, registers, control records, test results, review minutes, audit samples, or corrective actions.
Evidence of using can include the risk policy and criteria, contextual analysis, risk assessments, treatment decisions, communication, monitoring, and review records chosen by the organisation.
ISO/IEC 42001 timing follows implementation, audit, certification, review, supplier, incident, or change cycles rather than a single universal deadline.
has no universal compliance deadline. Organisations set risk-review cadence and change triggers appropriate to their AI lifecycle, context, and commitments.
ISO/IEC 42001 is usually tested through certification audits, internal audits, customer assurance, management review, or governance review, depending on how the organization adopts it.
risk records can support AIMS risk assessment and treatment when their scope, criteria, owners, and review status meet the relevant ISO/IEC 42001 requirement.
Use when the primary need is practical guidance for designing, integrating, or improving AI risk management without pursuing an AIMS conformity claim on that basis alone.
ISO/IEC 42001:2023 specifies requirements for establishing, implementing, maintaining, and continually improving an AIMS within a defined organisational scope.
:2023 guides organisations that develop, produce, deploy, or use AI products, systems, and services in managing AI-specific risk and integrating risk management into related activities and functions.
ISO/IEC 42001 ownership should sit with the team that can operate the relevant management system, control process, risk method, supplier relationship, incident process, privacy process, or AI governance scope.
risk ownership should be integrated into the organisation's activities and functions, with responsibilities suited to its AI lifecycle, context, stakeholders, and risk process.
ISO/IEC 42001 work is triggered by scope definition, implementation, certification readiness, customer assurance, control gaps, incidents, supplier changes, or management review.
Use to shape the risk method where helpful, but trigger and document ISO/IEC 42001 risk assessment, treatment, impact assessment, operational control and management-system review under their own requirements.
guides the design and integration of AI risk management, including context, assessment, treatment, communication and consultation, monitoring, and review. Its application can be customised to the organisation and context.
ISO/IEC 42001 evidence should show the process operating: owners, decisions, registers, control records, test results, review minutes, audit samples, or corrective actions.
Evidence of using can include the risk policy and criteria, contextual analysis, risk assessments, treatment decisions, communication, monitoring, and review records chosen by the organisation.
ISO/IEC 42001 timing follows implementation, audit, certification, review, supplier, incident, or change cycles rather than a single universal deadline.
has no universal compliance deadline. Organisations set risk-review cadence and change triggers appropriate to their AI lifecycle, context, and commitments.
ISO/IEC 42001 is usually tested through certification audits, internal audits, customer assurance, management review, or governance review, depending on how the organization adopts it.
risk records can support AIMS risk assessment and treatment when their scope, criteria, owners, and review status meet the relevant ISO/IEC 42001 requirement.
Use when the primary need is practical guidance for designing, integrating, or improving AI risk management without pursuing an AIMS conformity claim on that basis alone.
How should teams decide between ISO/IEC 42001 and ISO/IEC 23894?
For an AIMS conformity or certification objective, use ISO/IEC 42001 as the requirements baseline and as supporting risk guidance.
For an AI risk method within another governance programme, use without implying that the wider AIMS requirements have been met.
If both are used, map the risk method to ISO/IEC 42001 Clauses 6.1 and 8, then verify context, leadership, support, impact assessment, performance evaluation, and improvement separately.
Use ISO/IEC 42001:2023 as the lead standard when the objective is to establish, operate, assess, or certify an artificial intelligence management system (AIMS). Its requirements cover organisational context, scope, leadership, policy, roles, risk assessment and treatment, AI system impact assessment, objectives, support, operation, performance evaluation, internal audit, management review, and improvement.
Use :2023 when the immediate need is guidance on AI-specific risk management. It applies to organisations that develop, produce, deploy, or use AI products, systems, and services, and its application can be customised to the organisation and its context. It does not prescribe an AIMS, a certification scope, or one mandatory record set.
When both are used, can inform the method used to meet ISO/IEC 42001 risk requirements. ISO/IEC 42001 itself points to ISO/IEC 23894 for guidance on risk criteria, risk management implementation, impact analysis, and AI-related objectives and risk sources.
Choose ISO/IEC 42001 for an AIMS conformity or certification objective.
Choose for adaptable AI risk-management guidance without claiming AIMS conformity on that basis.
