ISO 42001 vs ISO 23894: which standard do you need for AI risk management?

Compliance8 min read·
K

Kees van der Vlies

Partner | IT Auditor

Also available in:Nederlands

Organisations setting up their AI risk management quickly encounter two standards that appear to do the same thing: ISO/IEC 42001 and ISO/IEC 23894. Both come from the same ISO committee, both address artificial intelligence and both have risk at their core. Yet they are fundamentally different documents, and confusing the two leads to wrong expectations in practice. We regularly get asked whether an organisation can be certified against ISO 23894. The answer is no, and explaining why immediately reveals the difference.

## What is ISO/IEC 42001?

ISO/IEC 42001 is a management system standard, published at the end of 2023. It defines the requirements for an AI management system (AIMS): the combination of policies, processes, roles and controls through which an organisation governs the development and use of AI. The standard follows the familiar harmonized structure also used by ISO 27001 and ISO 9001, with clauses on context, leadership, planning, support, operation, evaluation and improvement, complemented by an Annex A full of controls.

Its defining characteristic: ISO 42001 is certifiable. An accredited certification body can assess whether the management system meets the requirements and issue a certificate. That certificate provides customers, regulators and partners with demonstrable evidence of AI governance.

## What is ISO/IEC 23894?

ISO/IEC 23894 is a guidance document, published in early 2023. It provides guidance on managing AI-related risks and builds on ISO 31000, the general standard for risk management. ISO 23894 takes the familiar risk process from ISO 31000 (establishing context, identifying, analysing, evaluating and treating risks) and translates it to the specific characteristics of AI. Its annexes are the most practical part: they describe AI-specific risk sources and objectives, such as the complexity of the environment a system operates in, the level of automation, training data quality, transparency and explainability.

ISO 23894 contains no requirements, only recommendations. There is nothing to certify against. It is a handbook for the risk professional, not an assessment framework for an auditor.

## The core difference in one sentence

ISO 42001 tells you what management system to establish and requires you to assess and treat AI risks; ISO 23894 helps you with how to perform that risk assessment well. Anyone familiar with information security will recognise the pattern immediately: ISO 42001 relates to ISO 23894 the way ISO 27001 relates to ISO 27005. One standard sets the requirement, the other provides the method.

## How the two standards work together

In an ISO 42001 implementation, the interplay becomes concrete in the planning phase. Clause 6 of ISO 42001 requires the organisation to perform an AI risk assessment, define risk acceptance criteria and draw up a risk treatment plan. However, the standard does not tell you which risk sources to consider or how to analyse AI risks. That is exactly where ISO 23894 adds value.

An approach we apply in practice: use the risk sources from the annexes of ISO 23894 as a checklist when building the AI risk register. Think of data quality and bias, lack of transparency, the degree to which a system decides autonomously, the predictability of model behaviour after updates, and misuse by malicious actors. Systematically walking through these sources per AI system prevents the risk assessment from getting stuck in generic IT risks. The outcomes then land in the risk treatment plan of the AIMS, where they are linked to the controls from Annex A of ISO 42001.

For impact assessments on individuals and society there is also ISO/IEC 42005, which specifically covers AI impact assessments. The three documents complement each other: 42001 as the framework, 23894 for the risk process, 42005 for the impact analysis.

## When do you choose which standard?

The choice depends on the objective. Does the organisation want demonstrable AI governance, for example because customers ask for it, procurement processes test for it, or the EU AI Act demands accountability? Then ISO 42001 is the logical goal, because only that standard comes with a certificate. Does the organisation primarily want to improve the quality of its AI risk analyses, for example as part of an existing ERM programme, without certification ambitions? Then ISO 23894 suffices as guidance.

In practice it is rarely either-or. Virtually every serious ISO 42001 implementation uses ISO 23894 implicitly or explicitly as the methodological foundation of the risk assessment. Conversely, an organisation that only follows ISO 23894 has no mechanism to demonstrate the effectiveness of its risk management to third parties.

## Common mistakes

The first mistake we already mentioned: assuming ISO 23894 is certifiable and promising that in proposals or customer communication. The second mistake is treating AI risk as a subset of information security risk. Bias, lack of explainability and undesirable model outcomes are not security incidents, and a risk register that only tracks confidentiality, integrity and availability will structurally miss them. The third mistake is organising duplicate work: a separate AI risk register next to the existing risk register, with its own scales and its own owners, so that nobody retains the overall picture. Integrate AI risks into the existing risk management cycle and tag them as AI-related. The fourth mistake is assuming that following these standards automatically delivers EU AI Act compliance. The standards demonstrably help, but the regulation sets its own specific requirements per risk category that need to be assessed separately.

## Conclusion

ISO 42001 and ISO 23894 are not competitors but complementary instruments. One builds the house (a certifiable management system), the other supplies the tools for one of its most important rooms (the risk process). Organisations starting with AI governance are well advised to take ISO 42001 as the framework and use ISO 23894 wherever the risk process needs substantive depth.

Frequently asked questions

Can you get certified against ISO 23894?+

No. ISO 23894 is guidance without requirements and therefore without an assessment framework. Certification of AI governance runs through ISO 42001, which is a requirements-based management system standard.

Do I need ISO 23894 for an ISO 42001 certification?+

No, the certification audit assesses against ISO 42001. But ISO 23894 is a valuable methodological foundation for the risk assessment that ISO 42001 requires, and using it makes that assessment demonstrably more thorough.

What is the relationship between ISO 23894 and ISO 31000?+

ISO 23894 builds on ISO 31000, the general risk management standard, and translates that process to AI-specific risk sources and considerations. Organisations already using ISO 31000 can adopt ISO 23894 alongside it with relative ease.

Does ISO 42001 plus ISO 23894 cover the EU AI Act?+

Not automatically. The standards form a strong basis for the governance and risk management obligations, but the EU AI Act sets its own requirements per risk category, such as technical documentation and human oversight for high-risk systems. Assess those requirements separately.

Where does ISO 42005 fit in?+

ISO 42005 provides guidance for AI impact assessments: evaluating consequences for individuals and society. It complements ISO 23894, which primarily reasons from organisational risk.

Need help with compliance?

Need to comply with ISO 27001, ISO 42001, NEN 7510, NIS2 or DORA, or do you need a SOC 2 report? We guide you through the entire process: from gap analysis to implementation.

Explore Compliance Services

About the author

K
Kees van der Vlies

Partner | IT Auditor

Back to knowledge base

Have a question?

Get in touch for advice on IT audit, compliance and information security.

Contact us