ISO/IEC 38500:2024 - Governance of IT
Evidence request list. 42 controls, 42 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Acquisition
IT acquisitions are made for valid reasons on the basis of appropriate and ongoing analysis with clear, transparent decision-making and an appropriate balance of benefits, opportunities, costs, and risks.
- Investment governance framework with thresholds and approvals
- Business cases including TCO, benefits, and risks
- Procurement records demonstrating competitive process
- Post-acquisition benefits realisation reviews
- Vendor due diligence file
- Business cases benefit-heavy with thin risk analysis
- No benefits tracking after go-live
- Sole-source acquisitions without justification
- TCO ignores end-of-life and decommissioning
Clause 1-3: Introduction and Terms
Guiding principles for governing bodies on effective, efficient, and acceptable use of IT within organizations
- IT governance charter and committee terms of reference
- Board IT dashboard and reporting pack
- IT strategy document aligned with business strategy
- Conformance and performance review minutes
- Risk appetite and ethical conduct policy
- Board lacks IT-fluent members
- Evaluate, direct, monitor cycle not formalised
- Conformance reporting absent or thin
- Risk appetite for IT not articulated
References to ISO 37000 and other governance frameworks
- IT governance charter and committee terms of reference
- Board IT dashboard and reporting pack
- IT strategy document aligned with business strategy
- Conformance and performance review minutes
- Risk appetite and ethical conduct policy
- Board lacks IT-fluent members
- Evaluate, direct, monitor cycle not formalised
- Conformance reporting absent or thin
- Risk appetite for IT not articulated
IT governance terminology including governing body, management, IT, and stakeholder
- IT governance charter and committee terms of reference
- Board IT dashboard and reporting pack
- IT strategy document aligned with business strategy
- Conformance and performance review minutes
- Risk appetite and ethical conduct policy
- Board lacks IT-fluent members
- Evaluate, direct, monitor cycle not formalised
- Conformance reporting absent or thin
- Risk appetite for IT not articulated
Clause 4: IT Governance Model
Three tools for governing body: Principles, a Model showing main governance tasks, and a Framework
- IT governance charter and committee terms of reference
- Board IT dashboard and reporting pack
- IT strategy document aligned with business strategy
- Conformance and performance review minutes
- Risk appetite and ethical conduct policy
- Board lacks IT-fluent members
- Evaluate, direct, monitor cycle not formalised
- Conformance reporting absent or thin
- Risk appetite for IT not articulated
Governance task of evaluating current and future use of IT including proposals and ongoing operations
- IT governance charter and committee terms of reference
- Board IT dashboard and reporting pack
- IT strategy document aligned with business strategy
- Conformance and performance review minutes
- Risk appetite and ethical conduct policy
- Board lacks IT-fluent members
- Evaluate, direct, monitor cycle not formalised
- Conformance reporting absent or thin
- Risk appetite for IT not articulated
Governance task of directing preparation and implementation of plans and policies to ensure IT use meets business objectives
- IT governance charter and committee terms of reference
- Board IT dashboard and reporting pack
- IT strategy document aligned with business strategy
- Conformance and performance review minutes
- Risk appetite and ethical conduct policy
- Board lacks IT-fluent members
- Evaluate, direct, monitor cycle not formalised
- Conformance reporting absent or thin
- Risk appetite for IT not articulated
Governance task of monitoring IT performance through appropriate measurement systems to ensure conformance
- IT governance charter and committee terms of reference
- Board IT dashboard and reporting pack
- IT strategy document aligned with business strategy
- Conformance and performance review minutes
- Risk appetite and ethical conduct policy
- Board lacks IT-fluent members
- Evaluate, direct, monitor cycle not formalised
- Conformance reporting absent or thin
- Risk appetite for IT not articulated
Clause 5: Principles of IT Governance (Principles 1-4)
Clearly defining the organizational reason for existence and how IT supports it
- IT governance charter and committee terms of reference
- Board IT dashboard and reporting pack
- IT strategy document aligned with business strategy
- Conformance and performance review minutes
- Risk appetite and ethical conduct policy
- Board lacks IT-fluent members
- Evaluate, direct, monitor cycle not formalised
- Conformance reporting absent or thin
- Risk appetite for IT not articulated
Creating value aligned with organizational purpose through effective use of IT
- IT governance charter and committee terms of reference
- Board IT dashboard and reporting pack
- IT strategy document aligned with business strategy
- Conformance and performance review minutes
- Risk appetite and ethical conduct policy
- Board lacks IT-fluent members
- Evaluate, direct, monitor cycle not formalised
- Conformance reporting absent or thin
- Risk appetite for IT not articulated
Directing and engaging with organizational strategy to fulfil organizational purpose through IT integration
