An international standard for boards and senior executives on how to govern an organisation's use of AI — covering oversight, accountability, and strategic direction.
An international standard for boards and senior executives on how to govern an organisation's use of AI — covering oversight, accountability, and strategic direction.
ISO/IEC 38507:2022 (Information technology — Governance of IT — Governance implications of the use of artificial intelligence by organisations) applies the ISO/IEC 38500 IT governance principles (evaluate, direct, monitor) to AI. It addresses the responsibilities of governing bodies in setting AI strategy, ensuring AI systems align with organisational values, managing AI risk at board level, and establishing accountability structures for AI outcomes. It is complementary to ISO/IEC 42001 (AI management system) — where 42001 addresses the management layer, 38507 addresses the governance layer above it.
Boards and audit committees can use ISO/IEC 38507 to structure their AI oversight agenda — determining what questions to ask management, what evidence to request, and how to fulfil fiduciary duties in relation to AI risk.
Like ISO/IEC 38500 for IT governance — providing the framework for how a board should oversee and direct the organisation's technology strategy, applied specifically to AI.
An international standard for boards and senior executives on how to govern an organisation's use of AI — covering oversight, accountability, and strategic direction.
ISO/IEC 38507:2022 (Information technology — Governance of IT — Governance implications of the use of artificial intelligence by organisations) applies the ISO/IEC 38500 IT governance principles (evaluate, direct, monitor) to AI. It addresses the responsibilities of governing bodies in setting AI strategy, ensuring AI systems align with organisational values, managing AI risk at board level, and establishing accountability structures for AI outcomes. It is complementary to ISO/IEC 42001 (AI management system) — where 42001 addresses the management layer, 38507 addresses the governance layer above it.
Boards and audit committees can use ISO/IEC 38507 to structure their AI oversight agenda — determining what questions to ask management, what evidence to request, and how to fulfil fiduciary duties in relation to AI risk.