ISO 37000:2021
Evidence request list. 59 controls, 59 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Enabling
Establish clear accountability across governing body, executive, and operational layers with documented authorities.
- Delegation of authority schedule
- Role descriptions
- Performance review records
- Consequence framework
- Authority limits exceeded without escalation
- No upward reporting on delegated decisions
- Consequences inconsistent
Use accurate, reliable, and relevant data to inform governance decisions with documented decision trails.
- Board paper standard
- Data quality assessment
- Decision register
- Information policy
- Late or incomplete papers
- Decisions not formally recorded
- No data lineage
Demonstrate ethical leadership and tone from the top that drives values-based behaviour throughout the organization.
- Values statement
- Leadership messages
- Culture assessment
- Behavioural standards documentation
- Values not lived by leaders
- No behavioural measurement
- Ethical breaches not visible to board
Provide structured oversight of management execution, performance, and risk by the governing body.
- Board and committee charters
- Annual board calendar
- Management reports
- Action tracker
- Committee remits overlap
- No dedicated risk oversight
- Management reports lack assurance
Establish risk appetite and tolerance aligned with strategy and oversee risk holistically.
- Risk appetite statement
- Risk dashboard
- Emerging risk register
- Board risk committee minutes
- Risk appetite qualitative only
- No emerging risk scanning
- Appetite not cascaded
Integrate social, environmental, and economic responsibilities into governance and decisions.
- ESG strategy
- Sustainability KPIs
- Annual ESG disclosure
- Independent assurance over ESG data
- ESG strategy disconnected from core strategy
- Metrics unverified
- No board ESG accountability
Identify, prioritize, and engage stakeholders to inform decisions and maintain legitimacy.
- Stakeholder register
- Engagement strategy
- Materiality outputs
- Decision papers citing stakeholder input
- Stakeholders identified but not engaged
- No prioritization criteria
- Feedback ignored by board
Govern for long-term viability including financial, operational, and reputational resilience.
- Viability statement
- Stress test results
- BCP and crisis plans
- Reputational risk register
- Stress testing financial only
- No reputational scenarios
- Resilience siloed in operations
Enabling Principles
Governing body exercises effective oversight over management's execution of strategy, risk, and performance.
- Board charter
- Board meeting agendas and minutes
- Management reporting pack
- Independent director attestations
- Board acts as rubber stamp
- No structured oversight calendar
- Management reports lack assurance
Establish clear accountability for decisions, actions, and outcomes at governing body, management, and operational levels.
- Delegation of authority matrix
- Role descriptions
- Board and executive evaluation reports
- Accountability statements
- Authority limits unclear
- No upward accountability for delegated decisions
- Performance not tied to governance outcomes
Identify, prioritize, and engage stakeholders to inform governance decisions and maintain trust.
- Stakeholder register
- Engagement calendar
- Materiality assessment
- Stakeholder feedback log
- Stakeholder list static and outdated
- One-way communication only
- No feedback into board decisions
Demonstrate ethical leadership and tone from the top that reflects organizational values and purpose.
- Board and executive code of ethics
- Tone-from-the-top communications
- Culture assessment results
- Leadership development records
- Code exists but unenforced
- Culture surveys not actioned
- Leadership behaviour not measured
Base governance decisions on accurate, timely, and relevant data with documented decision processes.
- Board information pack standards
- Decision register
- Data quality controls
- Source documentation
- Board papers too voluminous to absorb
- No data lineage to decisions
- Verbal decisions undocumented
Govern risk holistically including risk appetite, tolerance, and integration with strategy execution.
- Risk appetite statement
- Enterprise risk register
- Board risk committee charter
- Risk reporting pack
- Risk appetite not quantified
- Risks managed in silos
- No emerging risk scanning
Account for social, environmental, and economic impacts in governance decisions consistent with sustainable development.
- Sustainability policy
- ESG materiality matrix
- Annual sustainability report
- Impact measurement framework
- ESG treated as compliance not strategy
- No board ESG competence
- Greenwashing risk uncontrolled
Govern for long-term viability balancing performance, resilience, and adaptability over time.
