International (ISO/TC 309); adopted as BS ISO 37000:2021, SIST ISO 37000:2021 and others

ISO 37000:2021

139 controls. 12 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

139 controls 12 frameworks share controls with it International (ISO/TC 309); adopted as BS ISO 37000:2021, SIST ISO 37000:2021 and others verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
GOV-ACCOUNTAccountability Mechanisms1
GOV-ADAPTAdaptive Governance0
GOV-ASSUREAssurance Arrangements0
GOV-COIConflicts of Interest0
GOV-COMPGoverning Body Composition1
GOV-DATAData Informed Decisions0
GOV-EVALGoverning Body Evaluation1
GOV-LEADEthical Leadership0
GOV-OUTCOMEGovernance Outcomes Measurement0
GOV-OVERSIGHTGoverning Body Oversight1
GOV-PURPOSEOrganizational Purpose0
GOV-REMRemuneration Governance0
GOV-REPORTReporting and Transparency0
GOV-RISKRisk Appetite and Tolerance0
GOV-SOCIALSocial Responsibility Integration1
GOV-STAKEStakeholder Identification and Engagement0
GOV-STRATEGYStrategy Setting and Review0
GOV-VALUEValue Generation Across Horizons1
GOV-VIABLELong-Term Viability0
ISO37000-4.2Value Generation1
ISO37000-4.3Strategy0
ISO37000-5.1Oversight0
ISO37000-5.2Accountability0
ISO37000-5.3Stakeholder Engagement1
ISO37000-5.4Leadership0
ISO37000-5.5Data and Decisions1
ISO37000-5.6Risk Governance1
ISO37000-5.7Social Responsibility1
ISO37000-5.8Viability and Performance1
ISO37000-6.1Governance Body Composition0
ISO37000-6.2Governing Body Effectiveness1
ISO37000-6.3Conflict of Interest0
ISO37000-6.4Remuneration0
ISO37000-6.5Assurance0
ISO37000-6.6Reporting and Transparency0
ISO37000-7.1Governance Outcomes0
ISO37000-7.2Adapting Governance0
ISO37000-CC-01Cl. 5.2 Governance culture - Tone at the top promoting integrity, accountability, and transparency0
ISO37000-CC-02Cl. 7.6 Organizational resilience - Capacity to anticipate, respond to, and recover from disruptions1
ISO37000-CC-03Cl. 4.3.2 Competence - Leadership development, succession planning, and talent management for governance3
ISO37000-CC-04Cl. 6.8 Data and decisions - Data governance and information management for informed decision-making0
ISO37000-GF-01Cl. 6.9 Ethical behavior - Acting with integrity, honesty, equity, and social responsibility4
ISO37000-GF-02Cl. 6.5 Accountability - Being answerable for decisions and actions to stakeholders10
ISO37000-GF-03Cl. 6.7 Transparency - Disclosing information to enable informed decision-making by stakeholders0
ISO37000-GF-04Cl. 5 Rule of law - Compliance with applicable laws, regulations, and governance codes5
ISO37000-GF-05Cl. 6.6 Stakeholder rights - Respecting and protecting stakeholder rights across governance decisions0
ISO37000-OA-01Cl. 4.3 Governing body - Composition, independence, competence, and commitment of the governing body0
ISO37000-OA-02Cl. 4.2.2 Delegation - Clear mandates with accountability for delegated oversight of management0
ISO37000-OA-03Cl. 6.4 Oversight - Internal control and assurance systems for managing risks and ensuring compliance0
ISO37000-OA-04Cl. 7.5 Monitoring and evaluation - Regular review of governance effectiveness and performance0
ISO37000-PV-01Cl. 6.1 Purpose - Defining organizational purpose aligned with stakeholder expectations3
ISO37000-PV-02Cl. 6.2 Value generation - Creating and preserving value for the organization and stakeholders over time0
ISO37000-PV-03Cl. 6.6 Stakeholder engagement - Understanding and responding to stakeholder interests and expectations0
ISO37000-PV-04Cl. 6.10 Social responsibility - Integrating economic, social, and environmental considerations into governance6
ISO37000-SD-01Cl. 6.3 Strategy - Formulating strategy aligned with organizational purpose and stakeholder expectations5
ISO37000-SD-02Cl. 7.3 Risk governance - Identifying and managing risks to strategic objectives through risk-based thinking2
