ISO 37004:2023
ISO 37004:2023 gives guidance on measuring the maturity of an organization's governance in terms of ISO 37000: how far the governing body has established the seven governance conditions and applied the eleven governance principles. Clause 4 defines the three maturity aspects, governance behaviour (adoption, understanding, application, analysis, evaluation, improvement), governance effectiveness (the practices used to apply each principle) and governance efficiency (how far the practices are made explicit, delegated, consistently applied and improved through the seven governance components: frameworks, strategies, policies, performance results, charters, management reports and component reviews, with Table 1 setting the contents of a governance framework). Clause 5 gives the measurement framework: five activities (commit, design, implement, oversee, action), nine measurement principles, and a six-point scale from 0 undefined to 5 optimizing described per aspect (Tables 2 to 6), with aggregation by arithmetic mean rounded down. Clause 6 gives the maturity model: the dimensions (conditions and principles), evaluation judgements (a dimension's result is the lowest of its aspects), aggregation, the determination of the appropriate rather than the highest level of maturity, short- and long-term improvement targets, prioritised and overseen improvement initiatives, an evaluation template and transparent maturity reporting. Guidance, not certifiable; the measurement companion to ISO 37000 and the basis for governance self-assessment, benchmarking and disclosure.
ISO 37004:2023 is a compliance framework from International with 3 domains and 35 controls. The largest domains are Clause 5: Governance maturity measurement framework – ISO 37004:2023 (13 controls), Clause 4: Governance maturity aspects – ISO 37004:2023 (11 controls), Clause 6: Governance maturity model – ISO 37004:2023 (11 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (3)
Clause 4: Governance maturity aspects – ISO 37004:2023
| Code | Title |
|---|---|
| iso-37004-2023::4.1 | General: the purpose of evaluating governance maturity and its three aspects |
| iso-37004-2023::4.2 | Governance behaviour |
| iso-37004-2023::4.3 | Governance effectiveness |
| iso-37004-2023::4.4.1 | General: governance efficiency and governance components |
| iso-37004-2023::4.4.2 | Governance frameworks |
| iso-37004-2023::4.4.3 | Governance strategies |
| iso-37004-2023::4.4.4 | Governance policies |
| iso-37004-2023::4.4.5 | Organizational performance results |
| iso-37004-2023::4.4.6 | Governance charters |
| iso-37004-2023::4.4.7 | Management reports |
| iso-37004-2023::4.4.8 | Governance component reviews |
Clause 5: Governance maturity measurement framework – ISO 37004:2023
| Code | Title |
|---|---|
| iso-37004-2023::5.1 | General: the measurement framework and its five activities |
| iso-37004-2023::5.2 | Measurement principles |
| iso-37004-2023::5.3.1 | Commitment |
| iso-37004-2023::5.3.2 | Design |
| iso-37004-2023::5.3.3 | Implement |
| iso-37004-2023::5.3.4 | Oversee |
| iso-37004-2023::5.3.5 | Action |
| iso-37004-2023::5.4.1 | General: the six-point scale |
| iso-37004-2023::5.4.2 | Governance behaviour scale |
| iso-37004-2023::5.4.3 | Governance effectiveness scale |
| iso-37004-2023::5.4.4 | Governance efficiency scale |
| iso-37004-2023::5.4.5 | Governance maturity scale |
| iso-37004-2023::5.5 | Measurement aggregation |
Clause 6: Governance maturity model – ISO 37004:2023
| Code | Title |
|---|---|
| iso-37004-2023::6.1 | General: the governance maturity model |
| iso-37004-2023::6.2.1 | Governance conditions |
| iso-37004-2023::6.2.2 | Governance principles |
| iso-37004-2023::6.3.1 | Maturity model content |
| iso-37004-2023::6.3.2 | Evaluation judgements |
| iso-37004-2023::6.3.3 | Aggregation of results |
| iso-37004-2023::6.4.1 | Determining governance appropriateness |
| iso-37004-2023::6.4.2 | Setting improvement targets |
| iso-37004-2023::6.4.3 | Implementing improvement initiatives |
| iso-37004-2023::6.5 | Governance maturity evaluation |
| iso-37004-2023::6.6 | Governance maturity reporting |
What is ISO 37004:2023 and who does it apply to?
ISO 37004:2023 is a compliance framework from International with 3 domains and 35 controls. ISO 37004:2023 gives guidance on measuring the maturity of an organization's governance in terms of ISO 37000: how far the governing body has established the seven governance conditions and applied the eleven governance principles. Clause 4 defines the three maturity aspects, governance behaviour (adoption, understanding, application, analysis, evaluation, improvement), governance effectiveness (the practices used to apply each principle) and governance efficiency (how far the practices are made explicit, delegated, consistently applied and improved through the seven governance components: frameworks, strategies, policies, performance results, charters, management reports and component reviews, with Table 1 setting the contents of a governance framework). Clause 5 gives the measurement framework: five activities (commit, design, implement, oversee, action), nine measurement principles, and a six-point scale from 0 undefined to 5 optimizing described per aspect (Tables 2 to 6), with aggregation by arithmetic mean rounded down. Clause 6 gives the maturity model: the dimensions (conditions and principles), evaluation judgements (a dimension's result is the lowest of its aspects), aggregation, the determination of the appropriate rather than the highest level of maturity, short- and long-term improvement targets, prioritised and overseen improvement initiatives, an evaluation template and transparent maturity reporting. Guidance, not certifiable; the measurement companion to ISO 37000 and the basis for governance self-assessment, benchmarking and disclosure. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ISO 37004:2023 actually require?
ISO 37004:2023 has 35 controls organised across 3 domains. The largest domains are Clause 5: Governance maturity measurement framework – ISO 37004:2023 (13 controls), Clause 4: Governance maturity aspects – ISO 37004:2023 (11 controls), Clause 6: Governance maturity model – ISO 37004:2023 (11 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ISO 37004:2023 do I already cover?
ISO 37004:2023 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I implement ISO 37004:2023?
Start your ISO 37004:2023 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO 37004:2023 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 35 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.
Get Started Free →Free forever — no credit card required