Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

The COBIT 2019 implementation explained

COBIT 2019 Implementation: A Clear Guide to the 7 Phases

A COBIT 2019 implementation is not a rollout of 40 objectives. It is a continual improvement loop that starts with a business problem and adds governance components only where they earn their place — which is why the framework ships an implementation guide with seven phases rather than a checklist.

This guide covers the seven phases, the three questions each one has to answer, where implementations stall, and how to scope a first cycle that finishes.

COBIT 2019 implementation: the seven phases and what each produces
Seven phases, and the deliverable that proves each one happened.

The seven phases of a COBIT 2019 implementation

Phase The question What it produces
1 What are the drivers? The pain point, the sponsor, and a mandate to act
2 Where are we now? Current capability against the objectives in scope
3 Where do we want to be? Target capability, justified by the design factors
4 What needs to be done? A prioritised set of changes with owners and benefits
5 How do we get there? The changes built and operating, not just designed
6 Did we get there? Measured benefits against the phase 1 drivers
7 How do we keep the momentum? The next cycle, scoped from what phase 6 found

Three threads run through every phase at once: the programme management of the change, the change enablement — the human side — and the continual improvement lifecycle itself. A COBIT 2019 implementation that treats the middle thread as optional produces designs nobody adopts.

Phase 1 is the one people skip

Starting at phase 2 with a full capability assessment feels productive and produces a report with no owner. The driver has to be something the business already complains about: failed audits, an outage that reached customers, a cloud spend nobody can explain, a regulator’s finding. Write it down in the sponsor’s words, because phase 6 will measure against it.

Scoping with the design factors

COBIT 2019 does not expect you to implement all 40 governance and management objectives. The design factors — enterprise strategy, goals, risk profile, IT-related issues, threat landscape, compliance requirements, the role of IT, sourcing and implementation models, technology adoption strategy and enterprise size — narrow that list to the objectives that matter for your organization, and set a target capability level for each.

Use them honestly. A design workshop that concludes every objective is critical has not designed anything, and the resulting COBIT 2019 implementation will run out of sponsorship before phase 5. Our guide to COBIT 2019 and its 40 objectives covers the objective set, and the three layers of an IT governance framework covers where COBIT sits against the risk and control layers.

Capability levels, and what a target really costs

Each objective is assessed on a capability scale, and each step up costs real money in process design, tooling and time. Set targets per objective rather than a single organizational number, and be prepared to leave objectives at their current level deliberately — a documented decision not to improve something is a legitimate output of phase 3.

Where a COBIT 2019 implementation stalls

It becomes a documentation exercise. Forty objectives, each with a policy, produces a library and no change in behaviour. The test at phase 6 is whether the phase 1 pain has reduced, not how many documents exist.

No governance and management split. COBIT separates evaluate-direct-monitor from plan-build-run-monitor because the board’s job differs from IT’s. When both live with the same committee, the implementation quietly becomes an IT project.

The cycle never closes. Phases 6 and 7 are the ones that get dropped when the budget runs out, which means nobody ever learns whether it worked and the next cycle starts from scratch.

Capability confused with certification. There is no organizational COBIT certificate. Individuals certify; enterprises assess themselves. Selling an implementation internally on a certificate that does not exist ends badly.

Frequently asked questions

How long does a COBIT 2019 implementation take?
One cycle through the seven phases, scoped to a handful of objectives, is typically a matter of months rather than years. Scope is the variable: a cycle covering forty objectives is not a cycle, it is a programme.

Do we have to use all 40 objectives?
No. The design factors exist to select and prioritise. Most organizations start with a dozen or fewer.

Can COBIT be certified?
Not at the organizational level. Individuals hold COBIT certifications; enterprises perform capability assessments against the objectives.

How does it fit with ISO 27001 or ISO 20000?
COBIT sits above them as the governance layer, and maps onto them rather than competing. Certifiable standards give you an auditable management system; COBIT gives the board a way to direct and monitor it.

Who should own the implementation?
A business sponsor with authority over the pain point in phase 1, supported by whoever runs IT governance day to day. IT owning the sponsorship is the most common reason phase 5 stalls.

Where this leaves you

Run the COBIT 2019 implementation as one narrow cycle rather than a framework rollout: name a real business driver, use the design factors to cut the objective list hard, set target capability per objective, and build only what phase 4 justified. Then finish phases 6 and 7 — measuring against the original driver and scoping the next cycle from what you learned is what turns a one-off project into governance that improves.

References

More on IT governance

Design worksheets, capability assessments and the governance document set are in the COBIT 2019 IT Governance Toolkit, or start with the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.