ISO/IEC 38500:2024
Model for the governance of IT – ISO/IEC 38500:2024

ISO/IEC 38500:2024 6.2.1: Engage stakeholders

The governing body should identify the relevant internal and external stakeholders in the organization's IT, consult them and involve them appropriately; in particular it should make sure that obligations around the use of IT and data are clearly defined, and that any breach of them is communicated at once so that the organization and the stakeholders concerned can deal with the consequences. This is the task the third edition adds to the model.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 14 controls across 5 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 23894:2023 · 7 controls

ISO/IEC TR 24028:2020 · 3 controls

  • 8.1 General: vulnerabilities, threats and challenges
  • 8.3.1 AI specific privacy threats: general
  • 8.4 Bias

COBIT 2019 · 2 controls

  • EDM01.01 EDM01.01 Evaluate the governance system
  • EDM05.01 EDM05.01 Evaluate stakeholder engagement and reporting requirements

ISO 14004:2016 · 1 control

ISO/IEC 42001:2023 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Model for the governance of IT – ISO/IEC 38500:2024

Query this from an agent

The graph holds this control, the 14 it maps to, and the evidence behind each claim, over MCP and REST.