Governance evaluates, directs and monitors. Management plans, builds, runs and measures. Most organisations blur the two.
COBIT separates them explicitly, with governance objectives in one domain and management objectives in four. That separation is what gives a board something to hold management to rather than a status report to receive.

- 40 objectivesGovernance and management combined
- 5 domainsOne governance, four management
- 7 componentsOf a governance system
- CustomisedThe content is generic and needs tailoring
A board that only monitors is not governing.
The governance domain names three activities, and organisations that struggle with technology oversight are almost always missing the first two.
- Evaluate. The governing body assesses strategic options, which requires being presented with options rather than with a single recommendation and a budget request. Where only one option ever reaches the board, evaluation is not happening.
- Direct. Senior management is directed on the chosen strategic options. That is an instruction with an owner and an expectation attached, and it is a very different artefact from a board minute noting that a presentation was received.
- Monitor. Achievement of the strategy is monitored, which is the part most boards do. Doing it without the first two produces reporting against targets nobody at board level actually set, which is why the reports so often feel unsatisfying.
- Separating governance from management is not bureaucracy. It is what allows a board to hold management accountable for outcomes it explicitly directed, rather than reacting to whatever is presented at the meeting.
Eight things a governance review establishes.
Governance is evaluate, direct and monitor
In the governance domain the governing body evaluates strategic options, directs senior management on the chosen options, and monitors achievement of the strategy. Three verbs, and most boards do only the third and only occasionally.
Management sits in four separate domains
Align, plan and organise. Build, acquire and implement. Deliver, service and support. Monitor, evaluate and assess. Separating them prevents the common pattern where delivery consumes all attention and planning and assurance quietly disappear.
Forty objectives give the conversation structure
The framework defines forty governance and management objectives across the five domains. That is a lot, and the point is not to implement all of them but to have a complete map against which to decide what your organisation actually needs.
Alignment, strategy and supporting activities
The align, plan and organise domain addresses the overall organisation, strategy and supporting activities for information and technology. It is where portfolio, architecture, risk and supplier decisions belong, and it is the domain most often thin.
Building and integrating into the business
The build, acquire and implement domain addresses the definition, acquisition and implementation of technology solutions and their integration in business processes. That last phrase is where most implementation projects are judged and found wanting.
Operations includes security explicitly
The deliver, service and support domain addresses the operational delivery and support of technology services, including security. Placing security inside operational delivery rather than beside it reflects how it actually has to work.
Assurance is its own domain
Monitor, evaluate and assess addresses performance monitoring and conformance with internal performance targets, internal control objectives and external requirements. Having it as a domain rather than an afterthought is what makes governance verifiable.
Seven components, and most are not technology
Processes, organisational structures, information, people skills and competencies, principles policies and procedures, culture ethics and behaviour, and services infrastructure and applications. Only the last is what most people mean by IT.
One governance domain, four management domains.
| Domain | Abbreviation | What it addresses | |
|---|---|---|---|
| Evaluate, Direct and Monitor | EDM | The governing body evaluating options, directing management and monitoring the strategy | |
| Align, Plan and Organize | APO | Overall organisation, strategy and supporting activities for information and technology | |
| Build, Acquire and Implement | BAI | Definition, acquisition and implementation of solutions and their integration in business processes | |
| Deliver, Service and Support | DSS | Operational delivery and support of technology services, including security | |
| Monitor, Evaluate and Assess | MEA | Performance monitoring and conformance with internal and external requirements | |
| Governance objectives | EDM only | Where the governing body acts | |
| Management objectives | APO, BAI, DSS, MEA | Where executive management acts | |
| Total objectives | 40 | Across all five domains |
Four things that keep a governance programme proportionate.
We select objectives rather than adopting all forty
The content is generic and needs customising, with applicability and value addition as the criteria. Recording which objectives are not adopted, and why, is as valuable as recording those that are, particularly when an auditor asks later.
We start with the governance domain
Evaluate, direct and monitor. If the governing body is not evaluating options and issuing direction, improvements in the management domains have nothing to align to, and the programme becomes a process improvement exercise instead.
We address the components that are not process
Organisational structures, information, people skills and competencies, principles policies and procedures, and culture ethics and behaviour. Five of the seven components are not process, and they are where governance programmes usually fail quietly.
We define what monitoring will actually look at
Performance monitoring and conformance with internal performance targets, internal control objectives and external requirements. Deciding what the governing body will see, and how often, is what stops the assurance domain becoming theoretical.
Three phases across roughly eight to fourteen weeks.
- 01Weeks 1 to 4
Establish the current position
Who decides what today, on what information, with what authority and what record. Then the current position mapped against the five domains, which usually shows heavy weight in delivery and support and very little in the governance domain.
- Current decision rights documented
- Position mapped across the five domains
- Governance and management activities distinguished
- Gaps identified with business consequence
- 02Weeks 5 to 9
Select and tailor
The objectives worth adopting given what the organisation actually struggles with, since the content is generic and needs customising. Selection weighted by applicability and value addition rather than by completeness.
- Objectives selected with reasoning recorded
- Objectives explicitly not adopted, with reasoning
- Target design described per selected objective
- Owners identified for each
- 03Weeks 10 to 14
Implement across the components
Governance is more than process. The seven components cover organisational structures, information, people and skills, principles and policies, culture and behaviour, and services and applications alongside processes.