- Long-term viability statement
- Scenario analysis outputs
- Business continuity plan
- Capital adequacy assessment
- Viability assessed only annually
- No stress testing of strategy
- Resilience treated as IT only
Foundational
Articulate a clear purpose that anchors governance choices and explains why the organization exists for stakeholders.
- Written purpose statement
- Board resolution
- Internal and external communications
- Onboarding materials referencing purpose
- Purpose conflated with vision or mission
- Purpose not used in decisions
- No periodic reaffirmation
Set, approve, and periodically review strategy that translates purpose into measurable objectives and resource decisions.
- Approved strategy document
- Objective cascade
- Annual strategy review minutes
- Resource allocation plan
- Strategy not refreshed
- No link to capital allocation
- Cascade stops at executive level
Generate and protect value for the organization and stakeholders over short, medium, and long-term time frames.
- Value generation framework
- Multi-year plan
- Stakeholder value mapping
- Integrated KPI set
- Annual financial focus only
- No long-term value indicators
- Stakeholder value undefined
Foundational Principles
Define and articulate the organization's purpose as the primary driver of governance decisions and value generation for stakeholders.
- Documented organizational purpose
- Board minutes approving purpose
- Purpose communication plan
- Stakeholder mapping to purpose
- Purpose treated as marketing slogan rather than governance anchor
- No linkage between purpose and capital allocation
- Purpose not refreshed after material business change
Generate value for the organization and its stakeholders over short, medium, and long-term horizons through sustainable governance.
- Multi-horizon value model
- Stakeholder value map
- Integrated reporting outputs
- Capital allocation policy
- Short-term financial focus only
- No non-financial value measurement
- Stakeholder value undefined
Establish strategy that operationalizes purpose, allocates resources, and addresses risks and opportunities across time horizons.
- Board-approved strategy document
- Strategic objectives cascade
- Strategy-risk register linkage
- Annual strategy review minutes
- Strategy disconnected from purpose
- No periodic strategy refresh
- Risk appetite not aligned with strategy
Governance Foundations
Ethical behavior - acting with integrity, honesty, equity, and social responsibility. Control from ISO 37000:2021 framework, domain: Governance Foundations.
- Code of ethics
- Accountability charter
- Disclosure policy
- Stakeholder rights register
- Code not enforced at executive level
- Disclosures not timely
- Stakeholder rights not mapped
Accountability - being answerable for decisions and actions to stakeholders. Control from ISO 37000:2021 framework, domain: Governance Foundations.
- Code of ethics
- Accountability charter
- Disclosure policy
- Stakeholder rights register
- Code not enforced at executive level
- Disclosures not timely
- Stakeholder rights not mapped
Transparency - disclosing information to enable informed decision-making by stakeholders. Control from ISO 37000:2021 framework, domain: Governance Foundations.
- Code of ethics
- Accountability charter
- Disclosure policy
- Stakeholder rights register
- Code not enforced at executive level
- Disclosures not timely
- Stakeholder rights not mapped
Rule of law - compliance with laws, regulations, and governance codes. Control from ISO 37000:2021 framework, domain: Governance Foundations.
- Code of ethics
- Accountability charter
- Disclosure policy
- Stakeholder rights register
- Code not enforced at executive level
- Disclosures not timely
- Stakeholder rights not mapped
Rights of stakeholders - respecting and protecting stakeholder rights. Control from ISO 37000:2021 framework, domain: Governance Foundations.
- Code of ethics
- Accountability charter
- Disclosure policy
- Stakeholder rights register
- Code not enforced at executive level
- Disclosures not timely
- Stakeholder rights not mapped
Operational
Obtain independent assurance over governance, risk, controls, and reported information through combined assurance.
- Internal audit plan
- External audit reports
- Combined assurance map
- Assurance findings tracker
- Assurance silos
- Findings unresolved
- No combined view to board
Identify, declare, and manage conflicts of interest with transparent recusal and decisioning.
- COI policy
- Disclosure register
- Recusal minutes
- Related party register
- Disclosures stale
- Recusals undocumented
- Related party transactions not approved
Maintain a governing body with appropriate skills, independence, diversity, and tenure for current and future needs.
- Skills matrix
- Independence assessment
- Succession plan
- Diversity policy
- Composition static
- No board renewal plan
- Diversity treated as gender only
Evaluate governing body and committee performance to drive continuous improvement.
