ISO/IEC 38507:2022 — Governance implications of the use of AI by organizations
ISO/IEC 38507:2022 — Governance implications of the use of AI by organizations — 83% of in-scope requirements covered.
12 requirements · 12 in scope (8 enforced · 4 designed). The 83% is weighted over the in-scope base.
Source: ISO/IEC 38507:2022 — Information technology — Governance of IT — Governance implications of the use of artificial intelligence by organizations. Guidance for the governing body (the Evaluate-Direct-Monitor model of the ISO/IEC 38500 family) applied to AI. The KYE™ registry paraphrases each governance implication's intent and cites the standard for crosswalk purposes only; it reproduces no substantial text and fabricates no clause numbers (ISO/IEC 38507 is guidance, not a shall-clause management-system standard). · License: ISO/IEC 38507:2022 is a copyrighted ISO/IEC standard. The KYE™ registry paraphrases the governance implication of each topic and cites the standard's title/scope for mapping purposes only, reproducing no substantial text. Mapping is one-directional (governance implication -> KYE™ artefact) and asserts no ISO/IEC endorsement.
By category
| Category | Reqs | Enforced | Designed | Advisory | Deferred | Coverage |
|---|---|---|---|---|---|---|
| Accountability & the governing body (EDM) | 3 | 2 | 1 | 0 | 0 | 83% |
| Direct — purpose, values & policy | 2 | 2 | 0 | 0 | 0 | 100% |
| Evaluate — AI-specific considerations | 3 | 0 | 3 | 0 | 0 | 50% |
| Monitor — oversight & assurance | 2 | 2 | 0 | 0 | 0 | 100% |
| Transparency & compliance | 2 | 2 | 0 | 0 | 0 | 100% |
Every requirement → the KYE™ artefact that enforces it
| ID | Title | Status | KYE™ enforcement |
|---|---|---|---|
iso-iec-38507.governing-body-accountability |
The governing body is accountable for the organization's use of AI and cannot delegate that accountability, even when management or AI agents operate the system | enforced | audit_events: kye.purpose.request.v1, kye.agent.governance.v1engines: internal, internalconstitution_refs: constitution/52-DELEGATED-AGENT-BINDING.md, constitution/00-INDEX.md |
iso-iec-38507.accountability-for-outcomes |
There must be clear accountability for AI outcomes — who is answerable for each consequential action is identifiable after the fact | enforced | audit_events: kye.evidence.pack.v1, kye.replay.proof.v1engines: internal, internalconstitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/30-AUDIT-WORM-RETENTION.md |
iso-iec-38507.governance-vs-management |
The governing body evaluates, directs and monitors (EDM) the use of AI; it does not operate the AI — the governance/management distinction of ISO/IEC 38500 applies | designed | audit_events: kye.purpose.admissibility.v1engines: internal, internalconstitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/16-EDGE-RUNTIME.md |
iso-iec-38507.purpose-alignment |
AI use must align with the organization's objectives, values and obligations, as directed by the governing body | enforced | audit_events: kye.purpose.admissibility.v1, kye.evidence.decision_map.v1engines: internal, internalconstitution_refs: constitution/12-PURPOSE-PERMISSION.md |
iso-iec-38507.acceptable-use-policy |
The governing body sets policies defining acceptable AI use, and those policies are enforced in operation | enforced | audit_events: kye.evidence.decision_map.v1engines: internal, internalconstitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/29-PROFILES-LITE.md |
iso-iec-38507.ai-characteristics-consequences |
The governing body must understand and address AI-specific characteristics — autonomy/agency, data-dependence, opacity and continuous adaptation — and their consequences | designed | audit_events: kye.purpose.admissibility.v1engines: internal, internalconstitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/52-DELEGATED-AGENT-BINDING.md |
iso-iec-38507.risk-oversight |
The governing body must oversee AI risk, including emergent and systemic risk | designed | audit_events: kye.evidence.decision_map.v1engines: internal, internalconstitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/25-EDGE-GOVERNANCE.md |
iso-iec-38507.data-governance-for-ai |
The governing body must ensure governance of the data used by AI — provenance, quality and lawful basis | designed | audit_events: kye.evidence.decision_map.v1, kye.purpose.admissibility.v1engines: internal, internalconstitution_refs: constitution/31-DATA-GOVERNANCE-PACK.md, constitution/12-PURPOSE-PERMISSION.md |
iso-iec-38507.material-decision-oversight |
The governing body must provide oversight of AI decisions with material consequences, including the ability to intervene (human oversight) | enforced | audit_events: kye.purpose.admissibility.v1, kye.compliance.attestation.v1engines: internal, internalconstitution_refs: constitution/36-GOVERNEDUI.md, constitution/21-DELEGATED-AUDITABILITY.md |
iso-iec-38507.continuous-monitoring |
The governing body must monitor AI use over time (the Monitor of EDM) — authority is not granted once at inception but overseen continuously | enforced | audit_events: kye.purpose.admissibility.v1, kye.compliance.attestation.v1engines: internal, internalconstitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/34-RECONCILIATION-ENGINE.md |
iso-iec-38507.transparency-explainability |
The governing body sets transparency and explainability expectations for AI use | enforced | audit_events: kye.evidence.decision_map.v1, kye.replay.proof.v1engines: internal, internalconstitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/21-DELEGATED-AUDITABILITY.md |
iso-iec-38507.compliance-obligations |
The governing body must ensure the organization's use of AI meets its compliance and regulatory obligations | enforced | audit_events: kye.compliance.attestation.v1engines: internal, internalconstitution_refs: constitution/00-INDEX.md, constitution/70-FRAMEWORK-MAPPING-RAIL.md |