Abstract

This document provides guidance on the implementation of effective governance of IT in an organization, in accordance with ISO/IEC 38500. It identifies the key activities that an organization can undertake and provides guidance on the design and establishment of the supporting and enabling arrangements for the governance of IT, clarifying the roles and responsibilities of key organizational stakeholders. This document can be used by individuals responsible for governance of IT in an organization, as well as individuals supporting the governance of IT in organizations, and is applicable to organizations of all sizes and types.

Status
Published
Publication Date
06-Oct-2026
Current Stage
6060 - International Standard published
Start Date
07-Oct-2026
Completion Date
07-Oct-2026

Buy Documents

Standard

ISO/IEC 38501-1:2026 - Information technology — Governance of IT implementation guidance — Part 1: General approach

Release Date:07-Oct-2026
English language (13 pages)
sale 15% off
Preview
sale 15% off
Preview

ISO/IEC 38501-1:2026 is an ISO/IEC International Standard that gives guidance on implementing effective governance of IT in an organization in accordance with ISO/IEC 38500. It explains the key activities, supporting arrangements, and stakeholder roles needed to put governance of IT into practice. The document is written for people responsible for governance of IT, and for those who support that work, in organizations of all sizes and types.

What does ISO/IEC 38501-1:2026 specify?

ISO/IEC 38501-1:2026 specifies a general approach for implementing governance of IT, not a separate set of governance principles. It shows how an organization can organize leadership, decision-making, monitoring, and review so that the use of IT supports organizational goals and responsibilities.

The document is organized into:

  • Clause 4 - implementation approach
  • Clause 5 - sponsorship
  • Clause 6 - enabling mechanisms
  • Clause 7 - governance tasks
  • Clause 8 - continual review

Clause 4 frames implementation as a cycle that starts with sponsorship and enabling mechanisms, then applies the governance tasks of engage, evaluate, direct, and monitor. In practice, this helps readers see governance of IT as an ongoing management activity rather than a one-time project.

What are the key requirements of ISO/IEC 38501-1:2026?

Clause 4 - implement governance of IT as a cycle

ISO/IEC 38501-1:2026 says implementation should combine the governance tasks with the framework elements from ISO/IEC 38500 and should be repeated over time. The initial cycle establishes a baseline, and later cycles support continual improvement. This matters because organizations change, and their governance arrangements need to be reviewed as IT, business needs, and risks evolve.

Clause 5 - secure sponsorship and leadership

ISO/IEC 38501-1:2026 requires clear leadership and commitment from the governing body and executive managers, with a selected sponsor to lead implementation. It also says the sponsor should be a key influential business, marketing, or operations executive manager, not a risk or governance specialist. In practice, this keeps implementation anchored in business leadership and makes it more likely that changes are accepted across the organization.

Clause 6 - put enabling mechanisms in place

ISO/IEC 38501-1:2026 says effective governance of IT is enabled by a framework, a governance support group, and appropriate governing body committees. The framework in Clause 6.2 has six elements: Direction, Capability, Policy, Delegation, Performance, and Accountability. For readers, this means governance needs named responsibilities, decision paths, and reporting lines, not just policies on paper.

Clause 6.3 describes the governance support group as the body that drives adoption or transformation, coordinates activities, and handles administration and reporting. Clause 6.4 points to committees such as audit, finance, investment, resourcing, and risk committees, and allows a strategic or innovation subcommittee where needed. This helps the governing body manage IT through existing governance structures instead of creating parallel ones.

Clause 7 - engage, evaluate, direct, and monitor

ISO/IEC 38501-1:2026 treats stakeholder engagement as an ongoing task covering internal and external stakeholders. It then uses evaluation to understand the internal and external environment and the current state of IT use, direction to define the desired state and identify gaps, and monitoring to track evidence of success. In practice, this gives organizations a repeatable way to move from understanding their situation to deciding changes and checking results.

