AI Assurance Institute Logo AI Assurance Institute

The Difference Between Management and Governance

As Described in ISO/IEC 38500 and ISO/IEC 38507 Standards

The ISO/IEC 38500 family of standards provides the international reference framework for the governance of information technology and related domains. The foundational document, ISO/IEC 38500:2024 (Information technology - Governance of IT for the organization - Second edition), defines the principles and model for governance of IT. It is complemented by ISO/IEC 38507:2022 (Information technology - Governance of IT - Governance implications of the use of artificial intelligence by organizations), which applies the same governance model specifically to AI, and ISO/IEC 38505:2017 (Governance of data). Together, these standards clearly distinguish between governance (the responsibility of the governing body) and management (the responsibility of executive management). This distinction is central to effective oversight of IT, data, and AI systems and has influenced modern frameworks, including ISO/IEC 42001 (AI management systems) and the EU AI Act's Quality Management System requirements.

Conceptual Foundation in ISO/IEC 38500:2024 and ISO/IEC 38507:2022

ISO/IEC 38500:2024 defines governance of IT as 'the system by which the current and future use of information technology is directed and controlled.' It emphasizes that governance is a governing body responsibility, while management is an executive responsibility. ISO/IEC 38507:2022 applies the same model to AI, stating that the governing body is responsible for the governance implications of AI use within the organization. The standards consistently separate the two concepts as follows:

The standards stress that the governing body cannot delegate its governance responsibility - it retains ultimate accountability to stakeholders - but it must delegate operational management to executives. The separation concerns roles, decision rights, and accountability, not necessarily separation of individuals.

Key Differences: Governance vs Management in the ISO/IEC 38500 Suite

The following table summarises the primary distinctions as articulated in ISO/IEC 38500:2024 and ISO/IEC 38507:2022:

Aspect Governance (Governing Body's Role) Management (Executive Role)
Primary Focus Direction, evaluation, monitoring Planning, building, running
Level Strategic / oversight Tactical / operational
Key Activities Approve IT/AI strategy & policy; ensure alignment with enterprise objectives; evaluate performance & value delivery; oversee risk appetite & major investments; monitor compliance, risks & outcomes; hold management accountable Develop and execute IT/AI plans; manage day-to-day operations; implement controls & processes; deliver projects & services; manage risks within delegated authority; report performance & incidents to the governing body
Accountability Governing body is ultimately accountable to stakeholders for IT/AI governance Management is accountable to the governing body for execution and results
Delegation Cannot delegate governance responsibility Governing body delegates operational management to executives

Practical Application in IT, Data, and AI Contexts

The ISO/IEC 38500 suite applies the governance-management distinction consistently across IT, data, and AI domains:

Governing Body (Governance):

Management (Execution):

Example in AI context: The governing body approves an enterprise AI governance policy, risk appetite, and major AI investment decisions (governance); management develops the AI management system per ISO/IEC 42001, implements life-cycle controls, manages data governance per ISO/IEC 38505, executes model development/deployment/monitoring, and reports quarterly to the governing body on AI performance, risks, and value (management).

Edge Cases and Nuances in the Governance-Management Distinction

Key nuances and edge cases:

Common failure modes include the governing body delegating too much (losing effective oversight) or micromanaging operations - both violate the ISO/IEC 38500 balance and increase risk exposure.

Strategic Implications and Influence on Modern Frameworks

The ISO/IEC 38500 suite's governance-management distinction profoundly influences contemporary governance and management standards:

Strategic implication: Organizations that consistently apply the ISO/IEC 38500 governance-management distinction build robust, defensible accountability structures - reducing legal, ethical, operational, and reputational risk while enabling scalable, responsible deployment of IT, data, and AI systems.

Summary

In summary, the ISO/IEC 38500 suite (particularly 38500:2024 and 38507:2022) clearly distinguishes governance (governing body direction, evaluation, and monitoring) from management (executive planning, building, and running). This separation ensures strategic direction and risk appetite are set at the highest level while operational responsibility is delegated - a foundational principle that remains central to effective governance of IT, data, and artificial intelligence in modern organizations.

Content based on ISO/IEC 38500:2024, ISO/IEC 38507:2022, ISO/IEC 38505:2017, ISO/IEC 42001:2023, the EU AI Act (Regulation (EU) 2024/1689), and publicly available analyses. Always consult the latest editions of the standards and legal experts for current application and implementation.