---
title: "ISO/IEC 23894, Definition | MedTech Terms"
description: "Guidance on AI-specific risk management for organizations developing or using AI systems. Plain-English Standards definition for MedTech teams, with examples an"
lang: en
json-ld: |
  {
    "@context": "https://schema.org",
    "@graph": [
      {
        "@type": "DefinedTerm",
        "@id": "https://medtechterms.com/terms/iso-iec-23894#term",
        "name": "ISO/IEC 23894",
        "description": "ISO/IEC 23894:2023 provides AI-specific guidance on risk management aligned with ISO 31000, addressing risks unique to AI such as bias, opacity, data drift, and autonomy.",
        "url": "https://medtechterms.com/terms/iso-iec-23894",
        "termCode": "iso-iec-23894",
        "inDefinedTermSet": {
          "@type": "DefinedTermSet",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com/terms"
        }
      },
      {
        "@type": "Article",
        "@id": "https://medtechterms.com/terms/iso-iec-23894#article",
        "headline": "ISO/IEC 23894",
        "description": "Guidance on AI-specific risk management for organizations developing or using AI systems.",
        "url": "https://medtechterms.com/terms/iso-iec-23894",
        "mainEntityOfPage": {
          "@type": "WebPage",
          "@id": "https://medtechterms.com/terms/iso-iec-23894"
        },
        "about": {
          "@id": "https://medtechterms.com/terms/iso-iec-23894#term"
        },
        "articleSection": "Standards",
        "inLanguage": "en",
        "keywords": "ISO/IEC 23894, Standards, medical device, MedTech",
        "author": {
          "@type": "Person",
          "name": "Christian Espinosa",
          "jobTitle": "Founder, Blue Goat Cyber",
          "url": "https://bluegoatcyber.com"
        },
        "publisher": {
          "@type": "Organization",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "isPartOf": {
          "@type": "WebSite",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "datePublished": "2026-05-05",
        "dateModified": "2026-05-05",
        "citation": [
          {
            "@type": "CreativeWork",
            "name": "ISO/IEC 23894:2023",
            "url": "https://www.iso.org/standard/77304.html",
            "publisher": {
              "@type": "Organization",
              "name": "ISO"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "ISO Standards Catalogue - Health",
            "url": "https://www.iso.org/ics/11/x/",
            "publisher": {
              "@type": "Organization",
              "name": "ISO"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "IEC Webstore - Medical Equipment",
            "url": "https://webstore.iec.ch/searchform&q=medical",
            "publisher": {
              "@type": "Organization",
              "name": "IEC"
            }
          }
        ],
        "mentions": [
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/iso-14971#term",
            "name": "ISO 14971",
            "url": "https://medtechterms.com/terms/iso-14971"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/eu-ai-act#term",
            "name": "EU AI Act",
            "url": "https://medtechterms.com/terms/eu-ai-act"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/ai-ml-device#term",
            "name": "AI/ML-Enabled Medical Device",
            "url": "https://medtechterms.com/terms/ai-ml-device"
          }
        ]
      },
      {
        "@type": "BreadcrumbList",
        "itemListElement": [
          {
            "@type": "ListItem",
            "position": 1,
            "name": "Home",
            "item": "https://medtechterms.com/"
          },
          {
            "@type": "ListItem",
            "position": 2,
            "name": "Terms",
            "item": "https://medtechterms.com/terms"
          },
          {
            "@type": "ListItem",
            "position": 3,
            "name": "Standards",
            "item": "https://medtechterms.com/terms?cat=Standards"
          },
          {
            "@type": "ListItem",
            "position": 4,
            "name": "ISO/IEC 23894",
            "item": "https://medtechterms.com/terms/iso-iec-23894"
          }
        ]
      },
      {
        "@type": "FAQPage",
        "@id": "https://medtechterms.com/terms/iso-iec-23894#faq",
        "mainEntity": [
          {
            "@type": "Question",
            "name": "How does ISO/IEC 23894 relate to ISO 14971 for medical AI?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "ISO/IEC 23894 provides guidance on AI-specific risks like bias and opacity, while ISO 14971 focuses on risks related to patient harm from medical devices. For medical AI, both standards are critical, with ISO 14971 addressing patient safety and ISO/IEC 23894 expanding to broader AI system and organizational risks."
            }
          },
          {
            "@type": "Question",
            "name": "What types of risks does ISO/IEC 23894 primarily address?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "It specifically addresses risks unique to AI systems, including algorithmic bias, data quality issues leading to drift, the inherent opacity of some AI models, and risks arising from autonomous operation. These risks extend beyond traditional medical device hazards."
            }
          },
          {
            "@type": "Question",
            "name": "Is ISO/IEC 23894 mandatory for AI in MedTech?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "While not explicitly mandated in all regulations, its principles are increasingly relevant, especially for demonstrating conformity with general safety and performance requirements for AI-powered medical devices. It is particularly helpful for narrative conformity under emerging regulations like the EU AI Act, which emphasizes trustworthy AI."
            }
          }
        ]
      }
    ]
  }
---

