Information Security

ISO/IEC 38500: What Every Board Should Know About IT Governance

By AGS Compliance Team February 4, 2026 5 min read
ISO/IEC 38500: What Every Board Should Know About IT Governance

Technology decisions have become board-level decisions. Digital transformation budgets, cyber risk, cloud strategy, AI adoption — all of them land, sooner or later, on the governing body's table. Yet many boards still treat IT as something delegated entirely to the CIO. ISO/IEC 38500 exists to close that gap. This guide explains what the standard is, how it differs from management system standards, who it is written for, and how organizations put its principles to work. It is aimed at directors, executives, company secretaries, governance advisers, and the IT leaders who support them.

What is ISO/IEC 38500?

ISO/IEC 38500 is the international standard providing guiding principles for the effective, efficient, and acceptable governance of information technology within organizations. Its purpose is to help those at the highest level of an organization understand and fulfil their legal, regulatory, and ethical obligations regarding the use of IT, and to give them a coherent framework for governing both current and future technology use.

Here is the crucial distinction: ISO/IEC 38500 is not a management system standard. It contains no certifiable requirements, no clause-by-clause checklist for auditors. It is a governance standard, directed primarily at the governing body — directors, owners, partners, and executives — and at the advisers and managers who support them. It deliberately separates governance (the accountability of the governing body) from management (the operational responsibility delegated to leaders such as the CIO). That separation is one of the standard's most valuable contributions, because confusion between the two is at the root of many technology failures.

Who is it for?

The scope of ISO/IEC 38500 covers organizations of all sizes — public, private, and not-for-profit — and all forms of IT use. Its natural audience includes:

  • Boards of directors and governing bodies accountable for organizational performance and conformance.
  • Owners and partners in smaller enterprises, where governance and management often blur.
  • Executive leadership — CEOs, CFOs, and CIOs who prepare plans and policies for board direction.
  • Governance, risk, and audit professionals who advise the board and provide assurance.
  • Public sector bodies, where stewardship of taxpayer-funded technology invites particular scrutiny.

If your organization spends meaningful money on technology, carries meaningful technology risk, or depends on IT to execute its strategy — which today means virtually every organization — the standard applies.

The benefits of principled IT governance

Adopting ISO/IEC 38500 does not produce a certificate; it produces something arguably more valuable — a board that governs technology deliberately. Typical outcomes include:

  • Stronger board-level oversight of IT investments, projects, and risks.
  • Better alignment of IT with strategy, so technology spend follows organizational objectives rather than vendor momentum.
  • Reduced governance risk — fewer failed projects, fewer compliance surprises, fewer "how did the board not know?" moments.
  • Clearer accountability between the governing body and management.
  • Improved stakeholder confidence among regulators, investors, and customers who expect responsible stewardship of technology.

The evaluate–direct–monitor model

At the heart of the standard sits a simple, powerful governance cycle:

  • Evaluate — the governing body assesses the current and future use of IT: proposals, plans, risks, and opportunities.
  • Direct — it directs the preparation and implementation of plans and policies, assigning responsibility and setting expectations.
  • Monitor — it monitors conformance to policies and performance against plans, using measurement and assurance to close the loop.

This cycle is the board's counterpart to management's Plan-Do-Check-Act. It keeps the governing body engaged at the right altitude — setting direction and verifying outcomes — without dragging it into operational detail.

The six principles of good IT governance

ISO/IEC 38500 articulates six core principles that guide decision-making:

  1. Responsibility — individuals and groups understand and accept their responsibilities for IT, and those with responsibility have the authority to act.
  2. Strategy — the organization's business strategy takes account of IT's current and future capabilities, and IT plans serve that strategy.
  3. Acquisition — IT investments are made for valid reasons, on the basis of transparent analysis, with balance between benefits, costs, risks, and opportunities.
  4. Performance — IT is fit for purpose, delivering the service levels and quality the organization requires.
  5. Conformance — IT use complies with all mandatory legislation and regulation, and policies are clearly defined and enforced.
  6. Human behaviour — IT policies and decisions respect the needs and behaviours of all the people involved, from employees to customers.

Applied together, the principles ensure IT investments support organizational objectives while risk is managed at an acceptable level.

How ISO/IEC 38500 fits the wider standards landscape

The standard complements — rather than replaces — management-oriented standards. ISO/IEC 20000-1 governs how services are managed; ISO/IEC 27001 governs how information security is managed; ISO/IEC 38500 governs how the board oversees all of it. It also connects to newer governance guidance, notably ISO/IEC 38507, which extends the same governance thinking to artificial intelligence. Boards adopting ISO/IEC 38500 today are laying exactly the foundation they will need as AI governance expectations mature.

The road to adoption

Because ISO/IEC 38500 is a guidance standard rather than a requirements specification, there is no accredited certification and no Stage 1/Stage 2 audit. Adoption instead follows a governance improvement path:

  1. Baseline assessment — evaluate current IT governance arrangements against the six principles and the evaluate–direct–monitor model.
  2. Framework design — define the board's IT governance charter, delegations, reporting lines, and policy architecture.
  3. Implementation — embed IT into board agendas, investment approval gates, risk reporting, and performance dashboards.
  4. Assurance and review — use internal audit and board self-assessment to verify the framework operates as intended, and refine it over time.

Organizations use the standard to shape governance frameworks, inform board assurance, support audits, and demonstrate responsible stewardship of technology to regulators and stakeholders.

How AGS can help

Translating governance principles into working board-level documentation is where most organizations stall — and where the AGS ISO/IEC 38500 IT Governance toolkit delivers immediate traction.

This Foundation-tier kit provides a coherent set of editable manuals, procedures, forms, and compliance matrices built around the evaluate–direct–monitor model and the six principles: governance charters, policy templates, investment evaluation forms, monitoring and reporting formats, and matrices that map your governance arrangements to the standard's guidance. Everything is fully editable, so you can calibrate the framework to your organization's size and structure — from a listed-company board to an owner-managed enterprise.

If your governing body is ready to move from delegating IT to genuinely governing it, the AGS toolkit gives you the documented framework to do it credibly and quickly. Explore it in the AGS online store.

View the toolkit →

The toolkit for this standard
ISO 38500- IT Governance
43 ready-to-use documentsEditable Word and Excel Instant download
AGS Compliance Team

Our toolkits and guides are written by practising auditors who assess management systems against ISO, BRCGS, HACCP and Halal schemes. Every document reflects what assessors actually look for.