• AI Risk Management • EU AI Act

prEN 18228 – AI Risk Management

Framework for AI risk management and assessment across the AI lifecycle.

prEN 18228 provides a structured approach to identifying, analyzing, evaluating, controlling, and monitoring risks associated with AI systems throughout their complete lifecycle.

— Standard Overview

What is prEN 18228?

prEN 18228 is the European draft standard defining systematic risk management principles tailored specifically to artificial intelligence. Traditional software risk models often fall short when addressing the probabilistic behavior, data dependency, and adaptive nature of modern AI.

AI risks can emerge across all phases: during data curation and training, model design, deployment, operational use, human interaction, and post-deployment updates. prEN 18228 establishes repeatable controls to keep systems reliable and safe.

+ Core Imperatives

Why AI Risk Management Matters

Safety & Reliability

Fundamental Rights

Risk Identification

Risk Assessment

Ensures AI outputs remain dependable, accurate, and safe under foreseeable operational conditions.

Protects individuals against bias, discrimination, and privacy infringement throughout system use.

Systematically detects technical, operational, and societal hazards before deployment occurs.

Quantifies severity and likelihood to prioritize vulnerabilities across complex data pipelines.

Risk Controls

Residual Risk

Monitoring

Continual Improvement

Implements targeted technical, structural, and operational mitigation safeguards.

Evaluates remaining exposure post-mitigation to confirm acceptable safety margins.

Tracks model performance continuously in live environments to catch operational drift early.

Feeds field telemetry and audit insights back into risk reassessments for model iteration.

/ Regulatory Context

AI Risk Management and the EU AI Act

Standard vs. Law Distinction

A harmonized European standard offers a structured pathway to demonstrate conformity. However, applying prEN 18228 does not automatically confer legal compliance: legal accountability ultimately rests on full regulatory adherence.

■ Lifecycle Framework

The AI Risk Management Process

1. Risk Planning

2. Hazard Identification

3. Risk Analysis

4. Risk Evaluation

Define system scope, intended purpose, context of use, operational boundaries, and evaluation criteria.

Identify reasonably foreseeable risks, sources of potential harm, failure modes, and misuse scenarios.

Assess occurrence probability, severity of potential damage, and underlying systemic characteristics.

Determine whether identified risks meet defined acceptability thresholds or demand mitigation.

5. Risk Control

6. Residual Evaluation

7. Post-Market Monitoring

8. Lifecycle Review

Select and deploy appropriate technical and procedural measures to minimize identified hazards.

Evaluate lingering exposure after controls are applied to ensure overall risk remains acceptable.

Track operational effectiveness, emerging vulnerabilities, unexpected incidents, and system changes.

Reassess and refine risk documentation continuously through recurrent lifecycle feedback loops.

Clarifications

Frequently Asked Questions

How does prEN 18228 relate to ISO 23894?

Is prEN 18228 mandatory for all AI systems?

While ISO 23894 provides general AI risk management guidance, prEN 18228 establishes specific normative requirements designed explicitly for European regulatory conformity.

It is primarily designed for high-risk AI systems under the EU AI Act, though adopting its principles offers best-practice governance for all production AI deployments.