Skip to content
Menu ▾
Patent pending

Regulayer  /  The 146 laws  /  International

ISO/IEC 23894:2023

AI risk management.

Applies to: Organisations managing AI risk.

What the signed record shows

Per-operation evidence of the risk-management process.

The proof is a signed, tamper-evident record. Anyone can check it, free, without an account, and nothing has to leave the building to make it. Evidence, not a promise.

Citation: Clause 6.4.2/6.4.3/6.5/6.6/6.7

In the same family

What to do about it

Seven days free, then $349 a month.

A signed record of which AI you used and what you checked, sealed to the exact file you deliver, made on your own machine and checkable free by anyone you send it to.

Start the free weekOr verify a real record, free →

Part of the Regulayer proof catalogue: 146 laws and standards, one sealed engine. This page is a product description, not legal advice.

What the standard requires, section by section

ISO/IEC 23894:2023, "Information technology, Artificial intelligence, Guidance on risk management". Provides guidance on managing risk related to AI; its risk-management PROCESS (Clause 6) is structured on ISO 31000. The process-stage clauses this mapper evidences from the per-decision signed record:

Clause 6.4.2
Risk identification (the AI system and its risk context are identified for each governed operation).
Clause 6.4.3
Risk analysis (a risk signal/state is recorded at the decision).
Clause 6.5
Risk treatment (a governance treatment action is recorded where a risk is acted upon).
Clause 6.6
Monitoring and review (each operation carries a monitoring record reference for ongoing review).
Clause 6.7
Recording and reporting (the risk-management process is recorded; each operation is recorded in the signed ledger).

Taken from the Regulayer entry for this instrument, which is built against the primary text.