ISO/IEC TS 38501-2:2026
(Main)Information technology — Governance of IT implementation guidance — Part 2: Assessment scheme and examples
General Information
- Abstract
This document provides guidance on the assessment scheme to be used when implementing the governance of IT in organizations in accordance with ISO/IEC 38500 and ISO/IEC 38501-1. It establishes the assessment framework and rating scale appropriate for principles-based governance of IT, and provides sample governance of IT characteristics for each of the 11 principles listed in ISO/IEC 38500 (see Annex A). This document can be used by individuals responsible for governance of IT in an organization, as well as individuals supporting the governance of IT in organizations, and is applicable to organizations of all sizes and types.
- Status
- Published
- Publication Date
- 24-Aug-2026
- Technical Committee
- ISO/IEC JTC 1/SC 40 - IT service management and IT governance
- Drafting Committee
- ISO/IEC JTC 1/SC 40/WG 1 - Governance of InformationTechnology
- Current Stage
- 6060 - International Standard published
- Start Date
- 25-Aug-2026
- Due Date
- 13-Dec-2026
- Completion Date
- 25-Aug-2026
Overview
ISO/IEC TS 38501-2:2026, published by the International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC), provides essential guidance for the assessment scheme used when implementing the governance of IT within organizations. This guidance document is designed to align with the principles set out in ISO/IEC 38500 and the implementation guidance from ISO/IEC 38501-1. It establishes a practical assessment framework and a qualitative rating scale appropriate for principles-based IT governance. ISO/IEC TS 38501-2 also includes sample characteristics for each of the 11 key principles outlined in ISO/IEC 38500, making it a critical resource for IT governance leaders and practitioners.
This technical specification is applicable to organizations of all sizes and types, and is especially valuable for those responsible for or supporting IT governance across various industries.
Key Topics
Assessment Framework: The document presents a structured framework for assessing IT governance. For each of the 11 governance principles, organizations are guided to evaluate:
- The extent to which governance tasks and practices are in place.
- The evidence of successful implementation and performance.
- The degree to which desired outcomes are being achieved.
Qualitative Rating Scale: Instead of a numeric scoring system, the standard uses a qualitative scale to rate implementation status:
- Unknown
- Not Applied
- Somewhat Applied
- Largely Applied
- Fully Applied
Sample Characteristics by Principle: Annex A provides practical examples for each of the 11 ISO/IEC 38500 principles, supporting users in contextualizing the assessment framework for:
- Purpose and value generation
- Strategic alignment
- Oversight and accountability
- Stakeholder engagement
- Leadership
- Data and decision-making
- Risk governance
- Social responsibility
- Performance over time
Alignment with Principles-Based Governance: The guidance is designed to be flexible, outcomes-focused, and adaptable to the unique needs and objectives of each organization.
Applications
ISO/IEC TS 38501-2:2026 is a key resource in the practical implementation and continual improvement of IT governance. It is beneficial for:
- IT Governance Committees and Boards: Using the assessment framework to monitor governance effectiveness, drive improvements, and report to stakeholders.
- IT Managers and Support Teams: Aligning IT management practices with internationally recognized governance principles.
- Auditors and Consultants: Assessing organizational maturity in IT governance and benchmarking against best practices.
- Organizations of All Sizes: From small businesses to large enterprises, the standard’s principles-based approach ensures relevance across different organizational contexts.
- Regulated Sectors: Supporting regulatory compliance and demonstrating due diligence in IT governance.
By providing structured assessment methods and examples, the standard helps organizations measure and enhance their governance maturity, inform decision-making, and focus resources effectively on continuous improvement.
Related Standards
To ensure comprehensive IT governance, ISO/IEC TS 38501-2:2026 should be used in conjunction with related standards, including:
- ISO/IEC 38500 – Information technology - Governance of IT for the organization: The foundational standard for IT governance principles.
- ISO/IEC 38501-1 – Information technology - Governance of IT - Implementation guidance, Part 1: Approach: Detailed guidance on implementing IT governance aligned to ISO/IEC 38500.
- Additional standards in the ISO/IEC 38500 and 38501 series, addressing specific aspects of IT governance, strategy, and management.
By integrating ISO/IEC TS 38501-2 with these related standards, organizations can establish a robust, principles-based governance framework that supports strategic alignment, risk management, accountability, and sustainable value from IT investments.
Keywords: IT governance, ISO/IEC 38500, assessment scheme, implementation guidance, governance framework, rating scale, principles-based governance, organizational maturity, governance assessment, IT management, best practices, compliance.
Get Certified
Connect with accredited certification bodies for this standard

BSI Group
BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

Bureau Veritas
Bureau Veritas is a world leader in laboratory testing, inspection and certification services.

DNV
DNV is an independent assurance and risk management provider.
Sponsored listings
Frequently Asked Questions
ISO/IEC TS 38501-2:2026 is a technical specification published by the International Organization for Standardization (ISO). Its full title is "Information technology — Governance of IT implementation guidance — Part 2: Assessment scheme and examples". This standard covers: This document provides guidance on the assessment scheme to be used when implementing the governance of IT in organizations in accordance with ISO/IEC 38500 and ISO/IEC 38501-1. It establishes the assessment framework and rating scale appropriate for principles-based governance of IT, and provides sample governance of IT characteristics for each of the 11 principles listed in ISO/IEC 38500 (see Annex A). This document can be used by individuals responsible for governance of IT in an organization, as well as individuals supporting the governance of IT in organizations, and is applicable to organizations of all sizes and types.
This document provides guidance on the assessment scheme to be used when implementing the governance of IT in organizations in accordance with ISO/IEC 38500 and ISO/IEC 38501-1. It establishes the assessment framework and rating scale appropriate for principles-based governance of IT, and provides sample governance of IT characteristics for each of the 11 principles listed in ISO/IEC 38500 (see Annex A). This document can be used by individuals responsible for governance of IT in an organization, as well as individuals supporting the governance of IT in organizations, and is applicable to organizations of all sizes and types.
ISO/IEC TS 38501-2:2026 is classified under the following ICS (International Classification for Standards) categories: 03.100.02 - Governance and ethics; 35.020 - Information technology (IT) in general. The ICS classification helps identify the subject area and facilitates finding related standards.
ISO/IEC TS 38501-2:2026 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.
Standards Content (Sample)
Technical
Specification
ISO/IEC TS 38501-2
First edition
Information technology —
2026-08
Governance of IT implementation
guidance —
Part 2:
Assessment scheme and examples
Technologies de l'information — Gouvernance des technologies
de l'information —
Partie 2: Schéma d'évaluation et exemples
Reference number
© ISO/IEC 2026
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
© ISO/IEC 2026 – All rights reserved
ii
Contents Page
Foreword .iv
Introduction .v
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Assessment scheme for the governance of IT. 1
4.1 General .1
4.2 Assessment framework .1
4.3 Rating scale.2
4.4 Assessment scheme .2
Annex A (informative) Sample governance of IT characteristics, by principle . 4
Bibliography .15
© ISO/IEC 2026 – All rights reserved
iii
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are
members of ISO or IEC participate in the development of International Standards through technical
committees established by the respective organization to deal with particular fields of technical activity.
ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations,
governmental and non-governmental, in liaison with ISO and IEC, also take part in the work.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types
of document should be noted. This document was drafted in accordance with the editorial rules of the ISO/
IEC Directives, Part 2 (see www.iso.org/directives or www.iec.ch/members_experts/refdocs).
ISO and IEC draw attention to the possibility that the implementation of this document may involve the
use of (a) patent(s). ISO and IEC take no position concerning the evidence, validity or applicability of any
claimed patent rights in respect thereof. As of the date of publication of this document, ISO and IEC had not
received notice of (a) patent(s) which may be required to implement this document. However, implementers
are cautioned that this may not represent the latest information, which may be obtained from the patent
database available at www.iso.org/patents and https://patents.iec.ch. ISO and IEC shall not be held
responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT) see www.iso.org/iso/foreword.html.
In the IEC, see www.iec.ch/understanding-standards.
This document was prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology,
Subcommittee SC 40, IT service management and IT governance.
This first edition of ISO/IEC TS 38501-2, together with the first edition of ISO/IEC 38501-1, cancel and replace
the first edition of ISO/IEC TS 38501:2015, which has been technically revised.
The main changes are as follows:
— the content has been aligned to take updates to ISO/IEC 38500:2024 into account;
— Annex A (assessment scheme) and Annex B (sample characteristics by principle) have been moved to
ISO/IEC TS 38501-2 (this document) to facilitate alignment and use with ISO/IEC 38503.
A list of all parts in the ISO/IEC 38501 series can be found on the ISO and IEC websites.
Any feedback or questions on this document should be directed to the user’s national standards
body. A complete listing of these bodies can be found at www.iso.org/members.html and
www.iec.ch/national-committees.
