COBIT vs ITIL is a comparison between a governance framework and a service management framework, and the reason it keeps being asked is that both are described, loosely, as “IT best practice”. They are not competitors. COBIT 2019, from ISACA, answers the governing body’s question — is our investment in information and technology delivering value at acceptable risk, and how do we know? — through 40 governance and management objectives, design factors that tailor them, and capability levels that measure them.
ITIL, from PeopleCert and now in its fifth version, answers the operating question — how do we design, deliver and improve the digital products and services the business runs on? — through a value system, a product and service lifecycle and 34 management practices. One decides and monitors; the other delivers. This guide sets the two frameworks side by side on eight points, explains the four differences that matter in practice, shows where COBIT objectives and ITIL practices map onto each other, and describes how organisations use both without duplicating either — including what ITIL 5 and the announced COBIT 7 change.

COBIT vs ITIL at a glance
| COBIT 2019 (ISACA) | ITIL 5 (PeopleCert) | |
|---|---|---|
| Purpose | Governance and management of enterprise information and technology (EGIT) | Management of digital products and services across their lifecycle |
| Primary audience | Boards, executives, CIOs, risk and audit functions | Service and product managers, IT operations, delivery teams |
| Core structure | 40 governance and management objectives in five domains: EDM, APO, BAI, DSS, MEA | ITIL Value System; product and service lifecycle with eight activities; 34 practices in two categories |
| Tailoring | Eleven design factors produce a tailored governance system with target capability per objective | Guiding principles and value streams; practices adopted as needed |
| Measurement | Capability levels 0–5 per process; maturity levels for focus areas | Practice maturity via the practice guides and the Maturity Model; no framework-level scale for the organisation |
| Certification | Individuals only — COBIT Foundation and Design & Implementation certificates; no organisational certificate | Individuals only — Foundation and the higher modules; no organisational certificate (ISO/IEC 20000 certifies service management systems) |
| Latest edition | COBIT 2019 (November 2018); ISACA has announced COBIT 7 certificates replacing the 2019 certificates from 27 October 2026 | ITIL 5, phased release from 2026, replacing ITIL 4 (2019) |
| Relationship | References ITIL as one of the standards it aligns to; DSS and BAI objectives correspond to ITIL practice areas | Sits inside a governance layer it does not itself define |
COBIT vs ITIL: the four differences that matter
- Governance versus management. COBIT’s central distinction is structural: the governing body evaluates, directs and monitors (the five EDM objectives), and management plans, builds, runs and monitors within that direction (the 35 objectives in APO, BAI, DSS and MEA). ITIL has no governance domain of its own; its guidance on governance is that the organisation’s governing body directs and the value system operates within it. An organisation with mature ITIL and no COBIT typically has competent operations and no evidence that anyone above the CIO decided what the operations were for.
- What is measured. COBIT measures capability per process on a 0–5 scale and lets the design factors set the target, so “we are at level 2 and need level 3 on APO12” is a meaningful sentence. ITIL measures value — outcomes, costs, risks — through practice metrics and value streams; it does not rate the organisation.
- Breadth versus depth. COBIT’s 40 objectives cover strategy, portfolio, architecture, budgets, risk, security, human resources, suppliers, projects, requirements, change, operations, service requests, incidents, problems, continuity, monitoring, compliance and assurance — at the level of what must be achieved and the components needed. ITIL’s 34 practices go deep on how service and product management is done, with detailed practice guides, roles, workflows and metrics.
- Risk and assurance. COBIT is written to be audited against; ISACA’s audit heritage shows in the management practices, activities and the assurance guidance. ITIL is written to be operated; audit is a consumer of its records, not its design goal.
COBIT vs ITIL by objective and practice: the mapping
| COBIT 2019 objective | ITIL practice(s) that deliver it | What each contributes |
|---|---|---|
| DSS02 Managed Service Requests and Incidents | Incident management; Service request management; Service desk | COBIT: the objective, purpose, metrics and capability target. ITIL: the practice guides, workflows and roles |
| DSS03 Managed Problems | Problem management | Same division |
| BAI06 Managed IT Changes; BAI07 Managed IT Change Acceptance and Transitioning | Change enablement; Release management; Deployment management | COBIT asks whether changes are governed; ITIL says how change enablement runs |
| BAI10 Managed Configuration | Service configuration management; IT asset management | Objective and evidence vs practice and CMDB design |
| APO09 Managed Service Agreements | Service level management; Relationship management | Governance of agreements vs the practice of setting and reviewing them |
| DSS04 Managed Continuity | Service continuity management | Continuity as a governed objective vs the practice |
| APO12 Managed Risk; APO13 Managed Security | Risk management; Information security management | COBIT’s risk and security objectives are broader — enterprise I&T risk — and ITIL’s practices operate within them |
| EDM01–EDM05 | None — governance is above ITIL | The layer ITIL assumes exists |
| MEA01–MEA04 | Measurement and reporting; Continual improvement (partly) | COBIT’s monitoring, control, compliance and assurance objectives; ITIL’s improvement practice feeds them |
The pattern is that ITIL practices are the components — processes, roles, information, tools — through which the COBIT objectives in BAI and DSS are achieved. COBIT 2019 itself lists ITIL among the standards it aligns to; the mapping is not a stretch. Our guide to the COBIT domains covers the objectives in full; ITIL 5 practices covers the 34 on the other side.
