Skip to content

Evidence request lists

ISO/IEC 38500:2024 - Governance of IT

Evidence request list. 42 controls, 42 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Acquisition

38500-3.3
Principle 3: Acquisition

IT acquisitions are made for valid reasons on the basis of appropriate and ongoing analysis with clear, transparent decision-making and an appropriate balance of benefits, opportunities, costs, and risks.

Artefacts an auditor will ask for
  • Investment governance framework with thresholds and approvals
  • Business cases including TCO, benefits, and risks
  • Procurement records demonstrating competitive process
  • Post-acquisition benefits realisation reviews
  • Vendor due diligence file
Where this commonly fails
  • Business cases benefit-heavy with thin risk analysis
  • No benefits tracking after go-live
  • Sole-source acquisitions without justification
  • TCO ignores end-of-life and decommissioning

Clause 1-3: Introduction and Terms

38500-1
Scope

Guiding principles for governing bodies on effective, efficient, and acceptable use of IT within organizations

Artefacts an auditor will ask for
  • IT governance charter and committee terms of reference
  • Board IT dashboard and reporting pack
  • IT strategy document aligned with business strategy
  • Conformance and performance review minutes
  • Risk appetite and ethical conduct policy
Where this commonly fails
  • Board lacks IT-fluent members
  • Evaluate, direct, monitor cycle not formalised
  • Conformance reporting absent or thin
  • Risk appetite for IT not articulated
38500-2
Normative references

References to ISO 37000 and other governance frameworks

Artefacts an auditor will ask for
  • IT governance charter and committee terms of reference
  • Board IT dashboard and reporting pack
  • IT strategy document aligned with business strategy
  • Conformance and performance review minutes
  • Risk appetite and ethical conduct policy
Where this commonly fails
  • Board lacks IT-fluent members
  • Evaluate, direct, monitor cycle not formalised
  • Conformance reporting absent or thin
  • Risk appetite for IT not articulated
38500-3
Terms and definitions

IT governance terminology including governing body, management, IT, and stakeholder

Artefacts an auditor will ask for
  • IT governance charter and committee terms of reference
  • Board IT dashboard and reporting pack
  • IT strategy document aligned with business strategy
  • Conformance and performance review minutes
  • Risk appetite and ethical conduct policy
Where this commonly fails
  • Board lacks IT-fluent members
  • Evaluate, direct, monitor cycle not formalised
  • Conformance reporting absent or thin
  • Risk appetite for IT not articulated

Clause 4: IT Governance Model

38500-4.1
Governance model overview

Three tools for governing body: Principles, a Model showing main governance tasks, and a Framework

Artefacts an auditor will ask for
  • IT governance charter and committee terms of reference
  • Board IT dashboard and reporting pack
  • IT strategy document aligned with business strategy
  • Conformance and performance review minutes
  • Risk appetite and ethical conduct policy
Where this commonly fails
  • Board lacks IT-fluent members
  • Evaluate, direct, monitor cycle not formalised
  • Conformance reporting absent or thin
  • Risk appetite for IT not articulated
38500-4.2
Evaluate

Governance task of evaluating current and future use of IT including proposals and ongoing operations

Artefacts an auditor will ask for
  • IT governance charter and committee terms of reference
  • Board IT dashboard and reporting pack
  • IT strategy document aligned with business strategy
  • Conformance and performance review minutes
  • Risk appetite and ethical conduct policy
Where this commonly fails
  • Board lacks IT-fluent members
  • Evaluate, direct, monitor cycle not formalised
  • Conformance reporting absent or thin
  • Risk appetite for IT not articulated
38500-4.3
Direct

Governance task of directing preparation and implementation of plans and policies to ensure IT use meets business objectives

Artefacts an auditor will ask for
  • IT governance charter and committee terms of reference
  • Board IT dashboard and reporting pack
  • IT strategy document aligned with business strategy
  • Conformance and performance review minutes
  • Risk appetite and ethical conduct policy
Where this commonly fails
  • Board lacks IT-fluent members
  • Evaluate, direct, monitor cycle not formalised
  • Conformance reporting absent or thin
  • Risk appetite for IT not articulated
38500-4.4
Monitor

