AI Risk Management and Impact Assessment: ISO/IEC 23894 and 42005
How ISO 31000’s risk architecture becomes AI-specific through ISO/IEC 23894, how ISO/IEC 42005:2025 turns impact assessment into a repeatable method, and how the two disciplines — organisational-risk lens and affected-party lens — interlock inside the AIMS and alongside DPIAs and FRIAs.
Content current as of 2026-09.