Artificial intelligence continues to reshape business landscapes, demanding robust alignment between AI capabilities and organisational strategies. Effective governance frameworks are essential to ensure AI drives value while managing ethical, operational, and regulatory risks. This article draws on three complementary international standards: ISO/IEC 38500:2024 (Governance of IT for the organization), ISO/IEC 38507:2022 (Governance implications of the use of artificial intelligence by organizations), and ISO 37000:2021 (Governance of organizations - Guidance). Together, these standards provide principles for governing IT broadly, AI specifically, and organisations holistically, supporting responsible AI integration that contributes to long-term purpose and performance.
These standards remain the current editions. ISO/IEC 38500 was updated in February 2024 (third edition) to better reflect modern IT realities, including AI, cloud computing, and cybersecurity, while strengthening its alignment with ISO 37000. ISO/IEC 38507:2022 and ISO 37000:2021 continue to serve as the primary references in their respective areas. Organisations increasingly use these standards alongside AI-specific frameworks such as ISO/IEC 42001, particularly in the context of regulations such as the EU AI Act.
ISO/IEC 38500:2024 - Governance of IT for the Organization
The third edition, published in February 2024, provides guiding principles for governing bodies to ensure the effective, efficient, and acceptable use of IT. It positions IT governance as an integral part of overall organisational governance and is explicitly aligned with the principles of ISO 37000.
- Regulatory & Strategic Perspective: Emphasises responsibility, strategy alignment, performance, conformance, and human and societal factors, with stronger attention to sustainability and cybersecurity.
- Practical Implementation: Governing bodies are expected to direct IT strategy in support of business objectives, monitor outcomes, and engage stakeholders.
- Ethical & Operational Nuances: Addresses human behaviour, ethical use, and long-term viability - considerations that are particularly relevant to AI deployments.
ISO/IEC 38507:2022 - Governance Implications of AI Use
This standard extends the principles of ISO/IEC 38500 to the specific context of artificial intelligence. It remains the dedicated high-level governance reference for AI, guiding governing bodies on issues of ethics, transparency, accountability, and risk. It complements more operational standards such as ISO/IEC 42001.
- Regulatory Depth: Covers transparency, explainability, bias mitigation, privacy, and societal impacts, requiring ongoing oversight of evolving AI systems.
- Operational Nuances: Integrates AI governance into broader IT governance processes, with emphasis on risk identification and human oversight.
- Ethical Implications: Promotes fairness, non-discrimination, and alignment with organisational values.
ISO 37000:2021 - Governance of Organizations - Guidance
This foundational standard sets out 11 principles for effective, ethical, and responsible organisational governance. It provides the overarching framework within which IT and AI governance should operate.
- Primary Principles: Purpose, value generation, strategy, oversight, and accountability.
- Enabling Principles: Leadership, data-driven decision-making, risk governance, social responsibility, viability, and stakeholder engagement.
- Practical & Ethical Nuances: Supports long-term sustainability, inclusivity, and trust - all of which are directly relevant to the societal impact of AI.
Integrating the Standards for AI-Business Alignment
ISO 37000 helps define organisational purpose and value. ISO/IEC 38500 provides the means to govern AI as a strategic form of IT. ISO/IEC 38507 adds the AI-specific layer of oversight. Together they form a coherent hierarchy: organisational governance ? IT governance ? AI governance.
- AI initiatives should support organisational purpose (ISO 37000), align with strategy (ISO/IEC 38500), and address AI-specific risks and ethical considerations (ISO/IEC 38507).
- Practical steps include establishing appropriate governance structures, conducting risk assessments, implementing ethical policies, and linking AI performance measures to business outcomes.
- This approach supports regulatory readiness (including under the EU AI Act), strengthens stakeholder trust, and enables more sustainable innovation.
Benefits, Challenges, and Broader Implications
Benefits include improved innovation, reduced risk, greater stakeholder confidence, and stronger competitive positioning through responsible AI use.
Challenges commonly include resource constraints (particularly for smaller organisations), cultural resistance, skills gaps in AI ethics and governance, and the need to integrate new practices with existing systems.
Broader implications: Consistent application of these standards helps standardise good practice, supports policy development, reduces systemic AI risks, and contributes to more equitable and trustworthy technology adoption.
Content based on ISO/IEC 38500:2024, ISO/IEC 38507:2022, and ISO 37000:2021. Always consult the official ISO publications and qualified experts for implementation guidance.