Governance task of monitoring IT performance through appropriate measurement systems to ensure conformance

Artefacts an auditor will ask for
  • IT governance charter and committee terms of reference
  • Board IT dashboard and reporting pack
  • IT strategy document aligned with business strategy
  • Conformance and performance review minutes
  • Risk appetite and ethical conduct policy
Where this commonly fails
  • Board lacks IT-fluent members
  • Evaluate, direct, monitor cycle not formalised
  • Conformance reporting absent or thin
  • Risk appetite for IT not articulated

Clause 5: Principles of IT Governance (Principles 1-4)

38500-5.1
Purpose

Clearly defining the organizational reason for existence and how IT supports it

Artefacts an auditor will ask for
  • IT governance charter and committee terms of reference
  • Board IT dashboard and reporting pack
  • IT strategy document aligned with business strategy
  • Conformance and performance review minutes
  • Risk appetite and ethical conduct policy
Where this commonly fails
  • Board lacks IT-fluent members
  • Evaluate, direct, monitor cycle not formalised
  • Conformance reporting absent or thin
  • Risk appetite for IT not articulated
38500-5.2
Value generation

Creating value aligned with organizational purpose through effective use of IT

Artefacts an auditor will ask for
  • IT governance charter and committee terms of reference
  • Board IT dashboard and reporting pack
  • IT strategy document aligned with business strategy
  • Conformance and performance review minutes
  • Risk appetite and ethical conduct policy
Where this commonly fails
  • Board lacks IT-fluent members
  • Evaluate, direct, monitor cycle not formalised
  • Conformance reporting absent or thin
  • Risk appetite for IT not articulated
38500-5.3
Strategy

Directing and engaging with organizational strategy to fulfil organizational purpose through IT integration

Artefacts an auditor will ask for
  • IT governance charter and committee terms of reference
  • Board IT dashboard and reporting pack
  • IT strategy document aligned with business strategy
  • Conformance and performance review minutes
  • Risk appetite and ethical conduct policy
Where this commonly fails
  • Board lacks IT-fluent members
  • Evaluate, direct, monitor cycle not formalised
  • Conformance reporting absent or thin
  • Risk appetite for IT not articulated
38500-5.4
Oversight

Monitoring IT performance and compliance through appropriate oversight mechanisms

Artefacts an auditor will ask for
  • IT governance charter and committee terms of reference
  • Board IT dashboard and reporting pack
  • IT strategy document aligned with business strategy
  • Conformance and performance review minutes
  • Risk appetite and ethical conduct policy
Where this commonly fails
  • Board lacks IT-fluent members
  • Evaluate, direct, monitor cycle not formalised
  • Conformance reporting absent or thin
  • Risk appetite for IT not articulated

Clause 5: Principles of IT Governance (Principles 5-8)

38500-5.5
Accountability

Ensuring clear accountability for IT decision-making and demonstrating responsibility for IT use

Artefacts an auditor will ask for
  • IT governance charter and committee terms of reference
  • Board IT dashboard and reporting pack
  • IT strategy document aligned with business strategy
  • Conformance and performance review minutes
  • Risk appetite and ethical conduct policy
Where this commonly fails
  • Board lacks IT-fluent members
  • Evaluate, direct, monitor cycle not formalised
  • Conformance reporting absent or thin
  • Risk appetite for IT not articulated
38500-5.6
Stakeholder engagement

Addressing stakeholder needs in IT governance decisions and communications

Artefacts an auditor will ask for
  • IT governance charter and committee terms of reference
  • Board IT dashboard and reporting pack
  • IT strategy document aligned with business strategy
  • Conformance and performance review minutes
  • Risk appetite and ethical conduct policy
Where this commonly fails
  • Board lacks IT-fluent members
  • Evaluate, direct, monitor cycle not formalised
  • Conformance reporting absent or thin
  • Risk appetite for IT not articulated
38500-5.7
Leadership

