General Information

Abstract

Status
Not Published
Current Stage
5020 - FDIS ballot initiated: 2 months. Proof sent to secretariat
Start Date
15-Jul-2026
Completion Date
15-Jul-2026

Buy Documents

Draft

ISO/IEC FDIS 38501-1 - Information technology — Governance of IT implementation guidance — Part 1: General approach

Release Date:01-Jul-2026
English language (13 pages)
sale 15% off
sale 15% off
Draft

REDLINE ISO/IEC FDIS 38501-1 - Information technology — Governance of IT implementation guidance — Part 1: General approach

Release Date:01-Jul-2026
English language (13 pages)
sale 15% off
sale 15% off

Overview

ISO/IEC FDIS 38501-1: Information Technology - Governance of IT Implementation Guidance - Part 1: General Approach provides comprehensive guidance for organizations seeking to implement effective IT governance in alignment with ISO/IEC 38500. Developed by ISO and the International Electrotechnical Commission (IEC), this standard targets the principles-based governance of IT, addressing the needs of executive managers, governing bodies, and those supporting IT governance initiatives. It is designed to be universally applicable for organizations of all sizes and sectors, offering a structured approach to establishing, monitoring, and continually improving the governance of IT.

Key Topics

This standard introduces foundational elements and practical steps for IT governance implementation, including:

  • Implementation Approach: Outlines a cyclic, principle-driven process for establishing and managing IT governance, starting with sponsorship and enabling mechanisms, and followed by governance activities and continual review.
  • Sponsorship and Leadership: Emphasizes the need for engagement and commitment from governing bodies and executive management to drive cultural changes and align IT use with organizational goals.
  • Enabling Mechanisms: Describes structures and processes required to support IT governance, such as frameworks, governance support groups, and relevant committees.
  • Governance Tasks: Details key activities including stakeholder engagement, evaluation of current IT use, direction-setting, and monitoring systems.
  • Stakeholder Roles and Responsibilities: Clarifies the roles of management, governing bodies, and other key stakeholders in IT governance.

The document stresses the necessity for organizations to differentiate clearly between the roles of management and governing bodies, ensuring responsibilities are defined and decision-making is informed and responsible.

Applications

The practical value of ISO/IEC FDIS 38501-1 lies in its structured guidance for:

  • Establishing IT Governance Frameworks: Organizations can set clear policies, delegation structures, performance requirements, and accountability mechanisms aligned with their strategic objectives.
  • Improving Stakeholder Engagement: Guidance on engaging both internal and external stakeholders supports awareness, onboarding, and sustained participation in governance activities.
  • Strategic IT Alignment: Enables organizations to ensure IT strategies are closely aligned with overall business purposes and value-generation models.
  • Managing IT Risk and Performance: With its focus on continual review and monitoring, the standard supports proactive management of risks, performance, and compliance with regulations.
  • Supporting Change Management: The standard aids in managing organizational change programs that often accompany IT governance improvement initiatives.
  • Ensuring Continual Improvement: Promotes a cycle of assessment and enhancement, helping organizations adapt their governance arrangements to evolving business and technology environments.

ISO/IEC FDIS 38501-1 is relevant for IT leaders, board members, risk and compliance managers, and anyone responsible for IT governance in sectors ranging from finance and healthcare to government and manufacturing.

Related Standards

Organizations implementing ISO/IEC FDIS 38501-1 should also consider these closely related standards for a comprehensive approach to IT governance:

  • ISO/IEC 38500:2024 – Information technology - Governance of IT for the organization (the foundational standard for governance principles and model).
  • ISO/IEC TS 38501-2 – Information technology - Governance of IT implementation guidance - Part 2 (supplementary practical tools and assessment schemes).
  • ISO/IEC 38503 – Information technology - Governance of IT - Assessment of the governance of IT.
  • ISO/IEC TR 38502 – Information technology - Governance of IT - Framework and vocabulary.

These documents collectively support organizations in designing effective IT governance frameworks, conducting assessments, and ensuring ongoing alignment with best practices and stakeholder expectations.

Keywords: IT governance, implementation guidance, ISO/IEC 38501, information technology, governance frameworks, stakeholder engagement, continual improvement, IT risk management, ISO standards, best practices.

Buy Documents

Draft

ISO/IEC FDIS 38501-1 - Information technology — Governance of IT implementation guidance — Part 1: General approach

Release Date:01-Jul-2026
English language (13 pages)
sale 15% off
sale 15% off
Draft

REDLINE ISO/IEC FDIS 38501-1 - Information technology — Governance of IT implementation guidance — Part 1: General approach

Release Date:01-Jul-2026
English language (13 pages)
sale 15% off
sale 15% off

Get Certified

Connect with accredited certification bodies for this standard

BSI Group

BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

UKAS United Kingdom Verified

Bureau Veritas

Bureau Veritas is a world leader in laboratory testing, inspection and certification services.

COFRAC France Verified

DNV

DNV is an independent assurance and risk management provider.

NA Norway Verified

Sponsored listings

Frequently Asked Questions

ISO/IEC FDIS 38501-1 is a draft published by the International Organization for Standardization (ISO). Its full title is "Information technology — Governance of IT implementation guidance — Part 1: General approach". This standard covers: Information technology — Governance of IT implementation guidance — Part 1: General approach

Information technology — Governance of IT implementation guidance — Part 1: General approach

ISO/IEC FDIS 38501-1 is classified under the following ICS (International Classification for Standards) categories: 03.100.02 - Governance and ethics; 35.020 - Information technology (IT) in general. The ICS classification helps identify the subject area and facilitates finding related standards.

ISO/IEC FDIS 38501-1 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.