- IT governance charter and committee terms of reference
- Board IT dashboard and reporting pack
- IT strategy document aligned with business strategy
- Conformance and performance review minutes
- Risk appetite and ethical conduct policy
- Board lacks IT-fluent members
- Evaluate, direct, monitor cycle not formalised
- Conformance reporting absent or thin
- Risk appetite for IT not articulated
Monitoring IT performance and compliance through appropriate oversight mechanisms
- IT governance charter and committee terms of reference
- Board IT dashboard and reporting pack
- IT strategy document aligned with business strategy
- Conformance and performance review minutes
- Risk appetite and ethical conduct policy
- Board lacks IT-fluent members
- Evaluate, direct, monitor cycle not formalised
- Conformance reporting absent or thin
- Risk appetite for IT not articulated
Clause 5: Principles of IT Governance (Principles 5-8)
Ensuring clear accountability for IT decision-making and demonstrating responsibility for IT use
- IT governance charter and committee terms of reference
- Board IT dashboard and reporting pack
- IT strategy document aligned with business strategy
- Conformance and performance review minutes
- Risk appetite and ethical conduct policy
- Board lacks IT-fluent members
- Evaluate, direct, monitor cycle not formalised
- Conformance reporting absent or thin
- Risk appetite for IT not articulated
Addressing stakeholder needs in IT governance decisions and communications
- IT governance charter and committee terms of reference
- Board IT dashboard and reporting pack
- IT strategy document aligned with business strategy
- Conformance and performance review minutes
- Risk appetite and ethical conduct policy
- Board lacks IT-fluent members
- Evaluate, direct, monitor cycle not formalised
- Conformance reporting absent or thin
- Risk appetite for IT not articulated
Setting vision for IT use and fostering a culture that supports good IT governance
- IT governance charter and committee terms of reference
- Board IT dashboard and reporting pack
- IT strategy document aligned with business strategy
- Conformance and performance review minutes
- Risk appetite and ethical conduct policy
- Board lacks IT-fluent members
- Evaluate, direct, monitor cycle not formalised
- Conformance reporting absent or thin
- Risk appetite for IT not articulated
Using data responsibly for IT governance decision-making and resource allocation
- IT governance charter and committee terms of reference
- Board IT dashboard and reporting pack
- IT strategy document aligned with business strategy
- Conformance and performance review minutes
- Risk appetite and ethical conduct policy
- Board lacks IT-fluent members
- Evaluate, direct, monitor cycle not formalised
- Conformance reporting absent or thin
- Risk appetite for IT not articulated
Clause 5: Principles of IT Governance (Principles 9-12)
Considering broader societal impacts including data privacy, digital inclusion, and environmental sustainability
- IT governance charter and committee terms of reference
- Board IT dashboard and reporting pack
- IT strategy document aligned with business strategy
- Conformance and performance review minutes
- Risk appetite and ethical conduct policy
- Board lacks IT-fluent members
- Evaluate, direct, monitor cycle not formalised
- Conformance reporting absent or thin
- Risk appetite for IT not articulated
Ensuring long-term viability and resilience of IT infrastructure and services
- IT governance charter and committee terms of reference
- Board IT dashboard and reporting pack
- IT strategy document aligned with business strategy
- Conformance and performance review minutes
- Risk appetite and ethical conduct policy
- Board lacks IT-fluent members
- Evaluate, direct, monitor cycle not formalised
- Conformance reporting absent or thin
- Risk appetite for IT not articulated
Acting ethically in all IT activities and ensuring IT use aligns with organizational ethical standards
- IT governance charter and committee terms of reference
- Board IT dashboard and reporting pack
- IT strategy document aligned with business strategy
- Conformance and performance review minutes
- Risk appetite and ethical conduct policy
- Board lacks IT-fluent members
- Evaluate, direct, monitor cycle not formalised
- Conformance reporting absent or thin
- Risk appetite for IT not articulated
Understanding and managing IT-related risks with a robust risk management framework
- IT governance charter and committee terms of reference
- Board IT dashboard and reporting pack
- IT strategy document aligned with business strategy
- Conformance and performance review minutes
- Risk appetite and ethical conduct policy
- Board lacks IT-fluent members
- Evaluate, direct, monitor cycle not formalised
- Conformance reporting absent or thin
- Risk appetite for IT not articulated
Clause 6: Governance Framework
Applying the responsibility principle: ensuring key roles in IT decision-making are clearly defined and assigned
- IT governance charter and committee terms of reference
- Board IT dashboard and reporting pack
- IT strategy document aligned with business strategy
- Conformance and performance review minutes
- Risk appetite and ethical conduct policy
- Board lacks IT-fluent members
- Evaluate, direct, monitor cycle not formalised
- Conformance reporting absent or thin
- Risk appetite for IT not articulated
