Instiq
Chapter 4 · IT governance & internal control·v1.0.0·Updated 7/11/2026·~14 min

What's changed: Initial version

4.1IT governance and COBIT

Key points

Covers IT governance (the responsibility of executive management, and alignment of IT strategy with business strategy), which ties the use of IT to business goals and controls it, and COBIT, the framework that organizes its control objectives, building the judgment an auditor needs to decide from which viewpoint to evaluate whether IT governance is functioning.

When a systems auditor says they "audit IT governance," the task is not to verify how individual servers or programs operate; it is to evaluate whether the mechanism by which executive management directs and monitors IT is working, so that IT investment and the use of information systems are properly tied to achieving business goals. What is examined here is not technical skill but a control framework: whether IT strategy is aligned with business strategy, whether responsibility and accountability are clear, and whether outcomes are measured. Grounded in the essence of IT governance and in COBIT, which organizes its control objectives, this section builds the viewpoint from which an auditor diagnoses "whether governance is functioning."

4.1.1What IT governance is

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.