STALE MEASUREMENTPast this project's own 2-release window: the published result was measured with v0.32.0, 9 releases ago. Why, and what unblocks it

ProductEvidenceTop 10LeaderboardCompliancePricingDocsStar on GitHub Quickstart
ISO/IEC 23894:2023

ISO/IEC 23894:2023

ISO/IEC 23894:2023 applies ISO 31000 risk-management practice to AI, and its hard part is the one every team hits first: naming the risks that actually apply to your system. Provael contributes to exactly that step - The EAI taxonomy as the mapped AI-risk context and the measured rate per risk as risk-assessment input to the AI risk-management process

Published 6 February 2023. Guidance on managing AI risk - it is not certifiable, and it does not tell you which risks to carry.Evidence, not certification.
What it is

The framework

  • Guidance for organisations that develop, produce, deploy or use AI, on managing AI-specific risk and integrating it into existing risk processes.
  • It is built on ISO 31000, so it describes a process - identify, analyse, evaluate, treat - rather than a checklist of controls.
  • It is guidance, not a certifiable standard. ISO/IEC 42001:2023 is the certifiable management-system counterpart.
  • It does not supply a domain risk catalogue. For a physical-AI system you have to bring one, which is the gap the Embodied AI Security Top 10 is written to fill.
The hook

Where a red-team result fits

Risk identification & assessment

AI risk management — risk identification & assessment input - a taxonomy gives the risk register its rows, and a measured rate per row turns qualitative likelihood into something with a denominator.

What Provael maps to it

Evidence produced

  • The Embodied AI Security Top 10 as a ready risk context for a physical-AI system, so the register starts from a named set rather than a blank page.
  • A measured rate per risk, with its interval and benign control, as risk-assessment input - evidence toward likelihood, not a determination of it.
  • Honest nulls carried alongside: risks that were tested and did not transfer are reported as such, which is what stops a register recording only the risks that happened to fire.
Timing

Dates (verified 19 Aug 2026)

Published
6 February 2023
ISO/IEC JTC 1/SC 42; verified 10 Aug 2026
How to read this mapping

What it is - and isn’t

  • adversarial-only - Provael measures adversarial robustness - susceptibility to manipulation - not general accuracy, reliability, or functional safety.
  • evidence-not-certification - The output is evidence you file, not a certificate. Provael is not a notified body, a lab, or a certification scheme.
  • behavioural-not-worst-case - The measured result uses templated, auditable attacks; the search-based families (optimized, universal_patch, gradient_patch) have only met the CPU fixture. Results are a floor on susceptibility - a behavioural lower bound, not a certified worst-case bound.
Evidence, not certification

Running Provael does not make a system compliant or certified - it generates measurements you can put into a conformity or assurance file.

Independent project. Not affiliated with or endorsed by ISO, the EU, NIST, IEC, OWASP, or MITRE. Not legal advice.

Clause references are indicative; a wrong clause citation is worse than a missing one.

Turn this into filed evidence.

Download the redacted sample pack, or book an assessment to get the crosswalk filled in for your policy.