ISO/IEC 38500:2024, "Information technology—IT governance in organizations," is the third edition of the IT governance standard jointly published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), replacing the second edition in 2015. This standard provides organizational governance bodies with principled guidance on the responsible, innovative, sustainable, and strategic use of IT, data, and digital capabilities. The standard emphasizes that IT governance is an area of organizational governance, consistent with ISO 37000, "Organizational Governance," ensuring that the use of IT effectively, responsibly, and ethically achieves organizational objectives.
The standard is applicable to all types of organizations (including public, private, government, and non-profit organizations), regardless of size or level of IT usage. It achieves good IT governance through three main tools: **governance principles**, **governance models**, and **governance frameworks**.
Compared to the previous version, this revision expands the number of principles (from 6 to 11), adding principles such as "Data and Decision Making," "Risk Governance," "Social Responsibility," and "Sustainable Performance," and updating the model to include "stakeholder participation."
According to ISO 37000, good IT governance should achieve three outcomes:
| Category | Principle | Implication of IT Governance | Expected Outcomes |
|---|---|---|---|
| Primary | Purpose (5.2) | IT should empower and enhance organizational purpose, considering the impact of emerging technologies | Expanding purpose, aligning IT with purpose, empowering people |
| Foundation | Value Generation (5.3) | IT impact value model, continuous assessment of technological change is required | Clarify value objectives, communicate value, adaptability |
| Foundation | Strategy (5.4) | IT strategy needs to be incorporated into organizational strategy, focusing on digital readiness | Digital capabilities, digital readiness, innovation, and management of emerging technologies |
| Foundation | Oversight (5.5) | Ensure IT compliance and controllable risks, and oversee procurement and lifecycle | Compliance, informed consent, and effective performance |
| Foundation | Accountability (5.6) | The governance body bears ultimate responsibility for IT governance, and authorization must be clear | Accountability, comprehensive decision-making, and assurance of the governance body |
| Enabling | Stakeholder Participation (5.7) | IT use must meet stakeholder expectations, and cultural support is essential | Stakeholder center, supportive culture |
| Enabling | Leadership (5.8) | Ethical leadership, driving digital transformation, cultivating a learning culture | Transformation capabilities, technological adaptability, learning culture |
| Enabling | Data and Decision Making (5.9) | Data is a strategic resource, requiring data governance and quality assurance | Using data strategically, using data responsibly, and ensuring data quality |
| Enabling | Risk Governance (5.10) | Managing IT-related risks, including cybersecurity and emerging technology risks | Risk monitoring, risk appetite, digital resilience |
| Enabling | Social Responsibility (5.11) | Automated decision-making requires ethical review, environmental and social impact assessment | Social responsibility, impact assessment, ethical checks and balances |
| Enabling | Sustainable Performance (5.12) | Ensuring long-term IT sustainability, infrastructure management, and protecting operations | Ecosystem effectiveness, infrastructure management, and protection |
The model (Chapter 6) consists of three core governance tasks and one new component:
Organizations implementing this standard should first assess their existing IT governance maturity and identify gaps by comparing them with the 11 principles.
It is recommended to start from **purpose** and **principles**, clarifying how IT supports the organization's mission; establish a data governance framework (referencing the ISO/IEC 38505 series); integrate risk governance into the enterprise's risk management system; and ensure that the governance body possesses sufficient IT literacy. The standard emphasizes "principles" rather than "norms," therefore, implementation should be tailored to the organization's specific context, flexibly applying models and frameworks. With the popularization of technologies such as artificial intelligence and cloud computing, IT governance will place greater emphasis on ethics, data sovereignty, and accountability for automated decision-making. ISO/IEC 38500:2024 provides organizations with a solid foundation for adapting to these changes.Note: This article provides a professional interpretation based on the official text of ISO/IEC 38500:2024, aiming to help organizations understand and apply this standard. Specific implementation should be tailored to the organization's actual situation.

Copyright ©2026 All Rights Reserved
Update:
Tue, 14 Jul 2026 03:39:01 +0000