ISO/IEC 38507:2022 — Governance implications of the use of AI by organizations

ISO/IEC 38507:2022 — Governance implications of the use of AI by organizations

ISO/IEC 38507:2022 — Governance implications of the use of AI by organizations — 83% of in-scope requirements covered.

12 requirements · 12 in scope (8 enforced · 4 designed). The 83% is weighted over the in-scope base.

Source: ISO/IEC 38507:2022 — Information technology — Governance of IT — Governance implications of the use of artificial intelligence by organizations. Guidance for the governing body (the Evaluate-Direct-Monitor model of the ISO/IEC 38500 family) applied to AI. The KYE registry paraphrases each governance implication's intent and cites the standard for crosswalk purposes only; it reproduces no substantial text and fabricates no clause numbers (ISO/IEC 38507 is guidance, not a shall-clause management-system standard). · License: ISO/IEC 38507:2022 is a copyrighted ISO/IEC standard. The KYE registry paraphrases the governance implication of each topic and cites the standard's title/scope for mapping purposes only, reproducing no substantial text. Mapping is one-directional (governance implication -> KYE artefact) and asserts no ISO/IEC endorsement.

By category

CategoryReqsEnforcedDesignedAdvisoryDeferredCoverage
Accountability & the governing body (EDM) 3 2 1 0 0 83%
Direct — purpose, values & policy 2 2 0 0 0 100%
Evaluate — AI-specific considerations 3 0 3 0 0 50%
Monitor — oversight & assurance 2 2 0 0 0 100%
Transparency & compliance 2 2 0 0 0 100%

Every requirement → the KYE artefact that enforces it

IDTitleStatusKYE enforcement
iso-iec-38507.governing-body-accountability The governing body is accountable for the organization's use of AI and cannot delegate that accountability, even when management or AI agents operate the system enforced audit_events: kye.purpose.request.v1, kye.agent.governance.v1
engines: internal, internal
constitution_refs: constitution/52-DELEGATED-AGENT-BINDING.md, constitution/00-INDEX.md
iso-iec-38507.accountability-for-outcomes There must be clear accountability for AI outcomes — who is answerable for each consequential action is identifiable after the fact enforced audit_events: kye.evidence.pack.v1, kye.replay.proof.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/30-AUDIT-WORM-RETENTION.md
iso-iec-38507.governance-vs-management The governing body evaluates, directs and monitors (EDM) the use of AI; it does not operate the AI — the governance/management distinction of ISO/IEC 38500 applies designed audit_events: kye.purpose.admissibility.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/16-EDGE-RUNTIME.md
iso-iec-38507.purpose-alignment AI use must align with the organization's objectives, values and obligations, as directed by the governing body enforced audit_events: kye.purpose.admissibility.v1, kye.evidence.decision_map.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
iso-iec-38507.acceptable-use-policy The governing body sets policies defining acceptable AI use, and those policies are enforced in operation enforced audit_events: kye.evidence.decision_map.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/29-PROFILES-LITE.md
iso-iec-38507.ai-characteristics-consequences The governing body must understand and address AI-specific characteristics — autonomy/agency, data-dependence, opacity and continuous adaptation — and their consequences designed audit_events: kye.purpose.admissibility.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/52-DELEGATED-AGENT-BINDING.md
iso-iec-38507.risk-oversight The governing body must oversee AI risk, including emergent and systemic risk designed audit_events: kye.evidence.decision_map.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/25-EDGE-GOVERNANCE.md
iso-iec-38507.data-governance-for-ai The governing body must ensure governance of the data used by AI — provenance, quality and lawful basis designed audit_events: kye.evidence.decision_map.v1, kye.purpose.admissibility.v1
engines: internal, internal
constitution_refs: constitution/31-DATA-GOVERNANCE-PACK.md, constitution/12-PURPOSE-PERMISSION.md
iso-iec-38507.material-decision-oversight The governing body must provide oversight of AI decisions with material consequences, including the ability to intervene (human oversight) enforced audit_events: kye.purpose.admissibility.v1, kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/36-GOVERNEDUI.md, constitution/21-DELEGATED-AUDITABILITY.md
iso-iec-38507.continuous-monitoring The governing body must monitor AI use over time (the Monitor of EDM) — authority is not granted once at inception but overseen continuously enforced audit_events: kye.purpose.admissibility.v1, kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/34-RECONCILIATION-ENGINE.md
iso-iec-38507.transparency-explainability The governing body sets transparency and explainability expectations for AI use enforced audit_events: kye.evidence.decision_map.v1, kye.replay.proof.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/21-DELEGATED-AUDITABILITY.md
iso-iec-38507.compliance-obligations The governing body must ensure the organization's use of AI meets its compliance and regulatory obligations enforced audit_events: kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/00-INDEX.md, constitution/70-FRAMEWORK-MAPPING-RAIL.md