ISO/IEC 23894 (framework self-assessment) v0.1.0
framework-iso23894 · 1 sections
Metadata
Scales, categories & audiences
Scales: maturity5 (5 levels) · Categories: process sources · Audiences: lead owner exec
Edit these in the raw JSON editor below — they change rarely and carry structure (levels, signals, deep-dive wiring) that a form would mangle.
23894 elements core
Everyone answers these. The enterprise risk owner (whoever runs the ISO 31000 process), the AI or data lead, and whoever keeps the AI risk register. Add the 42001 lead if certification is the goal.
| Id | Question | Type | Category | Scale | |
|---|---|---|---|---|---|
| p-consult | When you last looked at the risks of an AI system, who did you talk to outside the project, and what had you decided counted as too risky before you started? | scored_text · scored | process | maturity5 | |
| p-identify | Take one AI system you run. What could go wrong with it that could not go wrong with ordinary software, and where is that written down? | scored_text · scored | process | maturity5 | |
| p-analyse | For a risk you rated on an AI system, how did you rate it when the same input can give a different answer tomorrow, and who decided it was acceptable? | scored_text · scored | process | maturity5 | |
| p-treat | Pick one AI risk you have done something about. What did you do, what risk is left over now, and who signed off that the leftover is fine? | scored_text · scored | process | maturity5 | |
| p-monitor | When did you last go back and look at the risks of an AI system that has been live for a while, and what made you look: a date, an incident, or a change? | scored_text · scored | process | maturity5 | |
| p-record | If an auditor asked tomorrow to see how you decided an AI system was safe enough to run, what would you hand over, and how long would it take to find? | scored_text · scored | process | maturity5 | |
| s-data | For one AI system, where does its data come from, how do you know it is still good, and what would tell you if it had quietly changed? | scored_text · scored | sources | maturity5 | |
| s-model | Can you explain to the person affected why this system gave the answer it gave, and what happens to that answer when the input is slightly unusual? | scored_text · scored | sources | maturity5 | |
| s-use | Who is meant to check this system’s output before it counts, do they actually do it, and is the system now being used for anything it was not set up for? | scored_text · scored | sources | maturity5 | |
| s-supply | Which of your AI comes from a vendor, how would you find out if they changed the model underneath you, and what happens to the system when you stop using it? | scored_text · scored | sources | maturity5 |
+ Add question to “23894 elements”
Add section
Advanced — raw JSON
Full pack document, validated on save (schema yarn-pack/2). This is where scales, audiences, structured conditions and adaptive config live.