ISO 38505

Data has become one of the most important assets within modern organizations. Businesses use it to understand customers, manage operations, train artificial intelligence systems, measure performance, make strategic decisions, and meet regulatory obligations. As the amount and importance of organizational data increase, however, so does the need for stronger governance.

 

Organizations need to know who is accountable for data, how it should be used, how it should be protected, and whether decisions involving data support wider business objectives. These are governance questions rather than purely technical data management issues.

 

ISO 38505, formally the ISO/IEC 38505 series, provides guidance for the governance of data. It helps governing bodies and senior leaders establish an effective approach to how data is used, protected, controlled, and governed across an organization.

 

The series is closely connected with ISO/IEC 38500, the international standard for governance of information technology. The current ISO/IEC 38505-1:2026 applies the governance principles and model of ISO/IEC 38500 to data and is designed to help organizations govern data in an effective, efficient, and acceptable manner.

 

This guide explains what ISO 38505 is, how the series is structured, why data governance matters, who should use the standard, and how organizations can build a more structured approach to governing data.

 

 

What is ISO 38505?

 

ISO 38505 is a family of international guidance documents focused on the governance of data.

 

The central document is ISO/IEC 38505-1:2026, Information technology — Governance of data — Part 1: Application of ISO/IEC 38500 to the governance of data. ISO published the second edition in August 2026, replacing ISO/IEC 38505-1:2017.

 

ISO/IEC 38505-1 provides principles for governing bodies on the effective, efficient, and acceptable use of data. It applies the broader governance approach established by ISO/IEC 38500 specifically to data and is intended to help stakeholders have greater confidence in how an organization governs its data.

 

The scope is broad. ISO states that the standard applies to the current and future use of data that is created, collected, stored, secured, protected, or controlled by IT systems. It also covers the management processes and decisions associated with that data.

 

This distinction is important. ISO 38505 is not simply a guide for configuring databases, managing storage, or implementing technical security controls. It addresses how organizations establish governance around data so that decisions, responsibilities, policies, and management activities support organizational objectives.

 

What is data governance under ISO 38505?

 

Data governance provides the organizational direction and accountability needed to ensure that data is handled appropriately throughout the business.

 

ISO/IEC 38505-1 places governance of data within a wider governance structure. It defines data governance as a subset or domain of the governance of IT, while governance of IT itself sits within organizational or corporate governance.

 

This creates an important connection between data and executive decision-making.

 

A database administrator may be responsible for maintaining a database, a security team may protect the systems containing data, and a privacy team may oversee personal information. Governance sits above these individual operational responsibilities. It considers whether the organization has established appropriate direction, accountability, policies, oversight, and decision-making structures for data as a whole.

 

For example, an organization introducing an AI system may need to determine whether certain datasets should be used to train that system. Technical teams can evaluate whether the data can be processed, but governance needs to address wider questions about accountability, acceptable use, risk, organizational objectives, legal obligations, and stakeholder expectations.

 

ISO 38505 provides a structure for addressing these questions at the governance level.

 

The ISO 38505 series explained

 

ISO 38505 should not be viewed as a single document covering every aspect of data governance. The series contains several parts that address related areas.

 

ISO/IEC 38505-1:2026

 

ISO/IEC 38505-1:2026 is the core international standard in the series. It applies the principles and governance model of ISO/IEC 38500 to the governance of data.

 

The current edition was published in August 2026. It provides guidance for governing bodies while also being relevant to executive managers, professional advisers, service providers, consultants, and auditors. The standard applies to organizations of every size, including private companies, public bodies, government organizations, and not-for-profit entities.

 

Organizations researching ISO 38505 should pay close attention to the edition being referenced. The original ISO/IEC 38505-1:2017 has now been withdrawn and replaced by the 2026 edition.

 

ISO/IEC TR 38505-2:2018

 

ISO/IEC TR 38505-2:2018 focuses on the implications of ISO/IEC 38505-1 for data management.