© ISO/IEC 2026 – All rights reserved
iv
Introduction
The measurement of performance is an essential aspect when implementing the governance of IT in the
organization. It helps the governing body understand how well the organization is achieving its governance
of IT objectives and provides critical insights into the areas for improvement, thereby helping the governing
body to make informed decisions and allocate resources effectively.
ISO/IEC 38500 is a principles-based standard for the governance of IT. It is therefore crucial that an
appropriate assessment scheme, which enables the organization to define the practices, evidence of success
and outcomes that are appropriate for the organization, be used. Once this is in place, the organization will
be able to effectively measure its performance towards the achievement of its governance of IT objectives.
© ISO/IEC 2026 – All rights reserved
v
Technical Specification ISO/IEC TS 38501-2:2026(en)
Information technology — Governance of IT implementation
guidance —
Part 2:
Assessment scheme and examples
1 Scope
This document provides guidance on the assessment scheme to be used when implementing the governance
of IT in organizations in accordance with ISO/IEC 38500 and ISO/IEC 38501-1.
It establishes the assessment framework and rating scale appropriate for principles-based governance of IT,
and provides sample governance of IT characteristics for each of the 11 principles listed in ISO/IEC 38500
(see Annex A).
This document can be used by individuals responsible for governance of IT in an organization, as well as
individuals supporting the governance of IT in organizations, and is applicable to organizations of all sizes
and types.
2 Normative references
There are no normative references in this document.
3 Terms and definitions
No terms and definitions are listed in this document.
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
— ISO Online browsing platform: available at https:// www .iso .org/ obp
— IEC Electropedia: available at https:// www .electropedia .org/
4 Assessment scheme for the governance of IT
4.1 General
The assessment scheme for implementing principles-based governance of IT, based on ISO/IEC 38500,
comprises an assessment framework and rating scale in support of outcomes-based governance of IT.
These components provide structure and guidance to the assessment process, which can assist organizations
in creating more comprehensive assessments.
4.2 Assessment framework
The framework comprises the following three characteristics, which are applied to each of the principles in
ISO/IEC 38500 (see Figure 1).
— The extent to which governance tasks and practices are in place.
— The evidence demonstrating the successful performance of these tasks and practices.
© ISO/IEC 2026 – All rights reserved
— The extent to which outcomes are being achieved.
Figure 1 — Assessment framework for the governance of IT
4.3 Rating scale
The rating scale used to assess the status of implementation is qualitative rather than quantitative in nature,
since principles-based standards focus on the achievement of outcomes, rather than the means of achieving
outcomes. This is shown in Table 1.
Table 1 — Rating scale and description
Rating Description
— No knowledge of the governance tasks, practices, evidence of success or whether
Unknown
outcomes are being achieved.
— The majority of governance tasks and practices are not being performed and there is
little evidence of success.
Not applied
— Outcomes are not being achieved.
— Certain governance tasks and practices are being performed and there is some evidence
of success, although one or more aspects are not in place at all.
Somewhat applied
— Some outcomes are being achieved to a certain degree, but one or more outcomes are not
being achieved at all.
— Majority of governance tasks and practices are being performed and evidence of success
is visible to a large extent. Certain aspects are fully in place.
Largely applied
— Majority of outcomes are being achieved to a large degree with certain outcomes being
fully achieved.
— All governance tasks and practices are being fully performed and evidence of success is
fully visible.
Fully applied
— All outcomes are being fully achieved.
4.4 Assessment scheme
The assessment scheme for the governance of IT can be obtained by combining the assessment framework
and the rating scale defined in Figure 1 and Table 1 with the organization's current and desired state of
achievement. Figure 2 provides an example. Examples of how this can be populated are provided in Annex A.
© ISO/IEC 2026 – All rights reserved
Figure 2 — Assessment scheme for the governance of IT
© ISO/IEC 2026 – All rights reserved
Annex A
(informative)
Sample governance of IT characteristics, by principle
A.1 Purpose
Table A.1 provides an example assessment scheme for the principle "purpose".
Table A.1 — Example assessment scheme: Purpose
Governance tasks and practices Evidence of success Outcomes
— The governing body assesses — Appropriate governing — Confidentiality and integrity of
the engagement with internal mechanisms for the use of IT organizational data maintained
and external stakeholders to and data between ecosystem by external and internal
ensure that their use of the organizations. stakeholders.
organization’s IT and data is
— Relevant clauses for the use of — Organizational compliance to
aligned to the purpose and
IT and data in contracts with legislation and regulations.
values of the organization.
customers and suppliers.