ISO37000-SD-03Cl. 7.4 Resource governance - Ensuring resources are deployed to achieve strategic priorities and generate value0
ISO37000-SD-04Cl. 6.11 Viability and performance - Setting measurable objectives and monitoring outcomes for sustained performance3
44 The governance of organizations0
4.14.1 General0
4.24.2 Integrated governance0
4.2.14.2.1 General0
4.2.24.2.2 Governance and delegation0
4.2.34.2.3 Governance and management0
4.2.44.2.4 Governance and sustainability0
4.2.54.2.5 Governance and stakeholders0
4.34.3 The governing body0
4.3.14.3.1 Composition and structure0
4.3.24.3.2 Competence0
66 Principles of governance0
6.16.1 Purpose0
6.1.16.1.1 Principle0
6.1.36.1.3 Key aspects of practice0
6.1.3.26.1.3.2 Define the organizational purpose0
6.1.3.36.1.3.3 Define the organizational values0
6.1.3.46.1.3.4 Commit to the organizational purpose and values0
6.106.10 Social responsibility0
6.10.16.10.1 Principle0
6.10.36.10.3 Key aspects of practice0
6.116.11 Viability and performance over time0
6.11.16.11.1 Principle0
6.11.36.11.3 Key aspects of practice0
6.11.3.26.11.3.2 Articulate an integrated view of value generation0
6.11.3.36.11.3.3 Assess system relationships0
6.11.3.46.11.3.4 Govern for organizational viability over time0
6.26.2 Value generation0
6.2.16.2.1 Principle0
6.2.36.2.3 Key aspects of practice0
6.2.3.16.2.3.1 General: the value generation model0
6.2.3.26.2.3.2 Define value0
6.2.3.36.2.3.3 Create value0
6.2.3.46.2.3.4 Deliver value0
6.2.3.56.2.3.5 Sustain value0
6.36.3 Strategy0
6.3.16.3.1 Principle0
6.3.36.3.3 Key aspects of practice0
6.3.3.16.3.3.1 Provide strategic direction0
6.3.3.1.16.3.3.1.1 Set strategic outcomes0
6.3.3.1.26.3.3.1.2 Establish governance policies0
6.3.3.26.3.3.2 Engage the strategy0
6.3.3.2.16.3.3.2.1 Engage with strategic planning0
6.3.3.2.26.3.3.2.2 Steer the strategy0
6.46.4 Oversight0
6.4.16.4.1 Principle0
6.4.36.4.3 Key aspects of practice0
6.4.3.16.4.3.1 General: the four oversight duties0
6.4.3.26.4.3.2 Oversee performance0
6.4.3.36.4.3.3 Obtain assurance0
6.56.5 Accountability0
6.5.16.5.1 Principle0
6.5.36.5.3 Key aspects of practice0
6.5.3.26.5.3.2 Demonstrate accountability0
6.5.3.36.5.3.3 Hold to account0
6.66.6 Stakeholder engagement0
6.6.16.6.1 Principle0
6.6.36.6.3 Key aspects of practice0
6.76.7 Leadership0
6.7.16.7.1 Principle0
6.7.36.7.3 Key aspects of practice0
6.7.3.26.7.3.2 Demonstrate effective leadership0
6.7.3.36.7.3.3 Ensure ethical leadership0
6.7.3.46.7.3.4 Reconcile dilemmas0
6.86.8 Data and decisions0
6.8.16.8.1 Principle0
6.8.36.8.3 Key aspects of practice0
6.8.3.26.8.3.2 Ensure effective decision-making0
6.8.3.2.16.8.3.2.1 Ensure effective decision-making within the governing body0
6.8.3.2.26.8.3.2.2 Ensure effective decision-making throughout the organization0
6.8.3.36.8.3.3 Recognize data as a strategic resource0
6.8.3.46.8.3.4 Ensure responsible data use0
6.96.9 Risk governance0
6.9.16.9.1 Principle0
6.9.36.9.3 Key aspects of practice0
6.9.3.26.9.3.2 Set the tone for the management of risk0
6.9.3.36.9.3.3 Practise effective risk management0
6.9.3.46.9.3.4 Oversee risk management0
FAMILYThe ISO 37000 family and the standards that hang off this one0
OVERVIEWClause 5 Overview: outcomes, the principle structure, context and reporting0
STANDARDISO 37000:2021: scope, terms and what is held0

Tell me when ISO 37000:2021 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Lessons learned register
  • Governance change log
  • Investigation procedure
  • Case management system
  • Closure reports
  • Disciplinary records
  • Annual BIPA audit report
  • Findings register with owners
  • Management review minutes
  • Corrective action closure evidence

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for ISO 37000:2021, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition