Skip to main content
Category: Roles & Accountability

Governing Body (ISO/IEC 38507)

Also known as: Governing Body under ISO/IEC 38507, Governing body of an organization (ISO/IEC 38507:2022)
Simply put

In ISO/IEC 38507:2022, the governing body is the group at the top of an organization—such as a board of directors or its equivalent—that holds ultimate responsibility and accountability for how the organization uses artificial intelligence. The standard offers guidance to help these leaders provide oversight of AI, rather than telling technical staff how to build or operate AI systems. It is an organizational oversight role and should not be confused with the day-to-day technical management of individual models.

Formal definition

As addressed in ISO/IEC 38507:2022 (an international standard issued by ISO/IEC providing guidance rather than a binding legal requirement), the governing body denotes the members of an organization who are ultimately responsible and accountable for enabling and governing the organization's use of AI, including oversight of the decision-making capabilities of AI and its use. In this framing, the governing body operates at the level of governance—setting direction, accountability structures, and oversight—as distinct from the operational and technical activities of building, validating, or running specific AI systems or models, which typically sit with management and technical functions. The evidence provided does not specify the precise composition of the governing body or enumerate its detailed duties, so those particulars fall outside what can be stated here; readers should consult the standard directly for its full scope and terminology.

Why it matters

The concept of a governing body in ISO/IEC 38507:2022 matters because it locates ultimate accountability for an organization's use of AI at the top of the organization—typically a board of directors or its equivalent—rather than diffusing it across technical teams. As AI systems increasingly influence consequential decisions, many governance frameworks emphasize that responsibility cannot be delegated away to the engineers who build models or the vendors who supply them. ISO/IEC 38507 addresses this by providing guidance aimed specifically at those with governance authority, helping them provide oversight of how AI is used across the organization.

The distinction this term draws is one that professionals frequently blur: governance oversight is not the same as the operational and technical management of individual models. A governing body sets direction, establishes accountability structures, and oversees the organization's overall use of AI; it does not, in this framing, validate a specific model, tune its parameters, or run it in production. Conflating the two can leave a gap where boards assume technical staff have covered risk, while technical staff assume the board has set the risk appetite—so neither role fully owns the outcome.

It is worth being precise about the standard's status. ISO/IEC 38507:2022 is an international standard issued by ISO/IEC that provides guidance; based on the evidence available here, it is not a binding legal requirement, and it should not be treated as interchangeable with regulatory instruments such as the EU AI Act or with supervisory guidance such as SR 11-7. The evidence provided does not enumerate the standard's detailed duties or specify the governing body's precise composition, so organizations should consult the standard directly for its full scope.

Who it's relevant to

Board members and directors
Members of a board of directors or equivalent governing group are the primary audience the standard addresses. It provides guidance to help them understand their ultimate responsibility and accountability for the organization's use of AI and to exercise oversight without assuming technical or operational duties that sit elsewhere.
Executive leadership and management
Senior executives sit at the interface between the governing body's direction and the operational functions that implement it. Understanding where governance oversight ends and management activity begins helps leadership avoid the common error of assuming that board-level accountability substitutes for operational risk controls, or vice versa.
AI governance and compliance professionals
Those designing governance structures use frameworks such as ISO/IEC 38507 to clarify accountability at the top of the organization. They should note that the standard is guidance rather than binding law and is not interchangeable with regulatory instruments or supervisory guidance; it may complement, but does not replace, obligations arising under applicable regulation.
Model risk and technical functions
Model risk managers, data scientists, and validation teams benefit from understanding that the governing body role is deliberately separated from the day-to-day technical management of individual models. This distinction helps clarify reporting lines and prevents the assumption that governance oversight covers model-level validation, monitoring, or performance management.

Inside Governing Body (ISO/IEC 38507)

Accountability for AI Use
As commonly framed in ISO/IEC 38507, the governing body holds ultimate accountability for the organization's use of AI, even where operational responsibility is delegated to management. Accountability in this sense is not transferable through delegation.
Direction Setting
The governing body is typically responsible for setting the strategic direction and objectives for AI use, including whether and how AI aligns with organizational purpose, values, and risk appetite. This is distinct from day-to-day management execution.
Oversight and Evaluation
In many governance models, the governing body evaluates and monitors the outcomes of AI use against intended objectives, rather than performing the technical work of building or validating models.
Distinction from Management
ISO/IEC 38507 addresses the governing body as an oversight layer distinct from the management functions that operate AI systems. This separation reflects a broader governance concept and should not be collapsed into operational model risk management activities such as validation or monitoring.
Scope: Governance of IT and AI Use
The standard is positioned as guidance for the governing body on the governance implications of using AI, situated within the broader family of IT governance concepts. It is a voluntary standard and provides guidance rather than binding legal requirements.