 

This Technical Report provides guidance to governing bodies and executive managers on how the governance concepts established by Part 1 affect data management. It assumes familiarity with the ISO/IEC 38500 principles and with the data accountability concepts used within ISO 38505.

 

This part helps organizations connect high-level governance expectations with the management of data in practice.

 

ISO/IEC TS 38505-3:2021

 

ISO/IEC TS 38505-3:2021 provides guidelines for data classification.

 

Data classification is a critical part of governance because organizations cannot apply appropriate protection, handling, retention, and access requirements if they do not understand the nature and importance of the data they hold.

 

Part 3 provides guidance to governing bodies and management on using data classification to support an organization’s broader data governance policy and systems. It also identifies factors organizations should consider when designing and deploying a data classification system. ISO confirmed this edition in 2025, meaning it remains current.

 

Together, these documents provide organizations with a governance foundation, guidance on the implications for data management, and more specific guidance on data classification.

 


 

Why is ISO 38505 important?

 

Many organizations have invested heavily in data technology without developing equally mature governance structures.

 

Cloud platforms, analytics systems, SaaS applications, data lakes, AI models, customer platforms, and third-party services can cause organizational data to spread across a large technology ecosystem. Responsibility for that data can also become fragmented across IT, cyber security, privacy, legal, compliance, risk, and individual business units.

 

Without effective governance, several problems can develop.

 

Organizations may not know who is ultimately accountable for important datasets. Data may be used for purposes that were never properly evaluated. Different departments may apply inconsistent classification or protection requirements. Senior management may have limited visibility into data-related risk, while technical teams may make important data decisions without sufficient connection to business strategy.

 

ISO 38505 helps organizations approach these challenges as governance issues rather than treating each problem separately.

 

The result is a clearer relationship between organizational objectives, accountability, data use, risk, management, and oversight.

 

What organizations can use ISO 38505?

 

ISO 38505 is intentionally broad in its applicability. ISO/IEC 38505-1:2026 applies to public and private companies, government entities, not-for-profit organizations, and organizations of all sizes, regardless of how heavily they depend on data.

 

In practice, the standard becomes particularly relevant when data plays an important role in strategic or operational decisions.

 

Financial institutions, healthcare providers, technology companies, government agencies, telecommunications companies, manufacturers, retailers, energy organizations, and companies developing or deploying AI systems can all face significant data governance requirements.

 

The value is not limited to heavily regulated sectors. Any organization collecting large volumes of customer, employee, operational, financial, intellectual property, or business data needs to understand how that information is governed.

 

ISO 38505 and ISO 38500: What is the relationship?

 

Understanding ISO 38505 requires understanding its relationship with ISO/IEC 38500.

 

ISO/IEC 38500:2024 provides guiding principles for governing bodies and those supporting them regarding the effective, efficient, and acceptable use of information technology. It applies to the current and future use of IT and positions governance of IT as part of organizational governance.

 

ISO/IEC 38505-1 takes that governance foundation and applies it specifically to data.

 

The relationship can therefore be understood as a hierarchy:

 

Organizational governance → Governance of IT → Governance of data

 

This structure prevents data governance from becoming an isolated technical programme. Decisions about data should support organizational objectives and fit within the organization’s wider governance structure.

 

That connection becomes increasingly important as data drives more strategic decisions and emerging technologies such as artificial intelligence increase the scale at which organizational data can be processed and used.

 

ISO 38505 and data management are not the same thing

 

One of the most important distinctions for organizations implementing ISO 38505 is the difference between governance and management.

 

Governance establishes direction, accountability, expectations, and oversight. Management operates within that direction to plan, implement, operate, and maintain the necessary processes and capabilities.

 

Consider data classification as an example. Governance may establish that organizational information must be classified according to its sensitivity, business importance, legal requirements, and risk. Management then develops and operates the classification processes, technologies, procedures, and controls needed to meet that expectation.

