Back to Frameworks

ISO 37004:2023

International
v2023 (first edition)
3 domains
35 controls

ISO 37004:2023 gives guidance on measuring the maturity of an organization's governance in terms of ISO 37000: how far the governing body has established the seven governance conditions and applied the eleven governance principles. Clause 4 defines the three maturity aspects, governance behaviour (adoption, understanding, application, analysis, evaluation, improvement), governance effectiveness (the practices used to apply each principle) and governance efficiency (how far the practices are made explicit, delegated, consistently applied and improved through the seven governance components: frameworks, strategies, policies, performance results, charters, management reports and component reviews, with Table 1 setting the contents of a governance framework). Clause 5 gives the measurement framework: five activities (commit, design, implement, oversee, action), nine measurement principles, and a six-point scale from 0 undefined to 5 optimizing described per aspect (Tables 2 to 6), with aggregation by arithmetic mean rounded down. Clause 6 gives the maturity model: the dimensions (conditions and principles), evaluation judgements (a dimension's result is the lowest of its aspects), aggregation, the determination of the appropriate rather than the highest level of maturity, short- and long-term improvement targets, prioritised and overseen improvement initiatives, an evaluation template and transparent maturity reporting. Guidance, not certifiable; the measurement companion to ISO 37000 and the basis for governance self-assessment, benchmarking and disclosure.

Verified

ISO 37004:2023 is a compliance framework from International with 3 domains and 35 controls. The largest domains are Clause 5: Governance maturity measurement framework – ISO 37004:2023 (13 controls), Clause 4: Governance maturity aspects – ISO 37004:2023 (11 controls), Clause 6: Governance maturity model – ISO 37004:2023 (11 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard Blokdyk

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (3)

Clause 4: Governance maturity aspects – ISO 37004:2023

11 controls
Controls in the Clause 4: Governance maturity aspects – ISO 37004:2023 domain of ISO 37004:202311 controls
CodeTitle
iso-37004-2023::4.1General: the purpose of evaluating governance maturity and its three aspects
iso-37004-2023::4.2Governance behaviour
iso-37004-2023::4.3Governance effectiveness
iso-37004-2023::4.4.1General: governance efficiency and governance components
iso-37004-2023::4.4.2Governance frameworks
iso-37004-2023::4.4.3Governance strategies
iso-37004-2023::4.4.4Governance policies
iso-37004-2023::4.4.5Organizational performance results
iso-37004-2023::4.4.6Governance charters
iso-37004-2023::4.4.7Management reports
iso-37004-2023::4.4.8Governance component reviews

Clause 5: Governance maturity measurement framework – ISO 37004:2023

13 controls
Controls in the Clause 5: Governance maturity measurement framework – ISO 37004:2023 domain of ISO 37004:202313 controls
CodeTitle
iso-37004-2023::5.1General: the measurement framework and its five activities
iso-37004-2023::5.2Measurement principles
iso-37004-2023::5.3.1Commitment
iso-37004-2023::5.3.2Design
iso-37004-2023::5.3.3Implement
iso-37004-2023::5.3.4Oversee
iso-37004-2023::5.3.5Action
iso-37004-2023::5.4.1General: the six-point scale
iso-37004-2023::5.4.2Governance behaviour scale
iso-37004-2023::5.4.3Governance effectiveness scale
iso-37004-2023::5.4.4Governance efficiency scale
iso-37004-2023::5.4.5Governance maturity scale
iso-37004-2023::5.5Measurement aggregation

Clause 6: Governance maturity model – ISO 37004:2023

11 controls
Controls in the Clause 6: Governance maturity model – ISO 37004:2023 domain of ISO 37004:202311 controls
CodeTitle
iso-37004-2023::6.1General: the governance maturity model
iso-37004-2023::6.2.1Governance conditions
iso-37004-2023::6.2.2Governance principles
iso-37004-2023::6.3.1Maturity model content
iso-37004-2023::6.3.2Evaluation judgements
iso-37004-2023::6.3.3Aggregation of results
iso-37004-2023::6.4.1Determining governance appropriateness
iso-37004-2023::6.4.2Setting improvement targets
iso-37004-2023::6.4.3Implementing improvement initiatives
iso-37004-2023::6.5Governance maturity evaluation
iso-37004-2023::6.6Governance maturity reporting

What is ISO 37004:2023 and who does it apply to?

ISO 37004:2023 is a compliance framework from International with 3 domains and 35 controls. ISO 37004:2023 gives guidance on measuring the maturity of an organization's governance in terms of ISO 37000: how far the governing body has established the seven governance conditions and applied the eleven governance principles. Clause 4 defines the three maturity aspects, governance behaviour (adoption, understanding, application, analysis, evaluation, improvement), governance effectiveness (the practices used to apply each principle) and governance efficiency (how far the practices are made explicit, delegated, consistently applied and improved through the seven governance components: frameworks, strategies, policies, performance results, charters, management reports and component reviews, with Table 1 setting the contents of a governance framework). Clause 5 gives the measurement framework: five activities (commit, design, implement, oversee, action), nine measurement principles, and a six-point scale from 0 undefined to 5 optimizing described per aspect (Tables 2 to 6), with aggregation by arithmetic mean rounded down. Clause 6 gives the maturity model: the dimensions (conditions and principles), evaluation judgements (a dimension's result is the lowest of its aspects), aggregation, the determination of the appropriate rather than the highest level of maturity, short- and long-term improvement targets, prioritised and overseen improvement initiatives, an evaluation template and transparent maturity reporting. Guidance, not certifiable; the measurement companion to ISO 37000 and the basis for governance self-assessment, benchmarking and disclosure. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does ISO 37004:2023 actually require?

ISO 37004:2023 has 35 controls organised across 3 domains. The largest domains are Clause 5: Governance maturity measurement framework – ISO 37004:2023 (13 controls), Clause 4: Governance maturity aspects – ISO 37004:2023 (11 controls), Clause 6: Governance maturity model – ISO 37004:2023 (11 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of ISO 37004:2023 do I already cover?

ISO 37004:2023 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I implement ISO 37004:2023?

Start your ISO 37004:2023 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO 37004:2023 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 35 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.

Get Started Free →

Free forever — no credit card required