ISO/IEC 23894:2023 — Gestión de riesgos de IA
standardISO/IEC 23894:2023 es una norma internacional que ofrece orientación sobre cómo gestionar los riesgos a los que se enfrentan las organizaciones que desarrollan, ofrecen, implementan o utilizan sistemas de IA.
Technical explanation
The standard adapts risk-management principles to AI by addressing organisational context, lifecycle activities, stakeholders, sources of risk, assessment, treatment, communication, monitoring, and review. It is guidance rather than a certifiable requirements standard and is intended to integrate with broader risk-management practices.
Business relevance
ISO/IEC 23894 gives organisations a common structure for connecting AI-specific technical and societal concerns with enterprise risk governance and accountable decisions.
Implementation example
A provider uses the standard to identify risks across data, model, integration, user interaction, and post-deployment monitoring, then assigns treatments and residual-risk owners.
Limitations and common misconceptions
The standard does not prescribe universal controls or establish that residual risk is acceptable. It must be adapted to the system, stakeholders, legal context, and organisational risk criteria.
Temas
Sources
Discuss your systems
Need help implementing or evaluating this concept? Keenfunnel designs connected AI, automation, and data systems.
Reserva una sesión de descubrimiento