- Processes and structures defined
- Information flows to the governing body agreed
- Skills and role expectations documented
- Monitoring and reporting cadence established
Six situations that make governance a live question.
A regulated firm asked how technology decisions are made
Supervisors examine decision rights, accountability and oversight rather than only controls. A structure that separates the governing body role from management, with a recorded basis for decisions, is what that examination is looking for.
A board that keeps receiving surprises
Where significant technology commitments reach the board after they are effectively made, the governance domain is not operating. Evaluating options and directing management are the two activities that change that pattern.
A group with inconsistent practices across entities
A common framework with stable objective identifiers gives group and entity conversations a shared vocabulary. Tailoring can then differ by entity while the underlying map stays comparable across the group.
An organisation after a failed major programme
The post mortem usually finds unclear accountability, a business case nobody owned, and integration into business processes treated as a later problem. Those map directly onto the build, acquire and implement domain and onto governance.
A business where technology risk has no owner
Ensured risk optimisation sits in the governance domain, which places technology risk appetite with the governing body rather than with the technology function. Many organisations have never made that placement explicit.
A company preparing for external certification
Certification schemes assume decision rights, ownership and management review already exist. Organisations without a governance structure discover during preparation that the management system has no management behind it.
How UAE organisations govern technology.
| Feature | Tailored governance system | Reporting to the board | Decisions made informally |
|---|---|---|---|
Governance separated from management | Explicitly | Blurred | Not distinguished |
Options evaluated at board level | Yes | Rarely | No |
Direction given with owners | Yes | Implied | No |
Monitoring against agreed targets | Yes | Against management targets | Ad hoc |
Assurance treated as a domain | Yes | Occasional audit | None |
Non process components addressed | All seven | Process only | None |
Objectives selected deliberately | With reasoning | Not applicable | Not applicable |
Defensible to a regulator | Yes | Partially | No |
Speed of significant decisions | Predictable | Variable | Depends who is available |
Effort to reach | Months | Existing | None |
Adopting all forty objectives is how governance programmes fail.
The framework is explicit that its content is generic and needs customising, and organisations that ignore that produce a programme nobody can sustain.
- The published position is that the content is generic in nature and needs to be customised, with applicability and value addition emphasised when deciding what to adopt. A wholesale adoption ignores both of those criteria simultaneously.
- Forty objectives, each with processes, structures, information flows, skills and cultural expectations attached, is more governance apparatus than most mid sized organisations can operate. The apparatus then becomes the work rather than supporting it.
- The useful approach is to select on the basis of what the organisation is actually struggling with. Where decisions get made too slowly, where accountability is unclear, where projects fail at integration, where assurance is absent.
- That produces a shorter set of objectives with genuine ownership, which can be extended later. It also produces something a board can read, which a comprehensive governance framework document reliably is not.
Five steps, and none of them start with a document.
- 1
Document how decisions are actually made today
Who decides on technology investment, architecture, risk acceptance, supplier selection and prioritisation, on what information, and with what record. This is descriptive rather than evaluative, and it is frequently the most revealing phase.
- 2
Map the position across the five domains
Evaluate direct and monitor, align plan and organise, build acquire and implement, deliver service and support, and monitor evaluate and assess. The shape of the map tells you where attention has gone and what has been neglected.
- 3
Select the objectives worth adopting
Weighted by applicability and value addition, since the content is generic and needs customising. The objectives not adopted are recorded with reasoning, which is the part that keeps the programme defensible and proportionate.
- 4
Design across all seven components
Processes, organisational structures, information, people skills and competencies, principles policies and procedures, culture ethics and behaviour, and services infrastructure and applications. Process alone produces documentation without change.
- 5
Establish monitoring and review
What the governing body sees, how often, and against targets it actually set. Performance monitoring and conformance with internal targets, control objectives and external requirements is a domain in its own right for good reason.
What organisations ask about IT governance.
Fifteen questions a governing body should be able to answer.
Evaluate, direct, monitor
- Are options presented, or one recommendation?Evaluation needs options.
- Does the board direct, or only receive?Direction has an owner.
- Who set the targets we monitor?Often nobody at board level.
- Is risk appetite stated for technology?EDM03 covers risk optimisation.
- Is continuity a governance concern?DSS04 covers managed continuity.
Management domains
- Is there a technology strategy?The APO domain.
- Do projects integrate into processes?The BAI domain.
- Is security inside service delivery?Explicitly in DSS.
- Do we assess conformance?The MEA domain.
- Which domain is weakest?Usually APO or MEA.
Components
- Are organisational structures defined?A named component.
- Do decision makers get the right information?Also a component.
- Do people have the skills required?And competencies.
- Do culture and behaviour support it?The hardest component.
- Have we tailored rather than adopted?The content is generic.
Ask who approved your largest technology commitment of the last two years.
On what information, and whether alternatives were presented alongside it. The answer tells you whether your governing body is evaluating and directing, or only monitoring.
Related Services
Explore more solutions that work great with this service
IT Audit Services Dubai
Assessment, technical test or certification, scoped properly
IT Risk Assessment
A short register with an owner against every risk
Virtual CISO Dubai
Security governance and accountability, not more tools
IT General Controls
What your external auditor tests, and the evidence they sample
Security Policy Development
Policies you can actually comply with
Compliance as a Service
Keeping the position true between assessments
Gap Assessment
Distance to a target you actually have to meet
ISO 27001 Certification UAE
The 2022 edition, and whether you should certify at all