EDIH, EEN, Interreg: the platform for European programmes.Find out more

ISO 38500 Maturity · Governance of Information Technology

Your IT governance, measured against ISO 38500 and turned into a roadmap.

10 themes, a 5-level scale. And the action that moves each level to the next.

The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.

ISO 38500 Maturity · Governance of Information Technology

Responsibility and decision mandatesN1 → N5
Strategic alignmentN1 → N5
Acquisition and investment arbitrationN1 → N5
Performance and value in useN1 → N5

10 themes, 5-level scale.

Nordhavn Industries

53 / 100

Responsibility and decision mandates6484
Strategic alignment5379
Acquisition and investment arbitration6182
Performance and value in use3773
IAIndustrialised: your interview notes are enough, the AI fills in the audit.

They measure their maturity with Datamensio

  • ANITI
  • CNRS
  • LIRMM
  • CNES
  • Docaposte
  • KPMG

An example

This could be your situation.

Take one company as an example: three sites, three spreadsheets, no shared answer.

01

Nobody can consolidate.

Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.

02

Three weeks, a single base.

One ISO/IEC 38500:2024 assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.

03

Two costs avoided before being committed.

A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.

What it saved them

  • 3sites measured on the same base, instead of three questionnaires to reconcile
  • 2duplicate actions caught before the spend
  • 1committee report, with no manual rework

These figures are an example. They could be yours.

The standard imposes processes. Datamensio says where you stand.

01

The framework is already written

Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.

02

The score lands the same day

Online, by self-assessment link or in interview. Theme by theme, comparable over time.

03

The gap becomes a costed plan

Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.

04

Progress can be demonstrated

Campaign after campaign, against your target and against your own past. That is what your board asks for.

The maturity scale

One level, the next, and the action that links the two.

It is this mechanism, a level, the level above, and the action that connects the two, that turns a finding into a trajectory.

Are digital investment decisions made on explicit, comparable criteria?

  1. N1

    No shared criteria. Decisions are made as requests arrive, depending on the sponsor and the circumstances of the moment.

  2. N2

    Criteria exist in a document or a case template, but their use depends on the team and cases remain hard to compare.

  3. N3

    Criteria are shared and applied to most requests. Cases go through a common format and decisions are recorded.

  4. N4

    All digital investments are assessed against the same criteria, decisions and their rationale are tracked, and departures from the common format are justified.

  5. N5

    Criteria are reviewed periodically in light of the value actually delivered by past investments, with documented tracking of revisions.

Action to move from L2 to L3

Require a single format investment case, with decision criteria and expected value, as a condition for being placed on the arbitration committee agenda, and record every decision in the minutes.

« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »
Chambre de commerce et d'industrie

Director, CCI 94CCI Île-de-France

« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »
Interreg Danube Region

Maja SucekChief Operating Officer, Interreg Danube

Take your first measurementon ISO 38500.

What this framework covers

ISO/IEC 38500 is the framework for the governance of information technology. It does not describe how to run an information system: it describes how the governing body takes responsibility for it. Six principles form its backbone: responsibility, strategy, acquisition, performance, conformance and human behaviour. They apply through a simple cycle, evaluate, direct, monitor, which the governing body exercises over decisions related to digital technology. The framework is a reference for leaders, not a catalogue of technical controls, and it cannot be certified.

Putting it into practice is demanding because it touches on how decision-making power is shared. Who arbitrates between two projects drawing on the same budget, and on what explicit criteria? Does the digital investment committee rule on comparable cases, or on presentations each sponsor builds their own way? Is it known, a year after go live, whether an application delivered the value promised in its business case? In many organisations these questions have no traceable answer, even though the IT budget itself is tracked to the last cent.