Applying the acquisition principle: ensuring IT investments deliver business value through careful planning
- IT governance charter and committee terms of reference
- Board IT dashboard and reporting pack
- IT strategy document aligned with business strategy
- Conformance and performance review minutes
- Risk appetite and ethical conduct policy
- Board lacks IT-fluent members
- Evaluate, direct, monitor cycle not formalised
- Conformance reporting absent or thin
- Risk appetite for IT not articulated
Applying the performance principle: ensuring IT supports the organization with appropriate services and quality levels
- IT governance charter and committee terms of reference
- Board IT dashboard and reporting pack
- IT strategy document aligned with business strategy
- Conformance and performance review minutes
- Risk appetite and ethical conduct policy
- Board lacks IT-fluent members
- Evaluate, direct, monitor cycle not formalised
- Conformance reporting absent or thin
- Risk appetite for IT not articulated
Applying the conformance principle: ensuring IT complies with all mandatory legislation and regulations
- IT governance charter and committee terms of reference
- Board IT dashboard and reporting pack
- IT strategy document aligned with business strategy
- Conformance and performance review minutes
- Risk appetite and ethical conduct policy
- Board lacks IT-fluent members
- Evaluate, direct, monitor cycle not formalised
- Conformance reporting absent or thin
- Risk appetite for IT not articulated
Applying the human behaviour principle: ensuring IT policies and practices respect human factors
- IT governance charter and committee terms of reference
- Board IT dashboard and reporting pack
- IT strategy document aligned with business strategy
- Conformance and performance review minutes
- Risk appetite and ethical conduct policy
- Board lacks IT-fluent members
- Evaluate, direct, monitor cycle not formalised
- Conformance reporting absent or thin
- Risk appetite for IT not articulated
Conformance
IT complies with all mandatory legislation and regulations and policies and practices are clearly defined, implemented, and enforced.
- Regulatory and legal obligations register for IT
- IT policy framework with version control
- Internal audit plan covering IT
- Compliance dashboard reviewed by audit committee
- Issue and remediation log
- Obligations register stale, missing recent regulations
- Policies exist but not enforced through controls
- Audit findings repeat year over year
- No mapping of policies to regulatory requirements
Continuous Improvement
The governing body periodically reviews the IT governance framework itself and adapts it as the organisation and environment evolve.
- Annual IT governance review
- Maturity assessment against ISO/IEC 38500 principles
- Action plan from review
- Benchmark against peer practice
- Charter updates reflecting improvements
- Framework adopted once and never reviewed
- Maturity assessments performed without action plans
- Benchmarking absent
- Charter outdated
Data
The governing body ensures data is treated as a strategic asset with policies for quality, ownership, ethics, and privacy.
- Data governance framework approved by the board
- Data owners assigned for key data domains
- Data quality KPIs reported quarterly
- Ethics framework for analytics and AI
- Privacy impact assessment records
- Data ownership unassigned, IT defaults to owner
- Quality measured for one domain, ignored elsewhere
- No ethics framework despite AI deployment
- PIAs missing for material processing activities
Governance Tasks
The governing body evaluates the current and future use of IT including strategies, proposals, and supply arrangements to ensure use of IT meets business requirements.
- Board agenda including IT items at least quarterly
- Pre-read materials with options and trade-offs
- Evaluation criteria for major IT proposals
- Independent advice records for complex decisions
- Decision register
- Board sees IT only when something fails
- Pre-reads omit options, present only the preferred path
- No independent challenge on major proposals
- Decisions captured in minutes only, no formal register
The governing body directs preparation and implementation of plans and policies to ensure that IT use meets business objectives and provides direction on transition into operations.
- Board-approved IT policies and standards
- Strategic directives recorded in minutes
- Implementation plans with milestones
- Risk appetite statements applying to IT
- Communication of direction to executive team
- Policies approved years ago, never refreshed
- Direction implicit, not documented
- Risk appetite not translated into IT tolerances
- Implementation plans without board-level milestones
The governing body monitors the performance of IT through appropriate measurement systems and ensures performance conforms to plans and that IT conforms to obligations and policies.
- Board dashboard with IT KPIs and KRIs
- Internal audit reports on IT
- Independent assurance reviews
- Variance analysis of plan versus actual
- Action tracking for monitoring findings
- KPIs reported but no action when red
- Audit reports filed without follow-through
- No independent assurance, internal view only
- Variance explained narratively without quantification
Human Behaviour
IT policies, practices, and decisions demonstrate respect for human behaviour including the current and evolving needs of all people in the process.
