The ISO 31000 backbone

Lesson 1 of 5 in AI Risk Management and Impact Assessment: ISO/IEC 23894 and 42005.

Before AI risk management existed, risk management existed — and ISO decided not to reinvent it. ISO/IEC 23894:2023, the AI risk management standard, is deliberately a thin layer over ISO 31000:2018, the generic risk management standard that banks, hospitals, and mining companies have used for years. To read 23894 fluently, you first need the 31000 skeleton it hangs on.

ISO 31000 is built from three interlocking parts. Principles state what risk management is for: the creation and protection of value — pursued through eight qualities (integrated into everything, structured and comprehensive, customised, inclusive of stakeholders, dynamic, built on the best available information, aware of human and cultural factors, continually improving). The framework is the organisational scaffolding — leadership and commitment at the centre, surrounded by a cycle of integration, design, implementation, evaluation, and improvement. If clause language sounds familiar, it should: this is the same PDCA logic your AIMS runs on. The process is the part practitioners live in day to day, and the part 23894 spends most of its pages adapting.

The ISO 31000 risk management process — the skeleton 23894 adapts for AI

  1. Communication & consultation

    Runs continuously alongside every step: stakeholders inside and outside the organisation inform and are informed. For AI, 23894 stresses consulting parties affected by the system, not just parties who own it.

  2. Scope, context, criteria

    Define what is being assessed, the internal/external context, and the risk criteria — the scales and thresholds against which risk will be judged. The AI twist: criteria must capture harm to individuals and society, not just organisational loss.

  3. Risk identification

    Find, recognise, and describe risks. 23894 supplies AI-specific risk sources (Annex B) and lifecycle hooks (Annex C) so identification is systematic, not inspired.

  4. Risk analysis

    Understand each risk’s nature: likelihood, consequences, existing controls. AI complications: opaque causality, feedback loops, and failure modes that emerge only at scale or over time.

  5. Risk evaluation

    Compare analysed risk against the criteria: acceptable as-is, or does it need treatment? This is where risk appetite becomes a decision, recorded and owned.

  6. Risk treatment

    Select and implement options — avoid, modify, share, retain — then assess the residual risk and decide whether it is acceptable. In 42001, this step also produces the Statement of Applicability.

  7. Monitoring & review

    Check that treatments work and that the risk picture has not shifted — for AI, this is where drift detection and incident data feed back in.

  8. Recording & reporting

    The risk register, assessment reports, and escalation lines. Evidence for auditors, memory for the organisation.

Note the vocabulary discipline, because exam questions and auditors both trade on it. Risk assessment is the umbrella for exactly three steps: identification (find it), analysis (understand it), evaluation (judge it against criteria). Risk treatment is a separate, subsequent activity. People who say ‘risk assessment’ when they mean the whole process — or ‘we assessed the risk’ when they only identified it — write risk registers that fall apart under questioning.

And one definitional stake in the ground: ISO 31000 defines risk as the effect of uncertainty on objectives — not ‘bad things that might happen’. Effects can be positive or negative, and risk only exists relative to objectives. That is why 23894 leads you through AI-related objectives (Annex A) before it hands you risk sources: no objectives, no coherent risks.

Key terms: risk, risk assessment, risk treatment, risk criteria, risk register

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.