AI Assurance Institute Logo AI Assurance Institute

Aligning AI and Business Strategies
Insights from ISO 38500, ISO 38507, and ISO 37000

AI Governance Series

Artificial intelligence continues to reshape business landscapes, demanding robust alignment between AI capabilities and organisational strategies. Effective governance frameworks are essential to ensure AI drives value while managing ethical, operational, and regulatory risks. This article draws on three complementary international standards: ISO/IEC 38500:2024 (Governance of IT for the organization), ISO/IEC 38507:2022 (Governance implications of the use of artificial intelligence by organizations), and ISO 37000:2021 (Governance of organizations - Guidance). Together, these standards provide principles for governing IT broadly, AI specifically, and organisations holistically, supporting responsible AI integration that contributes to long-term purpose and performance.

These standards remain the current editions. ISO/IEC 38500 was updated in February 2024 (third edition) to better reflect modern IT realities, including AI, cloud computing, and cybersecurity, while strengthening its alignment with ISO 37000. ISO/IEC 38507:2022 and ISO 37000:2021 continue to serve as the primary references in their respective areas. Organisations increasingly use these standards alongside AI-specific frameworks such as ISO/IEC 42001, particularly in the context of regulations such as the EU AI Act.

ISO/IEC 38500:2024 - Governance of IT for the Organization

The third edition, published in February 2024, provides guiding principles for governing bodies to ensure the effective, efficient, and acceptable use of IT. It positions IT governance as an integral part of overall organisational governance and is explicitly aligned with the principles of ISO 37000.

ISO/IEC 38507:2022 - Governance Implications of AI Use

This standard extends the principles of ISO/IEC 38500 to the specific context of artificial intelligence. It remains the dedicated high-level governance reference for AI, guiding governing bodies on issues of ethics, transparency, accountability, and risk. It complements more operational standards such as ISO/IEC 42001.

ISO 37000:2021 - Governance of Organizations - Guidance

This foundational standard sets out 11 principles for effective, ethical, and responsible organisational governance. It provides the overarching framework within which IT and AI governance should operate.

Integrating the Standards for AI-Business Alignment

ISO 37000 helps define organisational purpose and value. ISO/IEC 38500 provides the means to govern AI as a strategic form of IT. ISO/IEC 38507 adds the AI-specific layer of oversight. Together they form a coherent hierarchy: organisational governance ? IT governance ? AI governance.

Benefits, Challenges, and Broader Implications

Benefits include improved innovation, reduced risk, greater stakeholder confidence, and stronger competitive positioning through responsible AI use.

Challenges commonly include resource constraints (particularly for smaller organisations), cultural resistance, skills gaps in AI ethics and governance, and the need to integrate new practices with existing systems.

Broader implications: Consistent application of these standards helps standardise good practice, supports policy development, reduces systemic AI risks, and contributes to more equitable and trustworthy technology adoption.

Content based on ISO/IEC 38500:2024, ISO/IEC 38507:2022, and ISO 37000:2021. Always consult the official ISO publications and qualified experts for implementation guidance.