What's changed: Initial version
4.1IT governance and COBIT
Covers IT governance (the responsibility of executive management, and alignment of IT strategy with business strategy), which ties the use of IT to business goals and controls it, and COBIT, the framework that organizes its control objectives, building the judgment an auditor needs to decide from which viewpoint to evaluate whether IT governance is functioning.
When a systems auditor says they "audit IT governance," the task is not to verify how individual servers or programs operate; it is to evaluate whether the mechanism by which executive management directs and monitors IT is working, so that IT investment and the use of information systems are properly tied to achieving business goals. What is examined here is not technical skill but a control framework: whether IT strategy is aligned with business strategy, whether responsibility and accountability are clear, and whether outcomes are measured. Grounded in the essence of IT governance and in COBIT, which organizes its control objectives, this section builds the viewpoint from which an auditor diagnoses "whether governance is functioning."
4.1.1What IT governance is
- A IT governance is the organizational capability by which a firm controls the formulation and execution of IT strategy and steers it in the right direction, aiming to build competitive advantage (per definitions such as JIS Q 38500). Its primary responsibility lies with executive management (the board and executives) and cannot be discharged by simply delegating it wholesale to the IT department or the CIO. Its core is that executive management directs, monitors, and evaluates whether the use of IT contributes to achieving business goals.
- The key point of IT governance is alignment of IT strategy with business strategy. No matter how advanced an information system a firm introduces, if it is not tied to business goals it is a governance problem. An auditor evaluates not "whether the latest technology was adopted" but whether IT investment is prioritized in line with business goals and whether outcomes are monitored.
4.1.2The role of COBIT
- A COBIT (Control Objectives for Information and related Technology) is a framework of control objectives for IT governance and IT management, developed by ISACA. It organizes IT-related goals, processes, control objectives, and a maturity model, providing a yardstick for the "target control state." An auditor uses COBIT as a reference standard (benchmark) when evaluating how well the audited organization's IT controls are designed.
- COBIT is characterized by clearly separating "governance (direction and monitoring)" from "management (planning, building, running, and monitoring)", the former corresponding to the role of executive management and the latter to the executing departments. Grounded in this separation, an auditor can evaluate by distinguishing whether a deficiency lies in the executives' governance function (EDM: evaluate, direct, monitor) or in the IT department's management function.
Most-tested: "the primary responsibility for IT governance lies with executive management", "its essence is alignment of IT strategy with business strategy", and "COBIT is a framework (reference standard) of control objectives for IT governance/management". Do not answer "IT governance is the responsibility of the IT department/CIO"—it is the responsibility of executive management (the board), and delegating it wholesale to the IT department is itself an absence of governance.
Suppose a systems auditor is evaluating the IT governance of manufacturer A. Company A's IT department keeps adopting the latest cloud platforms and AI analytics tools, and is technically advanced. As the auditor conducts interviews, however, they find that which business goal (e.g., shorter production lead time, lower defect rate) each of these IT investments contributes to has not been discussed or approved at the management meeting, and the post-adoption effects are not measured. The CIO explains, "we adopted it because the field said they wanted to use it." The judgment the auditor should make here is not "IT governance is sound because the latest technology is in use." The essence of IT governance is alignment of IT strategy with business strategy, and the evaluation axis is whether executive management directs and monitors IT investment in line with business goals. In this case, even though individual systems operate, the executives' governance function (EDM: evaluate, direct, monitor, in COBIT terms) is not working, and the controls for judging investment validity and measuring effect are missing. The auditor should therefore point out a design deficiency—"the IT-investment decision process has no mechanism linking investments to business goals and measuring their effect"—and recommend building an IT-investment evaluation process at the management meeting. The trap here is to place the audit's focus on "how new the technology is" or "how skillfully the IT department operates"—the object of an IT-governance audit is the executives' mechanism for direction and monitoring, which is a different layer from a technology assessment or an audit of the IT department's work quality.
| Viewpoint | IT governance (executives) | IT management (IT department) |
|---|---|---|
| Responsible party | The board and executives | CIO and IT department |
| COBIT division | EDM (evaluate, direct, monitor) | Plan, build, run, and monitor |
| Audit focus | Alignment of IT and business strategy; direction of investment | Operation and outcomes of individual processes |
Trap: "IT governance is sound as long as the latest technology is adopted" is wrong—the evaluation axis for governance is not how new the technology is but alignment of IT strategy with business strategy, plus direction and effect measurement by executive management. Also wrong: "responsibility for IT governance lies with the CIO/IT department"—the primary responsibility lies with executive management (the board), and delegating it wholesale to the IT department indicates an absence of governance.
4.1.3Section summary
- The primary responsibility for IT governance lies with executive management (the board); its essence is alignment of IT strategy with business strategy
- COBIT, developed by ISACA, is a framework of control objectives for IT governance/management and serves as a reference standard for audit
- An auditor evaluates not how new the technology is or the IT department's work quality, but whether the executives' mechanism for direction and monitoring is functioning
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. In an IT-governance audit of manufacturer A, the IT department keeps adopting the latest cloud platforms and AI analytics tools, but how they contribute to business goals is neither discussed nor approved at the management meeting, and their effect is not measured. Which is the most appropriate evaluation by the auditor?
Q2. When a systems auditor evaluates how well the audited organization's IT controls are designed, which framework is most appropriately used as a reference standard (benchmark) for the "target control state"?
Q3. An auditor is looking for signs that IT governance is not functioning at a firm. Which situation most strongly suggests an absence of IT governance?
Keep track of your progress
The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.

