Overview
ISO/IEC TR 38504:2016 - "Governance of information technology - Guidance for principles-based standards in the governance of information technology" - is a technical report that provides guidance on the information needed to support principles-based standards for IT governance. It is non-prescriptive: it does not define specific principles or implementation techniques but describes the elements, format and rationale authors should include when developing or applying principles-based governance standards. The aim is to promote clarity, consistency and traceability between governance principles and desired business outcomes.
Key topics
- Purpose and scope: Guidance for principles-based governance standards applicable to organizations of all sizes and sectors.
- Principles-based approach: Emphasizes outcome-focused, non-prescriptive guidance that allows flexible implementation across different organizational structures.
- General recommendations: Standards should be readable by governing bodies and executives, anchored in accepted governance concepts (e.g., OECD), and align with the Evaluate‑Direct‑Monitor model in ISO/IEC 38500.
- Information elements for each principle: Recommended elements include:
- Name of the principle (short, 1–3 words)
- Statement of the principle
- Rationale explaining why the principle matters
- Relationships with other principles
- Implications for governance and management
- Desired outcomes tied to the principle
- Governance behaviours expected from leaders and managers
- Relationship to business outcomes: Guidance on articulating how governance behaviours, management behaviours, IT enablers and organizational factors can lead to strategic business outcomes, recognizing variability by organization.
Applications
- Standards developers and editors: Use this TR to design consistent, clear descriptions of governance principles when drafting standards or technical reports.
- Governance and IT practitioners: Apply the recommended information elements to interpret principles, align governance behaviours and assess governance effectiveness.
- Governing bodies and executives: Use the framework to evaluate IT governance decisions, policies and oversight roles without being constrained to specific processes.
- Policy authors and auditors: Leverage the structured principle descriptions to map governance expectations to organizational policies and measurement criteria.
Related standards
- ISO/IEC 38500 - Corporate governance of IT (principles and model such as Evaluate‑Direct‑Monitor)
- ISO/IEC TR 38502 and ISO/IEC TS 38501 - Complementary guidance and management system considerations
- Developed under ISO/IEC JTC 1/SC 40 (IT service management and IT governance)
By following ISO/IEC TR 38504:2016, organizations and standards writers can produce principles-based IT governance guidance that is clear, outcome-oriented and adaptable - improving alignment between governance principles and business results.