Skip to main content
Category: Management System Governance

ISO/IEC 38507 (Governance Implications)

Also known as: ISO/IEC 38507, ISO/IEC 38507:2022, Governance implications of the use of artificial intelligence by organizations
Simply put

ISO/IEC 38507:2022 is an international standard that offers guidance to the leaders who direct and oversee an organization, helping them understand and govern how their organization uses artificial intelligence. Rather than telling technical teams how to build AI, it focuses on the governing body's role and the broader implications of adopting AI. It is guidance intended to support oversight and informed decision-making at the top of an organization.

Formal definition

ISO/IEC 38507:2022, titled to address the governance implications of the use of artificial intelligence by organizations, provides guidance for members of an organization's governing body on enabling and governing the organizational use of AI. Its stated scope centers on the role of the governing body with regard to AI use within the organization, addressing oversight, risk considerations, and related governance implications of AI adoption, and is described in the evidence as the first international standard designed specifically for this purpose. As a guidance document it operates at the governance layer (the direction, evaluation, and monitoring responsibilities of the governing body) and is distinct from operational model risk management activities such as model validation, monitoring, and control; it should not be read as binding law. The evidence provided does not detail the standard's specific clauses, required controls, or certification status, so those elements are out of scope for this entry, and readers should consult the standard text directly for its full requirements and structure.

Why it matters

As organizations adopt AI, decisions with significant legal, ethical, financial, and reputational consequences increasingly flow from systems that governing bodies may not fully understand. ISO/IEC 38507:2022 matters because it directs guidance at the level of the board or governing body rather than at the technical teams building models, addressing a gap that many organizations experience: those who are ultimately accountable for the organization's conduct often lack a structured way to evaluate, direct, and monitor AI use. Described in the evidence as the first international standard designed specifically for this purpose, it frames AI adoption as a governance responsibility, not solely a technical or operational one.

Who it's relevant to

Board members and governing bodies
The standard is explicitly directed at members of an organization's governing body. It is most relevant to directors and senior leaders accountable for directing, evaluating, and monitoring how their organization uses AI, and who need a structured way to exercise oversight without necessarily engaging in technical model-building details.
AI governance and policy specialists
Professionals responsible for establishing organizational AI governance structures may use ISO/IEC 38507:2022 as reference guidance for defining the governing body's role. They should distinguish its governance-layer focus from operational model risk management activities, which it does not itself prescribe.
Compliance officers and internal auditors
Those assessing whether governance oversight of AI is adequate may reference the standard when evaluating board-level accountability. Because the evidence does not describe certification or specific required controls, they should consult the standard text directly and treat its guidance as voluntary rather than as a binding legal requirement.
Model risk managers
Model risk professionals should understand where this governance-level guidance sits relative to their own work. ISO/IEC 38507:2022 addresses the governing body's oversight role and is distinct from operational model validation, monitoring, and control activities, though the two layers overlap where governance sets the expectations under which model risk management operates.

Inside ISO/IEC 38507

Scope as governance guidance
ISO/IEC 38507 is published by ISO and IEC as guidance addressed to governing bodies (such as boards and equivalent oversight groups) on the governance implications of the organization's use of AI. It is a standard oriented toward governance rather than a binding law, and it typically frames AI oversight within broader IT governance concepts.
Relationship to the ISO/IEC 38500 governance family
The standard is commonly positioned as an extension of governance thinking associated with the ISO/IEC 38500 family for governance of IT, applying those governance perspectives to the specific context of AI use rather than introducing a standalone management system.
Governing body focus, not operational control design
It concentrates on what those who govern an organization should consider, direct, and monitor regarding AI, rather than prescribing detailed operational or technical control implementations. In that sense it sits closer to AI governance (oversight, accountability, and direction) than to the measurement and control activities associated with model risk management.
Consideration of risks, obligations, and impacts from AI use
The guidance directs governing bodies to consider matters that can arise from adopting AI, which may include accountability, risk oversight, and the organizational implications of AI decision-making, so that oversight is informed rather than delegated by default.
Distinction from a certifiable management system standard
It is generally understood as guidance for governing bodies and is distinct in purpose from a management system standard such as ISO/IEC 42001, which is oriented toward establishing an AI management system. The two address different layers and should not be treated as interchangeable.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 38507.

