ISO/IEC 38500:2024
Information technology

Standard No.
ISO/IEC 38500:2024
Release Date
2024
Published By
International Organization for Standardization (ISO)  IX  /  ISO
Latest
ISO/IEC 38500:2024
 

Introduction

Standard Overview and Background

ISO/IEC 38500:2024, "Information technology—IT governance in organizations," is the third edition of the IT governance standard jointly published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), replacing the second edition in 2015. This standard provides organizational governance bodies with principled guidance on the responsible, innovative, sustainable, and strategic use of IT, data, and digital capabilities. The standard emphasizes that IT governance is an area of organizational governance, consistent with ISO 37000, "Organizational Governance," ensuring that the use of IT effectively, responsibly, and ethically achieves organizational objectives.

The standard is applicable to all types of organizations (including public, private, government, and non-profit organizations), regardless of size or level of IT usage. It achieves good IT governance through three main tools: **governance principles**, **governance models**, and **governance frameworks**.

Compared to the previous version, this revision expands the number of principles (from 6 to 11), adding principles such as "Data and Decision Making," "Risk Governance," "Social Responsibility," and "Sustainable Performance," and updating the model to include "stakeholder participation."


Three Outcomes of Governance: Effective Performance, Responsible Management, and Ethical Behavior

According to ISO 37000, good IT governance should achieve three outcomes:

  • Effective Performance: IT capabilities are aligned with organizational objectives; investments are reasonable; value extraction is appropriate; and data-driven decision-making.
  • Responsible Management: Ensuring the security, resilience, and proper use of digital capabilities and data; and making automated decisions explainable.
  • Ethical Behavior: Adhering to international norms of conduct; respecting data rights; and ensuring transparency and compliance.


Detailed Explanation of 11 Governance Principles

CategoryPrincipleImplication of IT GovernanceExpected Outcomes
PrimaryPurpose (5.2)IT should empower and enhance organizational purpose, considering the impact of emerging technologiesExpanding purpose, aligning IT with purpose, empowering people
FoundationValue Generation (5.3)IT impact value model, continuous assessment of technological change is requiredClarify value objectives, communicate value, adaptability
FoundationStrategy (5.4)IT strategy needs to be incorporated into organizational strategy, focusing on digital readinessDigital capabilities, digital readiness, innovation, and management of emerging technologies
FoundationOversight (5.5)Ensure IT compliance and controllable risks, and oversee procurement and lifecycleCompliance, informed consent, and effective performance
FoundationAccountability (5.6)The governance body bears ultimate responsibility for IT governance, and authorization must be clearAccountability, comprehensive decision-making, and assurance of the governance body
EnablingStakeholder Participation (5.7)IT use must meet stakeholder expectations, and cultural support is essentialStakeholder center, supportive culture
EnablingLeadership (5.8)Ethical leadership, driving digital transformation, cultivating a learning cultureTransformation capabilities, technological adaptability, learning culture
EnablingData and Decision Making (5.9)Data is a strategic resource, requiring data governance and quality assuranceUsing data strategically, using data responsibly, and ensuring data quality
EnablingRisk Governance (5.10)Managing IT-related risks, including cybersecurity and emerging technology risksRisk monitoring, risk appetite, digital resilience
EnablingSocial Responsibility (5.11)Automated decision-making requires ethical review, environmental and social impact assessmentSocial responsibility, impact assessment, ethical checks and balances
EnablingSustainable Performance (5.12)Ensuring long-term IT sustainability, infrastructure management, and protecting operationsEcosystem effectiveness, infrastructure management, and protection

Governance Model: Assessment-Guidance-Monitoring and Stakeholder Engagement

The model (Chapter 6) consists of three core governance tasks and one new component:

  • Stakeholder Engagement: Identifying internal and external stakeholders, understanding their expectations, and ensuring clear commitments.
  • Assessment: Judging current and future IT usage, considering technology trends, business needs, etc. Guidance: Assign responsibilities, develop strategies and policies, and encourage a culture of governance. Monitoring: Oversee performance and compliance through measurement systems. This model emphasizes the separation but collaboration between governance and management. The governance body is responsible for setting direction, and the management team executes within its authorized scope. The framework (Chapter 7) describes six elements: direction, capability, policy, authorization, performance, and accountability, forming a continuous improvement cycle. Six Elements of the Governance Framework The governance body sets the direction for IT usage based on purpose and strategy, considering emerging technologies such as cloud computing. Capabilities Identify existing and required digital capabilities, including identification, governance, and management. PolicyUse policies to articulate governance decisions, guide behavior, and ensure compliance and flexibility. AuthorizationClearly define authorization and responsibility allocation to ensure that power does not overstep its bounds, including third parties in the ecosystem. PerformanceSet performance expectations, monitor security, resilience, adaptability, etc., and use early warning when necessary. AccountabilityProve accountability through mechanisms such as policies, reports, and audits, and consider the challenges brought by adaptive systems such as AI.

    Implementation Recommendations and Future Outlook

    Organizations implementing this standard should first assess their existing IT governance maturity and identify gaps by comparing them with the 11 principles.

    It is recommended to start from **purpose** and **principles**, clarifying how IT supports the organization's mission; establish a data governance framework (referencing the ISO/IEC 38505 series); integrate risk governance into the enterprise's risk management system; and ensure that the governance body possesses sufficient IT literacy. The standard emphasizes "principles" rather than "norms," therefore, implementation should be tailored to the organization's specific context, flexibly applying models and frameworks. With the popularization of technologies such as artificial intelligence and cloud computing, IT governance will place greater emphasis on ethics, data sovereignty, and accountability for automated decision-making. ISO/IEC 38500:2024 provides organizations with a solid foundation for adapting to these changes.

    Note: This article provides a professional interpretation based on the official text of ISO/IEC 38500:2024, aiming to help organizations understand and apply this standard. Specific implementation should be tailored to the organization's actual situation.

ISO/IEC 38500:2024 Referenced Document

  • ISO 37000 Governance of organizations — Guidance

ISO/IEC 38500:2024 history

Information technology

Standard and Specification




Copyright ©2026 All Rights Reserved
Update: Tue, 14 Jul 2026 03:39:01 +0000