Skip to content

Advisory

IT Governance and COBIT 2019

Governance is the difference between technology decisions being made and technology decisions being owned. We assess where yours stands and design the structure that closes the gap.

The COBIT 2019 approach

COBIT 2019 organises technology governance and management into forty objectives across five domains: one governance domain — Evaluate, Direct and Monitor — and four management domains covering Align, Plan and Organise; Build, Acquire and Implement; Deliver, Service and Support; and Monitor, Evaluate and Assess.

A capability assessment scores your current position against the objectives that matter for your context, sets a realistic target, and produces a roadmap. The value is not the score. It is the conversation the score forces at board level about what technology is actually for and who is accountable when it fails.

Typical scope

  • Board and executive oversight of technology — mandate, composition, agenda and reporting.
  • IT strategy and its alignment to business objectives, with a traceable link between the two.
  • Technology investment governance, benefits realisation and portfolio management.
  • The IT operating model, organisational design and role accountability.
  • Performance measurement, metrics and management reporting.
  • Risk governance and the escalation path from IT risk to enterprise risk.
  • Third-party and outsourcing governance.
  • Assurance arrangements — who provides independent challenge, and to whom.

COBIT 2019 structure

EDM · Governance Evaluate, Direct and Monitor — the board's domain 40 governance and management objectives APO Align, Plan &Organise BAI Build, Acquire& Implement DSS Deliver,Service &Support MEA Monitor,Evaluate &Assess
One governance domain and four management domains, spanning forty objectives.

Framework selection

COBIT covers governance and management objectives. ITIL 4 covers service management practice. ISO/IEC 27001 covers information security management. They are complementary and we will not pretend one replaces the others. Part of the engagement is deciding which framework carries which obligation for your organisation, so you are not running three overlapping programmes that fight each other.

How the engagement runs

  1. 1

    Context and design factors

    Establish the enterprise strategy, risk profile, regulatory obligations and sourcing model that determine which objectives matter.

  2. 2

    Objective selection

    Select the governance and management objectives in scope. Assessing all forty is rarely a good use of anyone's time.

  3. 3

    Capability assessment

    Evidence-based scoring of current capability against each selected objective.

  4. 4

    Target state

    Agree the target capability level per objective, weighed against cost and organisational appetite.

  5. 5

    Gap and roadmap

    Translate the gap into a sequenced improvement programme with owners and dependencies.

  6. 6

    Board reporting

    Present findings and the proposed target operating model to the board or steering committee.

What you receive

Design factor analysis explaining why the selected objectives are the right ones
Current capability assessment with evidence per objective
Agreed target capability profile
Gap analysis and prioritised improvement roadmap
Proposed governance structure, committee terms of reference and RACI
Board-level presentation of findings and recommendations

Frequently asked questions

Yes, if applied proportionately. COBIT is a framework, not a compliance standard — you select the objectives that fit your context. The common failure is trying to implement all forty objectives at full rigour, which produces a large amount of documentation and very little governance.

COBIT governs technology broadly; ISO 27001 manages information security specifically. In practice the governance objectives in COBIT provide the organisational scaffolding that the ISO 27001 leadership and planning clauses assume already exists. Doing them together avoids building two parallel structures.

Related services

Related regulatory frameworks

Need an independent view?

Tell us the scope, the regulator and the deadline. We will come back with an approach, a team and a fee estimate.

Request a proposal
Top