 

The same distinction applies to data quality, access, retention, security, sharing, acquisition, and use.

 

This is why ISO/IEC TR 38505-2 is useful alongside Part 1. It helps organizations understand how governance expectations influence data management rather than treating the two disciplines as interchangeable.

 

Key areas organizations should address when implementing ISO 38505

 

ISO 38505 is principles-based, which means organizations need to translate governance guidance into structures and practices appropriate to their size, risk profile, regulatory environment, and use of data.

 

Several areas deserve particular attention.

 

Establish clear accountability for data

 

Effective data governance requires identifiable accountability.

 

Organizations should understand who has authority over important data, who is responsible for managing it, who can make decisions regarding its use, and who is accountable when governance requirements are not met.

 

This becomes particularly important when data crosses departmental or organizational boundaries. A dataset may originate in one business unit, be stored by IT, processed through a cloud provider, analyzed by another team, and eventually used by an AI application.

 

Without clearly defined accountability, important governance decisions can fall between organizational functions.

 

Understand what data the organization holds

 

Governance is difficult when the organization does not have adequate visibility into its data environment.

 

Organizations should understand the important categories of data they create, collect, store, process, share, and control. They should also understand where critical data resides, which systems process it, who can access it, and which third parties are involved.

 

This information supports risk assessment, classification, policy development, regulatory compliance, and strategic decision-making.

 

Develop a consistent data classification approach

 

Not all data requires identical treatment.

 

Public marketing information, internal business records, personal information, financial data, intellectual property, authentication credentials, and highly sensitive strategic information carry different levels of risk.

 

ISO/IEC TS 38505-3 provides specific guidance on using data classification to support broader data governance. A mature classification model allows organizations to apply controls and handling requirements according to the importance and sensitivity of information rather than treating every dataset in the same way.

 

Connect data governance with enterprise risk management

 

Data risk should not exist in a separate universe from enterprise risk.

 

Loss of sensitive information can create regulatory, financial, operational, strategic, and reputational consequences. Poor-quality data can affect important business decisions. Uncontrolled use of information by AI systems can introduce additional governance and compliance concerns. Third-party processing can create dependencies outside the organization’s direct operational control.

 

Organizations should therefore identify, assess, assign, monitor, and treat data-related risks through their wider risk management processes.

 

This connection also gives governing bodies a more useful view of how data risk affects organizational objectives.

 

Establish policies that translate governance into practice

 

Governance decisions need to be supported by policies that give management and employees clear direction.

 

Depending on the organization, these policies may address data classification, acceptable use, access control, data sharing, retention, deletion, privacy, security, third-party processing, AI use, and incident management.

 

Policies should also have clear ownership and review cycles. A policy that exists as an outdated document but is not connected to controls, responsibilities, risks, or evidence provides limited governance value.

 

Monitor whether governance expectations are being followed

 

Establishing policies and responsibilities is only part of the process.

 

Organizations also need mechanisms for understanding whether governance requirements continue to operate as intended. This may involve control monitoring, risk reviews, internal audits, management reporting, policy reviews, compliance assessments, and remediation tracking.

 

The objective is to give governing bodies reliable information about how data is being governed and whether corrective action is required.

 

ISO 38505 and cyber security

 

Data governance and cyber security are closely connected, but they serve different purposes.

 

Cyber security focuses heavily on protecting systems, networks, applications, and information against threats. Data governance takes a broader view by considering accountability, acceptable use, organizational direction, decision-making, risk, and stakeholder expectations around data.

 

Security controls therefore form an important part of effective data governance, but security alone does not provide complete governance.

 

An organization may technically protect a dataset with strong encryption and access controls while still lacking clear accountability for how that dataset should be used. Similarly, data can be secure from external attackers while being used internally in ways that create privacy, regulatory, ethical, or strategic risks.

