We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Audit and compliance
  2. COBIT IT governance
IT governance, UAE

Governance evaluates, directs and monitors. Management plans, builds, runs and measures. Most organisations blur the two.

COBIT separates them explicitly, with governance objectives in one domain and management objectives in four. That separation is what gives a board something to hold management to rather than a status report to receive.

Book an IT governance reviewSee the five domains
COBIT IT governance for UAE organisations
  • 40 objectivesGovernance and management combined
  • 5 domainsOne governance, four management
  • 7 componentsOf a governance system
  • CustomisedThe content is generic and needs tailoring
The distinction that does the work

A board that only monitors is not governing.

The governance domain names three activities, and organisations that struggle with technology oversight are almost always missing the first two.

  • Evaluate. The governing body assesses strategic options, which requires being presented with options rather than with a single recommendation and a budget request. Where only one option ever reaches the board, evaluation is not happening.
  • Direct. Senior management is directed on the chosen strategic options. That is an instruction with an owner and an expectation attached, and it is a very different artefact from a board minute noting that a presentation was received.
  • Monitor. Achievement of the strategy is monitored, which is the part most boards do. Doing it without the first two produces reporting against targets nobody at board level actually set, which is why the reports so often feel unsatisfying.
  • Separating governance from management is not bureaucracy. It is what allows a board to hold management accountable for outcomes it explicitly directed, rather than reacting to whatever is presented at the meeting.
Ask us to review your governance structure
What the framework provides

Eight things a governance review establishes.

Enterprise governance of information and technology is about decision rights and accountability rather than about controls. Most UAE organisations have controls and no clear answer to who decides what, on what basis, and who checks.

Governance is evaluate, direct and monitor

In the governance domain the governing body evaluates strategic options, directs senior management on the chosen options, and monitors achievement of the strategy. Three verbs, and most boards do only the third and only occasionally.

Management sits in four separate domains

Align, plan and organise. Build, acquire and implement. Deliver, service and support. Monitor, evaluate and assess. Separating them prevents the common pattern where delivery consumes all attention and planning and assurance quietly disappear.

Forty objectives give the conversation structure

The framework defines forty governance and management objectives across the five domains. That is a lot, and the point is not to implement all of them but to have a complete map against which to decide what your organisation actually needs.

Alignment, strategy and supporting activities

The align, plan and organise domain addresses the overall organisation, strategy and supporting activities for information and technology. It is where portfolio, architecture, risk and supplier decisions belong, and it is the domain most often thin.

Building and integrating into the business

The build, acquire and implement domain addresses the definition, acquisition and implementation of technology solutions and their integration in business processes. That last phrase is where most implementation projects are judged and found wanting.

Operations includes security explicitly

The deliver, service and support domain addresses the operational delivery and support of technology services, including security. Placing security inside operational delivery rather than beside it reflects how it actually has to work.

Assurance is its own domain

Monitor, evaluate and assess addresses performance monitoring and conformance with internal performance targets, internal control objectives and external requirements. Having it as a domain rather than an afterthought is what makes governance verifiable.

Seven components, and most are not technology

Processes, organisational structures, information, people skills and competencies, principles policies and procedures, culture ethics and behaviour, and services infrastructure and applications. Only the last is what most people mean by IT.

The five domains

One governance domain, four management domains.

Taken from the published description. The objective identifiers follow the domain abbreviations, which is why references such as EDM03 and DSS04 appear in governance documents.
DomainAbbreviationWhat it addresses
Evaluate, Direct and MonitorEDMThe governing body evaluating options, directing management and monitoring the strategy
Align, Plan and OrganizeAPOOverall organisation, strategy and supporting activities for information and technology
Build, Acquire and ImplementBAIDefinition, acquisition and implementation of solutions and their integration in business processes
Deliver, Service and SupportDSSOperational delivery and support of technology services, including security
Monitor, Evaluate and AssessMEAPerformance monitoring and conformance with internal and external requirements
Governance objectivesEDM onlyWhere the governing body acts
Management objectivesAPO, BAI, DSS, MEAWhere executive management acts
Total objectives40Across all five domains
How we approach it

Four things that keep a governance programme proportionate.

Governance frameworks attract documentation. The measure of success is whether decisions get made better and faster, not whether the framework is complete.

We select objectives rather than adopting all forty

The content is generic and needs customising, with applicability and value addition as the criteria. Recording which objectives are not adopted, and why, is as valuable as recording those that are, particularly when an auditor asks later.

We start with the governance domain

Evaluate, direct and monitor. If the governing body is not evaluating options and issuing direction, improvements in the management domains have nothing to align to, and the programme becomes a process improvement exercise instead.

We address the components that are not process

Organisational structures, information, people skills and competencies, principles policies and procedures, and culture ethics and behaviour. Five of the seven components are not process, and they are where governance programmes usually fail quietly.