Clause 8 - review and improve continuously

ISO/IEC 38501-1:2026 requires continual review after the first cycle has established a baseline. The governing body should use review and, where appropriate, audit and independent assessments to confirm that governance is effective and that the desired outcomes are being achieved. This matters because governance of IT should adapt as the organization, its risks, and its digital environment change.

What terms does ISO/IEC 38501-1:2026 define?

  • Information technology (IT) is the subject of the standard - the document is about governing how IT is used, directed, and monitored in the organization.
  • Internet of things (IoT) refers to one of the emerging digital technologies named in the introduction as affecting organizational outcomes and IT use.
  • Artificial intelligence (AI) is another emerging technology named in the introduction as part of the changing IT landscape.
  • Governing body is the body that provides direction and oversight for governance of IT and receives reporting for decisions.
  • Governance support group is the small group, or sometimes an individual, that coordinates implementation, administration, and reporting for governance of IT.
  • Evidence of success is the set of qualitative or quantitative signs used to show whether the desired state for the use of IT is being achieved.

Who uses ISO/IEC 38501-1:2026?

ISO/IEC 38501-1:2026 is used by governing bodies, executive managers, business managers, IT staff, and people supporting governance, risk, assurance, and compliance activities. It is also relevant to committees such as audit, finance, investment, resourcing, and risk committees. Organizations use it when they need a practical way to set up, run, and review governance of IT across the business.

What changed in ISO/IEC 38501-1:2026 from the previous edition?

  • This first edition cancels and replaces ISO/IEC TS 38501:2015.
  • The content has been aligned to reflect updates in ISO/IEC 38500:2024.
  • Annex A on the assessment scheme and Annex B on sample characteristics by principle were moved to ISO/IEC TS 38501-2 to support alignment and use with ISO/IEC 38503.

Which standards are used with ISO/IEC 38501-1:2026?

StandardWhat it contributes
ISO/IEC 38500Normative reference; provides the governance of IT principles, model, and framework used throughout the document.
ISO/IEC TR 38502Provides further guidance on the governance of IT framework and model, including role distinctions.
ISO/IEC 38503Covers assessment of the governance of IT and is referenced for roles, responsibilities, competencies, and independent assessment.
ISO/IEC TS 38501-2:2026Provides the assessment scheme and examples used with this part, including sample assessment criteria.

What does the ISO/IEC 38501-1:2026 document contain?

ISO/IEC 38501-1:2026 contains a figure for the overall implementation approach and a figure for the six-element governance framework. It also contains structured narrative guidance on sponsorship, enabling mechanisms, stakeholder engagement, evaluation, direction, monitoring, and continual review. The body text includes practical lists of considerations for internal and external context, gap analysis, change programmes, and evidence of success.

Buy Documents

Standard

ISO/IEC 38501-1:2026 - Information technology — Governance of IT implementation guidance — Part 1: General approach

Release Date:07-Oct-2026
English language (13 pages)
sale 15% off
Preview
sale 15% off
Preview

Get Certified

Connect with accredited certification bodies for this standard

BSI Group

BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

UKAS United Kingdom Verified

Bureau Veritas

Bureau Veritas is a world leader in laboratory testing, inspection and certification services.

COFRAC France Verified

DNV

DNV is an independent assurance and risk management provider.

NA Norway Verified

Sponsored listings

Frequently Asked Questions

ISO/IEC 38501-1:2026 is a standard published by the International Organization for Standardization (ISO). Its full title is "Information technology — Governance of IT implementation guidance — Part 1: General approach". This standard covers: This document provides guidance on the implementation of effective governance of IT in an organization, in accordance with ISO/IEC 38500. It identifies the key activities that an organization can undertake and provides guidance on the design and establishment of the supporting and enabling arrangements for the governance of IT, clarifying the roles and responsibilities of key organizational stakeholders. This document can be used by individuals responsible for governance of IT in an organization, as well as individuals supporting the governance of IT in organizations, and is applicable to organizations of all sizes and types.

