ISO/IEC 38507 — Governance of the Use of AI

In an organization that uses AI, what is the governing body — the board and executive leadership — accountable for?

In the previous article, ISO/IEC 5338's decision management referenced "gates" and pointed to ISO/IEC 38507. Responsibility for setting and overseeing those gates sits with the governing body, and ISO/IEC 38507:2022 is the guidance standard that addresses that role. This page sets out what responsibilities and policy considerations ISO/IEC 38507 puts to the governing body of an organization that uses AI, and how that connects to the ISO/IEC 42001 management system.

Here the "governing body" is the person or group that directs and oversees an organization and is accountable for its results. A board is the typical example, but depending on the organization the role can fall to executive leadership, a steering committee, or a representative. ISO/IEC 38507 is a guidance standard for that governing body — not a certification-requirements standard like ISO/IEC 42001. Its focus, as the title says, is the governance implications of the use of AI by organizations.

Scope note

This overview is based on the published text of ISO/IEC 38507:2022, read alongside the ISO/IEC 38500 governance series and ISO/IEC 42001:2023. Where a term could be ambiguous, the standard's wording is used. For formal citation or document submission, refer to the official standard text.

What is ISO/IEC 38507?

ISO/IEC 38507:2022, published in April 2022, addresses the governance implications of an organization's use of AI. Distinctively, it was written jointly by SC 40 (IT governance) and SC 42 (artificial intelligence) — so it treats an organization's use of AI from the standpoint of the ISO/IEC 38500 IT-governance family.

To understand it, you first have to separate "governance" from "management." In the definitions of ISO/IEC 38500 and ISO 37000, governance is the system that directs and oversees an organization and is accountable for achieving its purpose, while management is the execution that efficiently meets objectives within the direction and policy governance sets. ISO/IEC 38507 centers on the former, not the latter — its emphasis is not the technology that makes up an AI system, but the governance that people perform over the organization's use of AI.

Its starting premise is simple: AI is a powerful tool, and its use can bring new risks, responsibilities, and obligations along with new opportunities. The standard frames it this way — AI is not in itself good or evil, fair or biased, ethical or unethical, but its use can be evaluated in those terms. So the governing body has to responsibly oversee not the AI technology itself, but how the organization uses AI. (This maps directly onto the "Govern" function of the NIST AI Risk Management Framework, and onto the board-level accountability and human-oversight duties the EU AI Act places on organizations.)

Key point 1 — Using AI does not delegate the governing body's accountability

Even when AI automates a decision, accountability for that decision stays with the governing body. This accountability cannot be delegated.

ISO/IEC 38507's core message is clear in Clause 4: the governing body is accountable for all of the organization's activities, and that accountability cannot be delegated. Authority and tasks can be delegated throughout the organization, and an AI system may carry out some of them — but accountability for the results stays with the governing body. Whether a decision is partly or fully automated does not change this.

What the standard especially warns against here is anthropomorphising AI. Over-attributing human traits — thought, emotion, judgment, morality — to an AI system invites the misreading that responsibility lies with the system, as in "the system made that decision." ISO/IEC 38507 stresses that the governing body must not deflect responsibility onto the AI system but recognize and manage its responsibility for the use of AI. Where a problem arises from inadequate care, direction, training, oversight, or enforcement, members of the governing body can bear that responsibility.

So what should the governing body do? Clause 4.3 sets out four things to review and strengthen for the use of AI, corresponding to ISO/IEC 38500's evaluate-direct-monitor model:

ActivityWhat it means in an AI context
DirectionSetting the direction of AI use through policy, strategy, resource allocation, codes of ethics, values, and statements of purpose
OversightJudging AI's value and risk appetite, and ensuring assurance over implementation, monitoring, measurement, and decision-making
EvaluationWeighing internal and external factors, present and future threats and opportunities, performance achieved, the effectiveness of governance mechanisms, and the decisions made
ReportingDemonstrating to stakeholders that governance over the use of AI is working effectively

This accountability does not apply only to a particular lifecycle stage. ISO/IEC 38507 describes it as beginning with the review of AI's potential impact and the setting of business strategy, running through project stages (procurement, implementation, configuration, deployment, testing) all the way to retirement. It also covers operational change, the AI system's learning, behavior, decisions, and outputs, stakeholder impact, security controls, and the handling of knowledge and data at disposal. Responsibility follows AI not just "at adoption" but "throughout its use, and through its end."