- Change management approach for IT-driven business change
- User research and feedback in IT design decisions
- Accessibility statements for digital products
- Workforce capability and training plans
- Wellbeing considerations in IT project planning
- Technology selected without user input
- Accessibility treated as legal minimum, not principle
- Change management line item but not funded
- Workforce upskilling neglected when new platforms introduced
Innovation
The governing body provides direction on adoption and evaluation of emerging technologies including artificial intelligence, ensuring opportunities are pursued with proportionate risk management.
- Innovation portfolio reviewed at board level
- AI governance policy and use case register
- Horizon scanning reports
- Sandbox or pilot governance approach
- Linkage of innovation outcomes to strategy
- AI deployed across business with no central register
- Innovation projects bypass governance
- Horizon scanning ad hoc
- No criteria to move from pilot to production
Performance
IT is fit for purpose in supporting the organisation and provides services, levels of service, and service quality required to meet current and future business requirements.
- Service level agreements for critical IT services
- Performance reports against SLAs and OLAs
- Capacity and demand forecasts
- Customer satisfaction surveys (internal users)
- Continual improvement register
- SLAs measured but not reported to governing body
- No demand forecasting, capacity reactive only
- Internal customer satisfaction not measured
- Performance dashboards focus on uptime not business outcomes
Resilience
The governing body ensures resilience of IT-enabled business services is appropriate to dependence on IT and tested regularly.
- Business impact analysis with RTO and RPO for critical services
- IT disaster recovery plans tested annually
- Crisis management playbook
- Cyber resilience scenario exercises at board level
- Recovery test results with lessons captured
- RTOs aspirational, not tested
- DR test scope narrow, excluding interdependencies
- Board exercises absent
- Lessons from tests not implemented
Responsibility
The governing body ensures that individuals and groups have clear responsibility for the use of IT and are authorised and competent to act on those responsibilities.
- Board-approved RACI for IT decisions
- Delegations of authority covering IT investment and risk
- Position descriptions naming IT accountability
- Conflict of interest declarations
- Annual review of accountability framework
- IT accountability owned by CIO only without board oversight
- Business unit IT spend with no accountability defined
- Delegations stale and not aligned with current structure
- No competence requirements for IT decision rights
Risk
The governing body ensures information security and cyber risk are governed as enterprise risks with appropriate oversight, reporting, and resourcing.
- Cyber risk in enterprise risk register
- Cyber risk appetite statement
- Board cyber briefings at least biannually
- CISO reporting line and access to board
- Independent cyber maturity assessment
- Cyber risk discussed only after incidents
- No appetite statement, tolerances unclear
- CISO reports too deep in organisation to escalate effectively
- Maturity assessments self-administered
Stakeholders
The governing body engages stakeholders on IT decisions affecting them and communicates with appropriate transparency.
- Stakeholder map for major IT initiatives
- Communication plans approved
- Public disclosures relating to IT (privacy notices, security commitments)
- Customer and employee feedback mechanisms
- Reporting on IT in annual report
- Stakeholders identified but not engaged
- Disclosures generic, not specific to material risks
- Feedback mechanisms one-way
- Annual report silent on IT
Strategy
Business strategy considers the current and future capabilities of IT and IT strategic plans satisfy current and ongoing needs of the business.
- Board-endorsed IT strategy aligned to enterprise strategy
- Capability and maturity assessment of current IT
- Multi-year IT investment roadmap
- Annual strategy review minutes
- Linkage to enterprise risk appetite
- IT strategy authored in IT, not endorsed by board
- Strategy silent on emerging technology evaluation
- Roadmap items lacking business outcome statements
- Strategy not refreshed when business strategy changes
Sustainability
Governance considers environmental and social impacts of IT use including energy, electronic waste, and equitable access.
- IT contribution to enterprise emissions reporting
- Energy efficiency targets for data centres and cloud
- E-waste management procedure
- Sustainable procurement criteria for IT
- Supplier sustainability disclosures
- IT emissions not measured separately
- Cloud spend grows with no energy lens
- E-waste handled informally
- Procurement scoring sustainability at zero weight
Third Party
Governance extends to third parties providing IT goods and services with oversight of risk, performance, and ethical conduct across the supply chain.
- Vendor risk management programme
- Tiered supplier register with criticality ratings
- Contractual security and resilience clauses
- Annual supplier assurance reviews for tier 1 vendors
- Concentration risk analysis
- Supplier register incomplete
- Critical vendors with no contract review in years
- Concentration risk hidden behind multiple brands of same parent
- No exit plan for critical suppliers
Value
The governing body ensures expected benefits from IT investments are realised, measured, and reported.
- Benefits realisation framework
- Investment portfolio dashboard with value metrics
- Post-implementation reviews
- Linkage of benefits to financial reporting
- Decommissioning of underperforming investments
- Benefits promised at approval never measured
- Reviews completed for show, no decisions made
- Failed investments continue funded
- Value metrics not in financial reporting
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.