Standards Content (Sample)


FINAL DRAFT
International
Standard
ISO/IEC
FDIS
38501-1
ISO/IEC JTC 1/SC 40
Information technology —
Secretariat: SA
Governance of IT implementation
Voting begins on:
guidance —
2026-07-15
Part 1:
Voting terminates on:
2026-09-09
General approach
RECIPIENTS OF THIS DRAFT ARE INVITED TO SUBMIT,
WITH THEIR COMMENTS, NOTIFICATION OF ANY
RELEVANT PATENT RIGHTS OF WHICH THEY ARE AWARE
AND TO PROVIDE SUPPOR TING DOCUMENTATION.
IN ADDITION TO THEIR EVALUATION AS
BEING ACCEPTABLE FOR INDUSTRIAL, TECHNO­
LOGICAL, COMMERCIAL AND USER PURPOSES, DRAFT
INTERNATIONAL STANDARDS MAY ON OCCASION HAVE
TO BE CONSIDERED IN THE LIGHT OF THEIR POTENTIAL
TO BECOME STAN DARDS TO WHICH REFERENCE MAY BE
MADE IN NATIONAL REGULATIONS.
Reference number
ISO/IEC FDIS 38501­1:2026(en) © ISO/IEC 2026

FINAL DRAFT
International
Standard
ISO/IEC
FDIS
38501-1
ISO/IEC JTC 1/SC 40
Information technology —
Secretariat: SA
Governance of IT implementation
Voting begins on:
guidance —
Part 1:
Voting terminates on:
General approach
RECIPIENTS OF THIS DRAFT ARE INVITED TO SUBMIT,
WITH THEIR COMMENTS, NOTIFICATION OF ANY
RELEVANT PATENT RIGHTS OF WHICH THEY ARE AWARE
AND TO PROVIDE SUPPOR TING DOCUMENTATION.
© ISO/IEC 2026
IN ADDITION TO THEIR EVALUATION AS
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
BEING ACCEPTABLE FOR INDUSTRIAL, TECHNO­
LOGICAL, COMMERCIAL AND USER PURPOSES, DRAFT
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
INTERNATIONAL STANDARDS MAY ON OCCASION HAVE
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
TO BE CONSIDERED IN THE LIGHT OF THEIR POTENTIAL
or ISO’s member body in the country of the requester.
TO BECOME STAN DARDS TO WHICH REFERENCE MAY BE
MADE IN NATIONAL REGULATIONS.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland Reference number
ISO/IEC FDIS 38501­1:2026(en) © ISO/IEC 2026

© ISO/IEC 2026 – All rights reserved
ii
Contents Page
Foreword .iv
Introduction .v
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Implementation approach . 1
5 Sponsorship . 3
6 Enabling mechanisms . 3
6.1 General .3
6.2 Framework for the governance of IT .4
6.3 Governance support group .5
6.4 Committees of the governing body .5
7 Governance tasks . 6
7.1 Engage stakeholders.6
7.1.1 General .6
7.1.2 Internal stakeholders .6
7.1.3 External stakeholders .7
7.2 Evaluate .7
7.2.1 Overview .7
7.2.2 Understand internal environment .7
7.2.3 Understand external environment .8
7.2.4 Identify current state of the use of IT .8
7.3 Direct . .9
7.3.1 Overview .9
7.3.2 Define desired state for the use of IT .9
7.3.3 Gap analysis .9
7.3.4 Initiate change programme .10
7.4 Monitor .10
7.4.1 Overview .10
7.4.2 Define evidence of success.10
7.4.3 Establish monitoring system . . .11
8 Continual review .11
Bibliography .13

© ISO/IEC 2026 – All rights reserved
iii
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are
members of ISO or IEC participate in the development of International Standards through technical
committees established by the respective organization to deal with particular fields of technical activity.
ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations,
governmental and non-governmental, in liaison with ISO and IEC, also take part in the work.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types
of document should be noted. This document was drafted in accordance with the editorial rules of the ISO/
IEC Directives, Part 2 (see www.iso.org/directives or www.iec.ch/members_experts/refdocs).
ISO and IEC draw attention to the possibility that the implementation of this document may involve the
use of (a) patent(s). ISO and IEC take no position concerning the evidence, validity or applicability of any
claimed patent rights in respect thereof. As of the date of publication of this document, ISO and IEC had not
received notice of (a) patent(s) which may be required to implement this document. However, implementers
are cautioned that this may not represent the latest information, which may be obtained from the patent
database available at www.iso.org/patents and https://patents.iec.ch. ISO and IEC shall not be held
responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT) see www.iso.org/iso/foreword.html.
In the IEC, see www.iec.ch/understanding-standards.
This document was prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology,
Subcommittee SC 40, Service management and IT governance.
This first edition of ISO/IEC 38501-1, together with the first edition of ISO/IEC TS 38501-2, cancels and
replaces the first edition of ISO/IEC TS 38501:2015, which has been technically revised.
The main changes are as follows:
— the content has been aligned to take updates to ISO/IEC 38500:2024 into account;
— Annex A (assessment scheme) and Annex B (sample characteristics by principle) have been moved to
ISO/IEC TS 38501-2 to facilitate alignment and use with ISO/IEC 38503.
A list of all parts in the ISO/IEC 38501 series can be found on the ISO and IEC websites.
Any feedback or questions on this document should be directed to the user’s national standards
body. A complete listing of these bodies can be found at www.iso.org/members.html and
www.iec.ch/national-committees.

© ISO/IEC 2026 – All rights reserved
iv
Introduction
Information technology (IT) is now pervasive in supporting, enabling and transforming the strategy and
business opportunities of organizations. The extensive use of data, coupled with the rapid adoption of
digital capabilities and powerful emerging technologies, such as cloud computing, the internet of things
(IoT) and artificial intelligence (AI), can substantially improve organizational outcomes, thereby enabling
organizations to meet the needs and expectations of their various stakeholders.
However, the deployment and use of information technology is not without challenges, including the
increasing prevalence of cybersecurity threats, stringent legislative and regulatory environments, failure
to achieve planned benefits from IT investments, and the potential for financial and reputational damage
associated with the above risks.
Governing bodies are increasingly aware of the need for effective and efficient governance of IT to ensure
the appropriate and responsible use of IT in the organization. However, they are sometimes uncertain of
their responsibilities in this regard, or of what arrangements they need to have in place.
This document has therefore been developed to provide guidance on the implementation of the governance
of IT within organizations, in accordance with ISO/IEC 38500, to support the key organizational governance
outcomes (as defined in ISO/IEC 38500:2024, 4.1) of:
— effective performance;
— responsible stewardship; and
— ethical behaviour.
This document provides guidance on a method for implementing principles-based governance of IT, which
uses the principles, model and framework described in ISO/IEC 38500, and the assessment scheme for the
governance of IT described in ISO/IEC TS 38501-2.

