

prEN 18228 – AI Risk Management
prEN 18228 is the European draft standard defining systematic risk management principles tailored specifically to artificial intelligence. Traditional software risk models often fall short when addressing the probabilistic behavior, data dependency, and adaptive nature of modern AI.
AI risks can emerge across all phases: during data curation and training, model design, deployment, operational use, human interaction, and post-deployment updates. prEN 18228 establishes repeatable controls to keep systems reliable and safe.
Why AI Risk Management Matters
Safety & Reliability
Fundamental Rights
Risk Identification
Risk Assessment
Ensures AI outputs remain dependable, accurate, and safe under foreseeable operational conditions.
Protects individuals against bias, discrimination, and privacy infringement throughout system use.
Systematically detects technical, operational, and societal hazards before deployment occurs.
Quantifies severity and likelihood to prioritize vulnerabilities across complex data pipelines.
Risk Controls
Residual Risk
Monitoring
Continual Improvement
Implements targeted technical, structural, and operational mitigation safeguards.
Evaluates remaining exposure post-mitigation to confirm acceptable safety margins.
Tracks model performance continuously in live environments to catch operational drift early.
Feeds field telemetry and audit insights back into risk reassessments for model iteration.
AI Risk Management and the EU AI Act
Standard vs. Law Distinction
A harmonized European standard offers a structured pathway to demonstrate conformity. However, applying prEN 18228 does not automatically confer legal compliance: legal accountability ultimately rests on full regulatory adherence.
1. Risk Planning
2. Hazard Identification
3. Risk Analysis
4. Risk Evaluation
Define system scope, intended purpose, context of use, operational boundaries, and evaluation criteria.
Identify reasonably foreseeable risks, sources of potential harm, failure modes, and misuse scenarios.
Assess occurrence probability, severity of potential damage, and underlying systemic characteristics.
Determine whether identified risks meet defined acceptability thresholds or demand mitigation.
5. Risk Control
6. Residual Evaluation
7. Post-Market Monitoring
8. Lifecycle Review
Select and deploy appropriate technical and procedural measures to minimize identified hazards.
Evaluate lingering exposure after controls are applied to ensure overall risk remains acceptable.
Track operational effectiveness, emerging vulnerabilities, unexpected incidents, and system changes.
Reassess and refine risk documentation continuously through recurrent lifecycle feedback loops.
Frequently Asked Questions
How does prEN 18228 relate to ISO 23894?
Is prEN 18228 mandatory for all AI systems?
While ISO 23894 provides general AI risk management guidance, prEN 18228 establishes specific normative requirements designed explicitly for European regulatory conformity.
It is primarily designed for high-risk AI systems under the EU AI Act, though adopting its principles offers best-practice governance for all production AI deployments.