[

MedTech Terms

The authoritative reference



](/)

Browse

Learn

[Latest](/latest)

About

1.  [Home](/)
2.  /
3.  [Terms](/terms)
4.  /
5.  [Standards](/terms?cat=Standards)
6.  /
7.  ISO/IEC 23894

[All terms](/terms)

Standards [AI / ML in Devices](/ecosystems/ai-ml)[Quality System](/ecosystems/quality-system)

# ISO/IEC 23894

Guidance on AI-specific risk management for organizations developing or using AI systems.

Reviewed by [Christian Espinosa, Founder, Blue Goat Cyber](/authors/christian-espinosa) Last reviewed May 5, 2026 

## Definition

ISO/IEC 23894:2023 provides AI-specific guidance on risk management aligned with  [ISO 31000](/terms/iso-31000), addressing risks unique to AI such as bias, opacity, data drift, and autonomy. 

What the regulation says

ISO/IEC 23894:2023 offers specific guidance for managing risks associated with artificial intelligence systems, complementing general risk management principles outlined in  [ISO 31000](/terms/iso-31000). It addresses AI-specific risks such as algorithmic bias, lack of transparency (opacity), data drift, and autonomous decision-making, which are crucial considerations for regulatory bodies like the European Commission in the context of the  [EU AI Act](/terms/eu-ai-act). 

## What this means in practice

Often used alongside  [ISO 14971](/terms/iso-14971) for medical AI: 14971 covers patient harm; 23894 broadens to organizational and AI-system risks. Helpful for  [EU AI Act](/terms/eu-ai-act) conformity narratives. 

## Examples

-   A medical device manufacturer uses ISO/IEC 23894:2023 to identify and mitigate risks associated with an AI-powered diagnostic tool, such as potential diagnostic bias across different demographic groups.
-   During the development of an AI-driven surgical robot, the development team applies ISO/IEC 23894:2023 principles to assess and manage risks related to the AI system's autonomous decision-making in unforeseen scenarios.
-   A company developing an AI algorithm for predictive analytics in patient care utilizes ISO/IEC 23894:2023 to address risks of data drift that could lead to decreased accuracy over time and implement continuous monitoring strategies.

Common pitfalls

-   • A common pitfall is to apply ISO/IEC 23894:2023 in isolation, neglecting essential medical device risk management standards such as ISO 14971:2019. 
-   • Organizations may mistakenly believe that addressing AI-specific risks under ISO/IEC 23894:2023 fully covers all safety and performance requirements for medical AI. 
-   • Failing to integrate the risk management processes outlined in ISO/IEC 23894:2023 with the overall quality management system, as required by standards like 21 CFR Part 820, can lead to compliance gaps. 
-   • Overlooking the need for continuous monitoring and post-market surveillance of AI systems to detect and mitigate emerging risks not identified during initial risk assessment is a significant oversight. 
-   • Another pitfall is to narrowly interpret "risk" solely as patient harm, ignoring financial, reputational, or societal risks that ISO/IEC 23894:2023 aims to address. 

## Frequently asked questions

How does ISO/IEC 23894 relate to ISO 14971 for medical AI? 

ISO/IEC 23894 provides guidance on AI-specific risks like bias and opacity, while  [ISO 14971](/terms/iso-14971) focuses on risks related to patient harm from medical devices. For medical AI, both standards are critical, with ISO 14971 addressing patient safety and ISO/IEC 23894 expanding to broader AI system and organizational risks. 

What types of risks does ISO/IEC 23894 primarily address? 

Is ISO/IEC 23894 mandatory for AI in MedTech? 

## Cross-references

### Overlaps with

Covers some of the same ground; not interchangeable.

-   [
    
    ISO 14971
    
    
    
    ](/terms/iso-14971)

## Related terms

Grouped by theme 

### Editor's picks

· Hand-selected related concepts 

[

Standards

ISO 14971

International standard for the application of risk management to medical devices.





](/terms/iso-14971)[

Software & AI

AI/ML-Enabled Medical Device

Medical device that uses artificial intelligence or machine learning to perform its intended use.





](/terms/ai-ml-device)[

Software & AI

EU AI Act

EU regulation establishing risk-based requirements for AI systems, including most medical AI.





](/terms/eu-ai-act)

### More in Standards

· Same category 

[

Standards

ASTM F2503

Standard practice for marking medical devices and other items for safety in the magnetic resonance environment.





](/terms/astm-f2503)[

Standards

Essential Performance

Performance of a clinical function whose loss or degradation would result in unacceptable risk.





](/terms/essential-performance)[

Standards

ICH E6(R3) Good Clinical Practice(E6(R3)) 

Revision 3 of the ICH Good Clinical Practice guideline, restructured around principles, modernized for risk-based and decentralized trials, finalized in 2023.





](/terms/ich-e6-r3)[

Standards

IEC 60601-1

General requirements for basic safety and essential performance of medical electrical equipment.





](/terms/iec-60601-1)

Cited by

Where this term appears across MedTech Terms.

Ecosystems (2)

-   [AI / ML in Devices](/ecosystems/ai-ml)
-   [Quality System](/ecosystems/quality-system)

## Primary references

3 sources 

Link health:  3 verified · last checked 2026-06-20 

ISO· 2 IEC· 1 

1.  [1 
    
    ISO/IEC 23894:2023
    
    Verified 
    
    ISO · iso.org 
    
    
    
    ](https://www.iso.org/standard/77304.html)
2.  [2 
    
    ISO Standards Catalogue - Health
    
    Verified 
    
    ISO · iso.org 
    
    
    
    ](https://www.iso.org/ics/11/x/)
3.  [3 
    
    IEC Webstore - Medical Equipment
    
    Verified 
    
    IEC · webstore.iec.ch 
    
    
    
    ](https://webstore.iec.ch/searchform&q=medical)

Inline markers like \[1\]  jump to the matching reference above.

Sponsor note

### Implementing this standard on a device program?

Blue Goat Cyber helps MedTech teams operationalize cybersecurity standards across the design and post-market lifecycle.

[Book a 30-minute discovery session](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

-   No obligation
-   Expert-led from minute one
-   NDA available on request

MedTech Terms is a community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com). Definitions are independent of any vendor.

On this term

Category

Standards

Sources

3

Updated

5/5/2026

[Compare with another term](/compare?a=iso-iec-23894)

Learn in 60 seconds

Card Lesson Quiz

Guidance on AI-specific risk management for organizations developing or using AI systems.

-   · Often used alongside ISO 14971 for medical AI: 14971 covers patient harm; 23894 broadens to organizational and AI-system risks. 
-   · Helpful for EU AI Act conformity narratives. 

Remember this

Watch out: A common pitfall is to apply ISO/IEC 23894:2023 in isolation, neglecting essential medical device risk management standards such as ISO 14971:2019.

Related terms

-   [ISO 14971 ](/terms/iso-14971)
-   [EU AI Act ](/terms/eu-ai-act)
-   [AI/ML-Enabled Medical Device ](/terms/ai-ml-device)

You may also need

Auto-suggested from Standards and shared keywords.

-   [ISO/TR 24971 ](/terms/tr24971)
-   [Threat Modeling ](/terms/threat-modeling)
-   [ICH E6(R3) Good Clinical Practice(E6(R3)) ](/terms/ich-e6-r3)
-   [HSCC Joint Security Plan(HSCC JSP) ](/terms/hscc-jsp)
-   [ISO 31000 ](/terms/iso-31000)
-   [Premarket Cybersecurity Submission ](/terms/premarket-cybersecurity)

[All Standards terms](/terms?cat=Standards)

From the Blue Goat network

Related resources and services on this topic.

-   [
    
    MedTech Cybersecurity Standards 
    
    Authoritative reference for the standards and guidances behind medical device cybersecurity.
    
    ](https://medtechcyberstandards.com)
-   [
    
    MedTech Cybersecurity Crosswalk 
    
    International crosswalk of medical device cybersecurity requirements across regulators.
    
    ](https://mdccrosswalk.com)

MedTech Terms 

An authoritative, plain-language reference for the regulatory, quality, cybersecurity, and software terms that shape modern medical devices.

Browse

-   [All terms](/terms)
-   [A–Z index](/a-z)
-   [Categories](/categories)
-   [Ecosystems](/ecosystems)
-   [Learning paths](/paths)
-   [Compare terms](/compare)
-   [Quiz](/quiz)

Resources

-   [FDA Medical Devices](https://www.fda.gov/medical-devices)
-   [EU MDR](https://eur-lex.europa.eu/eli/reg/2017/745/oj)
-   [IMDRF](https://www.imdrf.org/)
-   [Methodology](/methodology)
-   [Changelog](/changelog)
-   [Editor: Christian Espinosa](/authors/christian-espinosa)
-   [About this site](/about)

© 2026 MedTech Terms. Reference content for educational purposes - not regulatory advice. A community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com)