White Paper on the differences between ISO/IEC 38500:2015 and ISO/IEC 38500:2024
- Introduction
In early 2024, a new revision of ISO/IEC 38500 was released to replace the previous version produced in 2015.
The revision was initiated because, since the "initial publication of ISO/IEC 38500, there have been significant changes in information technology, which have affected not only information and technology but also the pace and scope of organizational change. This phenomenon has impacted the structure and operations of organizations, stakeholder expectations and therefore the governance requirements and capabilities necessary for organizations to adapt." [1] Source; SC 40/AHG 01 Review of ISO/IEC 38500 family May 2020
- Governance Outcomes
ISO/IEC 38500: 2024 is now aligned with ISO 37000 Organizational governance to provide a model and framework for effective performance; responsible stewardship and ethical behaviour can be delivered.
A key aspect of ISO/IEC 38500 is that the standard explains the implications for the Governance of IT of ISO 37000's three key outcomes outlined below:
- Effective performance: The organization maintains alignment with its purpose, policies, and stakeholder expectations, ensuring required performance standards are met and value is generated for stakeholders.
- Responsible stewardship: Through responsible resource management and consideration of global impacts, the organization contributes to sustainable development while fostering trust and confidence within and beyond the communities it operates in.
- Ethical behaviour: Upholding an ethical culture, accountability, and transparency, the organization demonstrates fairness, integrity, and competence in its decision-making processes and interactions with stakeholders.
Adopting outcomes from ISO 37000 as a part of ISO/IEC 38500:2024 recognizes that the Governance of IT is an integral element of organizational Governance.
- Governance Principles
ISO/IEC 38500 continues to be a principle-based standard. However, ISO/IEC 38500:2024 has now adopted the principles within ISO 37000 with guidance on how they apply to the Governance of IT. See ISO 37000 Governance of Organizations - Guidance for a description of these principles.).
This change results in a move from six principles to eleven, as shown below, with an appropriate explanation of each principle.
ISO/IEC 38500:2024 discussion of each principle provides guidance on the implications of IT for applying the principles. As part of that discussion, it addresses how Governance has to address the significant changes in information technology, which have affected not only information and technology but also the pace and scope of organizational change.
Adopting ISO 37000 principles expands the focus to address the critical role that IT governance plays in using data within organizations, as well as environmental and social issues.
- Model for the Governance of IT:
ISO/IEC 38500: 2024 has updated the underlying model for the relationship between Governance and management of IT. This is illustrated in the changes to the supporting diagram shown below.
The more noticeable change is adding "engage stakeholders" as an element of the model.
However, the model changes also reflect a more significant change in the focus of the standard. Rather than primarily addressing the exercise of Governance by governing bodies, the new guidance stresses that Governance is exercised throughout the organization, with management operating within the framework defined by the governing body.
- Framework for the Governance of IT:
ISO/IEC 38500:2024 expands on the concept of the governance framework first identified in ISO/IEC 38502.
ISO 37000 defines "organizational governance framework: strategies, governance policies decision-making structures and accountabilities through which the organization's governance arrangements operate".
In the context of ISO/IEC 38500:2024, the framework provides the mechanism through which Governance and management should operate together for effective Governance.
ISO/IEC 38500:2024 identifies the six elements of a governance framework as summarised below;
- Direction: The direction for IT use is reviewed and aligned with organizational goals while considering emerging technologies and external stakeholder needs.
- Capability: The digital capabilities essential for supporting organizational objectives are identified, orchestrated, and managed, ensuring alignment with overall capabilities.
- Policy: Governance policies are established to guide IT use, reflect strategic decisions, and provide parameters for effective management while allowing flexibility to adapt to changing circumstances.
- Delegation: Delegation of authority and responsibility for IT use is supported through governance practices, ensuring alignment with organizational requirements and careful oversight across the organization's ecosystem.
- Performance: Clear performance expectations are established, and proactive monitoring mechanisms are implemented to measure and improve IT performance, especially in rapidly changing environments.
- Accountability: Accountability and compliance with IT policies are demonstrated through effective mechanisms and considering factors like AI adaptation and automated assurance.
More details on the ISO/IEC 38500:2024 can be found here: https://committee.iso.org/sites/jtc1sc40/home/projects/wg-1/published-wg1.html