© ISO/IEC 2026 – All rights reserved
v
FINAL DRAFT International Standard ISO/IEC FDIS 38501-1:2026(en)
Information technology — Governance of IT implementation
guidance —
Part 1:
General approach
1 Scope
This document provides guidance on the implementation of effective governance of IT in an organization, in
accordance with ISO/IEC 38500.
It identifies the key activities that an organization can undertake and provides guidance on the design and
establishment of the supporting and enabling arrangements for the governance of IT, clarifying the roles
and responsibilities of key organizational stakeholders.
This document can be used by individuals responsible for governance of IT in an organization, as well as
individuals supporting the governance of IT in organizations, and is applicable to organizations of all sizes
and types.
2 Normative references
The following documents are referred to in the text in such a way that some or all of their content constitutes
requirements of this document. For dated references, only the edition cited applies. For undated references,
the latest edition of the referenced document (including any amendments) applies.
ISO/IEC 38500, Information technology — Governance of IT for the organization
3 Terms and definitions
For the purposes of this document, the terms and definitions given in ISO/IEC 38500 apply.
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
— ISO Online browsing platform: available at https:// www .iso .org/ obp
— IEC Electropedia: available at https:// www .electropedia .org/
4 Implementation approach
The implementation of the governance of IT in an organization comprises the application of key governance
tasks (i.e. engage stakeholders, evaluate, direct and monitor), while taking into consideration the elements
of the governance framework, in the context of the governance of IT principles, and taking into consideration
the elements of the governance of IT as presented in ISO/IEC 38500.
Successful implementation, however, also requires various supporting and enabling arrangements to be in
place, including:
— appropriate sponsorship and engagement from key stakeholders in the organization;
— the establishment of enabling mechanisms that facilitate the governance of IT;

© ISO/IEC 2026 – All rights reserved
— continual review to ensure that desired outcomes are being achieved and that the governance
arrangements are appropriate for the organization.
These supporting and enabling arrangements form an integral part of the governance of IT, facilitating the
performance of governance tasks and activities, and ensuring the appropriate flow of governance-related
information, both arising from the management of IT and passed through to the governing body, as well as
from the governing body for implementation by management.
The distinction between the roles of the governing body and management varies across organizations,
and it is important to clearly differentiate their respective responsibilities, decision-making authorities
and actions as these relate to the current and future use of IT. These aspects are covered throughout this
document and further guidance can also be found in ISO/IEC TR 38502 and ISO/IEC TS 38501-2:—, Annex A.
A cyclic approach, considering the aspects described above, should be followed for the implementation of the
governance of IT in the organization. This is depicted in Figure 1.
Figure 1 — Implementation approach for the governance of IT, incorporating the model for the
governance of IT from ISO/IEC 38500
The implementation cycle would generally commence with establishing sponsorship and enabling
mechanisms, with the subsequent application of the governance tasks and framework elements to the
principles. This would then form the initial implementation cycle or “baseline”.
The duration of a cycle will be different for each organization, depending on various factors, including: the
organization's size, its industry, as well as the maturity of the governance of IT in the organization.
Subsequent cycles should be undertaken to support and enhance the governance of IT implementation,
to achieve continual improvement. It is important to note, however, that the cycle should not be
“mechanistically” followed and that it can be appropriate to undertake specific aspects “out of sequence”.

© ISO/IEC 2026 – All rights reserved
Further detail on each aspect of the implementation is provided as outlined the clauses below:
— Clause 5: Sponsorship
— Clause 6: Enabling mechanisms, including:
— The framework for the governance of IT
— Governance support group
— Other governance bodies
— Clause 7: Governance Tasks
— Engage Stakeholders
— Evaluate
— Direct
— Monitor
— Clause 8: Continual Review
5 Sponsorship
The implementation of the governance of IT requires clear leadership and commitment from the governing
body and the executive managers of the organization.
The level of engagement of the governing body and executive managers should be proportionate to
the importance of the role of IT to the organization, both currently and in the future, as required by the
organization's goals and strategy.
This can lead to change in terms of organizational culture and behaviours in respect of the use of IT, in
addition to requiring new or improved knowledge and processes related to the governance of IT.
A sponsor should be selected to lead the implementation. This should be a key influential business/
marketing/operations executive manager and should not be a risk or governance expert or department.
It is important that the governing body and executive managers have the necessary knowledge and skills to
fulfil their roles and responsibilities, which includes:
— knowledge of the organization’s context (see 7.2);
— understanding of ISO/IEC 38500 and related standards in the ISO/IEC 38501 series
Further information on key stakeholder roles, responsibilities and competencies can also be found in
ISO/IEC 38503.
6 Enabling mechanisms
6.1 General
Effective governance of IT in the organization is facilitated and enabled through mechanisms that support
the engagement and collaboration between the governance and management roles of the organization.
This includes the framework, comprising the six elements through which this collaboration is effected,
support mechanisms (see 6.2), as well as support from existing governance bodies in the organization (see
6.3 and 6.4)
© ISO/IEC 2026 – All rights reserved
6.2 Framework for the governance of IT
Effective governance involves establishing an appropriate governance framework based on the strategic
requirements of the organization.
The framework for the governance of IT from ISO/IEC 38500 is shown in Figure 2. It comprises six elements
which provide guidance on the policies, decision-making structures, behaviours, accountability mechanisms
and various other practices that are needed to ensure the effective implementation of the governance of IT.
Figure 2 — Framework for the governance of IT
Direction - The strategies for the design, development, deployment and use of IT, ensuring align-
ment with the organization’s purpose, objectives and model for value generation.
Capability - The digital capabilities that are required to support and enable the organization’s
products and services.
Policy - The policies that are established to guide the organization’s needs, expectations, risks,
use and impact of IT.
Delegation - The delegations of authority and responsibility for the use of IT, supported by govern-
ance practices and organizational structures - both within the organization as well as
beyond the organization’s boundaries, as appropriate.
Performance - The performance requirements and measurements for the use of IT, as well as for the
governance of IT.
© ISO/IEC 2026 – All rights reserved
Accountability - The mechanisms to hold management accountable for policy compliance and per-
formance. These can include audits and reviews, as well as reports, monitoring and
alerting systems.
Examples of how the framework elements can be applied when implementing the governance of IT are
provided in ISO/IEC TS 38501-2:—, Annex A.
6.3 Governance support group
There are many acti
...


Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
ISO/IEC DISFDIS 38501 - -1:2025(en)
Style Definition
...
ISO/IEC JTC 1/SC 40/WG 1
Style Definition
...
Style Definition
...
Secretariat: SA
Style Definition
...
Date: 2025-07-052026-06-30
Style Definition
...
Style Definition
INFORMATION TECHNOLOGY — GOVERNANCE OF IT IMPLEMENTATION GUIDANCE - PART 1: .
GENERAL APPROACH
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
Information technology — Governance of IT implementation
guidance —
Part 1:
General approach
FDIS stage
ISO #####-#:####(X/IEC FDIS 38501-1:2026(en) Formatted: Font: 11 pt, Bold
Formatted: Font: 11 pt, Bold
Formatted: HeaderCentered, Left, Space After: 0 pt,
© ISO/IEC 20252026
Line spacing: single
Formatted: Default Paragraph Font
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication
may be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, Formatted: Indent: Left: 0 cm, Right: 0 cm, Space
Before: 0 pt, No page break before, Adjust space
or posting on the internet or an intranet, without prior written permission. Permission can be requested from either ISO
between Latin and Asian text, Adjust space between
at the address below or ISO’s member body in the country of the requester.
Asian text and numbers
ISO copyright office
Formatted: Left: 1.5 cm, Right: 1.5 cm, Bottom: 1 cm,
CP 401 • Ch. de Blandonnet 8
Header distance from edge: 1.27 cm, Footer distance
CH-1214 Vernier, Geneva
from edge: 0.5 cm
Phone: + 41 22 749 01 11
EmailE-mail: copyright@iso.org
Website: www.iso.orgwww.iso.org
Published in Switzerland
Formatted: Font: 10 pt
Formatted: Font: 10 pt
Formatted: Font: 11 pt
Formatted: FooterPageRomanNumber, Space After: 0
pt, Line spacing: single
ii © ISO #### /IEC 2026 – All rights reserved
ii
ISO/IEC DISFDIS 38501-1:20252026(en) Formatted: Font: 11 pt, Bold
Formatted: Font: 11 pt, Bold
Formatted: Font: 11 pt, Bold
Contents
Formatted: HeaderCentered, Left, Space After: 0 pt,
Line spacing: single
Foreword . v
Formatted: Adjust space between Latin and Asian text,
Introduction . vi
Adjust space between Asian text and numbers
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Implementation approach . 1
5 Sponsorship . 4
6 Enabling mechanisms . 5
6.1 General. 5
6.2 Framework for the governance of IT . 5
6.3 Governance support group . 7
6.4 Committees of the governing body . 8
7 Governance tasks . 8
7.1 Engage stakeholders . 8
7.2 Evaluate . 10
7.3 Direct . 12
7.4 Monitor . 13
8 Continual review . 14
Bibliography . 16

Foreword . iv
Introduction . v
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Implementation approach . 1
5 Sponsorship . 3
6 Enabling mechanisms . 3
6.1 General. 3
6.2 Framework for the governance of IT . 3
6.3 Governance support group . 5
6.4 Committees of the governing body . 5
7 Governance Tasks . 6
7.1 Engage stakeholders . 6
7.1.1 General. 6
7.1.2 Internal stakeholders . 6
Formatted: Font: 10 pt
7.1.3 External stakeholders . 7
7.2 Evaluate . 7
Formatted: Font: 10 pt
7.2.1 Overview . 7
Formatted: FooterCentered, Left, Line spacing: single
7.2.2 Understand internal environment . 7
Formatted: Font: 11 pt
7.2.3 Understand external environment . 8
7.2.4 Identify current state of the use of IT . 8
Formatted: FooterPageRomanNumber, Left, Space
7.3 Direct . 9
After: 0 pt, Line spacing: single
© ISO/IEC 20252026 – All rights reserved
iii
ISO #####-#:####(X/IEC FDIS 38501-1:2026(en) Formatted: Font: 11 pt, Bold
Formatted: Font: 11 pt, Bold
Formatted: HeaderCentered, Left, Space After: 0 pt,
7.3.1 Overview . 9
Line spacing: single
7.3.2 Define desired state for the use of IT . 9
7.3.3 Initiate change program . 9
7.4 Monitor . 10
7.4.1 Overview . 10
7.4.2 Define evidence of success . 10
7.4.3 Establish monitoring system . 11
8 Continual review . 11
Bibliography . 12