Setting vision for IT use and fostering a culture that supports good IT governance

Artefacts an auditor will ask for
  • IT governance charter and committee terms of reference
  • Board IT dashboard and reporting pack
  • IT strategy document aligned with business strategy
  • Conformance and performance review minutes
  • Risk appetite and ethical conduct policy
Where this commonly fails
  • Board lacks IT-fluent members
  • Evaluate, direct, monitor cycle not formalised
  • Conformance reporting absent or thin
  • Risk appetite for IT not articulated
38500-5.8
Data and decisions

Using data responsibly for IT governance decision-making and resource allocation

Artefacts an auditor will ask for
  • IT governance charter and committee terms of reference
  • Board IT dashboard and reporting pack
  • IT strategy document aligned with business strategy
  • Conformance and performance review minutes
  • Risk appetite and ethical conduct policy
Where this commonly fails
  • Board lacks IT-fluent members
  • Evaluate, direct, monitor cycle not formalised
  • Conformance reporting absent or thin
  • Risk appetite for IT not articulated

Clause 5: Principles of IT Governance (Principles 9-12)

38500-5.10
Social responsibility

Considering broader societal impacts including data privacy, digital inclusion, and environmental sustainability

Artefacts an auditor will ask for
  • IT governance charter and committee terms of reference
  • Board IT dashboard and reporting pack
  • IT strategy document aligned with business strategy
  • Conformance and performance review minutes
  • Risk appetite and ethical conduct policy
Where this commonly fails
  • Board lacks IT-fluent members
  • Evaluate, direct, monitor cycle not formalised
  • Conformance reporting absent or thin
  • Risk appetite for IT not articulated
38500-5.11
Viability and performance over time

Ensuring long-term viability and resilience of IT infrastructure and services

Artefacts an auditor will ask for
  • IT governance charter and committee terms of reference
  • Board IT dashboard and reporting pack
  • IT strategy document aligned with business strategy
  • Conformance and performance review minutes
  • Risk appetite and ethical conduct policy
Where this commonly fails
  • Board lacks IT-fluent members
  • Evaluate, direct, monitor cycle not formalised
  • Conformance reporting absent or thin
  • Risk appetite for IT not articulated
38500-5.12
Ethical behaviour

Acting ethically in all IT activities and ensuring IT use aligns with organizational ethical standards

Artefacts an auditor will ask for
  • IT governance charter and committee terms of reference
  • Board IT dashboard and reporting pack
  • IT strategy document aligned with business strategy
  • Conformance and performance review minutes
  • Risk appetite and ethical conduct policy
Where this commonly fails
  • Board lacks IT-fluent members
  • Evaluate, direct, monitor cycle not formalised
  • Conformance reporting absent or thin
  • Risk appetite for IT not articulated
38500-5.9
Risk governance

Understanding and managing IT-related risks with a robust risk management framework

Artefacts an auditor will ask for
  • IT governance charter and committee terms of reference
  • Board IT dashboard and reporting pack
  • IT strategy document aligned with business strategy
  • Conformance and performance review minutes
  • Risk appetite and ethical conduct policy
Where this commonly fails
  • Board lacks IT-fluent members
  • Evaluate, direct, monitor cycle not formalised
  • Conformance reporting absent or thin
  • Risk appetite for IT not articulated

Clause 6: Governance Framework

38500-6.1
Responsibility principle application

Applying the responsibility principle: ensuring key roles in IT decision-making are clearly defined and assigned

Artefacts an auditor will ask for
  • IT governance charter and committee terms of reference
  • Board IT dashboard and reporting pack
  • IT strategy document aligned with business strategy
  • Conformance and performance review minutes
  • Risk appetite and ethical conduct policy
Where this commonly fails
  • Board lacks IT-fluent members
  • Evaluate, direct, monitor cycle not formalised
  • Conformance reporting absent or thin
  • Risk appetite for IT not articulated
38500-6.2
Acquisition principle application

Applying the acquisition principle: ensuring IT investments deliver business value through careful planning