Does ISO/IEC 38507 tell my organization how to build or validate AI models?
No. As commonly understood, ISO/IEC 38507 addresses the governance implications of using AI for the governing body of an organization, not the technical practice of model development, validation, or verification. It is oriented toward directors and senior leadership considering their oversight responsibilities when AI is adopted, rather than toward data scientists or model risk teams performing hands-on lifecycle work. Organizations frequently err by expecting it to supply engineering controls or validation methodologies; those needs are typically addressed through other instruments and internal frameworks. Confirm the precise scope against the published standard before relying on it.
Is ISO/IEC 38507 a management system standard that I can be certified against like ISO/IEC 42001?
These should not be conflated. ISO/IEC 42001 is commonly described as an AI management system standard, whereas ISO/IEC 38507 is generally positioned as governance guidance aimed at the governing body's oversight of AI use. They serve related but distinct purposes: one concerns the management system an organization operates, the other concerns how those at the top direct and monitor AI adoption. Whether any particular certification pathway exists should be verified against the standard's own stated status and the relevant certification bodies rather than assumed.
Who inside the organization is the intended audience for applying this guidance?
The guidance is typically framed for the governing body and those advising it, meaning boards, directors, and senior leaders accountable for oversight. In practice, second-line functions such as risk and compliance, and internal audit as a third line, often help translate governance expectations into operational activity, but the primary responsibility for direction and oversight rests with the governing body. Roles and boundaries should be confirmed against your own accountability structures and the standard's stated scope.
How does this guidance relate to model risk management activities we already perform?
AI governance and model risk management overlap but remain distinct. Governance guidance of this kind concerns the organizational structures, accountability, and oversight for AI use, while model risk management concerns identifying, measuring, monitoring, and controlling risks arising from model use. In practice, governance expectations set the direction and accountability under which model risk activities operate; they do not replace those activities. Organizations commonly map governance guidance to existing risk functions rather than treating either as a substitute for the other, and the exact interface should be defined internally.
Can adopting this guidance be treated as satisfying regulatory obligations such as those in the EU AI Act or supervisory guidance?
No such equivalence should be assumed. Voluntary standards, regulatory guidance, and binding law are different in nature and jurisdiction, and a governance standard does not by itself demonstrate compliance with any specific legal or supervisory instrument. Whether adoption supports a compliance narrative depends on the applicable regime and how obligations are scoped. Organizations typically treat governance guidance as one input among several, and map it explicitly to the requirements of whatever framework actually applies to them.
What are the practical limitations to keep in mind when using this guidance?
Because it is oriented toward governance and oversight rather than technical or operational controls, it will not on its own provide validation procedures, monitoring thresholds, or engineering safeguards. It is also intended to help the governing body direct and monitor AI use, so it should be understood as a means of reducing and managing risk rather than eliminating it. Definitions and expectations in this area continue to evolve, and sector-specific meanings may differ, so the guidance should be applied alongside other instruments and interpreted against your own regulatory and operational context.

Common misconceptions

ISO/IEC 38507 is a legal requirement that organizations must comply with.
It is a voluntary standard issued by ISO and IEC providing governance guidance, not binding law. Its authority derives from adoption, not statutory obligation, and it does not by itself impose regulatory duties on an organization.
ISO/IEC 38507 and ISO/IEC 42001 are alternatives that cover the same ground.
They serve different purposes. ISO/IEC 38507 is typically framed as governance guidance for governing bodies, while ISO/IEC 42001 is oriented toward an AI management system. They address different layers of oversight and management and should not be conflated or substituted for one another.
Following ISO/IEC 38507 provides a technical framework for validating models or eliminating AI-related risk.
The standard focuses on governance implications for those who direct and oversee the organization, not on detailed technical validation, testing, or model risk measurement. Governance guidance can help manage and reduce risk but does not eliminate it, and it is distinct from model risk management activities.

Best practices

Treat ISO/IEC 38507 as guidance for the governing body, using it to inform how the board or equivalent oversight group directs and monitors AI use, rather than as a substitute for operational or technical controls.
Position the standard alongside, not in place of, a management system standard such as ISO/IEC 42001, clarifying which layer of oversight each addresses so responsibilities are not duplicated or left uncovered.
Locate ISO/IEC 38507 within the broader IT governance thinking of the ISO/IEC 38500 family so AI oversight is integrated with existing governance structures rather than run as an isolated exercise.
Use the standard to help governing bodies ask informed questions about accountability, risk oversight, and organizational impacts of AI, avoiding default delegation of these matters.
Document that adoption is voluntary and does not create legal compliance by itself, and separately confirm any applicable jurisdictional obligations that may apply to the organization's AI use.
Maintain a clear distinction between governance guidance and model risk management activities such as validation and monitoring, ensuring the latter are addressed through appropriate technical and control processes.