Formatted: Font: 10 pt
Formatted: Font: 10 pt
Formatted: Font: 11 pt
Formatted: FooterPageRomanNumber, Space After: 0
pt, Line spacing: single
iv © ISO #### /IEC 2026 – All rights reserved
iv
ISO/IEC DISFDIS 38501-1:20252026(en) Formatted: Font: 11 pt, Bold
Formatted: Font: 11 pt, Bold
Formatted: Font: 11 pt, Bold
Foreword
Formatted: HeaderCentered, Left, Space After: 0 pt,
Line spacing: single
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are members Formatted: Adjust space between Latin and Asian text,
Adjust space between Asian text and numbers
of ISO or IEC participate in the development of International Standards through technical committees
established by the respective organization to deal with particular fields of technical activity. ISO and IEC
technical committees collaborate in fields of mutual interest. Other international organizations, governmental
and non-governmental, in liaison with ISO and IEC, also take part in the work.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types of
document should be noted. This document was drafted in accordance with the editorial rules of the ISO/IEC
Directives, Part 2 (see www.iso.org/directiveswww.iso.org/directives or
www.iec.ch/members_experts/refdocswww.iec.ch/members_experts/refdocs).
ISO and IEC draw attention to the possibility that the implementation of this document may involve the use of
(a) patent(s). ISO and IEC take no position concerning the evidence, validity or applicability of any claimed
patent rights in respect thereof. As of the date of publication of this document, ISO and IEC had not received
Formatted: Font color: Auto
notice of (a) patent(s) which may be required to implement this document. However, implementers are
cautioned that this may not represent the latest information, which may be obtained from the patent database
available at www.iso.org/patents and https://patents.iec.ch.www.iso.org/patents and https://patents.iec.ch.
ISO and IEC shall not be held responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT) see
www.iso.org/iso/foreword.html.www.iso.org/iso/foreword.html. In the IEC, see www.iec.ch/understanding-
standardswww.iec.ch/understanding-standards.
Formatted: English (United Kingdom)
This document was prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology,
Formatted: English (United Kingdom)
Subcommittee SC 40, Service management and IT governance.
Formatted: Font: Cambria, English (United Kingdom)
This first edition of ISO/IEC 38501-1, together with the first edition of ISO/IEC TS 38501-2, cancels and
Formatted: Don't keep with next
replaces the first edition of ISO/IEC TS 38501:2015, which has been technically revised.
Formatted: Default Paragraph Font
The main changes are as follows:
Formatted: Default Paragraph Font
Formatted: Default Paragraph Font
— — the content has been aligned to take updates to ISO/IEC 38500:2024 into account;
Formatted: Adjust space between Latin and Asian text,
— — Annex A (assessment scheme) and Annex B (sample characteristics by principle) have been moved to Adjust space between Asian text and numbers, Tab
ISO/IEC TS 38501-2 to facilitate alignment and use with ISO/IEC 38503. stops: Not at 0.7 cm + 1.4 cm + 2.1 cm + 2.8 cm +
3.5 cm + 4.2 cm + 4.9 cm + 5.6 cm + 6.3 cm + 7 cm
A list of all parts in the ISO/IEC 38501 series can be found on the ISO and IEC websites.
Formatted: Default Paragraph Font
Formatted: Default Paragraph Font
Any feedback or questions on this document should be directed to the user’s national standards body. A
complete listing of these bodies can be found at www.iso.org/members.html and www.iec.ch/national- Formatted: Font: 10 pt
committeeswww.iso.org/members.html and www.iec.ch/national-committees.
Formatted: Font: 10 pt
Formatted: FooterCentered, Left, Line spacing: single
Formatted: Font: 11 pt
Formatted: FooterPageRomanNumber, Left, Space
After: 0 pt, Line spacing: single
© ISO/IEC 20252026 – All rights reserved
v
ISO #####-#:####(X/IEC FDIS 38501-1:2026(en) Formatted: Font: 11 pt, Bold
Formatted: Font: 11 pt, Bold
Formatted: HeaderCentered, Left, Space After: 0 pt,
Introduction
Line spacing: single
Formatted: Adjust space between Latin and Asian text,
Information technology (IT) is now pervasive in supporting, enabling and transforming the strategy and
Adjust space between Asian text and numbers
business opportunities of organizations. The extensive use of data, coupled with the rapid adoption of digital
capabilities and powerful emerging technologies, such as cloud computing, the internet of things (IoT) and
artificial intelligence (AI), can substantially improve organizational outcomes, thereby enabling organizations
to meet the needs and expectations of their various stakeholders.
However, the deployment and use of information technology is not without challenges, including the
increasing prevalence of cybersecurity threats, stringent legislative and regulatory environments, failure to
achieve planned benefits from IT investments, and the potential for financial and reputational damage
associated with the above risks.
Governing bodies are increasingly aware of the need for effective and efficient governance of IT to ensure the
appropriate and responsible use of IT in the organization. However, they are sometimes uncertain of their
responsibilities in this regard, or of what arrangements they need to have in place.
This document has therefore been developed to provide guidance on the implementation of the governance
of IT within organizations, in accordance with ISO/IEC 38500, to support the key organizational governance
Formatted: Default Paragraph Font
outcomes (as defined in ISO/IEC 38500:2024, 4.1) of:
Formatted: Default Paragraph Font
Formatted: Default Paragraph Font
— — effective performance;
Formatted: Default Paragraph Font
— — responsible stewardship; and
Formatted: Adjust space between Latin and Asian text,
Adjust space between Asian text and numbers, Tab
— — ethical behaviour.
stops: Not at 0.7 cm + 1.4 cm + 2.1 cm + 2.8 cm +
3.5 cm + 4.2 cm + 4.9 cm + 5.6 cm + 6.3 cm + 7 cm
This document provides guidance on a method for implementing principles-based governance of IT, which
Formatted: Adjust space between Latin and Asian text,
uses the principles, model and framework described in ISO/IEC 38500, and the assessment scheme for the
Adjust space between Asian text and numbers