 

ISO 38505 encourages organizations to consider data as a governance matter across its wider lifecycle and organizational use.

 

ISO 38505 and privacy compliance

 

ISO 38505 can also support an organization’s broader privacy governance environment, particularly by improving accountability and visibility around data.

 

However, organizations should not treat ISO 38505 as a replacement for privacy laws or dedicated privacy management requirements.

 

Regulations such as the GDPR establish specific legal obligations regarding personal data. ISO 38505 provides governance guidance that can help organizations build stronger structures around data decision-making and accountability, but applicable legal and regulatory obligations still need to be identified and managed separately.

 

The practical value comes from integration. Organizations can connect data governance with privacy requirements, cyber security controls, enterprise risk management, policies, audits, and compliance monitoring rather than allowing each programme to operate independently.

 

ISO 38505 and AI governance

 

The growth of enterprise AI makes data governance increasingly important.

 

AI systems depend heavily on data. Organizations need to understand where training, testing, operational, and input data originates; whether it can appropriately be used; how sensitive information is protected; who is accountable for decisions; and what risks may arise from poor-quality, inappropriate, or uncontrolled data.

 

ISO 38505 does not replace dedicated AI governance standards such as ISO/IEC 42001. Instead, strong data governance can provide an important foundation for broader AI governance.

 

An organization cannot effectively govern AI if it has limited visibility into the data used by its AI systems.

 

For GRC leaders, this means data governance, information security, privacy, AI governance, and enterprise risk management increasingly need to operate as connected disciplines rather than separate compliance projects.

 

How to implement ISO 38505 in your organization

 

Implementing ISO 38505 should begin with understanding the organization’s existing governance environment rather than immediately creating new policies.

 

Assess your current data governance maturity

 

Start by identifying how data is currently governed.

 

Review existing policies, responsibilities, committees, risk registers, data inventories, classification schemes, security controls, privacy processes, third-party arrangements, and reporting mechanisms.

 

The objective is to understand which governance structures already exist and where gaps remain.

 

Define governance responsibilities

 

Establish clear roles for governing bodies, executive leadership, data owners, IT, cyber security, privacy, risk, compliance, and operational teams.

 

Responsibilities should be clear enough that important data decisions have identifiable owners and escalation paths.

 

Identify and classify important data

 

Develop sufficient visibility into the organization’s data environment and establish a classification approach appropriate to the organization’s risk profile.

 

Classification should influence how data is accessed, stored, shared, retained, protected, and monitored.

 

Map risks, requirements, and controls

 

Connect important data-related risks with applicable regulatory obligations, internal policies, and organizational controls.

 

This creates traceability between what could go wrong, what the organization is required or expected to do, and the controls used to manage those risks.

 

Implement monitoring and reporting

 

Develop mechanisms that provide management and governing bodies with meaningful visibility into data governance performance.

 

Useful reporting should highlight significant risks, control failures, policy exceptions, overdue remediation, third-party issues, and other matters requiring management attention rather than simply producing large volumes of compliance data.

 

Continually review the governance environment

 

Data environments change constantly.

 

New systems are introduced, cloud services change, organizations acquire new companies, regulations evolve, AI applications are deployed, and new categories of data are collected.

 

Data governance therefore needs ongoing review. Organizations should periodically reassess risks, policies, controls, accountability structures, classification practices, and governance reporting as their operating environment changes.

 

Is ISO 38505 a certification standard?

 

Organizations should be careful about describing ISO 38505 as a certification in the same way they may discuss ISO/IEC 27001 certification.

 

ISO/IEC 38505-1 is a principles-based governance standard providing guidance to governing bodies on the governance of data. It should not be presented as though it establishes a conventional management-system certification programme.

 

This distinction matters for compliance teams evaluating ISO standards. Implementing ISO 38505 can strengthen an organization’s data governance practices, but organizations should avoid assuming that every ISO publication follows the same certification model.

