ISO/IEC 23894 and Article 9
The most useful thing you can do with ISO/IEC 23894 is treat it as the structure for an Article 9 risk process, and the least useful is treat it as evidence of compliance with one. It is guidance, it is not certifiable, and it is not harmonised.
What it is
ISO/IEC 23894:2023 provides guidance on managing risk related to AI. It is built on ISO 31000: the general risk management standard, and adapts its principles, framework and process to AI-specific risk sources.
| Type | Guidance document, not a requirements standard |
| Certifiable? | No: there is nothing to audit conformity against |
| Harmonised under the AI Act? | No — no Article 40 presumption |
| Built on | ISO 31000 principles, framework and process |
| Relationship to ISO/IEC 42001 | 42001 requires AI risk assessment and treatment; 23894 is the guidance most often used to design that process |
| European equivalent in development | prEN 18228, risk management for AI systems, JTC 21 WG2. Deliverable map → |
Guidance versus requirements is not a technicality
A guidance document tells you how to think about a problem. A requirements standard states what must be true. Only the second can be certified, and only the second can be cited in the Official Journal to carry presumption of conformity. Vendors describing “ISO 23894 compliance” are using a word the document does not support.
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →
Where it helps with Article 9
Structurally, quite a lot. The ISO 31000 cycle, establishing scope and context, risk identification, analysis, evaluation, treatment, monitoring and review, recording and reporting — maps onto the Article 9 process without strain, and 23894 supplies AI-specific risk sources that a generic register will not contain.
Where it stops
Four things Article 9 requires that generic AI risk guidance does not supply:
| Article 9 requires | Why guidance does not get you there |
|---|---|
| Risk to health, safety and fundamental rights of persons | Risk management guidance is agnostic about whose risk. Article 9 is not: the object of assessment is harm to people, which is a different register with different categories. |
| Reasonably foreseeable misuse | You must model the user acting against your instructions, as a required limb rather than an optional scenario. |
| A prescribed hierarchy of measures | Article 9(5): eliminate by design first, mitigate second, inform the deployer last. Generic guidance does not impose an order. |
| A documented acceptance of residual risk | A named decision with a recorded rationale, not a colour on a heat map. |
How we would actually use it
Practical recommendation. Use 23894 to design the process and Article 9 to define the scope and outputs. Then record, per system: the risks identified, the foreseeable-misuse analysis, the treatments in hierarchy order, the test results, and who accepted the residual risk and when. That record is what Annex IV heading 5 asks for, and it is what an assessor examines, not which guidance document you consulted.
Status labels on this page
Verified fact: What ISO/IEC 23894 is, that it is guidance and not certifiable, that it is not harmonised, and the existence of prEN 18228 as the European risk management deliverable.
Expert analysis: The four-gap analysis and the recommendation to use 23894 for process and Article 9 for scope.
Unsettled: Whether any ISO/IEC risk management text is ultimately adopted into the European catalogue in a form that could be cited.
The risk file is the deliverable
Whichever guidance you follow, Article 9 is assessed on a per-system risk file. The management system that keeps those files current is the part worth building once.
Not sure where you sit?
The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.
Frequently asked
What is ISO/IEC 23894?
ISO/IEC 23894:2023 is an international standard providing guidance on managing risk related to artificial intelligence. It is structured around ISO 31000, the general risk management standard, and adapts its principles, framework and process to AI-specific risk sources. It is guidance rather than a requirements standard, which means organisations cannot be certified against it.
Can you get certified to ISO/IEC 23894?
No. ISO/IEC 23894 is a guidance document, not a requirements specification. There is no accredited certification scheme against it. Organisations seeking a certifiable AI standard use ISO/IEC 42001, which is a management system standard with auditable requirements.
Does ISO/IEC 23894 satisfy Article 9 of the EU AI Act?
No. ISO/IEC 23894 is not a harmonised standard under the AI Act and does not confer Article 40 presumption of conformity.
It is structurally compatible with Article 9 and useful for organising the process, but Article 9 has requirements that generic AI risk guidance does not supply: assessment of risks to health, safety and fundamental rights rather than to the organisation, coverage of reasonably foreseeable misuse, a prescribed hierarchy of risk management measures, and a documented judgement that residual risk is acceptable. CEN-CENELEC JTC 21 is developing prEN 18228 as the European risk management standard for Article 9.
What is the difference between ISO/IEC 23894 and ISO/IEC 42001?
ISO/IEC 23894 gives guidance on how to manage AI risk. ISO/IEC 42001 specifies requirements for an AI management system and is certifiable. They are complementary: 42001 requires an AI risk assessment and treatment process, and 23894 is the guidance most often used to design that process.