Bern, Lisbon, New York info@ai-ei.org +351 93 832 8533
Assessment Platform

ISO/IEC 23894 AI Risk Management Assessment

How mature your practice is from risk identification through analysis, evaluation, treatment and monitoring.

ISO Risk Management 30 questions About 15 minutes Free, no account
Step 1 of 2 Organisation context
Organisation context

This shapes the recommendations you get at the end. Nothing here changes your score.

Please enter your organisation name.

Please enter a valid email address.

Please choose an option.

Please choose an option.

Please choose an option.

Please choose an option.

Choose another framework

Self-assessment only. Not legal advice, not an audit opinion, and not certification.

Readiness questions

Answer all 30 questions as honestly as you can. There are no right or wrong answers; an honest picture produces a useful action plan.

01

Risk Management Framework

01 Is there a documented AI risk management framework or policy endorsed by leadership?

Critical requirement, weight 3

02 Is AI risk management integrated into existing enterprise risk management rather than run in isolation?

Critical requirement, weight 3

03 Are roles, accountabilities, and escalation paths for AI risk clearly assigned?

Critical requirement, weight 3

04 Are risk criteria defined (risk appetite, tolerance levels, and acceptance thresholds) for AI systems?

Critical requirement, weight 3

02

Risk Identification

05 Do you maintain an inventory of AI systems and their intended purposes as a basis for risk identification?

Critical requirement, weight 3

06 Are AI-specific risk sources systematically identified (data quality, bias, model drift, opacity, misuse, security)?

Critical requirement, weight 3

07 Are risks to individuals, groups, and society identified — not only risks to the organisation?

Critical requirement, weight 3

08 Are risks identified at each lifecycle stage (design, development, deployment, operation, retirement)?

Important requirement, weight 2

03

Risk Analysis

09 Are likelihood and consequences of identified AI risks analysed using a defined method?

Critical requirement, weight 3

10 Does risk analysis consider the level of automation and the potential for harm from incorrect outputs?

Important requirement, weight 2

11 Are interdependencies analysed between AI systems and other systems, data sources, or third parties?

Important requirement, weight 2

12 Is uncertainty (limited explainability, emergent behaviour) explicitly considered in AI risk analysis?

Important requirement, weight 2

04

Risk Evaluation

13 Are analysed risks compared against your defined risk criteria to decide on treatment priorities?

Critical requirement, weight 3

14 Are decisions to accept AI risks documented and approved at the appropriate management level?

Critical requirement, weight 3

15 Are ethical and societal considerations included in risk evaluation, beyond financial impact?

Important requirement, weight 2

05

Risk Treatment

16 Are risk treatment plans documented for significant AI risks, with owners and deadlines?

Critical requirement, weight 3

17 Are technical controls implemented as treatments (testing, monitoring, guardrails, fallback mechanisms)?

Critical requirement, weight 3

18 Are organisational controls implemented as treatments (approval gates, human oversight, training)?

Important requirement, weight 2

19 Is residual risk after treatment assessed and formally accepted?

Important requirement, weight 2

06

Monitoring and Review

20 Are AI risks and controls monitored on an ongoing basis, including model performance and drift?

Critical requirement, weight 3

21 Are risk assessments reviewed and updated when AI systems, data, or context change materially?

Critical requirement, weight 3

22 Are indicators or thresholds defined that trigger re-assessment or escalation of AI risks?

Important requirement, weight 2

23 Are incidents and near-misses fed back into the risk process to update assessments?

Important requirement, weight 2

07

Recording and Reporting

24 Is an AI risk register maintained and kept current?

Critical requirement, weight 3

25 Are AI risk reports provided to management and governance bodies at planned intervals?

Important requirement, weight 2

26 Is the rationale for key risk decisions documented and traceable?

Important requirement, weight 2

08

Communication and Consultation

27 Are internal stakeholders consulted during AI risk assessments (legal, security, data, business owners)?

Important requirement, weight 2

28 Are external stakeholders (users, customers, regulators) considered or consulted where appropriate?

Important requirement, weight 2

29 Is relevant risk information communicated to those who operate or are affected by AI systems?

Important requirement, weight 2

30 Is there a channel for staff and users to raise AI risk concerns, with follow-up?

Important requirement, weight 2

Results are generated instantly. Self-assessment only, not an audit.