 

The real value of ISO 38505 lies in improving how data governance is structured, directed, monitored, and connected with wider organizational governance.

 

What are the benefits of ISO 38505?

 

Organizations that use ISO 38505 as part of a mature governance programme can establish clearer accountability for data and improve the relationship between data decisions and organizational objectives.

 

It can also help create greater consistency between governance, data management, risk management, cyber security, privacy, compliance, and executive oversight.

 

For large organizations, this alignment is particularly important. Data frequently crosses business units, systems, cloud environments, countries, suppliers, and regulatory boundaries. Without a common governance structure, individual teams can make reasonable local decisions that collectively create inconsistent or unmanaged enterprise risk.

 

ISO 38505 provides a governance foundation that helps organizations address data at the organizational level rather than solely as a technical resource.

 

Conclusion: Strengthen data governance with CyberArrow GRC

 

Implementing ISO 38505 requires more than producing another set of governance documents. Organizations need a practical way to connect data-related risks, responsibilities, policies, controls, compliance requirements, evidence, monitoring, and remediation across the enterprise.

 

This becomes difficult when governance information is spread across spreadsheets, email threads, policy documents, ticketing systems, and disconnected compliance tools.

 

At CyberArrow, we help organizations bring these GRC activities into a connected environment.

 

With CyberArrow GRC, teams can automate risk assessments, manage enterprise and operational risks, centralize policies and controls, automate evidence collection, monitor controls, manage multiple standards and regulatory requirements, and maintain clearer visibility into their overall governance and compliance posture. Our platform is designed to reduce repetitive GRC work while helping organizations stay continuously prepared for changing risks and compliance requirements.

 

For organizations strengthening data governance around ISO 38505, this connected approach can help turn governance principles into accountable, measurable, and continuously monitored GRC processes. It also makes it easier to connect data governance with related areas such as cyber security, privacy, enterprise risk, regulatory compliance, and AI governance.

 

CyberArrow is trusted by the world’s biggest brands across the US, Europe, Africa, Asia and the Middle East, with organizations such as IKEA, Emirates, American Express, Vodafone, and Revolut featured across our global customer base.

 

As data becomes more important to business strategy, AI, customer experience, and operational decision-making, governance needs to keep pace. ISO 38505 provides organizations with a valuable framework for establishing that direction, while CyberArrow GRC helps teams put modern governance, risk, and compliance processes into practice.

 

Want to simplify and automate your GRC programme? Book a CyberArrow GRC demo and see how we can help your organization manage governance, risk, controls, and compliance from one platform.

 


 

Frequently asked questions about ISO 38505

 

What is ISO 38505?

ISO 38505, formally the ISO/IEC 38505 series, provides guidance on the governance of data. The current ISO/IEC 38505-1:2026 applies the governance principles and model of ISO/IEC 38500 to data and helps governing bodies guide the effective, efficient, and acceptable use of data within their organizations.

 

What is the latest version of ISO 38505-1?

The latest edition is ISO/IEC 38505-1:2026, published in August 2026. It is the second edition and replaced the withdrawn ISO/IEC 38505-1:2017 edition.

 

What is the difference between ISO 38505 and ISO 38500?

ISO/IEC 38500 provides broader principles for the governance of information technology within organizations. ISO/IEC 38505-1 applies that governance approach specifically to data. ISO describes governance of data as a domain of governance of IT, which in turn sits within organizational governance.

 

What are the three parts of the ISO 38505 series?

The current series includes ISO/IEC 38505-1 for the governance of data, ISO/IEC TR 38505-2 for the implications of data governance for data management, and ISO/IEC TS 38505-3 for data classification guidance.

 

Who should use ISO 38505?

ISO/IEC 38505-1 is relevant to governing bodies, executive managers, advisers, service providers, auditors, and other professionals involved in organizational data governance. It applies to public, private, government, and not-for-profit organizations of all sizes.

Avatar photo
CyberArrow team