Common questions

Answers to the questions practitioners most commonly ask about Governing Body (ISO/IEC 38507).

Is the governing body the same as an organization's AI or model risk management team?
No, and conflating the two is a common error. As commonly understood in ISO/IEC 38507, the governing body refers to the person or group accountable for the performance and conformance of the organization—typically a board or equivalent oversight authority—rather than the operational teams that build, validate, or run AI systems. Governance here concerns direction-setting, oversight, and accountability, which sits at a different level from the day-to-day identification, measurement, and control activities associated with model risk management. The governing body may set expectations that risk teams then implement, but the roles remain distinct.
Does having a governing body oversee AI mean the organization has satisfied its regulatory obligations?
Not necessarily. ISO/IEC 38507 is a standard addressing governance implications of AI use, and adherence to a voluntary standard does not by itself demonstrate compliance with binding law such as the EU AI Act or with supervisory guidance such as SR 11-7 in the banking context. These instruments are issued by different bodies, differ in legal status, and are scoped to different jurisdictions and use cases. A governing body's oversight is a mechanism for directing and monitoring AI use; it is one input into a broader compliance posture rather than a substitute for meeting specific legal or supervisory requirements.
How does a governing body typically exercise oversight of AI use without becoming involved in operational detail?
In many governance framings, the governing body directs, evaluates, and monitors rather than executes. This commonly means setting the organization's risk appetite and expectations for AI use, delegating operational responsibility to management, and receiving reporting sufficient to hold management accountable. The distinction between governance and management is central: the governing body's role is oversight and direction-setting, while implementation typically resides with management and specialized functions. The precise reporting cadence and thresholds are organization-specific and are not prescribed uniformly.
What kinds of information does a governing body typically need to oversee AI effectively?
Effective oversight generally depends on information that allows the governing body to understand how AI is being used, what risks arise, and how those risks are being managed. This can include summaries of the organization's AI use, the nature of associated risks, and the status of controls—framed at a level appropriate to a direction-setting role rather than technical granularity. The specific content, format, and frequency vary by organization and are not standardized across all contexts. Governance measures of this kind are intended to help manage and reduce risk, not to eliminate it.
How does the governing body's role relate to the three lines of defense model?
These operate at different levels and should not be collapsed. The three lines of defense—commonly described as operational management (first line), risk and compliance oversight functions (second line), and internal audit (third line)—describe how risk management responsibilities are distributed within management and assurance functions. The governing body typically sits above these lines, providing overall direction and accountability and receiving assurance from them. The governing body is not itself one of the lines of defense; rather, it is the body to which those functions ultimately report in a governance structure.
How should responsibility be allocated between the governing body and management for AI decisions?
In common governance practice, the governing body remains accountable for oversight and for setting direction, while delegating operational decision-making to management. Accountability for the outcome typically cannot be delegated even where specific tasks are, so allocation usually involves clear articulation of which decisions require governing-body direction or approval and which are within management's authority. The exact boundary is organization-specific and may also be shaped by applicable legal and sector requirements, which fall outside the scope of the standard itself.

Common misconceptions

The governing body performs model validation, monitoring, or other model risk management tasks.
As commonly understood, the governing body provides oversight and direction and holds accountability, but does not perform the technical validation, verification, or ongoing monitoring activities that typically fall to management and to model risk management functions. AI governance and model risk management overlap but are not the same, and the governing body sits at the governance layer.
Accountability can be delegated away from the governing body along with operational responsibility.
In the governance framing reflected by ISO/IEC 38507, operational responsibility for AI can be delegated to management, but ultimate accountability for AI use is typically retained by the governing body and is not transferred by that delegation.
ISO/IEC 38507 is a binding regulatory requirement that applies universally.
ISO/IEC standards are voluntary standards, not binding law, and their adoption and application depend on organizational and jurisdictional context. They should not be treated as interchangeable with binding instruments or with sector-specific supervisory guidance.

Best practices

Clearly separate the governing body's oversight and direction-setting role from management's operational responsibility for building, validating, and monitoring AI systems, and document this separation.
Retain and explicitly acknowledge accountability for AI use at the governing body level, even where operational responsibility is delegated to management.
Set the organization's direction, objectives, and risk appetite for AI use through the governing body, so that management activities can be evaluated against defined expectations.
Establish mechanisms for the governing body to evaluate and monitor AI outcomes against intended objectives without displacing the technical functions that operate the systems.
Treat ISO/IEC 38507 as voluntary guidance and map its recommendations against any binding legal or supervisory requirements that apply in the organization's jurisdiction and sector, rather than assuming universal applicability.
Position governing-body oversight within the broader IT and AI governance context while ensuring it complements, rather than substitutes for, model risk management controls.