Using AI also tests the governing body's own competence. The standard suggests strengthening members' AI-related competence, increasing the review cadence for IT and AI use in particular, updating the criteria for scanning the internal and external environment, and establishing or reinforcing subcommittees for strategy, risk, audit, and ethics. Which structure to choose is up to the organization's needs; ISO/IEC 38507 mandates no particular model.

Key point 2 — Three ways AI differs from conventional IT

ISO/IEC 38507 names three things that set AI apart from conventional IT: decision automation, data-driven problem-solving, and adaptiveness.

Why might existing governance fall short? In Clause 5, ISO/IEC 38507 names three characteristics that distinguish AI from other technology from a governance standpoint:

  • Decision automation — modern AI, especially ML-based systems, usually expresses output as a probability (for example, "97% probability this part fails to meet the quality requirement"). The more important shift is that an AI system can move beyond presenting options for action to executing the action without human intervention. The standard names this boundary as a key matter the governing body must consider.
  • Data-driven problem-solving — traditional software has people design and program the logic steps directly, while AI infers results from data. So the quality of the training data drives the quality of the result.
  • Adaptive systems — some AI systems adjust their internal model through retraining or continuous learning in operation, so over time they can produce different outputs for the same input. You cannot assume the way an AI system behaved at initial validation stays fixed throughout its operating life.

The implication for governance is clear: you cannot expect from AI the common sense and contextual understanding you take for granted when delegating work to a person. As the standard's example has it, "hold off on repayment until after the holiday" is enough for a human officer but too imprecise for an AI system to execute correctly. So existing instructions and controls built around people can be hard to apply to an AI system as-is, and in some cases their control effect can weaken.

At the same time, ISO/IEC 38507 stresses balance. AI can also reduce existing risk — cutting errors in repetitive work, or sustaining attention on rare anomalies a person would struggle to watch for continuously. So the governing body has to adjust its risk assessment with a view to both the risk AI newly creates and the risk it reduces.

Key point 3 — The AI use policy: six areas governance must examine

The body of ISO/IEC 38507 (Clause 6) sets out six policy areas governance should review and reinforce to handle the use of AI.

Direction and control that suited an organization not using AI may not be enough for one that does. So ISO/IEC 38507 guides the governing body to review and reinforce existing governance mechanisms for the use of AI, naming six policy areas to examine:

AreaWhat the governing body checksClause
Oversight frameworkIs the chain of responsibility, authority, and human oversight clearly defined and agreed?6.2
Decision-makingDo automated decisions operate within allowed bounds and stay traceable?6.3
Data useAre data quality, bias, privacy, and retention managed?6.4
Culture and valuesIs AI's behavior overseen to align with the organization's values?6.5
ComplianceIs AI configured and maintained so it does not breach legal or voluntary obligations?6.6
RiskIs the risk AI newly creates within the risk appetite?6.7

The foundation of the six is the first, the oversight framework (6.2). ISO/IEC 38507 guides the governing body to put oversight in place commensurate with the risk of AI use, and to make individual and collective responsibility clear as a "chain of responsibility." In particular it specifies that everyone who uses AI, or is responsible for its use, should have four things: an appropriate understanding of the AI system they use; the information and training to know to whom and how to raise a concern; the authority to make or request decisions and know whom to report to; and sufficient control to intervene when needed. It makes plain that "a human can intervene" presupposes real authority and capability.

One caution: these six areas do not mean "six new departments." ISO/IEC 38507 presents them as activities governance and management carry out together, and the organization decides how to handle them within its existing governance structure. The standard also states the guidance "cannot be comprehensive" and assumes application tailored to the organization's context.

Key point 4 — Decision governance and data governance

The crux is to keep the boundary of human responsibility clear even for automated decisions, and to confirm and oversee, at the governance level, that the data used by AI is good enough for its intended purpose.

Of the six areas, the two most affected by the use of AI are decision-making and data.

Decision governance (6.3). The principle that authority and responsibility can be delegated but accountability stays with the governing body becomes concrete here. Regardless of automation, ISO/IEC 38507 recommends adjusting the decision policy so that a person or group is clearly responsible for delegated decisions. The governing body has to monitor the types of decisions and outputs an automated system produces and direct appropriate controls so the system operates within allowed bounds. Those controls have to let the governing body confirm whether decisions align with organizational policy, and what the exceptions are. This is the governance-level basis for understanding the "gates" mentioned in ISO/IEC 5338 — the approval points that major decisions such as retirement, refactoring, and updating have to pass.

The standard especially stresses defining human accountability clearly for automated decisions and assigning it to a person with appropriate authority and tools, who can take corrective action when a problem arises. It also specifies that all stakeholders should have a means to identify and report non-compliant behavior or inappropriate decision outcomes, and to receive a meaningful and timely response.