Artefacts an auditor will ask for
  • IT governance charter and committee terms of reference
  • Board IT dashboard and reporting pack
  • IT strategy document aligned with business strategy
  • Conformance and performance review minutes
  • Risk appetite and ethical conduct policy
Where this commonly fails
  • Board lacks IT-fluent members
  • Evaluate, direct, monitor cycle not formalised
  • Conformance reporting absent or thin
  • Risk appetite for IT not articulated
38500-6.3
Performance principle application

Applying the performance principle: ensuring IT supports the organization with appropriate services and quality levels

Artefacts an auditor will ask for
  • IT governance charter and committee terms of reference
  • Board IT dashboard and reporting pack
  • IT strategy document aligned with business strategy
  • Conformance and performance review minutes
  • Risk appetite and ethical conduct policy
Where this commonly fails
  • Board lacks IT-fluent members
  • Evaluate, direct, monitor cycle not formalised
  • Conformance reporting absent or thin
  • Risk appetite for IT not articulated
38500-6.4
Conformance principle application

Applying the conformance principle: ensuring IT complies with all mandatory legislation and regulations

Artefacts an auditor will ask for
  • IT governance charter and committee terms of reference
  • Board IT dashboard and reporting pack
  • IT strategy document aligned with business strategy
  • Conformance and performance review minutes
  • Risk appetite and ethical conduct policy
Where this commonly fails
  • Board lacks IT-fluent members
  • Evaluate, direct, monitor cycle not formalised
  • Conformance reporting absent or thin
  • Risk appetite for IT not articulated
38500-6.5
Human behaviour principle application

Applying the human behaviour principle: ensuring IT policies and practices respect human factors

Artefacts an auditor will ask for
  • IT governance charter and committee terms of reference
  • Board IT dashboard and reporting pack
  • IT strategy document aligned with business strategy
  • Conformance and performance review minutes
  • Risk appetite and ethical conduct policy
Where this commonly fails
  • Board lacks IT-fluent members
  • Evaluate, direct, monitor cycle not formalised
  • Conformance reporting absent or thin
  • Risk appetite for IT not articulated

Conformance

38500-3.5
Principle 5: Conformance

IT complies with all mandatory legislation and regulations and policies and practices are clearly defined, implemented, and enforced.

Artefacts an auditor will ask for
  • Regulatory and legal obligations register for IT
  • IT policy framework with version control
  • Internal audit plan covering IT
  • Compliance dashboard reviewed by audit committee
  • Issue and remediation log
Where this commonly fails
  • Obligations register stale, missing recent regulations
  • Policies exist but not enforced through controls
  • Audit findings repeat year over year
  • No mapping of policies to regulatory requirements

Continuous Improvement

38500-3.18
Governance Review and Continuous Improvement

The governing body periodically reviews the IT governance framework itself and adapts it as the organisation and environment evolve.

Artefacts an auditor will ask for
  • Annual IT governance review
  • Maturity assessment against ISO/IEC 38500 principles
  • Action plan from review
  • Benchmark against peer practice
  • Charter updates reflecting improvements
Where this commonly fails
  • Framework adopted once and never reviewed
  • Maturity assessments performed without action plans
  • Benchmarking absent
  • Charter outdated

Data

38500-3.11
Data Governance

The governing body ensures data is treated as a strategic asset with policies for quality, ownership, ethics, and privacy.

Artefacts an auditor will ask for
  • Data governance framework approved by the board
  • Data owners assigned for key data domains
  • Data quality KPIs reported quarterly
  • Ethics framework for analytics and AI
  • Privacy impact assessment records
Where this commonly fails
  • Data ownership unassigned, IT defaults to owner
  • Quality measured for one domain, ignored elsewhere
  • No ethics framework despite AI deployment
  • PIAs missing for material processing activities

Governance Tasks

38500-3.7
Evaluate Task

The governing body evaluates the current and future use of IT including strategies, proposals, and supply arrangements to ensure use of IT meets business requirements.