We define what monitoring will actually look at

Performance monitoring and conformance with internal performance targets, internal control objectives and external requirements. Deciding what the governing body will see, and how often, is what stops the assurance domain becoming theoretical.

How an engagement runs

Three phases across roughly eight to fourteen weeks.

Governance work moves at the speed of the people who hold the decisions. The analysis is quick and the agreement is not.
  1. 01
    Weeks 1 to 4

    Establish the current position

    Who decides what today, on what information, with what authority and what record. Then the current position mapped against the five domains, which usually shows heavy weight in delivery and support and very little in the governance domain.

    • Current decision rights documented
    • Position mapped across the five domains
    • Governance and management activities distinguished
    • Gaps identified with business consequence
  2. 02
    Weeks 5 to 9

    Select and tailor

    The objectives worth adopting given what the organisation actually struggles with, since the content is generic and needs customising. Selection weighted by applicability and value addition rather than by completeness.

    • Objectives selected with reasoning recorded
    • Objectives explicitly not adopted, with reasoning
    • Target design described per selected objective
    • Owners identified for each
  3. 03
    Weeks 10 to 14

    Implement across the components

    Governance is more than process. The seven components cover organisational structures, information, people and skills, principles and policies, culture and behaviour, and services and applications alongside processes.

    • Processes and structures defined
    • Information flows to the governing body agreed
    • Skills and role expectations documented
    • Monitoring and reporting cadence established
Where this comes up

Six situations that make governance a live question.

Governance work is rarely elective. It usually follows a decision that went badly or a requirement that arrived from outside.

A regulated firm asked how technology decisions are made

Supervisors examine decision rights, accountability and oversight rather than only controls. A structure that separates the governing body role from management, with a recorded basis for decisions, is what that examination is looking for.

A board that keeps receiving surprises

Where significant technology commitments reach the board after they are effectively made, the governance domain is not operating. Evaluating options and directing management are the two activities that change that pattern.

A group with inconsistent practices across entities

A common framework with stable objective identifiers gives group and entity conversations a shared vocabulary. Tailoring can then differ by entity while the underlying map stays comparable across the group.

An organisation after a failed major programme

The post mortem usually finds unclear accountability, a business case nobody owned, and integration into business processes treated as a later problem. Those map directly onto the build, acquire and implement domain and onto governance.

A business where technology risk has no owner

Ensured risk optimisation sits in the governance domain, which places technology risk appetite with the governing body rather than with the technology function. Many organisations have never made that placement explicit.

A company preparing for external certification

Certification schemes assume decision rights, ownership and management review already exist. Organisations without a governance structure discover during preparation that the management system has no management behind it.

Three positions

How UAE organisations govern technology.

The middle column is where most organisations sit, and it works until a significant technology decision has to be made or defended.
Governance separated from management
Tailored governance systemExplicitly
Reporting to the boardBlurred
Decisions made informallyNot distinguished
Options evaluated at board level
Tailored governance systemYes
Reporting to the boardRarely
Decisions made informallyNo
Direction given with owners
Tailored governance systemYes
Reporting to the boardImplied
Decisions made informallyNo
Monitoring against agreed targets
Tailored governance systemYes
Reporting to the boardAgainst management targets
Decisions made informallyAd hoc
Assurance treated as a domain
Tailored governance systemYes
Reporting to the boardOccasional audit
Decisions made informallyNone
Non process components addressed
Tailored governance systemAll seven
Reporting to the boardProcess only
Decisions made informallyNone
Objectives selected deliberately
Tailored governance systemWith reasoning
Reporting to the boardNot applicable
Decisions made informallyNot applicable
Defensible to a regulator
Tailored governance systemYes
Reporting to the boardPartially
Decisions made informallyNo
Speed of significant decisions
Tailored governance systemPredictable
Reporting to the boardVariable
Decisions made informallyDepends who is available
Effort to reach
Tailored governance systemMonths
Reporting to the boardExisting
Decisions made informallyNone
Feature
Tailored governance system
Reporting to the board
Decisions made informally
Governance separated from management
ExplicitlyBlurredNot distinguished
Options evaluated at board level
YesRarelyNo
Direction given with owners
YesImpliedNo
Monitoring against agreed targets
YesAgainst management targetsAd hoc
Assurance treated as a domain
YesOccasional auditNone
Non process components addressed
All sevenProcess onlyNone
Objectives selected deliberately
With reasoningNot applicableNot applicable
Defensible to a regulator
YesPartiallyNo
Speed of significant decisions
PredictableVariableDepends who is available
Effort to reach
MonthsExistingNone
The mistake to avoid

Adopting all forty objectives is how governance programmes fail.

