Comply · International standards
ISO/IEC 23894:2023 — AI risk management
Guidance on AI risk management.
ISO/IEC 23894:2023 provides guidance on managing risk related to AI, adapting the ISO 31000 risk-management approach to the AI context. It describes how to integrate AI risk management into organizational processes throughout the AI lifecycle.
Who it applies to
Organizations building an AI risk-management practice, often as a complement to ISO/IEC 42001.
Key obligations
- Integrate AI risk management into organizational processes
- Identify, analyze, evaluate, and treat AI risks
- Monitor and review risks across the lifecycle
- Document risk decisions
How Maetra maps agents to ISO/IEC 23894
Maetra records AI risk identification, treatment, and monitoring per agent, giving a lifecycle risk trail aligned to the guidance. (Licensed standard — activated on demand.)
In practice, Maetra:
- Scans and fingerprints each agent. Discover reads the agent’s code — its tools, data access and sensitivity, actions, model, and environment — into an evidence-backed profile tied to the exact file and commit.
- Decides what applies. That profile determines whether ISO/IEC 23894 is in scope for the agent and which of its requirements apply.
- Auto-detects controls and surfaces gaps. Controls your code already satisfies are detected automatically from the scan; the rest become a clear list of gaps, each tied to the requirement and the evidence it still needs.
- Proves it and keeps it current. Close gaps with linked evidence or generated documents — reused across every framework the same control supports — and Maetra re-checks on each rescan and flags evidence that has gone stale.
Related frameworks
Prove ISO/IEC 23894 compliance with Maetra
Classify your AI agents once and Maetra maps them to ISO/IEC 23894 and every other framework it supports — generating the evidence and documentation, tracking gaps and deadlines, and sealing every decision in an immutable audit trail.