Artefacts an auditor will ask for
  • Board agenda including IT items at least quarterly
  • Pre-read materials with options and trade-offs
  • Evaluation criteria for major IT proposals
  • Independent advice records for complex decisions
  • Decision register
Where this commonly fails
  • Board sees IT only when something fails
  • Pre-reads omit options, present only the preferred path
  • No independent challenge on major proposals
  • Decisions captured in minutes only, no formal register
38500-3.8
Direct Task

The governing body directs preparation and implementation of plans and policies to ensure that IT use meets business objectives and provides direction on transition into operations.

Artefacts an auditor will ask for
  • Board-approved IT policies and standards
  • Strategic directives recorded in minutes
  • Implementation plans with milestones
  • Risk appetite statements applying to IT
  • Communication of direction to executive team
Where this commonly fails
  • Policies approved years ago, never refreshed
  • Direction implicit, not documented
  • Risk appetite not translated into IT tolerances
  • Implementation plans without board-level milestones
38500-3.9
Monitor Task

The governing body monitors the performance of IT through appropriate measurement systems and ensures performance conforms to plans and that IT conforms to obligations and policies.

Artefacts an auditor will ask for
  • Board dashboard with IT KPIs and KRIs
  • Internal audit reports on IT
  • Independent assurance reviews
  • Variance analysis of plan versus actual
  • Action tracking for monitoring findings
Where this commonly fails
  • KPIs reported but no action when red
  • Audit reports filed without follow-through
  • No independent assurance, internal view only
  • Variance explained narratively without quantification

Human Behaviour

38500-3.6
Principle 6: Human Behaviour

IT policies, practices, and decisions demonstrate respect for human behaviour including the current and evolving needs of all people in the process.

Artefacts an auditor will ask for
  • Change management approach for IT-driven business change
  • User research and feedback in IT design decisions
  • Accessibility statements for digital products
  • Workforce capability and training plans
  • Wellbeing considerations in IT project planning
Where this commonly fails
  • Technology selected without user input
  • Accessibility treated as legal minimum, not principle
  • Change management line item but not funded
  • Workforce upskilling neglected when new platforms introduced

Innovation

38500-3.13
Innovation and Emerging Technology

The governing body provides direction on adoption and evaluation of emerging technologies including artificial intelligence, ensuring opportunities are pursued with proportionate risk management.

Artefacts an auditor will ask for
  • Innovation portfolio reviewed at board level
  • AI governance policy and use case register
  • Horizon scanning reports
  • Sandbox or pilot governance approach
  • Linkage of innovation outcomes to strategy
Where this commonly fails
  • AI deployed across business with no central register
  • Innovation projects bypass governance
  • Horizon scanning ad hoc
  • No criteria to move from pilot to production

Performance

38500-3.4
Principle 4: Performance

IT is fit for purpose in supporting the organisation and provides services, levels of service, and service quality required to meet current and future business requirements.

Artefacts an auditor will ask for
  • Service level agreements for critical IT services
  • Performance reports against SLAs and OLAs
  • Capacity and demand forecasts
  • Customer satisfaction surveys (internal users)
  • Continual improvement register
Where this commonly fails
  • SLAs measured but not reported to governing body
  • No demand forecasting, capacity reactive only
  • Internal customer satisfaction not measured
  • Performance dashboards focus on uptime not business outcomes

Resilience

38500-3.15
Resilience and Continuity

The governing body ensures resilience of IT-enabled business services is appropriate to dependence on IT and tested regularly.

Artefacts an auditor will ask for
  • Business impact analysis with RTO and RPO for critical services
  • IT disaster recovery plans tested annually
  • Crisis management playbook
  • Cyber resilience scenario exercises at board level
  • Recovery test results with lessons captured
Where this commonly fails
  • RTOs aspirational, not tested
  • DR test scope narrow, excluding interdependencies
  • Board exercises absent
  • Lessons from tests not implemented

Responsibility

38500-3.1
Principle 1: Responsibility

The governing body ensures that individuals and groups have clear responsibility for the use of IT and are authorised and competent to act on those responsibilities.

