ISO/IEC 38500 is the international standard for the corporate governance of IT, and it is aimed at a group most IT training ignores entirely: the governing body. Directors, owners and executive committees who are accountable for technology decisions they do not make personally, and who are increasingly asked to evidence that accountability.
The distinction the standard rests on is between governing and managing. Managing is running IT — delivering, operating, securing. Governing is directing, evaluating and monitoring: deciding what IT is for, what the organisation will and will not do, and whether what is happening matches what was decided. Most organisations that say they have an IT governance problem have a management system doing both, badly, because nobody separated the two.
The pressure to fix this has become concrete. NIS2 and its national implementations put duties on the management body personally, including a knowledge requirement. The EU AI Act expects accountability to be located. Boards are being asked to demonstrate that technology risk reaches them in a form they can act on — and a board that receives a monthly status report is not governing, it is being briefed.
The three levels follow the responsibility rather than the seniority. Foundation gives a governing body the vocabulary and the principles. The IT Corporate Governance Manager level is for the person who operates the framework — decision rights, forums, reporting cadence. The Lead level is for whoever establishes the framework and the assurance loop behind it.
This track pairs naturally with ISO/IEC 27001 and ISO/IEC 42001. Those standards give you management systems; this one tells the governing body how to direct and monitor them without taking over the running of them.