ISO 31000:2018 – Risk Management – Guidelines provides high-level principles and a generic framework for identifying, assessing, and mitigating risks — including those emerging from AI systems.
While ISO/IEC 27005 focuses on information security risk (related to ISO/IEC 27001), ISO 31000 is broader and commonly adopted by organizations for all types of operational and strategic risk management — including ethical, legal, and technical AI risks.
ISO/IEC 42001 references ISO 31000 as the baseline standard for managing AI-related risks.
Option C (ISO/IEC 23895) is not an officially recognized ISO standard as of the current publication.
[Reference:, , * ISO 31000:2018 – Clause 5–8 (Principles, Framework, Process), * ISO/IEC 42001:2023, Clause 6.1.2 – Risk-based thinking and alignment with ISO 31000, * PECB AI Lead Auditor Guide – Chapter 5.2 – Risk identification and treatment, , \===========, ]
Submit