44% of ISO/IEC 23894:2023 you already have
ISO 37301:2021 already covers about 44% of ISO/IEC 23894:2023, leaving
45 of 80 controls as genuinely new work.
Already covered 10
Likely covered 25
New work 45
What is genuinely new work
Nothing in ISO 37301:2021 reaches these. This is the list to scope.
23894-4.1AI Risk Management Principles
23894-5.3Integration into Organizational Processes
23894-5.4.2AI Risk Management Policy
23894-5.4.4Allocation of Resources
23894-6.3AI Risk Assessment Scope and Criteria
23894-6.4.2AI Risk Identification
23894-6.4.3AI Risk Analysis
23894-6.4.4AI Risk Evaluation
23894-6.5AI Risk Treatment
23894-6.6Monitoring and Review
23894-6.7Recording and Reporting
23894-A.2AI Objectives and Risk Sources
23894-A.3Lifecycle Risk Considerations
23894-A.5Human Oversight Controls
23894-A.6Transparency and Explainability
23894-A.7Data Quality and Provenance
23894-A.8Robustness and Resilience Testing
23894-A.9Third-Party AI Components
ISO23894-4.1Integrated AI Risk Management
ISO23894-4.2Structured and Comprehensive Approach
ISO23894-4.3Customized to AI Context
ISO23894-4.4Inclusive Stakeholder Engagement
ISO23894-4.5Dynamic and Responsive
ISO23894-4.6Best Available Information
ISO23894-4.7Human and Cultural Factors
ISO23894-5.3AI Risk Management Design
ISO23894-5.4AI Risk Management Implementation
ISO23894-5.6Framework Improvement
ISO23894-6.3.2AI Risk Analysis
ISO23894-6.4AI Risk Treatment
ISO23894-6.5Monitoring and Review
ISO23894-6.6Recording and Reporting
ISO23894-A.1Data Quality and Representativeness
ISO23894-A.2Model Transparency and Explainability
ISO23894-A.3Algorithmic Bias and Fairness
ISO23894-A.4AI System Robustness
ISO23894-A.5Privacy and Data Protection in AI
ISO23894-A.7Human Oversight of AI
ISO23894-A.8AI Accountability and Governance
5.4.2Articulating risk management commitment
5.7.2Continually improving
6.3.3External and internal context
6.5.3Preparing and implementing risk treatment plans
6.7Recording and reporting
Show the 35 you already have
23894-5.2Leadership and Commitment
23894-5.4.1Understanding Organization and Context
23894-5.4.3Roles, Authorities, Responsibilities
23894-5.5Communication and Consultation
ISO23894-4.8Continual Improvement
ISO23894-5.1Leadership and Commitment
ISO23894-6.1Communication and Consultation
5.2Leadership and commitment
5.4.1Understanding the organization and its context
6.2Communication and consultation
23894-A.4AI System Impact Assessment
ISO23894-1Scope of AI Risk Management
ISO23894-3AI-Specific Terminology
ISO23894-5.2AI Risk Management Integration
ISO23894-5.5Framework Evaluation
ISO23894-6.2Scope, Context and Criteria
ISO23894-6.3AI Risk Assessment
ISO23894-6.3.1AI Risk Identification
ISO23894-6.3.3AI Risk Evaluation
ISO23894-A.6AI System Security
5.4.3Assigning organizational roles, authorities, responsibilities and
5.4.4Allocating resources
5.4.5Establishing communication and consultation
6.3.4Defining risk criteria
6.5.2Selection of risk treatment options
How this is calculated
Already covered means a mapping runs from a control in ISO 37301:2021 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition