By document type
| Category | Files |
|---|---|
| Manuals | 4 |
| Procedures & SOPs | 14 |
| Forms & Records | 14 |
| Checklists & Audit Tools | 5 |
| Registers, Logs & Matrices | 2 |
| Guides & Work Instructions | 4 |
Key documents
| Reference | Document | Format |
|---|---|---|
| AGS-ITGF-MAN-01 | IT Governance Framework Manual | Word |
| AGS-ITGF-PR-02 | Engage–Evaluate–Direct–Monitor Governance Cycle | Word |
| AGS-ITGF-PR-05 | Value Generation & IT Investment Governance | Word |
| AGS-ITGF-PR-11 | IT Risk Governance | Word |
| AGS-ITGF-CL-01 | ISO 38500 Governance Self-Assessment & Gap Analysis | Word |
| AGS-ITGF-CL-03 | Eleven Principles Conformance Checklist | Word |
- Need the complete document list? Request it — same day
- Want to check the quality first? Preview free samples
Overview
ISO/IEC 38500 sets out the guiding principles for the effective, efficient and acceptable governance of information technology. It is guidance rather than a requirements specification, directed at directors, owners, partners and executives and the advisers who support them, helping them meet their legal, regulatory and ethical obligations for the way technology is used. It suits public, private and not-for-profit bodies of any size, and draws a firm line between governance, which belongs to the governing body, and management, which is delegated.
The framework assembled here is organised around that cycle: the governing body evaluates current and future use of IT, directs the preparation of plans and policies, and monitors conformance and performance against them, with stakeholder engagement alongside. The principles of responsibility, strategy, acquisition, performance, conformance and human behaviour shape the decision records, registers and oversight checklists, which reach across investment approval, sourcing, delegation of authority, IT risk and ethical use. Not being intended for accredited certification, the material is built for board assurance, internal audit and self-assessment, complementing ISO/IEC 20000-1, ISO/IEC 27001 and ISO/IEC 38507.
What this system covers
- Governing body accountability: decision rights and the boundary with management
- The evaluate, direct and monitor cycle: assessing IT use, setting direction, testing what returns
- IT strategy and alignment: connecting technology plans to organisational objectives
- Value, investment and acquisition governance: business cases, thresholds and sourcing decisions
- IT risk governance and conformance: appetite, legal obligations and ethical use
- Performance oversight: governance indicators, board reporting and escalation of IT incidents
- Human behaviour and responsible stewardship: culture, stakeholder engagement and social responsibility
Who it's for
For chairs, non-executive directors, company secretaries and CIOs who must show a regulator, auditor or shareholder that technology decisions are governed and not merely managed. They gain a framework the board can adopt, a cycle to run, and self-assessment checklists that expose where oversight is currently thin.
Everything you get
Every toolkit gives you a full set of working documents for your standard, ready to edit and use.
Native Microsoft files. Add your logo and adapt every document to how you work.
Your full toolkit arrives as a ZIP the moment payment clears.
One purchase covers everyone in your organisation. No per-seat fees.
Built by people who run real audits, so the content matches what assessors check.
One payment, perpetual licence for your organisation. No subscriptions, no renewals.
Full refund if your files are faulty, incomplete or not as described and we can't put it right
Frequently asked questions
What exactly do I receive?
A downloadable ZIP containing the full set of ready-to-use documents for this toolkit — manuals, procedures, forms, records, checklists, guidance and training material, all in editable Word and Excel format. The exact document count is shown at the top of this page.
Are the documents really editable?
Yes. Every file is native Microsoft Word or Excel — no locked PDFs. Add your logo, change wording, and tailor the content to your organisation. The toolkit is yours to keep and reuse.
Does this certify my organisation?
No. These are documentation toolkits aligned to the relevant standard to help you prepare. Certification itself is issued by an accredited certification body after their audit. Our toolkits give you a strong, audit-ready starting point.
How is it delivered?
Instantly and digitally. There's no physical shipment — you download the files right after payment and receive a backup link by email.
Do I get updates?
Yes. If we revise this toolkit, you're entitled to the updated version at no extra cost — just contact us with your order details.
What is your refund policy?
These are digital products, so once a toolkit has been downloaded we cannot take it back. If you have not downloaded yet, contact us and we will cancel the order and refund you in full. We also refund in full if the files are damaged, incomplete, or not what the product page described.
Cannot find your standard?
Tell us which scheme you work to. We will point you to the right toolkit.