The 2024 revision tightened the focus on the governing body and its relationship with management. It also reflects the fact that digital decisions are no longer made solely by the IT department: business units buy their own application services, artificial intelligence and data now enter into the arbitration, and external dependencies keep multiplying. One common confusion is worth clearing up: ISO 38500 governs, ITIL and COBIT provide the tools. Adopting a service management framework does not remove the need to govern.

A maturity assessment does not ask the same question as an audit. An audit concludes with a gap or a conformance finding. An assessment places each practice on a progressive scale, from an informal gesture to a practice reviewed periodically, and points to the action that moves it up a level. On a governance topic, this nuance is decisive: almost nothing is entirely absent, almost everything is partial. The score by theme shows where decision making is structured and where it still rests on a handful of people.

In Datamensio, the framework is ready to use and you keep full control of it. The AI adjusts the themes, the questions and the wording of the levels to your organisation, or builds a variant from your own governance documents: committee charter, arbitration procedure, investment case template. Assessments run across several business units can be compared with each other and over time.

Reference standard: ISO/IEC 38500:2024

The themes assessed

  • Responsibility and decision mandates

    Explicit allocation of digital responsibilities within the governing body, committee mandates, delegations, distinction between governing and managing.

  • Strategic alignment

    Translation of business strategy into digital direction, planning horizon, consideration of technology change, review of direction.

  • Acquisition and investment arbitration

    Decision criteria, format of investment cases, comparability of requests, consideration of total cost and supplier dependencies.

  • Performance and value in use

    Indicators tracked by the governing body, measurement of value after go live, fit between capacity and business needs, perceived service quality.

  • Conformance and legal framework

    Identification of obligations applicable to digital activity, tracking of contractual commitments, alignment with data and AI requirements.

  • Human behaviour and usage

    Consideration of users in decision making, change management, business led IT purchasing practices, decision maker competence.

  • Governance of data and models

    Attachment of data and algorithm decisions to an identified body, ownership of datasets, arbitration on AI use cases.

  • Monitoring and reporting to the governing body

    Nature and frequency of information escalated, reporting format, traceability of decisions, tracking of gaps between decision and delivery.

  • Portfolio and resource management

    Consolidated view of projects and assets, prioritisation, allocation of internal and external skills, stopping initiatives with no value.

  • Improving the governance arrangements

    Lessons learnt from past decisions, review of criteria and mandates, comparison across entities, maturity of the arrangements themselves.

A short version of the framework is available for the online self-assessment.

Frequently asked questions

Can ISO 38500 be certified?

No. It is a set of principles for governing bodies, with no requirements auditable by a certification body. The assessment measures the maturity of your governance practices and prepares the decisions that strengthen it.

How does this differ from a conformance audit?

An audit concludes with a gap or a conformance finding against a requirement. An assessment places each practice on a maturity scale and points to the action that moves it up to the next level. On governance, where almost everything exists partially, this gradation is more useful than a binary verdict.

What is the difference with COBIT or ITIL?

ISO 38500 says who decides and on what principles. COBIT and ITIL provide the tools for managing IT services and processes. The two levels are complementary: the assessment can in fact reveal a mature management setup sitting above governance that is still informal.

How long does the assessment take?

The short version can be completed in a single working session. In collaborative mode, with the IT department, a business representative and the committee secretariat involved, allow one to two weeks, most of the time going into gathering evidence.

Who should answer the questions?

The questions concern governing bodies, criteria and decisions, not technical configurations. An IT director, a transformation director or an internal auditor can answer them. Collaborative mode lets you assign certain questions to the right person.

Can the framework be adapted to our organisation?

Yes. You can change the questions, the themes and the wording of the levels. The AI produces a variant based on your committee charters and arbitration procedures, so the assessment uses the vocabulary of your own governing bodies.

Can several entities be compared?

Yes. Running the same assessment across several business units produces a comparable score by theme, and a cross entity roadmap consolidates common actions rather than duplicating them entity by entity.

Where is the data hosted?

In France, with OVH, backed up with Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European providers.

Take your first measurementon ISO 38500.