Skip to content

Governance

What is Governance?

The system by which an organisation is directed and controlled. IT governance ensures that IT investments support business objectives and manage risks appropriately.

Governance

What the standards actually require on governance

Requirements naming governance across 6 standards, quoted from the control text.

ISO 37000:202132 controls

Adapt governance arrangements in response to internal changes, external context, and lessons learned.

ISO37000-7.2 · Adapting Governance

Information security governance integrates with broader enterprise governance frameworks and risk management.

27014-8.1 · Alignment with Enterprise Governance

Requirement defined in ISO/IEC 38500:2024, clause 5.10 (Risk governance). See licensed source for normative text. Implementation focus is to demonstrate conformity with the obligations of this clause through the artefacts listed in evidence_requirements.

iso-iec-38500-2024::5.10 · Risk governance

Set up an ASEAN Working Group on AI Governance to drive and oversee the technical and operational implementation of AI governance action plans in the region.

AIGE-RR-1 · Establish an ASEAN Working Group on AI Governance
HKMA SPM9 controls

HKMA SPM Corporate Governance + Internal Control + Auditing modules. CG CORPORATE GOVERNANCE MODULES: (1) CG-1 Corporate Governance of Locally Incorporated AIs - board composition + independent directors + executive accountability + governance structure + fitn...

HKMA-SPM-CG-IC-AC-Governance-Control-Audit · HKMA SPM Corporate Governance (CG-1/2/3/5/6), Internal Control (IC-1/5), Auditing (AC-G)
Solvency II9 controls

Description of governance structure, fit and proper requirements, risk management system including ORSA, internal control system, internal audit, actuarial function, outsourcing policy.

SII-P3-06 · SFCR Section B: System of Governance

Questions people ask about governance

What is Governance?
The system by which an organisation is directed and controlled. IT governance ensures that IT investments support business objectives and manage risks appropriately.
Why is Governance important for compliance?
Governance is a key concept in Governance. Understanding governance helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
What concepts are related to Governance?
Key concepts related to Governance include GRC, COBIT. Understanding these interconnected concepts provides a more comprehensive view of Governance requirements and helps organizations build holistic compliance programs.
Which compliance frameworks address Governance?
Governance appears in the requirement text of ISO 37000:2021, ISO/IEC 27014:2020, ISO/IEC 38500:2024, ASEAN Guide on AI Governance and Ethics, HKMA SPM. Across these standards we have identified 90 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Governance?
Explore our compliance framework pages to see how governance applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Governance applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.