- Evaluation methodology
- Annual evaluation outputs
- Triennial external review
- Director development plans
- Self-assessment only
- Findings not actioned
- No external benchmarking
Govern executive and board remuneration aligned to purpose, strategy, performance, and stakeholder expectations.
- Remuneration policy
- Scorecards
- Committee minutes
- Annual remuneration disclosure
- Short-term focus
- No malus or clawback
- Disclosure incomplete
Provide balanced, transparent, and timely reporting on performance, prospects, and governance to stakeholders.
- Integrated annual report
- Disclosure controls policy
- Materiality assessment
- Reporting calendar
- Selective disclosure
- No materiality process
- Reports lack forward-looking content
Compose governing body with appropriate skills, independence, diversity, and capacity to discharge duties.
- Board skills matrix
- Independence declarations
- Diversity policy and metrics
- Succession plan
- Skills matrix not refreshed
- Independence assessed by tenure only
- No diversity targets
Evaluate and continuously improve governing body effectiveness through structured reviews and development.
- Annual board evaluation report
- Director induction program
- Continuing education log
- Evaluation action plan
- Self-assessment only no external review
- Evaluation findings not actioned
- No induction for new directors
Identify, disclose, and manage conflicts of interest at all governance levels.
- Conflicts of interest policy
- Annual disclosure declarations
- Recusal records in minutes
- Related party transactions log
- Annual disclosure only
- No mid-year update process
- Recusals not documented
Govern remuneration to align with purpose, strategy, performance, and stakeholder interests over appropriate horizons.
- Board-approved remuneration policy
- Performance scorecards
- Remuneration committee charter
- Annual remuneration report
- Short-term metrics dominate
- No clawback provisions
- Pay ratios undisclosed
Obtain independent assurance over governance arrangements, controls, and reported information.
- Internal audit charter and plan
- External audit reports
- Combined assurance map
- Assurance findings tracker
- No combined assurance view
- Internal audit lacks independence
- Findings not tracked to closure
Provide transparent, balanced, and timely reporting on governance, performance, and prospects to stakeholders.
- Annual integrated report
- Disclosure controls policy
- Materiality determination
- Stakeholder communication log
- Reporting emphasises positives only
- No materiality process
- Late or inconsistent reporting
Organizational Culture and Capability
Governance culture - tone at the top promoting integrity, accountability, and trust. Control from ISO 37000:2021 framework, domain: Organizational Culture and Capability.
- Tone at the top statement
- Resilience plan
- Leadership development plan
- Data governance framework
- Tone not measured at working level
- Resilience plan untested
- Data quality not governed
Organizational resilience - capacity to anticipate, respond to, and recover from disruptions. Control from ISO 37000:2021 framework, domain: Organizational Culture and Capability.
- Tone at the top statement
- Resilience plan
- Leadership development plan
- Data governance framework
- Tone not measured at working level
- Resilience plan untested
- Data quality not governed
Human governance - leadership development, succession, and talent management. Control from ISO 37000:2021 framework, domain: Organizational Culture and Capability.
- Tone at the top statement
- Resilience plan
- Leadership development plan
- Data governance framework
- Tone not measured at working level
- Resilience plan untested
- Data quality not governed
Data governance and information management for informed decision-making. Control from ISO 37000:2021 framework, domain: Organizational Culture and Capability.
- Tone at the top statement
- Resilience plan
- Leadership development plan
- Data governance framework
- Tone not measured at working level
- Resilience plan untested
- Data quality not governed
Oversight and Assurance
Governing body effectiveness - composition, independence, competence, and commitment. Control from ISO 37000:2021 framework, domain: Oversight and Assurance.
- Board composition matrix
- Delegation of authority
- Internal control framework
- Board evaluation report
- Independence criteria not enforced
- Delegation thresholds unclear
- Board evaluation light
Delegation and oversight of management - clear mandates with accountability. Control from ISO 37000:2021 framework, domain: Oversight and Assurance.
- Board composition matrix
- Delegation of authority
- Internal control framework
- Board evaluation report
- Independence criteria not enforced
- Delegation thresholds unclear
- Board evaluation light
Internal control and assurance - systems for managing risks and ensuring compliance. Control from ISO 37000:2021 framework, domain: Oversight and Assurance.