governance of IT described in ISO/IEC TS 38501-2.
Formatted: Default Paragraph Font
Formatted: Default Paragraph Font
Formatted: Default Paragraph Font
Formatted: Default Paragraph Font
Formatted: Default Paragraph Font
Formatted: Font: 10 pt
Formatted: Font: 10 pt
Formatted: Font: 11 pt
Formatted: FooterPageRomanNumber, Space After: 0
pt, Line spacing: single
vi © ISO #### /IEC 2026 – All rights reserved
vi
DRAFT International Standard ISO/IEC DIS 38501-1:2025(en)

INFORMATION TECHNOLOGY — GOVERNANCE OF IT
IMPLEMENTATION GUIDANCE - PART 1 : APPROACH
Formatted: Left: 1.5 cm, Right: 1.5 cm, Bottom: 1 cm,
Information technology — Governance of IT implementation
Section start: New page, Header distance from edge:
1.27 cm, Footer distance from edge: 0.5 cm
guidance —
Part 1:
General approach
1 Scope
Formatted: Adjust space between Latin and Asian text,
Adjust space between Asian text and numbers
This document provides guidance on the implementation of effective governance of IT in an organization, in
accordance with ISO/IEC 38500.
Formatted: Default Paragraph Font
Formatted: Default Paragraph Font
It identifies the key activities that an organization can undertake and provides guidance on the design and
establishment of the supporting and enabling arrangements for the governance of IT, clarifying the roles and
responsibilities of key organizational stakeholders.
This document can be used by individuals responsible for governance of IT in an organization, as well as
individuals supporting the governance of IT in organizations, and is applicable to organizations of all sizes and
types.
2 Normative references
The following documents are referred to in the text in such a way that some or all of their content constitutes
Formatted: Default Paragraph Font
requirements of this document. For dated references, only the edition cited applies. For undated references,
Formatted: Default Paragraph Font
the latest edition of the referenced document (including any amendments) applies.
Formatted: Default Paragraph Font
ISO/IEC 38500, Information technology — Governance of IT for the organization
Formatted: Adjust space between Latin and Asian text,
Adjust space between Asian text and numbers, Tab
3 Terms and definitions
stops: Not at 0.7 cm + 1.4 cm + 2.1 cm + 2.8 cm +
3.5 cm + 4.2 cm + 4.9 cm + 5.6 cm + 6.3 cm + 7 cm
For the purposes of this document, the terms and definitions given in ISO/IEC 38500 apply.
Formatted: Adjust space between Latin and Asian text,
Adjust space between Asian text and numbers
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
Formatted: Adjust space between Latin and Asian text,
— — ISO Online browsing platform: available at https://www.iso.org/obphttps://www.iso.org/obp Adjust space between Asian text and numbers, Tab
stops: Not at 0.7 cm + 1.4 cm + 2.1 cm + 2.8 cm +
— — IEC Electropedia: available at https://www.electropedia.org/https://www.electropedia.org/ 3.5 cm + 4.2 cm + 4.9 cm + 5.6 cm + 6.3 cm + 7 cm
Formatted: Adjust space between Latin and Asian text,
4 Implementation approach
Adjust space between Asian text and numbers
Formatted: Default Paragraph Font
The implementation of the governance of IT in an organization comprises the application of key governance
Formatted: Default Paragraph Font
tasks (i.e. engage stakeholders, evaluate, direct and monitor), whilstwhile taking into consideration the
elements of the governance framework, in the context of the governance of IT principles, and taking into
Formatted: Font: 11 pt
consideration the elements of the governance of IT as presented in ISO/IEC 38500.
Formatted: Footer, Left, Space After: 0 pt, Line
spacing: single, Tab stops: Not at 17.2 cm
© ISO/IEC 2025 – All rights reserved
ISO #####-#:####(X/IEC FDIS 38501-1:2026(en) Formatted: Font: 11 pt, Bold
Formatted: Font: 11 pt, Bold
Formatted: HeaderCentered, Left, Space After: 0 pt,
Successful implementation, however, also requires various supporting and enabling arrangements to be in
Line spacing: single
place, including:
— — appropriate sponsorship and engagement from key stakeholders in the organization;
Formatted: Adjust space between Latin and Asian text,
Adjust space between Asian text and numbers, Tab
— — the establishment of enabling mechanisms that facilitate the governance of IT;
stops: Not at 0.7 cm + 1.4 cm + 2.1 cm + 2.8 cm +
3.5 cm + 4.2 cm + 4.9 cm + 5.6 cm + 6.3 cm + 7 cm
— — continual review to ensure that desired outcomes are being achieved and that the governance
arrangements are appropriate for the organization.
These supporting and enabling arrangements form an integral part of the governance of IT, facilitating the
Formatted: Adjust space between Latin and Asian text,
performance of governance tasks and activities, and ensuring the appropriate flow of governance-related Adjust space between Asian text and numbers
information, both arising from the management of IT and passed through to the governing body, as well as
from the governing body for implementation by management.
The distinction between the roles of the governing body and management varies across organizations, and it
is important to clearly differentiate their respective responsibilities, decision-making authorities and actions
as these relate to the current and future use of IT. These aspects are covered throughout this document and
further guidance maycan also be found in ISO/IEC TR 38502 and ISO/IEC TS 38501-2:—, Annex AAA. A cyclic
Formatted: Default Paragraph Font
approach, considering the aspects described above, should be followed for the implementation of the
Formatted: Default Paragraph Font
governance of IT in the organization. This is depicted in Figure 1.Figure 1.
Formatted: Default Paragraph Font
Formatted: Default Paragraph Font
Formatted: Default Paragraph Font
Formatted: Default Paragraph Font
Formatted: Default Paragraph Font
Formatted: Font: 10 pt
Formatted: Font: 10 pt
Formatted: Font: 11 pt
Formatted: FooterPageNumber, Space After: 0 pt, Line
spacing: single
2 © ISO #### /IEC 2026 – All rights reserved
ISO/IEC DISFDIS 38501-1:20252026(en) Formatted: Font: 11 pt, Bold
Formatted: Font: 11 pt, Bold
Formatted: Font: 11 pt, Bold
Formatted: HeaderCentered, Left, Space After: 0 pt,
Line spacing: single
Formatted: Font: 10 pt
Formatted: Font: 10 pt
Formatted: FooterCentered, Left, Line spacing: single

