ISO/IEC 38507:2022 — Governance Implications of AI
An international standard providing guidance to governing bodies on the implications of an organisation’s use of artificial intelligence.
It helps leadership distinguish governance responsibilities from operational management and ask informed questions about AI investment, risk, oversight, and value.
A board uses ISO/IEC 38507 to define decision rights for high-impact AI, require management reporting, review acquisition criteria, and monitor whether AI outcomes remain aligned with policy.
The standard provides governance guidance, not detailed engineering controls or certification requirements. Effective application depends on reliable information from management and clear organisational accountability.
The standard extends governance-of-IT principles to AI. It addresses accountability, strategy, acquisition, performance, conformance, and human behaviour, helping boards and governing bodies evaluate whether AI use aligns with organisational purpose, obligations, and stakeholder expectations.
Cybersecurity, Systems Architecture
ISO — ISO/IEC 38507:2022 — https://www.iso.org/standard/56641.html
