Skip to product information
1 of 1

Information Security, Risk & Business ContinuityAGS-06-004

ISO IEC 38507-2022-Governance implications of the use of AI

ISO IEC 38507-2022-Governance implications of the use of AI

Accountability for artificial intelligence stays with the board, including for the AI an organisation buys rather than builds.

Regular price $490USD
Regular price USD Sale price $490USD
Taxes included.
Secure checkout American Express Apple Pay Diners ClubDiscoverGoogle Pay JCBMastercard Visa

Written by practising auditors with 20+ years in the field.

Preview free samples

View full details
43 ready-to-use documents 43 Word · plus the AGS license

By document type

Total 43
CategoryFiles
Manuals4
Procedures & SOPs14
Forms & Records14
Checklists & Audit Tools5
Registers, Logs & Matrices2
Guides & Work Instructions4

Key documents

ReferenceDocumentFormat
AGS-AIGF-MAN-01AI Governance Framework Manual Word
AGS-AIGF-SCH-01Governance Scheme - EDM Model & Policy-Area Map Word
AGS-AIGF-PR-02Evaluate–Direct–Monitor Governance Cycle Word
AGS-AIGF-PR-05Governance of AI Decision-Making Word
AGS-AIGF-PR-09AI Risk Governance Appetite, Sources & Controls Word
AGS-AIGF-CL-01ISO 38507 Governance Self-Assessment & Gap Analysis Word

Overview

ISO/IEC 38507:2022 guides members of a governing body through the governance implications of using artificial intelligence. Its scope reaches organisations of every type and size that use AI, are considering it, or are affected by it, whether they build systems or acquire them, and it addresses directors, owners and executive leaders with the advisers who support them. Consistent with ISO/IEC 38500, it applies the evaluate, direct and monitor model so that AI adoption aligns with organisational objectives, obligations and stakeholder expectations.

Its substance is the questions a board must be able to answer: where AI-related risk originates, how the data used to train and operate systems was obtained and authorised, what transparency and explainability are owed to interested parties, and how the ethical, legal and societal implications of automated and algorithmic decision-making are weighed. The standard is explicit that operational responsibility may be delegated while accountability for acceptable use may not. As guidance rather than a certifiable specification, it complements ISO/IEC 42001 and draws on ISO/IEC 22989 for terminology and ISO/IEC 23894 for AI risk.

What this system covers

  • AI use-case authorisation: where AI may be deployed, on what conditions, approved by whom
  • Governance of AI decision-making: limits on automated decisions and how they are reviewed
  • Governance of data use for AI: provenance, permitted purposes and the record of authorisation
  • Transparency and explainability: what is disclosed about AI use, to whom and when
  • AI risk governance: appetite, sources, controls and escalation when an incident occurs
  • Accountability and delegation: duties split between board, executives and delivery teams
  • Compliance obligations, culture and human behaviour: legal, ethical and societal expectations

Who it's for

Suited to directors, risk committee members, general counsel and heads of technology at the moment AI reaches the corporate risk register or a regulator's questions. They finish with a governance framework, an authorised inventory of AI use cases and a documented trail of the decisions taken about each.

Everything you get

Every toolkit gives you a full set of working documents for your standard, ready to edit and use.

Editable Word and Excel

Native Microsoft files. Add your logo and adapt every document to how you work.

Instant download

Your full toolkit arrives as a ZIP the moment payment clears.

Unlimited users

One purchase covers everyone in your organisation. No per-seat fees.

Written by auditors

Built by people who run real audits, so the content matches what assessors check.

Yours to keep

One payment, perpetual licence for your organisation. No subscriptions, no renewals.

Refund guarantee

Full refund if your files are faulty, incomplete or not as described and we can't put it right

Frequently asked questions

What exactly do I receive?

A downloadable ZIP containing the full set of ready-to-use documents for this toolkit — manuals, procedures, forms, records, checklists, guidance and training material, all in editable Word and Excel format. The exact document count is shown at the top of this page.

Are the documents really editable?

Yes. Every file is native Microsoft Word or Excel — no locked PDFs. Add your logo, change wording, and tailor the content to your organisation. The toolkit is yours to keep and reuse.

Does this certify my organisation?

No. These are documentation toolkits aligned to the relevant standard to help you prepare. Certification itself is issued by an accredited certification body after their audit. Our toolkits give you a strong, audit-ready starting point.

How is it delivered?

Instantly and digitally. There's no physical shipment — you download the files right after payment and receive a backup link by email.

Do I get updates?

Yes. If we revise this toolkit, you're entitled to the updated version at no extra cost — just contact us with your order details.

What is your refund policy?

These are digital products, so once a toolkit has been downloaded we cannot take it back. If you have not downloaded yet, contact us and we will cancel the order and refund you in full. We also refund in full if the files are damaged, incomplete, or not what the product page described.

Cannot find your standard?

Tell us which scheme you work to. We will point you to the right toolkit.

Request a toolkit