Use both when the AIMS needs a detailed risk method, but test every ISO/IEC 42001 requirement separately.
What evidence should the integrated approach produce?
ISO/IEC 42001 requires documented information at defined points. The integrated evidence set should include the AIMS scope, policy and objectives, role assignments, risk criteria, repeatable risk-assessment process, assessment results, risk-treatment process and plan, statement of applicability, residual-risk acceptance, AI system impact assessments, operating controls, monitoring and measurement results, internal audits, management reviews, and corrective actions.
can shape the risk process behind those records: context, risk identification, analysis, evaluation, treatment, communication and consultation, monitoring, and review. Keep the chosen method, scales, assumptions, affected stakeholders, uncertainty, decision criteria, treatment owner, residual risk, and review triggers visible.
A completed risk register is only part of AIMS evidence. It does not replace leadership, competence, communication, operational control, impact assessment, internal audit, management review, or continual-improvement records. The record must also show how uncertainty, positive and negative consequences, affected parties, and the organisation's acceptance criteria changed the decision.
Method record: purpose, scope, context, definitions, risk criteria, scales, data sources, assumptions, uncertainty, and responsible roles.
Assessment record: AI system and lifecycle stage, intended use and foreseeable misuse, affected parties, consequences, likelihood where applicable, risk level, prioritisation, and decision.
Treatment record: selected option, necessary controls, Annex A comparison, statement-of-applicability justification, residual-risk acceptance, owner, due date, and effectiveness measure.
Review record: monitoring result, changed context, incident or feedback, reassessment decision, corrective action, approval, and next trigger.
Build one risk process when the scope and terminology can be kept consistent. Label each step as an ISO/IEC 42001 requirement, an method choice, or both. That distinction matters because ISO/IEC 23894 guidance does not create a substitute conformity route.
Run the process initially, at planned intervals, and when change warrants reassessment. ISO/IEC 42001 requires risk assessments at planned intervals and when significant changes are proposed or occur; the organisation must define what counts as significant in its context. Relevant triggers can include a changed intended purpose, model or data change, new deployment context, new affected population, supplier change, control failure, incident, monitoring result, legal change, or revised organisational risk criteria.
1. Define the AIMS scope, organisational roles, interested parties, and AI systems covered.
2. Establish AI risk criteria that distinguish acceptable from unacceptable risk and support assessment, treatment, and impact work.
3. Use guidance to design the contextualised risk process and its communication, monitoring, and review.
4. Perform ISO/IEC 42001 risk assessment and AI system impact assessment; retain the required documented results.
5. Select treatment options and controls, compare necessary controls with Annex A, justify inclusions and exclusions, approve the plan, and accept residual risk through designated management.
6. Monitor effectiveness, audit the AIMS, review it through management, and correct nonconformities.
Do not claim ISO/IEC 42001 conformity because the organisation follows . The guidance can support risk work, but AIMS conformity depends on all applicable ISO/IEC 42001 requirements.
Do not treat the ISO/IEC 42001 Annex A control list as a fixed checklist. The organisation determines necessary controls from risk treatment, compares them with Annex A to avoid omissions, justifies inclusion and exclusion in the statement of applicability, and can add controls beyond Annex A.
Keep AI risk assessment and AI system impact assessment distinct. Under ISO/IEC 42001, the impact assessment addresses potential consequences for individuals, groups, and societies and feeds the risk assessment; it is not merely another risk score.
Do not cite a standard title as evidence that a process is operating.
Do not reuse an old audit artifact after the scope, service, supplier, or risk has changed.
Do not hide exceptions; record them as risk acceptance, corrective action, or management-review inputs.
Set planned review intervals, then add event-based triggers. Neither standard sets one universal calendar interval for every organisation or system. Reassess whether the context, risk criteria, impact assumptions, treatment decisions, controls, and residual-risk acceptance still fit the current system and its use.
Use monitoring, incidents, complaints, audit findings, control failures, supplier changes, and stakeholder feedback as inputs. When the result changes, update both the risk record and every AIMS record that depends on it, including the statement of applicability, treatment plan, impact assessment, operating controls, objectives, or management-review decision.
Set a review date and a change-trigger rule.
Track findings until closure and connect them to corrective actions or risk acceptance.
Use management review to decide resourcing, risk appetite, scope changes, and evidence quality.