Formatted: Font: 11 pt
Formatted: FooterPageNumber, Left, Space After: 0 pt,
Line spacing: single
© ISO/IEC 20252026 – All rights reserved
ISO #####-#:####(X/IEC FDIS 38501-1:2026(en) Formatted: Font: 11 pt, Bold
Formatted: Font: 11 pt, Bold
Formatted: HeaderCentered, Left, Space After: 0 pt,
Figure 1 — Implementation approach for the governance of IT, incorporating the model for the
Line spacing: single
governance of IT from ISO/IEC 38500
Formatted: None, Adjust space between Latin and
Asian text, Adjust space between Asian text and
The implementation cycle would generally commence with establishing sponsorship and enabling
numbers
mechanisms, with the subsequent application of the governance tasks and framework elements to the
Formatted: Default Paragraph Font
principles. This would then form the initial implementation cycle or “baseline”.
Formatted: Default Paragraph Font
The duration of a cycle will be different for each organization, depending on various factors, including: the
Formatted: Adjust space between Latin and Asian text,
organization's size, its industry, as well as the maturity of the governance of IT in the organization.
Adjust space between Asian text and numbers
Subsequent cycles should be undertaken to support and enhance the governance of IT implementation, to
achieve continual improvement. It is important to note, however, that the cycle should not be
“mechanistically” followed and that it maycan be appropriate to undertake specific aspects “out of sequence”.
Further detail on each aspect of the implementation is provided as outlined the clauses below:
— — Clause 5:Clause 5: Sponsorship
Formatted: Adjust space between Latin and Asian text,
Adjust space between Asian text and numbers, Tab
— — Clause 6:Clause 6: Enabling mechanisms, including:
stops: Not at 0.7 cm + 1.4 cm + 2.1 cm + 2.8 cm +
3.5 cm + 4.2 cm + 4.9 cm + 5.6 cm + 6.3 cm + 7 cm
— — The framework for the governance of IT
— — Governance support group
— — Other governance bodies
— — Clause 7:Clause 7: Governance Tasks
— — Engage Stakeholders
— — Evaluate
— — Direct
— — Monitor
— — Clause 8:Clause 8: Continual Review
5 Sponsorship
Formatted: Adjust space between Latin and Asian text,
Adjust space between Asian text and numbers
The implementation of the governance of IT requires clear leadership and commitment from the governing
body and the executive managers of the organization.
The level of engagement of the governing body and executive managers should be proportionate to the
importance of the role of IT to the organization, both currently and in the future, as required by the
organisation'sorganization's goals and strategy.
This can lead to change in terms of organizational culture and behaviours in respect of the use of IT, in addition
to requiring new or improved knowledge and processes related to the governance of IT.
Formatted: Font: 10 pt
A sponsor should be selected to lead the implementation. This should be a key influential
Formatted: Font: 10 pt
business/marketing/operations executive manager and should not be a risk or governance expert or
department.
Formatted: Font: 11 pt
Formatted: FooterPageNumber, Space After: 0 pt, Line
spacing: single
4 © ISO #### /IEC 2026 – All rights reserved
ISO/IEC DISFDIS 38501-1:20252026(en) Formatted: Font: 11 pt, Bold
Formatted: Font: 11 pt, Bold
Formatted: Font: 11 pt, Bold
It is important that the governing body and executive managers have the necessary knowledge and skills to
Formatted: HeaderCentered, Left, Space After: 0 pt,
fulfil their roles and responsibilities, which includes:
Line spacing: single
— — knowledge of the organization’s context (see 7.2);7.2);
Formatted: Default Paragraph Font
Formatted: Adjust space between Latin and Asian text,
— — understanding of ISO/IEC 38500 and related standards in the ISO/IEC 3850038501 series
Adjust space between Asian text and numbers, Tab
stops: Not at 0.7 cm + 1.4 cm + 2.1 cm + 2.8 cm +
Further information on key stakeholder roles, responsibilities and competencies can also be found in ISO/IEC
3.5 cm + 4.2 cm + 4.9 cm + 5.6 cm + 6.3 cm + 7 cm
38503.
Formatted: Default Paragraph Font
6 Enabling mechanisms Formatted: Default Paragraph Font
Formatted: Default Paragraph Font
6.1 General
Formatted: Default Paragraph Font
EeffectiveEffective governance of IT in the organization is facilitated and enabled through mechanisms that
Formatted: Adjust space between Latin and Asian text,
support the engagement and collaboration between the governance and management roles of the
Adjust space between Asian text and numbers
organization.
Formatted: Default Paragraph Font
Formatted: Adjust space between Latin and Asian text,
This includes the framework, comprising the six elements through which this collaboration is effected, support
Adjust space between Asian text and numbers, Tab
mechanisms (see 6.2),6.2), as well as support from existing governance bodies in the organization (see 6.36.3
stops: Not at 0.71 cm
and 6.4)6.4)
Formatted: Adjust space between Latin and Asian text,
6.2 Framework for the governance of IT
Adjust space between Asian text and numbers
Formatted: Adjust space between Latin and Asian text,
Effective governance involves establishing an appropriate governance framework based on the strategic
Adjust space between Asian text and numbers, Tab
requirements of the organization.
stops: Not at 0.71 cm
Formatted: Adjust space between Latin and Asian text,
The framework for the Governancegovernance of IT, from ISO/IEC 38500, is shown in Figure 2.Figure 2. It
Adjust space between Asian text and numbers
comprises six elements which provide guidance on the policies, decision-making structures, behaviours,
accountability mechanisms and various other practices that are needed to ensure the effective Formatted: Default Paragraph Font
implementation of the governance of IT.
Formatted: Default Paragraph Font
Formatted: Font: 10 pt
Formatted: Font: 10 pt
Formatted: FooterCentered, Left, Line spacing: single
Formatted: Font: 11 pt
Formatted: FooterPageNumber, Left, Space After: 0 pt,
Line spacing: single
© ISO/IEC 20252026 – All rights reserved
ISO #####-#:####(X/IEC FDIS 38501-1:2026(en) Formatted: Font: 11 pt, Bold
Formatted: Font: 11 pt, Bold
Formatted: HeaderCentered, Left, Space After: 0 pt,
Line spacing: single
Formatted: None, Adjust space between Latin and
Asian text, Adjust space between Asian text and
numbers
Formatted: Font: 10 pt
Formatted: Font: 10 pt
Formatted: Font: 11 pt
Formatted: FooterPageNumber, Space After: 0 pt, Line
Figure 2 — Framework for the governance of IT
spacing: single
6 © ISO #### /IEC 2026 – All rights reserved
Formatted
...
Formatted
...
ISO/IEC DISFDIS 38501-1:20252026(en)
Formatted
...
Formatted
...
Formatted
...
Direction - The strategies for the design, development, deployment and use of IT, ensuring
alignment with the organization’s purpose, objectives and model for value Formatted Table
...
generation.
Formatted
...
Capability - The digital capabilities that are required to support and enable the organization’s
Formatted
...
products and services.
Formatted
...
Policy - The policies that are established to guide the organization’s needs, expectations,
Formatted
...
risks, use and impact of IT.
Formatted
...
Delegation - The delegations of authority and responsibility for the use of IT, supported by
Formatted
...
governance practices and organizational structures - both within the organization as
Formatted
well as beyond the organization’s boundaries, as appropriate.
...
Formatted
Performance - The performance requirements and measurements for the use of IT, as well as for the
...
governance of IT.
Formatted
...
Accountability - The mechanisms to hold management accountable for policy compliance and
Formatted
...
performance. These can include audits and reviews, as well as reports, monitoring
Formatted
...
and alerting systems.
Formatted
...
Examples of how the framework elements can be applied when implementing the governance of IT are Formatted
...
provided in ISO/IEC TS 38501-2:—, Annex A.
Formatted
...
Formatted
6.3 Governance support group .
Formatted
...
There are many activities associated with implementing and maintaining effective governance of IT that need
Formatted
...
to be actively managed within the organization. These include awareness and education about the governance
Formatted
of IT, as well as on-going coordination and administration activities.
...
Formatted
...
Further, depending on the size of the organization, its potential reliance on IT for business outcomes and the
Formatted
...
current effectiveness of the governance arrangement, implementing a programme to improve governance of
IT can potentially be a significant change programme in itself. Even if it is a small change programme, it should Formatted
...
be subject to sound programme management, including a business case, programme plan, risk management,
Formatted
...
governance oversight, monitoring of progress and benefits realization.
Formatted
...
It is therefore important to establish a governance support group that has the responsibility to drive the
