Documentation kit
ISO/IEC 38500:2024 Complete Documentation Kit + Internal Auditor Training
In preparation — 50 documents for it governance framework, with a complete internal-auditor training pack.
ISO/IEC 38500:2024 — Information technology — Governance of IT for the organization
In preparation. This kit is being written now and is not yet available to download. Tell us you want it and we will send it to you the day it is released — and hold the current price for you.
Download the free sample (PDF) — the complete document master list for this kit and its clause-by-clause cross-reference matrix, so you can see exactly which document answers each requirement of ISO/IEC 38500:2024 before you buy.
Every document you need to implement IT Governance Framework to ISO/IEC 38500:2024 and evidence it, written by our lead auditors and supplied as editable Microsoft Word files in an organised folder tree. Replace the highlighted placeholders with your own details and the system is yours — no blank pages, no guessing what an auditor expects.
What it will contain
- 00 Read Me First — Kit guide and implementation roadmap, document master list, clause cross-reference matrix
- 01 Manual — 3 manual documents covering every clause
- 02 Policies — 9 policies
- 03 Procedures — 8 procedures
- 04 Forms, Registers & Templates — 12 forms and registers
- 05 Plans & Programmes — 6 plans
- 06 Checklists — 1 checklists including gap analysis and internal audit
- 07 Internal Auditor Training Pack — 8 documents: handbook, trainer's guide, slides outline, exercises, 30-question exam and answer key, course forms
50 documents in total, as planned in the kit's document manifest.
How it is written
Each procedure states the steps, the responsible roles, the frequencies and the records produced, so it can be followed on the day you buy it. Every requirement of the standard is mapped to a document in the clause cross-reference matrix — so you can show an assessor where each requirement is met. Auditor notes flag what assessors look for and the nonconformities that come up most often.
Internal auditor training included
This edition adds a complete internal-auditor (IQA) training pack: a participant handbook covering the standard clause by clause from an auditor's viewpoint, a trainer's guide with a two-day agenda, a slide outline, exercises with model answers, a 30-question examination with its marking scheme, and the course records.
Licence
Supplied for the internal use of one organisation, with unlimited internal copies and edits. Not for resale or redistribution outside your organisation.
Please note
ISO/IEC 38500:2024 is a guidance standard and no organisation can be certified against it. It uses advisory language throughout, has no requirements clause, no Harmonized Structure clauses and mandates no documented information at all, so there is nothing an auditor could raise a nonconformity against and nothing an audit could sample; there is also no scheme requirements standard of the kind ISO/IEC 27006 provides for ISO/IEC 27001 or ISO 50003 for ISO 50001, so no body can be accredited under ISO/IEC 17021-1 to certify it and no IAF MLA sub-scope covers it. Conformance is demonstrated by assessment instead, and ISO publishes the instrument: ISO/IEC 38503:2022, Governance of IT — Assessment of the governance of IT, which supplies assessment approaches, criteria, evidence guidance and a maturity scoring method supporting internal audit, governing-body self-assessment, second-party review by a customer or parent, or an advisor-led assessment — yielding a maturity rating and improvement roadmap, never a certificate, and requiring its 2015-era criteria to be re-based onto the eleven principles and four-task model of this edition before use. Where a certificate is genuinely needed, the certifiable layer sits beneath board governance rather than at it: ISO/IEC 20000-1:2018 for IT service management, ISO/IEC 27001:2022 for information security, ISO/IEC 42001:2023 for AI and ISO 9001 for quality; the parent standard ISO 37000, normatively referenced at Clause 2, is likewise guidance and equally not certifiable. Personal qualifications in ISO/IEC 38500 do exist under the ISO/IEC 17024 persons regime and certify an individual's knowledge, and unaccredited bodies do advertise organisational "ISO 38500:2024 certification" as a private attestation with no accredited standing — neither may be presented as certification of this organisation.
More from the e-shop
Documentation kitISO 45001:2018 Complete Documentation Kit
67 editable Word documents — manual, policies, procedures, forms, registers and audit checklists.
Documentation kitISO 45001:2018 Complete Documentation Kit + Internal Auditor Training
75 editable Word documents — manual, policies, procedures, forms, registers and audit checklists, with internal auditor training.
Documentation kitISO 14065:2020 Complete Documentation Kit + Internal Auditor Training
64 editable Word documents — manual, policies, procedures, forms, registers and audit checklists, with internal auditor training.
