Comply · International standards
ISO/IEC 38507:2022 — Governance implications of AI
Governance implications of AI for boards and executives.
ISO/IEC 38507:2022 provides guidance for the governing body of an organization — boards and executives — on the governance implications of using AI, helping leaders oversee AI use responsibly, align it with strategy, and meet their accountability and stakeholder obligations.
Who it applies to
Boards, executives, and governing bodies overseeing organizational use of AI.
Key obligations
- Set direction and policy for responsible AI use
- Oversee AI risk, ethics, and compliance
- Ensure accountability and stakeholder trust
How Maetra maps agents to ISO/IEC 38507
Maetra gives leadership a single, evidence-backed view of the AI estate — inventory, compliance posture, approvals, and incidents — to exercise oversight. (Licensed standard — activated on demand.)
In practice, Maetra:
- Scans and fingerprints each agent. Discover reads the agent’s code — its tools, data access and sensitivity, actions, model, and environment — into an evidence-backed profile tied to the exact file and commit.
- Decides what applies. That profile determines whether ISO/IEC 38507 is in scope for the agent and which of its requirements apply.
- Auto-detects controls and surfaces gaps. Controls your code already satisfies are detected automatically from the scan; the rest become a clear list of gaps, each tied to the requirement and the evidence it still needs.
- Proves it and keeps it current. Close gaps with linked evidence or generated documents — reused across every framework the same control supports — and Maetra re-checks on each rescan and flags evidence that has gone stale.
Related frameworks
Prove ISO/IEC 38507 compliance with Maetra
Classify your AI agents once and Maetra maps them to ISO/IEC 38507 and every other framework it supports — generating the evidence and documentation, tracking gaps and deadlines, and sealing every decision in an immutable audit trail.