InternationalAI governancePublished 2023

AI Risk Management Guidance

The companion risk guidance that pairs with 42001 and ISO 31000 on AI-specific risk.

What we know in this framework.

The specific clauses, articles, appendices and supervisory expectations we work against, anchored to primary source and maintained as the regime evolves.

01AI-specific risk sources
02Risk evaluation criteria
03Treatment options
04Lifecycle integration

How the firm carries ISO/IEC 23894 into client work.

ISO/IEC 23894 is read against the services below. Each one draws on the same compliance intelligence layer — indexed to primary source, versioned alongside the regulator, and carried into the engagement.

This framework is carried through our cross-framework control mapping. Use the contact page for a scoped plan against your portfolio.

Playbooks that ship against ISO/IEC 23894.

Each playbook walks from discovery through artifact, phases, controls, evidence. Agents assist the mechanical steps; specialists own the sign-off.

Map your posture against ISO/IEC 23894.

Bring us your current documentation, controls and inventory. We will map them clause by clause against ISO/IEC 23894, and against every other regime your portfolio touches, and produce the evidence artifact your supervisor will read.