- Board composition matrix
- Delegation of authority
- Internal control framework
- Board evaluation report
- Independence criteria not enforced
- Delegation thresholds unclear
- Board evaluation light
Monitoring and evaluation - regular review of governance effectiveness. Control from ISO 37000:2021 framework, domain: Oversight and Assurance.
- Board composition matrix
- Delegation of authority
- Internal control framework
- Board evaluation report
- Independence criteria not enforced
- Delegation thresholds unclear
- Board evaluation light
Performance
Adapt governance arrangements in response to context changes, performance feedback, and emerging issues.
- Horizon scan
- Lessons learned register
- Governance change log
- Crisis after-action reviews
- Reactive change only
- Lessons not captured
- No systematic scanning
Measure governance outcomes including value, ethics, and stakeholder trust to drive accountability and improvement.
- Governance KPI set
- Annual outcome report
- Improvement plan
- Trust indicators
- No outcome metrics
- Improvement reactive only
- Trust not measured
Define, measure, and review governance outcomes to demonstrate value creation and continuous improvement.
- Governance KPI dashboard
- Annual governance review
- Benchmarking studies
- Improvement action log
- No outcome metrics defined
- Improvement actions not tracked
- No external benchmarking
Adapt governance arrangements in response to internal changes, external context, and lessons learned.
- Governance change log
- Lessons learned register
- Horizon scan reports
- Board reflection notes
- Governance reviewed only after incident
- No structured horizon scanning
- Lessons not captured
Purpose and Value Generation
Defining organizational purpose aligned with stakeholder expectations. Control from ISO 37000:2021 framework, domain: Purpose and Value Generation.
- Purpose statement
- Value creation model
- Stakeholder engagement plan
- Sustainability report
- Purpose not operationalized
- Value model not integrated with strategy
- Stakeholder engagement reactive
Value generation for the organization and stakeholders over time. Control from ISO 37000:2021 framework, domain: Purpose and Value Generation.
- Purpose statement
- Value creation model
- Stakeholder engagement plan
- Sustainability report
- Purpose not operationalized
- Value model not integrated with strategy
- Stakeholder engagement reactive
Stakeholder inclusiveness - understanding and responding to stakeholder interests. Control from ISO 37000:2021 framework, domain: Purpose and Value Generation.
- Purpose statement
- Value creation model
- Stakeholder engagement plan
- Sustainability report
- Purpose not operationalized
- Value model not integrated with strategy
- Stakeholder engagement reactive
Sustainable development - integrating economic, social, and environmental considerations. Control from ISO 37000:2021 framework, domain: Purpose and Value Generation.
- Purpose statement
- Value creation model
- Stakeholder engagement plan
- Sustainability report
- Purpose not operationalized
- Value model not integrated with strategy
- Stakeholder engagement reactive
Strategy and Direction
Strategy formulation aligned with organizational purpose and stakeholder expectations. Control from ISO 37000:2021 framework, domain: Strategy and Direction.
- Strategic plan
- Risk governance charter
- Resource allocation framework
- Performance scorecard
- Strategy not stress-tested
- Risk governance not board-led
- Resource allocation opaque
Risk-based thinking - identifying and managing risks to strategic objectives. Control from ISO 37000:2021 framework, domain: Strategy and Direction.
- Strategic plan
- Risk governance charter
- Resource allocation framework
- Performance scorecard
- Strategy not stress-tested
- Risk governance not board-led
- Resource allocation opaque
Resource allocation - ensuring resources are deployed to achieve strategic priorities. Control from ISO 37000:2021 framework, domain: Strategy and Direction.
- Strategic plan
- Risk governance charter
- Resource allocation framework
- Performance scorecard
- Strategy not stress-tested
- Risk governance not board-led
- Resource allocation opaque
Performance-based governance - setting measurable objectives and monitoring outcomes. Control from ISO 37000:2021 framework, domain: Strategy and Direction.
- Strategic plan
- Risk governance charter
- Resource allocation framework
- Performance scorecard
- Strategy not stress-tested
- Risk governance not board-led
- Resource allocation opaque
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.