Formatted
...
adoption or transformation (or both) of the governance of IT in the organization. This is generally be a small
Formatted
...
group of individuals, but in smaller organizations it can simply be an individual.
Formatted
...
The governance support group plays a critical role in facilitating the transparent delegation of authority. It is
Formatted
...
also responsible for tracking progress on change programme activities, as well as performing the necessary
Formatted
...
administration activities to effectively orchestrate the governance of IT. These include:
Formatted
...
— — administering procedures and documenting and recording activities;
Formatted
...
Formatted
...
— — compiling the terms of reference for the governance support group;
Formatted
...
— — compiling a charter that records the IT related delegations of authority;
Formatted
...
Formatted
— — presenting all necessary information to the governing body for review and direction;
...
Formatted
...
— — follow-following up with executive managers and other relevant parties; and
Formatted
...
— — gathering and co-ordinating all relevant information required for monitoring.
Formatted
...
Formatted
...
Formatted
...
© ISO/IEC 20252026 – All rights reserved
ISO #####-#:####(X/IEC FDIS 38501-1:2026(en) Formatted: Font: 11 pt, Bold
Formatted: Font: 11 pt, Bold
Formatted: HeaderCentered, Left, Space After: 0 pt,
6.4 Committees of the governing body
Line spacing: single
Formatted: Adjust space between Latin and Asian text,
Consideration should also be given to the various committees of the governing body and their support services
Adjust space between Asian text and numbers, Tab
and teams that have a potential interest in the governance of IT. These can include:
stops: Not at 0.71 cm
— — audit committees; Formatted: Adjust space between Latin and Asian text,
Adjust space between Asian text and numbers
— — finance committees;
Formatted: Adjust space between Latin and Asian text,
Adjust space between Asian text and numbers, Tab
— — investment committees;
stops: Not at 0.7 cm + 1.4 cm + 2.1 cm + 2.8 cm +
3.5 cm + 4.2 cm + 4.9 cm + 5.6 cm + 6.3 cm + 7 cm
— — resourcing committees; and
— — risk committees.
The governing body may also establish a subcommittee to assist it in overseeing the organization's use of IT
Formatted: Adjust space between Latin and Asian text,
from strategic and innovation perspectives. The need for such a subcommittee depends on the importance of
Adjust space between Asian text and numbers
IT to the organization and its size.
The governing body should ensure that the members of such a subcommittee have the necessary
organizational knowledge, as well as appropriate knowledge and understanding of future trends and
directions in IT and digital technologies. The governing body should assign the appropriate authority to such
a committee to address its responsibilities.
7 Governance tasks
7.1 Engage stakeholders
Formatted: Adjust space between Latin and Asian text,
Adjust space between Asian text and numbers, Tab
7.1.1 General
stops: Not at 0.71 cm
Formatted: Adjust space between Latin and Asian text,
Internal and external stakeholder interests should be considered when implementing the governance of IT in
Adjust space between Asian text and numbers, Tab
an organization. This includes understanding the requirements and expectations of stakeholders, as well as
stops: Not at 0.71 cm + 0.99 cm + 1.27 cm
developing and promoting awareness in stakeholders of their roles and responsibilities as regards the
Formatted: Adjust space between Latin and Asian text,
governance of IT in the organization.
Adjust space between Asian text and numbers
This will ensureensures that new stakeholders are appropriately onboarded and will refinerefines and
updateupdates the knowledge and responsibilities for existing stakeholders, leading to greater stakeholder
understanding and diligence in the performance of their respective roles and responsibilities.
The key factors to consider when engaging internal and external stakeholders include:
— — adopting a stakeholder-centric approach;
Formatted: Adjust space between Latin and Asian text,
Adjust space between Asian text and numbers, Tab
— — agreeing stakeholder roles and responsibilities;
stops: Not at 0.7 cm + 1.4 cm + 2.1 cm + 2.8 cm +
3.5 cm + 4.2 cm + 4.9 cm + 5.6 cm + 6.3 cm + 7 cm
— — overall stakeholder satisfaction and ensuring that this can be monitored;
— — organization-wide approach for stakeholders (customers, suppliers, employees, etc.) to interact with
the organization;
— — leveraging digital capabilities for engagement;
Formatted: Font: 10 pt
Formatted: Font: 10 pt
— — ensuring appropriate behaviour regarding the use of IT as well as associated cyber threats and risks;
Formatted: Font: 11 pt
— — aligning IT investments with stakeholder requirements and organizational goals; and
Formatted: FooterPageNumber, Space After: 0 pt, Line
spacing: single
8 © ISO #### /IEC 2026 – All rights reserved
ISO/IEC DISFDIS 38501-1:20252026(en) Formatted: Font: 11 pt, Bold
Formatted: Font: 11 pt, Bold
Formatted: Font: 11 pt, Bold
— — ensuring a stakeholder supportive culture.
Formatted: HeaderCentered, Left, Space After: 0 pt,
Line spacing: single
Engaging stakeholders is an on-going process that is further enhanced through the continual application of
the activities described in this document.
Formatted: Adjust space between Latin and Asian text,
Adjust space between Asian text and numbers
7.1.2 Internal stakeholders
Formatted: Adjust space between Latin and Asian text,
Adjust space between Asian text and numbers, Tab
Internal stakeholders include the governing body, executive managers (e.g. chief executive officer, chief
stops: Not at 0.71 cm + 0.99 cm + 1.27 cm
financial officer, chief information officer, HRhuman resources executive), business managers, IT staff (e.g.
Formatted: Adjust space between Latin and Asian text,
developers, infrastructure administrators, application administrators, data experts), business information
Adjust space between Asian text and numbers
management and the general user community.
Understanding internal stakeholder expectations helps the organization to :
— set appropriate strategies, policies and decision-making structures, as well as to ;
— define behavioural, performance and stewardship requirements, as well as roles and responsibilities for
Formatted: List Continue 1, Adjust space between Latin
these stakeholders.
and Asian text, Adjust space between Asian text and
numbers
This can be achieved by holding briefing sessions or workshops with internal stakeholders, aimed at both
assisting in determining their expectations, and providing the opportunity to develop awareness of key
aspects of the governance of IT, including:
— — the need for the governance of IT and how it fits in with corporate governance;
Formatted: Adjust space between Latin and Asian text,
Adjust space between Asian text and numbers, Tab
— — how business value is realized from the use of IT in the organization;
stops: Not at 0.7 cm + 1.4 cm + 2.1 cm + 2.8 cm +
3.5 cm + 4.2 cm + 4.9 cm + 5.6 cm + 6.3 cm + 7 cm
— — climate action and organizational sustainability;
— — the risks associated with maintaining current and implementing new IT capabilities;
Formatted: Default Paragraph Font
Formatted: Default Paragraph Font
— — the principles, model and framework described in ISO/IEC 38500, and the implementation process
that the organization will be undertaking; and
Formatted: Default Paragraph Font
Formatted: Default Paragraph Font
— — facilitating stakeholder assessments of the effectiveness of current governance of IT arrangements
Formatted: Default Paragraph Font
(see ISO/IEC TS 38501-2:—, Annex A).
Formatted: Default Paragraph Font
7.1.3 External stakeholders
Formatted: Default Paragraph Font
External stakeholders can vary considerably between organizations and can include: shareholders, investors,
Formatted: Adjust space between Latin and Asian text,
individuals, society at large, customers, suppliers, consortium members, third-party developers, third-party
Adjust space between Asian text and numbers, Tab
service providers, as well as governments and regulatory authorities. stops: Not at 0.71 cm + 0.99 cm + 1.27 cm
Formatted: Adjust space between Latin and Asian text,
Understanding the expectations of these stakeholders and clarifying the roles, responsibilities and
Adjust space between Asian text and numbers
accountabilities of the various parties will assistassists in achieving desired organizational outcomes,
Formatted: Adjust space between Latin and Asian text,
including:
Adjust space between Asian text and numbers, Tab
stops: Not at 0.7 cm + 1.4 cm + 2.1 cm + 2.8 cm +
— — streamlining the supply and demand of third-party services in the organizational ecosystem;
3.5 cm + 4.2 cm + 4.9 cm + 5.6 cm + 6.3 cm + 7 cm
Formatted: Font: 10 pt
— — achieving resilience and minimizing the risks of negative events for the organization and these
stakeholders;
Formatted: Font: 10 pt
Formatted:
...