The framework is explicit that its content is generic and needs customising, and organisations that ignore that produce a programme nobody can sustain.

  • The published position is that the content is generic in nature and needs to be customised, with applicability and value addition emphasised when deciding what to adopt. A wholesale adoption ignores both of those criteria simultaneously.
  • Forty objectives, each with processes, structures, information flows, skills and cultural expectations attached, is more governance apparatus than most mid sized organisations can operate. The apparatus then becomes the work rather than supporting it.
  • The useful approach is to select on the basis of what the organisation is actually struggling with. Where decisions get made too slowly, where accountability is unclear, where projects fail at integration, where assurance is absent.
  • That produces a shorter set of objectives with genuine ownership, which can be extended later. It also produces something a board can read, which a comprehensive governance framework document reliably is not.
Ask us to select the objectives that fit
How an engagement runs

Five steps, and none of them start with a document.

The first output that matters is a shared understanding of who currently decides what. Framework mapping comes after that, not before.
  1. 1

    Document how decisions are actually made today

    Who decides on technology investment, architecture, risk acceptance, supplier selection and prioritisation, on what information, and with what record. This is descriptive rather than evaluative, and it is frequently the most revealing phase.

  2. 2

    Map the position across the five domains

    Evaluate direct and monitor, align plan and organise, build acquire and implement, deliver service and support, and monitor evaluate and assess. The shape of the map tells you where attention has gone and what has been neglected.

  3. 3

    Select the objectives worth adopting

    Weighted by applicability and value addition, since the content is generic and needs customising. The objectives not adopted are recorded with reasoning, which is the part that keeps the programme defensible and proportionate.

  4. 4

    Design across all seven components

    Processes, organisational structures, information, people skills and competencies, principles policies and procedures, culture ethics and behaviour, and services infrastructure and applications. Process alone produces documentation without change.

  5. 5

    Establish monitoring and review

    What the governing body sees, how often, and against targets it actually set. Performance monitoring and conformance with internal targets, control objectives and external requirements is a domain in its own right for good reason.

Straight answers

What organisations ask about IT governance.

Control Objectives for Information Technologies. It is focused on enterprise governance of information and technology, which is a broader question than IT control and covers decision rights, accountability and oversight.

Governance objectives sit in the evaluate, direct and monitor domain, where the governing body evaluates strategic options, directs senior management on the chosen options and monitors achievement. Management objectives sit in the other four domains.

Forty governance and management objectives across the five domains. The point of having a complete map is to choose deliberately from it, not to implement all forty, which very few organisations could sustain.

Evaluate, Direct and Monitor for governance. Then Align, Plan and Organize; Build, Acquire and Implement; Deliver, Service and Support; and Monitor, Evaluate and Assess for management. The objective identifiers use those abbreviations.

No, and you should not. The content is generic in nature and needs to be customised, with applicability and value addition as the stated criteria. Selecting a smaller set that addresses real difficulties produces a programme people will actually run.

Seven of them: processes, organisational structures, information, people skills and competencies, principles policies and procedures, culture ethics and behaviour, and services infrastructure and applications. Only the last is technology in the narrow sense.

The deliver, service and support domain addresses the operational delivery and support of technology services, including security. Placing it inside service delivery rather than alongside it reflects how security actually has to operate day to day.

Risk optimisation is a governance objective, which places technology risk appetite with the governing body rather than delegating it to the technology function. Making that placement explicit is often the single most useful output of a review.

No, provided it is tailored. A mid sized business benefits from clear decision rights and a governing body that evaluates and directs. What it cannot sustain is forty objectives with full apparatus, which is why selection matters so much.

A management system standard is certifiable and focused on information security. A governance framework is broader, addressing decision rights and accountability across technology generally, and it is not a certification scheme.

That is one of its stated design intentions. Organisations commonly run it alongside service management, security and risk frameworks, using it as the governance layer above them rather than as a replacement for any of them.

In our experience the align, plan and organise domain and the monitor, evaluate and assess domain. Delivery and support attract attention because they are visible, while planning and assurance are easy to defer indefinitely.

The decision rights work usually changes behaviour within a quarter, because it resolves ambiguity people were already working around. The cultural component takes considerably longer and is where most of the eventual value sits.

Somebody on the governing body, because the governance domain describes what that body does. A programme sponsored entirely from within the technology function can improve management practices and cannot establish governance over them.

We scope by organisation size and how many entities are involved. The free first step: ask who approved your largest technology commitment of the last two years, on what information, and whether alternatives were presented alongside it.

The detailed publications are licensed, and the structure and vocabulary are widely described in public material. An engagement can be scoped either way, and the value comes from applying the structure rather than from owning the documents.

Service management describes how services are delivered and supported. A governance framework describes who decides what and how they are held to account. They coexist, and the governance layer sits above rather than competing with service management.

