Frameworks / ISO/IEC 23894:2023 / 6.4.1 ISO/IEC 23894:2023
Risk management process – ISO/IEC 23894:2023
ISO/IEC 23894:2023 6.4.1: General Risk assessment covers identification, analysis and evaluation together, done methodically, repeatedly and with stakeholders, using their knowledge and the best information available (ISO 31000:2018, 6.4.1). For AI it is redone whenever the system, its data or its uses change, and it draws on the AI objectives and risk sources of Annexes A and B.
Maintained by Gerard Blokdyk · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 39 controls across 4 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
4.1.1 Overview: governance of IT as a domain of the governance of organizations 4.1.2 Effective performance 4.1.4 Ethical behaviour 4.2 Principles, model and framework 5.1 Overview of the principles 5.10.1 Risk governance: principle 5.11.1 Social responsibility: principle 5.12.1 Viability and performance over time: principle 5.2.1 Purpose: principle 5.2.2 Purpose: governance implications for use of IT 5.3.1 Value generation: principle 5.3.2 Value generation: governance implications for use of IT 5.4.1 Strategy: principle 5.4.2 Strategy: governance implications for use of IT 5.4.3 Strategy: outcomes 5.5.1 Oversight: principle 5.6.1 Accountability: principle 5.6.2 Accountability: governance implications for use of IT 5.7 Stakeholder engagement 5.7.1 Stakeholder engagement: principle 5.7.2 Stakeholder engagement: governance implications for use of IT 5.8 Leadership 5.8.1 Leadership: principle 5.8.2 Leadership: governance implications for use of IT 5.9.1 Data and decisions: principle 5.9.2 Data and decisions: governance implications for use of IT 6.2 Governance of IT practice 6.2.1 Engage stakeholders 6.2.2 Evaluate 6.2.3 Direct 6.2.4 Monitor 6.4 Framework for the governance of IT 7.1 Framework: general 7.2.1 General: the elements 7.2.5 Delegation 8.1.1 General guidance: Operational control Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Risk management process – ISO/IEC 23894:2023 Query this from an agent The graph holds this control, the 39 it maps to, and the evidence behind each claim, over MCP and REST.