§13 · Lane 4 — ISO/IEC AI Management System Family
ISO/IEC 38507:2022 (Governance Implications of AI)
ISO/IEC (2022) · ISO/IEC 38507
Bibliographic data
- Title
- ISO/IEC 38507:2022 — Governance implications of the use of artificial intelligence by organizations
- Authors / Issuing body
- ISO/IEC
- Venue / Publisher
- ISO/IEC
- Year
- 2022
- Designation
- Standard
- Licence
- Stable URL — refer to publisher for full licence terms.
- Canonical link
- https://www.iso.org/standard/56641.html
How to cite
ISO/IEC (2022). ISO/IEC 38507:2022 — Governance implications of the use of artificial intelligence by organizations. ISO/IEC. https://www.iso.org/standard/56641.html.
The governance standard addressed to the governing body (board / top management), not the AIMS owner. Overlays ISO/IEC 38500:2015 (governance of IT) and ISO 37000:2021 (governance of organizations) with AI-specific guidance. Sits above 42001 in the stack — governs the body that owns the AIMS rather than the AIMS itself.
Why it matters for NETEVO
ISO/IEC 38507:2022 is the governance standard addressed to the board itself, not to the AI management system the board owns — and that altitude is precisely why it closes the highest-leverage citation gap in NETEVO's substrate.
Direct overlay onto the AU board-paper regime. Where ISO/IEC 42001 governs the AI management system and ISO/IEC 23894 governs AI risk, ISO/IEC 38507 binds the governing body that owns the management system into Australian director-duty law. NETEVO's digest catalogues fourteen such mappings — Corporations Act 2001 (Cth) ss 180-183, ASX CGC Principles 1, 4 and 7, APRA CPS 230 operational risk management, Privacy Act 1988 governance hooks, the NSW AI Assessment Framework, and the AICD/HTI Director's Guide eight elements among them. This is the citation that lets NETEVO position director duties under section 180 as operationalised against an international standard rather than asserted from first principles.
Two substantive shall obligations carry unusual weight for a guidance standard. Clause 4.1 normatively forward-references Annex A, so the annex is treated as binding rather than informative; Clause 6.7.3 obligates stakeholder consideration of reputation and trust. Both modal verbs are preserved verbatim in the digest paraphrase, signalling compliance weight to anyone drafting board charters or policies against the standard.
The natural anchor for Implicit Authority Cascade. Where 42001 governs AI systems and 23894 governs AI risks, ISO/IEC 38507 governs who delegates authority into the AI system in the first place — the precise question Implicit Authority Cascade frames. It is the only international standard in the stack whose normative structure maps cleanly onto board-level agentic-authority accountability, and the natural anchor for the forthcoming AI-Washing Audit whitepaper alongside the AICD/HTI Director's Guide.
Where NETEVO applies this
- AI Governance in ANZ Whitepaper — AU director-duty overlay and ASX CGC mapping
- Listed Leaders ICP — standard addressed to ASX-listed boards