Governing Artificial Intelligence: A Guide to ISO/IEC 38507:2022
Artificial intelligence has moved from the innovation lab to the boardroom agenda with startling speed. Algorithms now approve loans, screen job candidates, price products, and draft customer communications — and when they go wrong, it is not the data science team that answers to regulators and shareholders. It is the board. ISO/IEC 38507:2022 was written for precisely this moment. This guide explains what the standard covers, who it is for, how it connects to the wider AI standards ecosystem, and how organizations can use it to govern AI responsibly. It is written for directors, executives, governance professionals, and the advisers who support them.
What is ISO/IEC 38507:2022?
ISO/IEC 38507:2022 provides guidance for members of the governing body of an organization on the governance implications of the use of artificial intelligence. Its purpose is to enable boards to govern their organization's use of AI responsibly — ensuring that AI adoption aligns with organizational objectives, obligations, and stakeholder expectations, while the associated risks and opportunities are properly managed.
The standard is the AI-focused companion to ISO/IEC 38500, the foundational standard for the corporate governance of IT. It applies the same evaluate–direct–monitor governance model and reflects the same principles, extending them into the distinctive territory that AI creates: automated decision-making, opaque algorithms, data provenance, and societal impact.
One point deserves emphasis at the outset: ISO/IEC 38507 is a governance guidance document, not a requirements specification. It is not intended for certification. Its value lies in shaping how boards think, deliberate, and assign accountability — not in generating a certificate.
Who needs this guidance?
The scope covers organizations of all types and sizes that use, are considering using, or are affected by AI — whether they develop AI in-house or acquire it from third parties. That last clause matters: you do not need a data science department to need AI governance. Buying an AI-powered recruitment tool or embedding a vendor's model in your customer service creates governance obligations just as surely as building your own.
The primary audience is:
- Directors, owners, and executive leaders who hold accountability at governance level.
- Board committees — audit, risk, and technology committees grappling with AI oversight.
- Advisers, specialists, and managers who prepare board papers, policies, and assurance on AI matters.
- Governance, risk, and compliance professionals building AI oversight into enterprise frameworks.
Why AI governance matters now
The benefits of adopting ISO/IEC 38507 flow directly from the risks of not doing so:
- Informed board oversight of AI — directors who understand what AI is doing in their organization, rather than discovering it after an incident.
- Clearer accountability — the standard is emphatic that while operational responsibility for AI can be delegated, accountability for its acceptable use remains with the governing body.
- Better management of ethical and regulatory risk, as AI-specific legislation and regulatory expectations accelerate worldwide.
- Increased trust among customers, regulators, and society — organizations that can explain how they govern AI earn the license to use it.
What the standard addresses
ISO/IEC 38507 guides the governing body through the questions AI forces onto the agenda:
- Governance versus management of AI — what the board must retain, and what it may delegate to management.
- The nature and sources of AI-related risk — from model error and bias to misuse, drift, and dependency on third-party providers.
- Data use and provenance — where training and operational data come from, whether the organization has the right to use them, and how their quality is assured.
- Transparency and explainability — whether the organization can explain the decisions its AI systems make, to the people affected by them.
- Accountability for automated and algorithmic decision-making — ensuring that a human institution remains answerable even where a machine decides.
- Ethical, legal, and societal implications — the impacts of AI use on individuals, communities, and the organization's social license.
Running through all of it is the evaluate–direct–monitor cycle: the board evaluates AI use and proposals, directs policy and plans, and monitors performance and conformance.
Where ISO/IEC 38507 fits in the AI standards ecosystem
The standard does not stand alone. It occupies the governance tier of a rapidly maturing family:
- ISO/IEC 38500 — the parent standard for governance of IT, whose model and principles ISO/IEC 38507 applies to AI.
- ISO/IEC 42001 — the certifiable AI management system standard; where 38507 tells the board how to govern, 42001 tells management how to operationalize.
- ISO/IEC 22989 — foundational AI concepts and terminology.
- ISO/IEC 23894 — guidance on AI risk management.
For boards, the practical sequence is often: use ISO/IEC 38507 to establish governance posture and policy, then direct management to implement ISO/IEC 42001 as the operational machinery beneath it.
The road to responsible AI governance
With no certification audit at the end, the journey is one of governance maturity rather than conformity assessment:
- Discovery and evaluation — inventory where AI is already in use or planned, including AI embedded in procured products and services.
- Policy and direction — establish the board's AI governance policy, risk appetite, and delegations; direct management to implement controls and reporting.
- Integration — embed AI into existing governance structures: risk registers, investment approval, audit plans, and board reporting cycles.
- Monitoring and assurance — track AI performance, incidents, and conformance; commission independent assurance where stakes are high.
- Review and adaptation — revisit the framework as regulation, technology, and the organization's AI footprint evolve.
Organizations use the standard to inform board deliberations, shape AI governance frameworks, and support responsible, defensible AI adoption — evidence of diligence that regulators and stakeholders increasingly expect to see.
How AGS can help
Boards rarely lack willingness to govern AI; they lack the documented framework to do it. The AGS ISO/IEC 38507:2022 toolkit — a Foundation-tier documentation kit — closes that gap.
The kit provides editable manuals, procedures, forms, and compliance matrices structured around the standard's guidance: AI governance policy templates, evaluate–direct–monitor working documents, AI use inventories, risk and accountability registers, board reporting formats, and matrices mapping your governance arrangements to the standard. Every file is fully editable, letting you calibrate the framework to your organization's AI exposure — whether you are deploying your first vendor AI tool or overseeing an in-house model portfolio.
If your governing body wants to move from uneasy awareness of AI to confident, documented oversight of it, the AGS toolkit provides the fastest credible route. You will find it in the AGS online store.