Data governance (6.4). The governing body has to document the obligations for data acquisition and provision, privacy and security, and retention and disposal, and obtain confirmation from management that data quality is sufficient for the intended use. ISO/IEC 38507 names as governance considerations the data design choices, collection, preparation (annotation, labeling, cleaning, enrichment, aggregation), explicit statement of assumptions, advance assessment of availability/quality/quantity/suitability, bias checks, and identification of data gaps.

The standard also makes one thing clear: though it is commonly called "AI bias," bias is not something the AI system creates on its own — it arises or is amplified through data and conditions that people design, collect, process, and operate. An AI system trained on past data can repeat past errors, or make inappropriate decisions about situations not well represented in the data. For data use specifics, ISO/IEC 38505-1 (data governance) can be read alongside.

Key point 5 — Culture, values, and compliance

AI has no common sense, morality, or contextual understanding. So the organization's values have to be defined explicitly, with mechanisms to oversee and review that AI operates within them.

Culture and values (6.5). An organization's culture and values are usually reflected implicitly in members' behavior and processes. But an AI system has no human contextual understanding, common sense, or moral judgment — it produces results by relying on its model, algorithm, and training data. So the governing body has to state the organization's culture and values explicitly and put in place governance mechanisms and policies to monitor and, where needed, correct the AI system's operation. ISO/IEC 38507 offers examples such as a culture-and-values committee or an ethics review board — not mandates, but options an organization can choose — including reviewing a sensitive or high-risk AI project before approval, or setting specific escalation criteria. The standard also notes AI can surface flaws in human decision-making (inappropriate bias, discrimination, weak reasoning) and give the organization a chance to improve its own processes.

Compliance (6.6). The governing body has to confirm that the AI systems the organization uses are configured and maintained to meet compliance obligations and avoid breaches. The standard's examples of breaches include a pricing mechanism that violates antitrust law, and the use of training data that infringes civil rights or is discriminatory. ISO/IEC 38507 explains that the use of AI can shift the center of gravity of the human element in compliance — meaning the focus of compliance management extends beyond human behavior at the operation stage to controls at the design, development, and implementation stages. Awareness, training, and monitoring have to be adjusted to how AI is used: raising the level and frequency of monitoring, providing a process for a person to request re-evaluation of an AI decision, and considering extra checks where AI monitors other AI. A compliance management system such as ISO 37301 can help handle security, quality, and privacy requirements within one framework.

Key point 6 — AI risk governance: appetite, sources, controls

The governing body sets and owns the risk appetite, and management manages risk within it. If ISO/IEC 23894 is "how to manage," ISO/IEC 38507 is "what to be accountable for and oversee."

ISO/IEC 38507's risk clause (6.7) makes the division of roles between the governing body and management clear: the governing body sets and owns the risk appetite, and management manages risk within it. Where ISO/IEC 23894 focuses on how to identify, assess, and treat AI risk, ISO/IEC 38507 addresses the perspective from which the governing body should be accountable for and oversee that risk. The standard presents three components of risk governance:

ComponentContent
ObjectivesWhat is being protected — not just data and assets but accountability, reputation, trust, duty of care, and strategy
Sources of riskCyber threats, capability hollowing-out, contractual/legal/environmental factors, individual autonomy, missed opportunities
ControlsExplainability, an ethics review board, management processes, technical controls, education and training

One source of risk carries an insight distinctive to ISO/IEC 38507. Agent atrophy — the erosion of individual experience and organizational expertise as AI automation reduces people's everyday decision-making opportunities — is identified as a significant risk to the organization and to society at large. The standard also balances in environmental risk (carbon emissions from the energy use of AI training and data processing, premature hardware obsolescence) and the risk of missed opportunities where a governing body is so conservative it forgoes them. On controls, it cites describing an AI system's algorithm, data, and model transparently enough, ethics review for high-risk applications, and education and training for everyone involved at every stage of AI use.

How it connects to ISO/IEC 42001

ISO/IEC 38507 was published in 2022, a year ahead of ISO/IEC 42001 (2023), so it does not cite 42001 directly. Even so, the two play different roles and connect complementarily. ISO/IEC 38507 sets the responsibilities and oversight direction of the governing body; ISO/IEC 42001 provides the management system to implement that as the organization's processes and controls.