This document provides guidance on the implementation of effective governance of IT in an organization, in accordance with ISO/IEC 38500. It identifies the key activities that an organization can undertake and provides guidance on the design and establishment of the supporting and enabling arrangements for the governance of IT, clarifying the roles and responsibilities of key organizational stakeholders. This document can be used by individuals responsible for governance of IT in an organization, as well as individuals supporting the governance of IT in organizations, and is applicable to organizations of all sizes and types.

ISO/IEC 38501-1:2026 is classified under the following ICS (International Classification for Standards) categories: 03.100.02 - Governance and ethics; 35.020 - Information technology (IT) in general. The ICS classification helps identify the subject area and facilitates finding related standards.

ISO/IEC 38501-1:2026 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.

Standards Content (Sample)


International
Standard
ISO/IEC 38501-1
First edition
Information technology —
2026-10
Governance of IT implementation
guidance —
Part 1:
General approach
Technologies de l'information — Recommandations pour la mise
en application de la gouvernance des TI —
Partie 1: Approche générale
Reference number
© ISO/IEC 2026
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
© ISO/IEC 2026 – All rights reserved
ii
Contents Page
Foreword .iv
Introduction .v
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Implementation approach . 1
5 Sponsorship . 3
6 Enabling mechanisms . 3
6.1 General .3
6.2 Framework for the governance of IT .4
6.3 Governance support group .5
6.4 Committees of the governing body .5
7 Governance tasks . 6
7.1 Engage stakeholders.6
7.1.1 General .6
7.1.2 Internal stakeholders .6
7.1.3 External stakeholders .7
7.2 Evaluate .7
7.2.1 Overview .7
7.2.2 Understand internal environment .7
7.2.3 Understand external environment .8
7.2.4 Identify current state of the use of IT .8
7.3 Direct . .9
7.3.1 Overview .9
7.3.2 Define desired state for the use of IT .9
7.3.3 Gap analysis .9
7.3.4 Initiate change programme .10
7.4 Monitor .10
7.4.1 Overview .10
7.4.2 Define evidence of success.10
7.4.3 Establish monitoring system . . .11
8 Continual review .11
Bibliography .13

© ISO/IEC 2026 – All rights reserved
iii
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are
members of ISO or IEC participate in the development of International Standards through technical
committees established by the respective organization to deal with particular fields of technical activity.
ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations,
governmental and non-governmental, in liaison with ISO and IEC, also take part in the work.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types
of document should be noted. This document was drafted in accordance with the editorial rules of the ISO/
IEC Directives, Part 2 (see www.iso.org/directives or www.iec.ch/members_experts/refdocs).
ISO and IEC draw attention to the possibility that the implementation of this document may involve the
use of (a) patent(s). ISO and IEC take no position concerning the evidence, validity or applicability of any
claimed patent rights in respect thereof. As of the date of publication of this document, ISO and IEC had not
received notice of (a) patent(s) which may be required to implement this document. However, implementers
are cautioned that this may not represent the latest information, which may be obtained from the patent
database available at www.iso.org/patents and https://patents.iec.ch. ISO and IEC shall not be held
responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT) see www.iso.org/iso/foreword.html.
In the IEC, see www.iec.ch/understanding-standards.
This document was prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology,
Subcommittee SC 40, Service management and IT governance.
This first edition of ISO/IEC 38501-1, together with the first edition of ISO/IEC TS 38501-2, cancels and
replaces the first edition of ISO/IEC TS 38501:2015, which has been technically revised.
The main changes are as follows:
— the content has been aligned to take updates to ISO/IEC 38500:2024 into account;
— Annex A (assessment scheme) and Annex B (sample characteristics by principle) have been moved to
ISO/IEC TS 38501-2 to facilitate alignment and use with ISO/IEC 38503.
A list of all parts in the ISO/IEC 38501 series can be found on the ISO and IEC websites.
Any feedback or questions on this document should be directed to the user’s national standards
body. A complete listing of these bodies can be found at www.iso.org/members.html and
www.iec.ch/national-committees.

