AI Risk Management and Impact Assessment: ISO/IEC 23894 and 42005

How ISO 31000’s risk architecture becomes AI-specific through ISO/IEC 23894, how ISO/IEC 42005:2025 turns impact assessment into a repeatable method, and how the two disciplines — organisational-risk lens and affected-party lens — interlock inside the AIMS and alongside DPIAs and FRIAs.

Content current as of 2026-09.

Lessons

  1. The ISO 31000 backbone
  2. What 23894 adds: objectives, risk sources, lifecycle hooks
  3. Criteria, identification, and treatment
  4. ISO/IEC 42005: the impact assessment method
  5. Four instruments, one system: risk, impact, DPIA, FRIA