Where ISO/IEC 42005 and ISO/IEC 23894 Fit Alongside 42001

Lesson concept diagram

ISO 42001 is not the only ISO standard for AI. As of January 2026, two other standards exist or are under development: ISO/IEC 42005 and ISO/IEC 23894. Understanding how these fit together will help you know when to use which standard.

ISO/IEC 23894 is titled “Information technology / Artificial intelligence / AI risk management.” It was published in 2023, before ISO 42001. ISO 23894 is focused on risk management specifically. It sets out a process for identifying, analysing and treating risks from AI systems. If you want detailed guidance on how to conduct an AI risk assessment, ISO 23894 is the standard to read. ISO 23894 says things like: what sources of information should you look at when identifying risks? How should you think about the likelihood and impact of each risk? How should you prioritise which risks to address first? How should you document your risk assessment so that others can understand it?

ISO 42001 assumes you are doing AI risk management and refers to ISO 23894 for the detailed approach. Clause 6 of ISO 42001 says you should conduct risk assessments, and in the notes section it points to ISO 23894 as a source of guidance on how to do that. So the relationship is this: ISO 42001 says “you must do risk assessment.” ISO 23894 says “here is how to do it well.”

Many organisations use both standards together. They use ISO 42001 as their overall management system standard and ISO 23894 as their risk assessment methodology. This is a sensible combination because ISO 23894 gives you a step-by-step process for risk management and ISO 42001 puts that risk management into the context of a complete governance system.

ISO/IEC 42005 is titled “Artificial intelligence / Quality based on AI system design and development.” It is still under development as of January 2026, but the working draft is available and many organisations are looking at it. ISO 42005 is focused on quality assurance for AI systems specifically. It is similar to ISO 25010, which is the quality standard for general software products. If ISO 25010 says “software should be reliable,” ISO 42005 says “AI systems should be reliable, and here is what reliability means in the context of AI.”

ISO 42005 goes deep into quality characteristics like accuracy, resilience, fairness and explainability. It asks: what does accuracy mean for your system? How do you measure it? What level of accuracy is acceptable? It asks similar questions about bias, drift and other AI-specific quality concerns. ISO 42005 also gives guidance on model evaluation and model validation.

The relationship between ISO 42001 and ISO 42005 is similar to the relationship between ISO 42001 and ISO 23894. ISO 42001 says “you must have processes for validation and verification of AI systems.” ISO 42005 says “here is what quality means for AI systems and how to check whether your validation and verification processes are adequate.”

In practice, many organisations end up using all three standards together. ISO 42001 is the overall governance framework. ISO 23894 provides the methodology for risk assessment. ISO 42005 provides the methodology for quality assurance and testing. A large organisation with a mature AI programme might train people on all three standards and integrate them into one coherent system.

Clause 12 of ISO 42001 also mentions ISO/IEC 42006, which is the standard for competence of professionals certifying AI management systems. ISO 42006 is important for certification bodies and auditors. If you are choosing which certification body will audit your ISO 42001 compliance, you should check whether the auditors have the competence defined in ISO 42006. ISO 42006 specifies what knowledge and skills an auditor of AI management systems should have.