Artefacts an auditor will ask for
  • Board-approved RACI for IT decisions
  • Delegations of authority covering IT investment and risk
  • Position descriptions naming IT accountability
  • Conflict of interest declarations
  • Annual review of accountability framework
Where this commonly fails
  • IT accountability owned by CIO only without board oversight
  • Business unit IT spend with no accountability defined
  • Delegations stale and not aligned with current structure
  • No competence requirements for IT decision rights

Risk

38500-3.10
Information Security Governance

The governing body ensures information security and cyber risk are governed as enterprise risks with appropriate oversight, reporting, and resourcing.

Artefacts an auditor will ask for
  • Cyber risk in enterprise risk register
  • Cyber risk appetite statement
  • Board cyber briefings at least biannually
  • CISO reporting line and access to board
  • Independent cyber maturity assessment
Where this commonly fails
  • Cyber risk discussed only after incidents
  • No appetite statement, tolerances unclear
  • CISO reports too deep in organisation to escalate effectively
  • Maturity assessments self-administered

Stakeholders

38500-3.17
Stakeholder Engagement and Transparency

The governing body engages stakeholders on IT decisions affecting them and communicates with appropriate transparency.

Artefacts an auditor will ask for
  • Stakeholder map for major IT initiatives
  • Communication plans approved
  • Public disclosures relating to IT (privacy notices, security commitments)
  • Customer and employee feedback mechanisms
  • Reporting on IT in annual report
Where this commonly fails
  • Stakeholders identified but not engaged
  • Disclosures generic, not specific to material risks
  • Feedback mechanisms one-way
  • Annual report silent on IT

Strategy

38500-3.2
Principle 2: Strategy

Business strategy considers the current and future capabilities of IT and IT strategic plans satisfy current and ongoing needs of the business.

Artefacts an auditor will ask for
  • Board-endorsed IT strategy aligned to enterprise strategy
  • Capability and maturity assessment of current IT
  • Multi-year IT investment roadmap
  • Annual strategy review minutes
  • Linkage to enterprise risk appetite
Where this commonly fails
  • IT strategy authored in IT, not endorsed by board
  • Strategy silent on emerging technology evaluation
  • Roadmap items lacking business outcome statements
  • Strategy not refreshed when business strategy changes

Sustainability

38500-3.14
Sustainability and ESG of IT

Governance considers environmental and social impacts of IT use including energy, electronic waste, and equitable access.

Artefacts an auditor will ask for
  • IT contribution to enterprise emissions reporting
  • Energy efficiency targets for data centres and cloud
  • E-waste management procedure
  • Sustainable procurement criteria for IT
  • Supplier sustainability disclosures
Where this commonly fails
  • IT emissions not measured separately
  • Cloud spend grows with no energy lens
  • E-waste handled informally
  • Procurement scoring sustainability at zero weight

Third Party

38500-3.12
Third-Party and Supply Chain Governance

Governance extends to third parties providing IT goods and services with oversight of risk, performance, and ethical conduct across the supply chain.

Artefacts an auditor will ask for
  • Vendor risk management programme
  • Tiered supplier register with criticality ratings
  • Contractual security and resilience clauses
  • Annual supplier assurance reviews for tier 1 vendors
  • Concentration risk analysis
Where this commonly fails
  • Supplier register incomplete
  • Critical vendors with no contract review in years
  • Concentration risk hidden behind multiple brands of same parent
  • No exit plan for critical suppliers

Value

38500-3.16
Value and Benefits Realisation

The governing body ensures expected benefits from IT investments are realised, measured, and reported.

Artefacts an auditor will ask for
  • Benefits realisation framework
  • Investment portfolio dashboard with value metrics
  • Post-implementation reviews
  • Linkage of benefits to financial reporting
  • Decommissioning of underperforming investments
Where this commonly fails
  • Benefits promised at approval never measured
  • Reviews completed for show, no decisions made
  • Failed investments continue funded
  • Value metrics not in financial reporting
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.