ISO/IEC 38507:2022 PDF
Information technology — Governance of IT — Governance implications of the use of artificial intelligence by organizations
Information technology — Governance of IT — Governance implications of the use of artificial intelligence by organizations
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 28
- Дата публикации:
- 8 апреля 2022 г.
- Издание:
- ISO/IEC IS 38507 edition 1 version 1
- ICS:
- 35.020
This document provides guidance for members of the governing body of an organization to enable and govern the use of Artificial Intelligence (AI), in order to ensure its effective, efficient and acceptable use within the organization. This document also provides guidance to a wider community, including: — executive managers; — external businesses or technical specialists, such as legal or accounting specialists, retail or industrial associations, or professional bodies; — public authorities and policymakers; — internal and external service providers (including consultants); — assessors and auditors. This document is applicable to the governance of current and future uses of AI as well as the implications of such use for the organization itself. This document is applicable to any organization, including public and private companies, government entities and not-for-profit organizations. This document is applicable to an organization of any size irrespective of their dependence on data or information technologies.
Abstract
Overview
ISO/IEC 38507:2022 - Information technology - Governance of IT - Governance implications of the use of artificial intelligence by organizations - provides guidance for members of an organization’s governing body to enable and govern the use of Artificial Intelligence (AI). The standard helps ensure AI is used effectively, efficiently and acceptably across the organization and is applicable to any organization (public, private, government or not‑for‑profit) of any size. It also addresses a broader audience including executive managers, external specialists, policymakers, service providers and auditors.
Key topics and requirements
ISO/IEC 38507:2022 focuses on governance implications rather than technical implementation. Core topics covered include:
- Governance principles and accountability
- Role of the governing body in setting goals, oversight and remaining accountable for AI use.
- Maintaining governance when introducing AI
- Ensuring policies, controls and organisational structures adapt to AI adoption.
- AI system characteristics
- How AI differs from other IT (decision automation, data‑driven problem solving, adaptive systems) and implications for governance.
- AI ecosystem, benefits and constraints
- High‑level discussion of opportunities and limitations that affect organisational strategy.
- Policies to address AI use
- Guidance areas: governance oversight, decision‑making, data use, culture and values, compliance and risk.
- Risk and compliance
- Considerations for risk appetite, risk management, compliance obligations and controls specific to AI use.
- Normative references and terminology
- Aligns with ISO/IEC 38500 and ISO/IEC 22989 terminology and governance concepts.
Note: the document emphasizes governance (human decision‑making and policy) and references related standards for detailed technical controls, risk management and trustworthiness.
Practical applications and users
ISO/IEC 38507 is practical for:
- Boards and governing bodies establishing strategic direction and oversight for AI initiatives.
- Executive management integrating AI into business strategy, risk and compliance programs.
- Legal, audit and compliance teams assessing obligations and controls for AI deployment.
- IT and data leaders aligning AI projects with organisational governance and data policies.
- Consultants, assessors and policymakers designing frameworks, audits or regulation around AI use.
Typical use cases: setting AI governance frameworks, updating data governance and accountability practices, defining oversight and reporting for automated decision systems, and aligning AI initiatives with organisational ethics and compliance.
Related standards
- ISO/IEC 38500 - Governance of IT for the organization (governance principles)
- ISO/IEC 22989 - AI concepts and terminology (terminology referenced by 38507)
Keywords: ISO/IEC 38507:2022, AI governance, governance of AI, AI risk management, data governance, oversight, accountability, AI policy.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 42 - Artificial intelligence
- SKU
- ISO/IEC 38507:2022
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO/IEC 38505-1:2017
ДействующийInformation technology — Governance of IT — Governance of data — Part 1: Application of ISO/IEC 38500 to the…
Overview ISO/IEC 38505-1:2017 - Information technology - Governance of IT - Governance of data (Part 1) is a high‑level, principles‑based ISO standard that applies the governance model of ISO/IEC 385…
BS EN ISO/IEC 22989:2023
ДействующийInformation technology. Artificial intelligence. Artificial intelligence concepts and terminology.
ISO 8689-1:2000
ДействующийWater quality — Biological classification of rivers — Part 1: Guidance on the interpretation of biological qu…
Overview ISO 8689-1:2000, titled Water quality - Biological classification of rivers - Part 1: Guidance on the interpretation of biological quality data from surveys of benthic macroinvertebrates, is…
ISO/ASTM51540-04(2012)
ОтменёнStandard Practice for Use of a Radiochromic Liquid Dosimetry System (Withdrawn 2020)
Significance and Use4.1 The radiochromic liquid dosimetry system provides a means of measuring absorbed dose in materials (5-7). Under the influence of ionizing radiation, chemical reactions take pla…
ISO/ASTM51204-04
ДействующийStandard Practice for Dosimetry in Gamma Irradiation Facilities for Food Processing (Withdrawn 2013)
Significance and Use4.1 Food products may be treated with ionizing radiation, such as gamma-rays from 60Co or 137Cs sources, for numerous purposes, including control of parasites and pathogenic micro…
ISO/ASTM51431-05
ОтменёнStandard Practice for Dosimetry in Electron Beam and X-Ray (Bremsstrahlung) Irradiation Facilities for Food P…
Significance and Use4.1 Food products may be treated with acceleratorgenerated radiation (electrons and X-rays) for numerous purposes, including control of parasites and pathogenic microorganisms, in…
ISO/ASTM52628-20e1
ДействующийStandard Practice for Dosimetry in Radiation Processing
1.1 This practice describes the basic requirements that apply when making absorbed dose measurements in accordance with the ASTM E61 series of dosimetry standards. In addition, it provides guidance o…
ISO/ASTM52921-13(2019)
ДействующийStandard Terminology for Additive Manufacturing—Coordinate Systems and Test Methodologies
Significance and Use 3.1 Although many additive manufacturing systems are based heavily upon the principles of Computer Numerical Control (CNC), the coordinate systems and nomenclature specific to CN…