— Stakeholders embrace the
— The governing body evaluates
— Policies and procedures organization’s purpose and
how new and emerging
enforcing appropriate use of IT values by using its digital
technologies can enable or
and data within the organization. capabilities.
enhance the organization’s
purpose and values.
— Governing body assessment of
emerging technology projects to
ensure alignment to the purpose
and values of the organization.
Assessment Assessment Assessment
Are the governance
Is there evidence of Are outcomes being
tasks and practices
success? achieved?
being applied?
Current state Current state Current state
Desired state Desired state Desired state
A.2 Value generation
Table A.2 provides an example assessment scheme for the principle "value generation".
© ISO/IEC 2026 – All rights reserved
Unknown
Not
Somewhat
Largely
Fully
Unknown
Not
Somewhat
Largely
Fully
Unknown
Not
Somewhat
Largely
Fully
Table A.2 — Example assessment scheme: Value generation
Governance tasks and practices Evidence of success Outcomes
— The governing body evaluates — Products transformed into — New models of business value
whether IT is embedded into services through the inclusion of enabled through the adoption of
the organization’s products and digital capabilities. digital capabilities.
services to support new value
— Key digital roles identified and — New value generation projects
generation models.
filled in organogram. successfully delivered, achieving
— The governing body directs that projected benefits.
— Service contracts entered
the periodical assessment of
into with partners to provide — Compliance to legislation and
the impact of market changes to
required digital services. regulation relating to new value
the value generation models is
generation models by:
performed.
— Organizational policies contain
statements relating to digital — the organization’s digital
— The governing body directs that
technologies supporting new products and services;
the digital capabilities to support
value generation models, e.g.:
new value generation models
— the organization’s partners
exist within the organization’s
— the ethical use of IT; in the value generation
ecosystem.
ecosystem.
— ecosystem partner roles,
— The governing body directs that
responsibilities and — Governing body fully endorses
appropriate policies are in place
behaviours. the risks and opportunities of
to support the organization’s
digital technologies supporting
value generation models.
— Decisions regarding the use of
the organization’s value
AI in the organization’s value
generation models.
— The governing body monitors
generation are approved by the
that appropriate delegation
governing body. — Business value generated for:
of authority is in place to
support the organization’s value
— Relevant metrics defined, — the organization;
generation models and ensures
measured and reported to
that these are not exceeded.
— the organization’s
ensure successful digital support
ecosystem.
for value generation models, e.g.:
— The governing body directs
that appropriate performance
— High level of trust in the
— network effects;
measurement is in place to
organization’s digital products
determine the effectiveness of
— service levels across and services.
digitally enabled value creation
organizational ecosystems;
models.
— Organization’s good reputation
— user experience. maintained.
— The governing body monitors
that the organization complies
— Relevant metrics defined,
with its policies pertaining to
measured and reported to
new value generation models.
ensure regulatory compliance for
value generation models, e.g.:
— personal data protection
data provenance / use in AI.
Assessment Assessment Assessment
Are the governance
Is there evidence of Are outcomes being
tasks and practices
success? achieved?
being applied?
Current state Current state Current state
Desired state Desired state Desired state
A.3 Strategy
Table A.3 provides an example assessment scheme for the principle "strategy".
© ISO/IEC 2026 – All rights reserved
Unknown
Not
Somewhat
Largely
Fully
Unknown
Not
Somewhat
Largely
Fully
Unknown
Not
Somewhat
Largely
Fully
Table A.3 — Example assessment scheme: Strategy
Governance tasks and practices Evidence of success Outcomes
— The governing body evaluates — IT strategy clearly articulates — The organization's IT, data and
whether the IT strategy aligns to how it supports the business digital capabilities successfully
the organizational strategy. strategy and goals. support and enable the
achievement of business goals
— The governing body directs — Business strategy incorporates
and objectives.
that the organizational strategy new technologies to achieve
considers the impact of new and competitive advantage. — The organization invests
emerging technologies. appropriately in digital
— Key internal factors covered
technologies, innovation and
— The governing body evaluates in reports to governing body
personnel, to ensure its IT
whether internal factors / addressed in the IT strategy,
remains current and does not
relevant to the organization are including:
degrade and become obsolete
adequately addressed in the IT
over time.
— strategic business and
strategy.
technology change
— The organization is not
— The governing body evaluates initiatives;
compromised by cyber security
whether external factors
breaches.
— the digital ecosystem in
relevant to the organization are
which the organization
adequately addressed in the IT — Th
...