COBIT vs ITIL in practice: using both together
- Put the governance layer in with COBIT. EDM objectives, a governance system designed with the eleven design factors, and target capability levels for the objectives that matter — usually a dozen, not forty.
- Operate service management with ITIL. Where a COBIT objective is delivered by ITIL practices, adopt the practice guides rather than writing a second process; the COBIT objective supplies the purpose and metrics, the ITIL practice supplies the how.
- Measure once. ITIL practice metrics feed COBIT’s MEA01 performance monitoring; a COBIT capability assessment of DSS02 is, in practice, an assessment of the incident management practice.
- Certify the service management system to ISO/IEC 20000-1 if a customer needs a certificate. Neither framework certifies organisations; ISO 20000 does, and its process requirements align with ITIL. Our guide to ISO 20000 vs ITIL covers that pairing.
- Read the version notes. ITIL 5 kept all 34 practices and replaced the six-activity service value chain with an eight-activity product and service lifecycle; the mapping above holds. ISACA has announced COBIT 7 certificates from 27 October 2026, with the 2019 certificates sunset on 26 April 2027; the framework’s changes are ISACA’s to publish, and the objectives-and-practices relationship is unlikely to be what changes. Our guides to ITIL 5 and COBIT 2019 track both.
Frequently asked questions
What is the difference in COBIT vs ITIL?
COBIT is a governance and management framework for enterprise information and technology — what must be achieved, at what capability, and how the board knows. ITIL is a service management framework — how digital products and services are designed, delivered and improved. COBIT has a governance layer (EDM) that ITIL does not; ITIL has practice-level depth that COBIT does not.
Which should we adopt first?
Whichever answers the question you are being asked. A regulator, auditor or board asking how IT is governed points to COBIT; an operations problem — incidents, changes, service levels — points to ITIL practices. Most organisations of any size need both: COBIT for the governance system, ITIL for service management within it.
Can COBIT replace ITIL, or ITIL replace COBIT?
No. COBIT’s DSS and BAI objectives state what service management must achieve but do not contain ITIL’s practice guidance; ITIL contains no governance domain and no capability scale. Each assumes the other, or something like it, exists.
Is either certifiable for an organisation?
No. Both certify individuals — COBIT Foundation and Design & Implementation (ISACA), ITIL Foundation and its higher modules (PeopleCert). Organisations wanting a service management certificate use ISO/IEC 20000-1.
Do ITIL 5 and COBIT 7 change the comparison?
ITIL 5 kept the 34 practices and changed the lifecycle, so the mapping to COBIT objectives holds. ISACA has announced COBIT 7 certificates from 27 October 2026 and the sunset of the 2019 certificates on 26 April 2027; until the framework is published, COBIT 2019’s objectives are the ones to map.
Where this leaves you
Settle COBIT vs ITIL by layer, not by preference: COBIT for the governance system — the EDM objectives, the design factors and the capability targets that tell the board what IT is for and whether it is delivering — and ITIL for the practices that deliver the BAI and DSS objectives inside it. Map them once, measure them once, and certify the service management system to ISO 20000 if a certificate is what the customer actually wants.
References
- ISACA — COBIT — The COBIT 2019 framework publications: Introduction and Methodology, Governance and Management Objectives, Design Guide, Implementation Guide.
- ISACA — COBIT Foundation certificate — The individual certificate, and the notice that COBIT 7 Foundation replaces it from 27 October 2026.
- PeopleCert — ITIL 5 Foundation — The ITIL 5 syllabus: value system, lifecycle and practices.
More on COBIT
- COBIT vs ITIL — you are here
- COBIT 2019: the complete guide
- COBIT domains: EDM, APO, BAI, DSS and MEA
- IT governance framework: the three layers
- ITIL 5: what changed
- ISO 20000 vs ITIL
The governance framework manual, the design factor workbook, the objective-to-practice cross-mapping appendix and the document set for each of the five COBIT domains are in the COBIT 2019 IT Governance Toolkit, or start with the free templates.