Enough to evaluate options, issue direction and monitor achievement. In practice that means investment options with trade offs rather than single recommendations, risk exposure in business terms, and progress against targets it set itself.

Somebody with a foot in both worlds, usually reporting to the governing body rather than into the technology function. Ownership placed entirely inside technology tends to produce better management practices without establishing governance over them.

Far fewer than forty. A focused selection addressing the specific difficulties an organisation has is both achievable and sustainable, and it can be extended later once the initial set is genuinely operating rather than merely documented.

It addresses the overall organisation, strategy and supporting activities for information and technology. Portfolio management, architecture, risk, budget and supplier arrangements sit here, and it is the domain most often thin in practice.

Because the build, acquire and implement domain addresses it explicitly. A solution that works technically and was never integrated into how people actually work is a common and expensive failure mode, and the framework names it directly.

Culture, ethics and behaviour is one of the seven governance system components. Decision rights that everybody routes around are not decision rights, and the cultural component is what determines whether the structure is real or nominal.

That governance depends on the right information reaching the right people. A governing body cannot evaluate options it never sees, so the information flows into the decision points are a designed element rather than an administrative detail.

By whether significant decisions get made at a predictable speed with a recorded basis, and by whether monitoring reports against targets the governing body set. Both are observable, and neither requires a maturity assessment to answer.

Yes. Every organisation has a governing function even where it is an owner or a small leadership group. The distinction between evaluating and directing on the one hand and executing on the other applies at any scale.

In the four management domains, executing against direction. That placement is often the most useful thing an engagement clarifies, because it moves technology leadership from defending decisions to implementing ones the organisation made.

Longer than the structural change, which is why the structural work is done first. Decision rights can be clarified in a quarter. Behaviour catching up with them takes considerably longer and depends on the structure being used consistently.

A map of who actually decides what, which is usually different from the org chart. That single artefact resolves a surprising number of stalled decisions, because it makes visible where authority was assumed rather than assigned.

By selecting few objectives, assigning real owners, and changing something observable within the first quarter. Documentation produced ahead of behaviour change reliably becomes shelfware, and the framework itself warns that content must be customised.

It helps considerably, because examiners ask about decision rights, accountability and oversight rather than only about controls. A structure that separates governance from management, with records, is what those questions are looking for.

That is the recommended approach. Selecting a small number of objectives addressing current difficulties, operating them properly, and extending later produces something sustainable, whereas comprehensive adoption produces apparatus nobody maintains.

Requiring options rather than a single recommendation for significant technology decisions. It is a small procedural change, it makes the evaluate activity real, and it changes the quality of board discussion almost immediately.
Governance check

Fifteen questions a governing body should be able to answer.

The first group is the governance domain in practice. Difficulty answering it usually explains most of what follows.

Evaluate, direct, monitor

  • Are options presented, or one recommendation?
    Evaluation needs options.
  • Does the board direct, or only receive?
    Direction has an owner.
  • Who set the targets we monitor?
    Often nobody at board level.
  • Is risk appetite stated for technology?
    EDM03 covers risk optimisation.
  • Is continuity a governance concern?
    DSS04 covers managed continuity.

Management domains

  • Is there a technology strategy?
    The APO domain.
  • Do projects integrate into processes?
    The BAI domain.
  • Is security inside service delivery?
    Explicitly in DSS.
  • Do we assess conformance?
    The MEA domain.
  • Which domain is weakest?
    Usually APO or MEA.

Components

  • Are organisational structures defined?
    A named component.
  • Do decision makers get the right information?
    Also a component.
  • Do people have the skills required?
    And competencies.
  • Do culture and behaviour support it?
    The hardest component.
  • Have we tailored rather than adopted?
    The content is generic.
Related reading

The pages around this one.

IT audit services

The assurance activity governance depends on.

Learn more

IT risk assessment

Feeding the risk optimisation objective.

Learn more

Virtual CISO

Security leadership inside the structure.

Learn more
Next step

Ask who approved your largest technology commitment of the last two years.

On what information, and whether alternatives were presented alongside it. The answer tells you whether your governing body is evaluating and directing, or only monitoring.

Book an IT governance reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

IT Audit Services Dubai

Assessment, technical test or certification, scoped properly

Learn more

IT Risk Assessment

A short register with an owner against every risk

Learn more

Virtual CISO Dubai

Security governance and accountability, not more tools

Learn more

IT General Controls

What your external auditor tests, and the evidence they sample

Learn more

Security Policy Development

Policies you can actually comply with

Learn more

Compliance as a Service

Keeping the position true between assessments

Learn more

Gap Assessment

Distance to a target you actually have to meet

Learn more

ISO 27001 Certification UAE

The 2022 edition, and whether you should certify at all

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy