What is it?
ISO/IEC 38507 belongs to the IT governance family (ISO/IEC 38500) and focuses on the governing body — board and senior executives: what to ask about AI and what to oversee.
Why does it matter?
Using AI is not only a technical decision; accountability rests with leadership. The standard helps executives govern effectively without technical detail.
Who needs it?
- Board members
- CEOs and senior executives
- Audit and risk committees
Key concepts
Accountability remains
Using AI does not transfer responsibility to a machine.
Evaluate, direct, monitor
The governing body’s three core tasks for AI.
Risk appetite
Deciding how much AI risk the organization will accept.
Requirements
- Guidance only; no certifiable requirements.
Implementation
- 01Define the board’s role in AI decisions
- 02Set AI risk appetite
- 03Report AI status to the board regularly
Assessment
The “Governance & Accountability” dimension covers this area.
Training
See “AI Governance for Executives” and “AI for Managers”.
Resources
This page is AI STANDARD's explanation and interpretation; it does not reproduce the official text. Obtain the full standard from its publisher.