Contact us
Illustration for ISO management-system services

ISO/IEC 38507

ISO/IEC 38507 AI governance implementation

ISO/IEC 38507 consulting helps governing bodies decide how AI should be used and overseen. Vosurein translates technical project details into information about purpose, value, responsibilities and risks that leaders can assess, so AI governance extends beyond an IT policy.

Discuss ISO/IEC 38507 AI governance consulting

For Your Business

Who this service is for and when to start

Suitable for organizations preparing to expand AI usage, establish internal policies, or needing to set up management-level oversight arrangements. Before investment and procurement decisions, clarify which uses can be authorized and which situations require escalated review.

The Challenge

Common challenges faced by businesses

Departments often buy AI tools independently, leaving leaders unsure where data goes or which decisions depend on models. Asking technical staff to guarantee safety cannot replace the organisation’s judgement about acceptable uses.

If oversight information only includes accuracy or usage frequency, it may not show changes in responsibilities for personnel, customers, and the organization.

Our Approach

Methods and applicable requirements

ISO/IEC 38507:2022 provides organizational governance guidance for current and future AI usage, and can also serve as a reference for managers and relevant professionals. The focus is on effective, efficient, and acceptable use, not model testing or management system certification requirements.

The priorities below depend on the organisation’s context. Confirm the scope and level of supporting evidence at the start.

Governance Roles

Clearly distinguish between governance oversight, management decisions, and technical execution, confirm who approves the usage and who tracks issues, avoiding leaving all responsibility to the IT contact point.

Decision Principles

Discuss the purpose of AI usage, expected value, and unacceptable conditions, converting principles into judgment questions usable before procurement or rollout.

Performance Monitoring

Organize the effectiveness, limitations, and significant issue information needed by supervisors, design escalation thresholds, so reports can support decision-making.

Governance Review

Review whether policies still align with organizational and external changes, understand usage scale and personnel role changes, and adjust authorizations as necessary.

Process

Consulting scope and process

  1. Identify governance needs

    Organize AI used and planned, confirm existing decision-making and supervisory gaps.

  2. Establish Authority Principles

    Discuss usage, approval, and escalation arrangements with supervisors to form executable governance rules.

  3. Pilot Management Reports

    Test needed information and decision questions with actual projects, avoiding reporting only technical indicators.

  4. Schedule Regular Reviews

    Confirm the frequency of policy, report, and major change checks, and hand over governance maintenance responsibilities.

Preparation

What documents do companies need to prepare?

  • Overview of AI Usage: Applications, departments, objectives, and supplier relationships.
  • Governance and Authorization: Existing policies, committees, and decision-making authority.
  • Effectiveness and Risks: Project outcomes, constraints, and critical issues.
  • Supervision Records: Supervisor reports, approvals, and change information.

An index or summary is enough for an initial discussion. Before sharing personal data, confidential contract information or system records, agree on access authorisation, redaction and retention.

Project Planning

Estimating time and cost

We assess scope by governance levels, department numbers, policy coverage and workshop depth. Board or executive training can be separated from piloting governance procedures. Technical tests, legal reviews and system implementation require their own agreed scope.

FAQ

Frequently asked questions

Is this a standard for engineers?

Its main focus is how governing bodies oversee and decide on AI use. Technical staff provide information but cannot carry governance responsibilities alone.

Is this useful if we already have an internal AI use policy?

First check whether the policy covers decisions, oversight and escalation. If it already does, there is no need to create duplicate documents.

Is it necessary to establish a new committee?

Not assumed. Existing governance arrangements can be used according to organizational size; the key is that responsibilities and information can operate effectively.

Will model accuracy be evaluated?

This item focuses on governance; technical evaluation can serve as input, and if additional testing is needed, data and methods must be confirmed.

Can it be integrated with ISO/IEC 42001?

Governance principles can be connected to management systems, but the purposes and requirements are different, and each still needs to confirm its applicable scope.

How to avoid policies becoming slogans?

Link principles to actual project approval, reporting, and stopping conditions, and use case studies to check whether supervisors can make decisions.

Related

Related services and enquiries

Tell us your industry, the activities you want to improve, your existing system and your target completion date so we can define the scope together.

Content checked: . Applicable versions and requirements depend on the company’s circumstances.

Let's Talk

Start a conversation about your needs.

Tell us how the work is done today and when you hope to finish,
so we can agree the scope and way of working together.

Discuss your service needsBack to ISO management-system contents