Skip to product information
1 of 1

Information Security, Risk & Business ContinuityAGS-06-003

ISO 38500- IT Governance

ISO 38500- IT Governance

Governance documentation written for the governing body rather than for the IT department.

Regular price $490USD
Regular price USD Sale price $490USD
Taxes included.
Secure checkout American Express Apple Pay Diners ClubDiscoverGoogle Pay JCBMastercard Visa

Written by practising auditors with 20+ years in the field.

Preview free samples

View full details
43 ready-to-use documents 43 Word · 1 interactive HTML · plus the AGS license · 1 support file

By document type

Total 43
CategoryFiles
Manuals4
Procedures & SOPs14
Forms & Records14
Checklists & Audit Tools5
Registers, Logs & Matrices2
Guides & Work Instructions4

Key documents

ReferenceDocumentFormat
AGS-ITGF-MAN-01IT Governance Framework Manual Word
AGS-ITGF-PR-02Engage–Evaluate–Direct–Monitor Governance Cycle Word
AGS-ITGF-PR-05Value Generation & IT Investment Governance Word
AGS-ITGF-PR-11IT Risk Governance Word
AGS-ITGF-CL-01ISO 38500 Governance Self-Assessment & Gap Analysis Word
AGS-ITGF-CL-03Eleven Principles Conformance Checklist Word

Overview

ISO/IEC 38500 sets out the guiding principles for the effective, efficient and acceptable governance of information technology. It is guidance rather than a requirements specification, directed at directors, owners, partners and executives and the advisers who support them, helping them meet their legal, regulatory and ethical obligations for the way technology is used. It suits public, private and not-for-profit bodies of any size, and draws a firm line between governance, which belongs to the governing body, and management, which is delegated.

The framework assembled here is organised around that cycle: the governing body evaluates current and future use of IT, directs the preparation of plans and policies, and monitors conformance and performance against them, with stakeholder engagement alongside. The principles of responsibility, strategy, acquisition, performance, conformance and human behaviour shape the decision records, registers and oversight checklists, which reach across investment approval, sourcing, delegation of authority, IT risk and ethical use. Not being intended for accredited certification, the material is built for board assurance, internal audit and self-assessment, complementing ISO/IEC 20000-1, ISO/IEC 27001 and ISO/IEC 38507.

What this system covers

  • Governing body accountability: decision rights and the boundary with management
  • The evaluate, direct and monitor cycle: assessing IT use, setting direction, testing what returns
  • IT strategy and alignment: connecting technology plans to organisational objectives
  • Value, investment and acquisition governance: business cases, thresholds and sourcing decisions
  • IT risk governance and conformance: appetite, legal obligations and ethical use
  • Performance oversight: governance indicators, board reporting and escalation of IT incidents
  • Human behaviour and responsible stewardship: culture, stakeholder engagement and social responsibility

Who it's for

For chairs, non-executive directors, company secretaries and CIOs who must show a regulator, auditor or shareholder that technology decisions are governed and not merely managed. They gain a framework the board can adopt, a cycle to run, and self-assessment checklists that expose where oversight is currently thin.

Everything you get

Every toolkit gives you a full set of working documents for your standard, ready to edit and use.

Editable Word and Excel

Native Microsoft files. Add your logo and adapt every document to how you work.

Instant download

Your full toolkit arrives as a ZIP the moment payment clears.

Unlimited users

One purchase covers everyone in your organisation. No per-seat fees.

Written by auditors

Built by people who run real audits, so the content matches what assessors check.

Yours to keep

One payment, perpetual licence for your organisation. No subscriptions, no renewals.

Refund guarantee

Full refund if your files are faulty, incomplete or not as described and we can't put it right

Frequently asked questions

What exactly do I receive?

A downloadable ZIP containing the full set of ready-to-use documents for this toolkit — manuals, procedures, forms, records, checklists, guidance and training material, all in editable Word and Excel format. The exact document count is shown at the top of this page.

Are the documents really editable?

Yes. Every file is native Microsoft Word or Excel — no locked PDFs. Add your logo, change wording, and tailor the content to your organisation. The toolkit is yours to keep and reuse.

Does this certify my organisation?

No. These are documentation toolkits aligned to the relevant standard to help you prepare. Certification itself is issued by an accredited certification body after their audit. Our toolkits give you a strong, audit-ready starting point.

How is it delivered?

Instantly and digitally. There's no physical shipment — you download the files right after payment and receive a backup link by email.

Do I get updates?

Yes. If we revise this toolkit, you're entitled to the updated version at no extra cost — just contact us with your order details.

What is your refund policy?

These are digital products, so once a toolkit has been downloaded we cannot take it back. If you have not downloaded yet, contact us and we will cancel the order and refund you in full. We also refund in full if the files are damaged, incomplete, or not what the product page described.

Cannot find your standard?

Tell us which scheme you work to. We will point you to the right toolkit.

Request a toolkit