Concretely, ISO/IEC 38507's direction and oversight perspective can be read against ISO/IEC 42001's leadership (Clause 5), AI policy (A.2), and roles and responsibilities (A.3). Its data governance (6.4) connects to ISO/IEC 42001's data controls (A.7), and its risk governance (6.7) to ISO/IEC 42001's AI risk assessment (6.1.2) and treatment (6.1.3) and to ISO/IEC 23894. In short, for an organization preparing for ISO/IEC 42001 certification, ISO/IEC 38507 is the governance-level reference explaining why and what executive leadership and the governing body have to be accountable for.

One balance is needed: where to place the AI governance role in the org structure — a dedicated new function, or linked to or integrated with existing governance, risk, quality, legal, and data functions — is for the organization's needs to decide. Neither ISO/IEC 38507 nor ISO/IEC 42001 mandates a particular model; the point is that accountability and oversight do not break.

From an audit perspective — points to watch

ISO/IEC 38507 is not a certification standard, but it is a useful reference for gauging how well leadership and governance controls are implemented in an ISO/IEC 42001 audit. The gaps that can surface include the following. (These are situations that can arise in practice, not assertions of frequency.)

  • A broken chain of responsibility — who is ultimately accountable for an AI-automated decision, and who holds the authority to intervene, is not defined or agreed, leaving responsibility ambiguous.
  • Missing governing-body-level oversight — AI use stays at the management-practice level and is not raised into a mechanism by which the governing body directs, oversees, evaluates, and reports on AI.
  • Token human oversight — it says "a human reviews," but sufficient authority, capability, and real ability to intervene are not actually in place.
  • No prior-review criteria for high-risk AI — there is no defined ethics or values review, or escalation criterion, before approving a sensitive or high-risk project.
  • AI omitted from existing governance scope — AI is not explicitly included in the scope of compliance, risk, and data governance.

In an audit, you would typically be asked to show not just policy documents but the actual outputs — AI items in governing-body minutes, the chain-of-responsibility and authority definitions, high-risk AI review and approval records, and the monitoring and exception-handling records for automated decisions.

Putting it into practice — where to start

  • Board and executive leadership — start by checking against the four governance activities: how you set the direction of AI use through policy and resources (direction), whether you assess AI's value and risk and assure delivery (oversight), whether you review internal and external factors and the effectiveness of governance (evaluation), and what you report to stakeholders (reporting).
  • An organization preparing for ISO/IEC 42001 certification — use ISO/IEC 38507 as the "basis document" for leadership (Clause 5), AI policy (A.2), and roles and responsibilities (A.3). Document the governing body's accountability and oversight mechanisms and connect the outputs to audit evidence. See our templates for the document set.
  • Risk and compliance functions — update the risk assessment to reflect both the risk AI newly creates and the risk it reduces, and include AI explicitly in compliance scope. For risk methodology see ISO/IEC 23894.

To see where this sits in the wider portfolio, the ISO/IEC AI Standards Map lays out the SC 42 standards on a single page.

Key terms at a glance

TermMeaning
governing bodyThe person or group that directs and oversees an organization and is accountable for its results (e.g. a board).
accountability vs responsibilityUltimate answerability for the result (cannot be delegated) vs responsibility for an assigned task (can be delegated).
EDM modelEvaluate, direct, monitor — ISO/IEC 38500's governance activities; 38507 adds stakeholder reporting in the AI-use context.
oversightMonitoring policy implementation and adjusting it to change (3.2.1).
risk appetiteThe amount and type of risk an organization is willing to pursue or retain (3.2.3).
anthropomorphising AIOver-attributing human traits to AI and thereby deflecting responsibility onto the system.
agent atrophyThe risk that human experience and expertise weaken as AI takes on more decisions.

The bottom line

ISO/IEC 38507:2022 makes clear that an organization cannot escape responsibility by saying "the AI decided." However much AI automates, accountability for the use of AI stays with the governing body — and it cannot be delegated. Two things matter most. First, using AI does not mean building governance anew, but it does mean reviewing and reinforcing existing policy across decision-making, data, culture, compliance, and risk to fit AI. Second, ISO/IEC 38507 is not a higher-level requirement above ISO/IEC 42001, but a guidance standard explaining the governance direction the management system should follow.

Once the governing body is accountable and the management system implements that direction as processes and controls, one question remains: who certifies the management system's conformity, and against what criteria? That is the subject of the final article: ISO/IEC 42006:2025 — Requirements for bodies providing audit and certification of AI management systems.

 


📚 SC 42 AI Standards Series

← Previous: ISO/IEC 5338:2023 — AI System Lifecycle Processes

📍 Current: ISO/IEC 38507:2022 — Governance Implications of the Use of AI

→ Next: ISO/IEC 42006:2025 — Requirements for AIMS Certification Bodies (forthcoming)

Download the SC 42 AI Standards Map