COBIT 2019 is ISACA’s framework for the governance and management of enterprise information and technology — and the first thing worth knowing about it is that your organisation cannot be certified against it.
Individuals can hold the COBIT Foundation certificate. Enterprises cannot hold a COBIT certificate, because there isn’t one. That single fact reframes the whole exercise: COBIT is adopted to improve decisions, not to produce a document for a customer.
What COBIT 2019 is for
COBIT answers a narrow, difficult question: how does an organisation know that its investment in technology is producing value, at an acceptable level of risk, using resources sensibly?
It is not a delivery method and not a control catalogue. It sits above both — deliberately.
The framework’s central distinction is between governance and management, and it is not a semantic one. Governance is what the governing body does: evaluate options, direct a course, monitor whether it was followed. Management plans, builds, runs and monitors within that direction. Most organisations that describe themselves as having weak IT governance actually have competent management and no governance layer at all.
The 40 objectives and five domains

COBIT 2019 defines 40 governance and management objectives, grouped into five domains. One of them — EDM — is the governance domain. The other four are management.
The naming matters more than it appears. An objective is a thing to be achieved, not a process to be run. Each one comes with components: a process, but also organisational structures, information flows, people and skills, policies and procedures, culture and behaviour, and the services and infrastructure underneath. Implementing an objective by writing only the process is the most common way COBIT 2019 gets adopted badly.
COBIT 2019 design factors: the part that makes it usable
Nobody implements all 40 objectives. The framework’s design guidance exists precisely so you do not try.
Instead you work through a set of design factors — enterprise strategy, goals, the risk profile, IT-related issues, the threat landscape, compliance requirements, the role of IT, the sourcing and implementation models, technology adoption strategy and enterprise size — and let them tell you which objectives matter and how much capability each one needs.
This is the genuine advance over earlier versions. The output is a tailored governance system: a defensible, written argument for why this organisation prioritises these objectives at these capability levels. That argument is the deliverable. The document set follows from it.
Capability and performance
COBIT 2019 measures each objective’s process on a capability scale from 0 to 5, drawn from the CMMI approach. Higher is not automatically better — the target is what the design factors justify, and paying for level 4 capability where level 2 is adequate is a real and common waste.
Performance management in COBIT 2019 covers more than process capability, though. Organisational structures, information items and the other components have their own maturity considerations, and a governance system that scores well on processes while the culture undermines them is a familiar failure.
Certification: individuals only
The COBIT Foundation certificate has no prerequisites. It is a remotely proctored two-hour exam of 75 multiple-choice questions, with a pass mark of 65%, covering the framework introduction, principles, the business case, the governance system and components, designing a tailored governance system, the governance and management objectives, implementation and performance management.
Beyond it sit the COBIT Design and Implementation certificate and, for career purposes, ISACA’s CGEIT certification. What does not exist, at any level, is an accredited certificate stating that an enterprise conforms to COBIT 2019. If a supplier claims one, they are describing something else.
How COBIT 2019 fits with standards you can certify
| Framework | Relationship |
|---|---|
| ISO 27001 | A certifiable management system for information security. COBIT tells you how much security governance the enterprise needs and who decides; ISO 27001 gives you a system you can be audited against |
| ISO 20000 | Certifiable IT service management. COBIT’s DSS domain overlaps heavily — use COBIT to set the ambition and ISO 20000 to prove the delivery |
| ITIL 4 | Service management practice rather than governance. The two are complementary by design and are frequently run together |
| ISO 31000 | Gives you one risk method underneath COBIT’s risk-related objectives, instead of a bespoke IT risk scale nobody else recognises |
ISACA is explicit that COBIT is designed to integrate with the standards and regulations an enterprise already carries, rather than replace them. In practice COBIT 2019 is the layer that decides what the others are for.
Where COBIT 2019 adoption goes wrong
- Implementing all 40 objectives. The design factors exist to stop this and are routinely skipped because tailoring takes judgement and a checklist does not.
- Writing processes and calling it governance. If the governing body’s role has not changed, nothing has been governed.
- Targeting the highest capability level everywhere. Expensive, slow, and unsupported by any design factor.
- Treating it as an audit framework. Auditors use COBIT well, but adopting it to satisfy an auditor produces documentation rather than decisions.
- Expecting a certificate. There is none, so define what success looks like before you start or the programme will never end.
Where to start
- Establish the governance and management line. Who evaluates, directs and monitors, and where does that happen on a calendar?
- Work the design factors honestly, and record the reasoning. This is the artefact that justifies everything else.
- Select a small set of objectives the design factors actually point at — most organisations land on ten to fifteen.
- Set target capability levels per objective, with a reason attached to each.
- Build all the components, not just the process: structures, information, skills, policies, culture.
- Define what “done” means in advance, because no external body will tell you.
This guide reflects ISACA’s published material at 15 August 2026, on which COBIT 2019 remains the current release.
The COBIT 2019 IT Governance Toolkit provides 31 editable templates covering the design factor analysis, the tailored governance system, the objective implementation records, the capability assessments and the performance reporting — the documentation a tailored governance system needs in order to be reviewable a year later.