MedTech Terms
    The authoritative reference
    All terms

    ISO/IEC 23894

    Guidance on AI-specific risk management for organizations developing or using AI systems.

    Reviewed by Christian Espinosa, Founder, Blue Goat CyberLast reviewed May 5, 2026

    Definition

    ISO/IEC 23894:2023 provides AI-specific guidance on risk management aligned with ISO 31000, addressing risks unique to AI such as bias, opacity, data drift, and autonomy.
    What the regulation says
    ISO/IEC 23894:2023 offers specific guidance for managing risks associated with artificial intelligence systems, complementing general risk management principles outlined in ISO 31000. It addresses AI-specific risks such as algorithmic bias, lack of transparency (opacity), data drift, and autonomous decision-making, which are crucial considerations for regulatory bodies like the European Commission in the context of the EU AI Act.

    What this means in practice

    Often used alongside ISO 14971 for medical AI: 14971 covers patient harm; 23894 broadens to organizational and AI-system risks. Helpful for EU AI Act conformity narratives.

    Examples

    • A medical device manufacturer uses ISO/IEC 23894:2023 to identify and mitigate risks associated with an AI-powered diagnostic tool, such as potential diagnostic bias across different demographic groups.
    • During the development of an AI-driven surgical robot, the development team applies ISO/IEC 23894:2023 principles to assess and manage risks related to the AI system's autonomous decision-making in unforeseen scenarios.
    • A company developing an AI algorithm for predictive analytics in patient care utilizes ISO/IEC 23894:2023 to address risks of data drift that could lead to decreased accuracy over time and implement continuous monitoring strategies.
    Common pitfalls
    • A common pitfall is to apply ISO/IEC 23894:2023 in isolation, neglecting essential medical device risk management standards such as ISO 14971:2019.
    • Organizations may mistakenly believe that addressing AI-specific risks under ISO/IEC 23894:2023 fully covers all safety and performance requirements for medical AI.
    • Failing to integrate the risk management processes outlined in ISO/IEC 23894:2023 with the overall quality management system, as required by standards like 21 CFR Part 820, can lead to compliance gaps.
    • Overlooking the need for continuous monitoring and post-market surveillance of AI systems to detect and mitigate emerging risks not identified during initial risk assessment is a significant oversight.
    • Another pitfall is to narrowly interpret "risk" solely as patient harm, ignoring financial, reputational, or societal risks that ISO/IEC 23894:2023 aims to address.

    Frequently asked questions

    ISO/IEC 23894 provides guidance on AI-specific risks like bias and opacity, while ISO 14971 focuses on risks related to patient harm from medical devices. For medical AI, both standards are critical, with ISO 14971 addressing patient safety and ISO/IEC 23894 expanding to broader AI system and organizational risks.

    Cross-references

    Overlaps with

    Covers some of the same ground; not interchangeable.

    Grouped by theme

    Primary references

    3 sources
    Link health: 3 verified· last checked 2026-06-20
    ISO·2IEC·1
    1. 1
      ISO/IEC 23894:2023
      Verified
      ISOiso.org
    2. 2
      ISO Standards Catalogue - Health
      Verified
      ISOiso.org
    3. 3
      IEC Webstore - Medical Equipment
      Verified
      IECwebstore.iec.ch

    Inline markers like [1] jump to the matching reference above.