© ISO/IEC 2026 – All rights reserved
iv
Introduction
Information technology (IT) is now pervasive in supporting, enabling and transforming the strategy and
business opportunities of organizations. The extensive use of data, coupled with the rapid adoption of
digital capabilities and powerful emerging technologies, such as cloud computing, the internet of things
(IoT) and artificial intelligence (AI), can substantially improve organizational outcomes, thereby enabling
organizations to meet the needs and expectations of their various stakeholders.
However, the deployment and use of information technology is not without challenges, including the
increasing prevalence of cybersecurity threats, stringent legislative and regulatory environments, failure
to achieve planned benefits from IT investments, and the potential for financial and reputational damage
associated with the above risks.
Governing bodies are increasingly aware of the need for effective and efficient governance of IT to ensure
the appropriate and responsible use of IT in the organization. However, they are sometimes uncertain of
their responsibilities in this regard, or of what arrangements they need to have in place.
This document has therefore been developed to provide guidance on the implementation of the governance
of IT within organizations, in accordance with ISO/IEC 38500, to support the key organizational governance
outcomes (as defined in ISO/IEC 38500:2024, 4.1) of:
— effective performance;
— responsible stewardship; and
— ethical behaviour.
This document provides guidance on a method for implementing principles-based governance of IT, which
uses the principles, model and framework described in ISO/IEC 38500, and the assessment scheme for the
governance of IT described in ISO/IEC TS 38501-2.

© ISO/IEC 2026 – All rights reserved
v
International Standard ISO/IEC 38501-1:2026(en)
Information technology — Governance of IT implementation
guidance —
Part 1:
General approach
1 Scope
This document provides guidance on the implementation of effective governance of IT in an organization, in
accordance with ISO/IEC 38500.
It identifies the key activities that an organization can undertake and provides guidance on the design and
establishment of the supporting and enabling arrangements for the governance of IT, clarifying the roles
and responsibilities of key organizational stakeholders.
This document can be used by individuals responsible for governance of IT in an organization, as well as
individuals supporting the governance of IT in organizations, and is applicable to organizations of all sizes
and types.
2 Normative references
The following documents are referred to in the text in such a way that some or all of their content constitutes
requirements of this document. For dated references, only the edition cited applies. For undated references,
the latest edition of the referenced document (including any amendments) applies.
ISO/IEC 38500, Information technology — Governance of IT for the organization
3 Terms and definitions
For the purposes of this document, the terms and definitions given in ISO/IEC 38500 apply.
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
— ISO Online browsing platform: available at https:// www .iso .org/ obp
— IEC Electropedia: available at https:// www .electropedia .org/
4 Implementation approach
The implementation of the governance of IT in an organization comprises the application of key governance
tasks (i.e. engage stakeholders, evaluate, direct and monitor), while taking into consideration the elements
of the governance framework, in the context of the governance of IT principles, and taking into consideration
the elements of the governance of IT as presented in ISO/IEC 38500.
Successful implementation, however, also requires various supporting and enabling arrangements to be in
place, including:
— appropriate sponsorship and engagement from key stakeholders in the organization;
— the establishment of enabling mechanisms that facilitate the governance of IT;

© ISO/IEC 2026 – All rights reserved
— continual review to ensure that desired outcomes are being achieved and that the governance
arrangements are appropriate for the organization.
These supporting and enabling arrangements form an integral part of the governance of IT, facilitating the
performance of governance tasks and activities, and ensuring the appropriate flow of governance-related
information, both arising from the management of IT and passed through to the governing body, as well as
from the governing body for implementation by management.
The distinction between the roles of the governing body and management varies across organizations, and it
is important to clearly differentiate their respective responsibilities, decision-making authorities and actions
as these relate to the current and future use of IT. These aspects are covered throughout this document
and further guidance can also be found in ISO/IEC TR 38502 and ISO/IEC TS 38501-2:2026, Annex A. A
cyclic approach, considering the aspects described above, should be followed for the implementation of the
governance of IT in the organization. This is depicted in Figure 1.
Figure 1 — Implementation approach for the governance of IT, incorporating the model for the
governance of IT from ISO/IEC 38500
The implementation cycle would generally commence with establishing sponsorship and enabling
mechanisms, with the subsequent application of the governance tasks and framework elements to the
principles. This would then form the initial implementation cycle or “baseline”.
The duration of a cycle will be different for each organization, depending on various factors, including: the
organization's size, its industry, as well as the maturity of the governance of IT in the organization.
Subsequent cycles should be undertaken to support and enhance the governance of IT implementation,
to achieve continual improvement. It is important to note, however, that the cycle should not be
“mechanistically” followed and that it can be appropriate to undertake specific aspects “out of sequence”.

