Training

    IT corporate governance training

    ISO/IEC 38500 is about the governing body's job, not the IT department's. Three accredited tracks, from a shared vocabulary for the board through to establishing the framework and the evidence that shows it works.

    Governance is not management, and the distinction is the whole point

    ISO/IEC 38500 is the international standard for the corporate governance of IT, and it is aimed at a group most IT training ignores entirely: the governing body. Directors, owners and executive committees who are accountable for technology decisions they do not make personally, and who are increasingly asked to evidence that accountability.

    The distinction the standard rests on is between governing and managing. Managing is running IT — delivering, operating, securing. Governing is directing, evaluating and monitoring: deciding what IT is for, what the organisation will and will not do, and whether what is happening matches what was decided. Most organisations that say they have an IT governance problem have a management system doing both, badly, because nobody separated the two.

    The pressure to fix this has become concrete. NIS2 and its national implementations put duties on the management body personally, including a knowledge requirement. The EU AI Act expects accountability to be located. Boards are being asked to demonstrate that technology risk reaches them in a form they can act on — and a board that receives a monthly status report is not governing, it is being briefed.

    The three levels follow the responsibility rather than the seniority. Foundation gives a governing body the vocabulary and the principles. The IT Corporate Governance Manager level is for the person who operates the framework — decision rights, forums, reporting cadence. The Lead level is for whoever establishes the framework and the assurance loop behind it.

    This track pairs naturally with ISO/IEC 27001 and ISO/IEC 42001. Those standards give you management systems; this one tells the governing body how to direct and monitor them without taking over the running of them.

    Which level

    LevelWho it is forWhat they can do afterwards
    ISO/IEC 38500 FoundationDirectors, owners, executive committee members, and anyone advising themUnderstand the six principles, ask better questions of IT, and know what the governing body is accountable for
    IT Corporate Governance ManagerThe person who operates the governance framework day to dayRun decision rights, forums and board reporting so that direction and monitoring actually happen
    Lead IT Corporate Governance ManagerWhoever establishes the framework and its assuranceDesign the governance framework, define the assurance loop, and evidence that it works

    Courses in this track

    Foundation · 2 days

    ISO/IEC 38500 Foundation

    Two days on the corporate governance of IT. ISO/IEC 38500 is about the governing body's role, evaluate, direct and monitor, rather than about IT management practice. Confusing the two is the failure this standard exists to prevent.

    Delivery:
    Classroom, In-company, Live online, Self-paced
    Exam:
    Included
    Price:
    €1,150–1,450 per seat

    Practitioner · 3 days

    ISO/IEC 38500 IT Corporate Governance Manager

    Three days on operating an IT corporate governance framework: turning six principles into decision rights, forums, reporting and evidence a board can act on. The practitioner track between Foundation and Lead.

    Delivery:
    Classroom, In-company, Live online, Self-paced
    Exam:
    Included
    Price:
    €1,850–2,250 per seat

    Lead · 5 days

    ISO/IEC 38500 Lead IT Corporate Governance Manager

    Five days on establishing and leading IT corporate governance across an organisation, from the governing body's mandate down to the evidence that shows the model works. The senior track, and the natural companion to ISO/IEC 42001 now that AI decisions have become board decisions.

    Delivery:
    Classroom, In-company, Live online, Self-paced
    Exam:
    Included
    Price:
    €2,350–2,850 per seat

    All prices exclude VAT. Classroom sessions held in the Netherlands are subject to 21% Dutch VAT for all attendees, regardless of the attendee's country — EU rules tax admission to an educational event where the event takes place. Online and in-company delivery to businesses elsewhere in the EU is reverse-charged.

    Courseware and examination in English. Sessions facilitated in English or French.

    GSNA Solutions is a PECB Certified Partner and authorised reseller. PECB personnel certifications are issued under ISO/IEC 17024. Course participants who complete a certificate programme hold a certificate; they are not thereby certified, licensed, accredited or registered to practise an occupation. Certification follows successful examination and verification of professional experience against PECB's published requirements.

    See every course in one table

    Questions

    Is this the same as COBIT?

    They complement each other. ISO/IEC 38500 is a short, principles-based standard aimed at the governing body; COBIT is a detailed framework aimed at the people implementing governance and management practices. Organisations frequently use the standard to set direction and COBIT to build the detail.

    Our board is not technical. Is Foundation appropriate?

    It is designed for exactly that audience. The standard is deliberately not technical — it is about direction, accountability and monitoring. The hardest part for a board is usually not the content but accepting that receiving a status report is not the same as governing.

    How does this relate to NIS2 board obligations?

    The national implementations put duties on the management body, including a requirement to have relevant knowledge. This track is a defensible way to meet that requirement and to evidence it with a dated record, alongside the readiness work itself.

    Which languages?

    Accredited courseware and examinations are in English. Sessions are facilitated in English or French.

    Leave with your top three risks documented

    Thirty minutes with a senior practitioner. No slideware, no sales engineer.