Skip to content

Standard · ISO/IEC

Governance implications of the use of AI by organizations

Guidance for boards and executives on their governance responsibilities when the organization uses AI.

ISO/IEC 38507:2022

What is it?

ISO/IEC 38507 belongs to the IT governance family (ISO/IEC 38500) and focuses on the governing body — board and senior executives: what to ask about AI and what to oversee.

Why does it matter?

Using AI is not only a technical decision; accountability rests with leadership. The standard helps executives govern effectively without technical detail.

Who needs it?

  • Board members
  • CEOs and senior executives
  • Audit and risk committees

Key concepts

Accountability remains

Using AI does not transfer responsibility to a machine.

Evaluate, direct, monitor

The governing body’s three core tasks for AI.

Risk appetite

Deciding how much AI risk the organization will accept.

Requirements

  • Guidance only; no certifiable requirements.

Implementation

  1. 01Define the board’s role in AI decisions
  2. 02Set AI risk appetite
  3. 03Report AI status to the board regularly

Assessment

The “Governance & Accountability” dimension covers this area.

Training

See “AI Governance for Executives” and “AI for Managers”.

Resources

This page is AI STANDARD's explanation and interpretation; it does not reproduce the official text. Obtain the full standard from its publisher.