© ISO/IEC 2026 – All rights reserved
Further detail on each aspect of the implementation is provided as outlined in the clauses below:
— Clause 5: Sponsorship
— Clause 6: Enabling mechanisms, including:
— The framework for the governance of IT
— Governance support group
— Committees of the governing body
— Clause 7: Governance tasks
— Engage stakeholders
— Evaluate
— Direct
— Monitor
— Clause 8: Continual review
5 Sponsorship
The implementation of the governance of IT requires clear leadership and commitment from the governing
body and the executive managers of the organization.
The level of engagement of the governing body and executive managers should be proportionate to
the importance of the role of IT to the organization, both currently and in the future, as required by the
organization's goals and strategy.
This can lead to change in terms of organizational culture and behaviours in respect of the use of IT, in
addition to requiring new or improved knowledge and processes related to the governance of IT.
A sponsor should be selected to lead the implementation. This should be a key influential business/
marketing/operations executive manager and should not be a risk or governance expert or department.
It is important that the governing body and executive managers have the necessary knowledge and skills to
fulfil their roles and responsibilities, which includes:
— knowledge of the organization’s context (see 7.2);
— understanding of ISO/IEC 38500 and related standards in the ISO/IEC 38501 series.
Further information on key stakeholder roles, responsibilities and competencies can also be found in
ISO/IEC 38503.
6 Enabling mechanisms
6.1 General
Effective governance of IT in the organization is facilitated and enabled through mechanisms that support
the engagement and collaboration between the governance and management roles of the organization.
This includes the framework, comprising the six elements through which this collaboration is effected,
support mechanisms (see 6.2), as well as support from existing governance bodies in the organization (see
6.3 and 6.4).
© ISO/IEC 2026 – All rights reserved
6.2 Framework for the governance of IT
Effective governance involves establishing an appropriate governance framework based on the strategic
requirements of the organization.
The framework for the governance of IT from ISO/IEC 38500 is shown in Figure 2. It comprises six elements
which provide guidance on the policies, decision-making structures, behaviours, accountability mechanisms
and various other practices that are needed to ensure the effective implementation of the governance of IT.
Figure 2 — Framework for the governance of IT
Direction - The strategies for the design, development, deployment and use of IT, ensuring align-
ment with the organization’s purpose, objectives and model for value generation.
Capability - The digital capabilities that are required to support and enable the organization’s
products and services.
Policy - The policies that are established to guide the organization’s needs, expectations, risks,
use and impact of IT.
Delegation - The delegations of authority and responsibility for the use of IT, supported by govern-
ance practices and organizational structures - both within the organization as well as
beyond the organization’s boundaries, as appropriate.
Performance - The performance requirements and measurements for the use of IT, as well as for the
governance of IT.
© ISO/IEC 2026 – All rights reserved
Accountability - The mechanisms to hold management accountable for policy compliance and per-
formance. These can include audits and reviews, as well as reports, monitoring and
alerting systems.
Examples of how the framework elements can be applied when implementing the governance of IT are
provided in ISO/IEC TS 38501-2:2026, Annex A.
6.3 Governance support group
There are many activities associated with implementing and maintaining effective governance of IT that
need to be actively managed within the organization. These include awareness and education about the
governance of IT, as well as on-going coordination and administration activities.
Further, depending on the size of the organization, its potential reliance on IT for business outcomes and the
current effectiveness of the governance arrangement, implementing a programme to improve governance
of IT can potentially be a significant change programme in itself. Even if it is
...