Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

COBIT design factors explained

COBIT Design Factors: All 11 Explained With a Worked Example

The COBIT design factors are the eleven inputs COBIT 2019 uses to turn a generic framework of 40 governance and management objectives into a governance system for one specific enterprise, and they are the part of the framework that answers the objection every previous COBIT version attracted: that nobody can implement all of it. Nobody is meant to.

The Design Guide — one of the four core COBIT 2019 publications — works the eleven factors through a four-stage design workflow whose output is a prioritised set of objectives, each with a target capability level and, where a factor demands it, a focus-area variant. This guide lists the eleven COBIT design factors with the values each can take and the objectives each tends to raise or lower, walks the four design stages, gives a worked example for a mid-sized regulated company, and lists the ways a design workshop produces a governance system nobody can afford.

The 11 COBIT design factors and the four-stage design workflow
1 Enterprise strategy · 2 Enterprise goals · 3 Risk profile · 4 I&T-related issues · 5 Threat landscape · 6 Compliance requirements · 7 Role of IT · 8 Sourcing model · 9 IT implementation methods · 10 Technology adoption strategy · 11 Enterprise size → scope, refine, conclude the governance system design.

The eleven COBIT design factors

# Design factor Values it can take What it tends to prioritise
1 Enterprise strategy Growth/acquisition; innovation/differentiation; cost leadership; client service/stability — one primary, one secondary Innovation raises APO04 (innovation) and BAI objectives; cost leadership raises APO06 (budget and costs) and DSS efficiency; client service raises APO09, DSS02
2 Enterprise goals The 13 COBIT enterprise goals, rated by importance, cascading to 13 alignment goals Each enterprise goal maps to alignment goals, which map to objectives — the goals cascade is the mechanism
3 Risk profile 19 I&T risk categories rated for impact and likelihood — from IT investment decision-making through data and information management to industrial control High-rated categories raise the objectives that mitigate them: security risk raises APO13 and DSS05; project risk raises BAI01 and BAI11
4 I&T-related issues 20 listed issues rated for seriousness — frustration between IT and business, failed initiatives, hidden or rogue IT spend, insufficient resources, regulatory non-compliance Each issue points at the objectives whose absence causes it
5 Threat landscape Normal or high High raises APO12, APO13, DSS05, DSS04 and their target capability
6 Compliance requirements Low, normal or high High raises MEA03 (compliance with external requirements), MEA04 (assurance) and APO12
7 Role of IT Support, factory, turnaround or strategic (the Nolan–McFarlan grid) Strategic and turnaround raise EDM and APO strategy objectives; factory raises DSS reliability; support lowers targets across the board
8 Sourcing model for IT Outsourcing, cloud, insourced, or hybrid Outsourcing and cloud raise APO10 (vendors) and the supplier aspects of security and continuity
9 IT implementation methods Agile, DevOps, traditional, or hybrid Agile and DevOps invoke the focus-area variants of BAI objectives; the DevOps focus area publication exists for this
10 Technology adoption strategy First mover, follower, or slow adopter First mover raises APO04 and risk; slow adopter raises stability objectives
11 Enterprise size Large (over 250 FTE) or small and medium (50–250 FTE) Small and medium invokes the SME focus area and reduces the expected formality of components

The factors are not weighted equally by the framework; they are weighted by the enterprise. The Design Guide’s toolkit assigns each factor’s values to objectives through published mapping tables, and the sum across factors produces a relative importance score per objective — which the design team then reviews rather than accepts. Our guide to COBIT 2019 covers the objectives the factors act on; the COBIT domains lists all 40.

The four stages: applying the COBIT design factors

Stage Design factors used Output
1. Understand the enterprise context and strategy 1 Enterprise strategy; 2 Enterprise goals; 3 Risk profile; 4 I&T-related issues An initial view of which objectives the strategy, goals, risks and pain points point to
2. Determine the initial scope of the governance system Stages 1’s factors applied through the goals cascade and the risk and issues mappings An initial prioritised list of objectives with relative importance scores
3. Refine the scope 5 Threat landscape; 6 Compliance requirements; 7 Role of IT; 8 Sourcing model; 9 Implementation methods; 10 Technology adoption; 11 Enterprise size The list adjusted; focus-area variants selected (DevOps, SME, security, risk); target capability levels proposed
4. Conclude the governance system design All, resolved by judgement The tailored governance system: the objectives in scope, target capability per objective, the focus areas, and the specific component variants — documented with the reasoning

Stage 4 is where the design becomes a document: the argument for why this enterprise prioritises these objectives at these levels. That argument is what the board approves, what the implementation programme scopes from, and what an auditor or regulator reads to understand why, say, BAI03 is at level 2 and APO12 at level 4. Our guide to COBIT capability levels covers the scale the targets are set on.

A worked example of the COBIT design factors

A 400-person financial services firm, regulated, with a client-service strategy, a hybrid sourcing model heavy on SaaS, agile delivery, a follower adoption stance and a high compliance requirement.

Factor Value Effect on the design
Enterprise strategy Client service/stability (primary), growth (secondary) APO09 service agreements, DSS02, DSS04 rise; APO04 innovation modest
Enterprise goals Customer-oriented service culture; compliance with external laws; business service continuity rated highest Cascade raises DSS01–DSS05, MEA03, APO12
Risk profile Data and information management, third-party/supplier, regulatory compliance rated high APO10, APO12, APO13, DSS05, DSS06 rise
I&T-related issues Hidden SaaS spend; audit findings on access control APO06 budget and cost, DSS05, DSS06 rise
Threat landscape High APO13, DSS05 target capability raised to 4
Compliance requirements High MEA03, MEA04 in scope at level 3–4
Role of IT Factory Reliability objectives prioritised; EDM at level 3
Sourcing model Hybrid, cloud-heavy APO10 managed vendors at level 4; cloud aspects of DSS05 and DSS04 emphasised
Implementation methods Agile BAI02, BAI03, BAI06 use the agile focus-area variants
Technology adoption Follower APO04 at level 2
Enterprise size Large Full component set expected
Result 14 objectives in scope at level 3 or 4; the remaining 26 at level 1–2 or out of scope A governance system a 400-person firm can run

Where COBIT design factor workshops go wrong

  • Everything is critical. Every enterprise goal rated 5, every risk high, every issue serious — the mapping then prioritises all 40 objectives and the design has designed nothing.
  • The strategy is invented in the room. Factor 1 must come from the enterprise’s actual strategy documents; a design team choosing “innovation” because it sounds better than “cost leadership” produces a governance system for a different company.
  • Risk profile copied from a generic register. The 19 categories are rated for this enterprise’s impact and likelihood, with the risk function in the room.
  • Target capability set at 5 by default. Level 5 is optimising and continuously improving; most objectives in most enterprises are appropriately targeted at 2 or 3, and the design factors say which deserve more.
  • Focus areas ignored. Agile, DevOps, SME and cloud variants exist so that the generic objectives fit the enterprise; applying the generic components to a DevOps shop produces controls the shop will route around.
  • No reasoning recorded. The output is not the list; it is the argument. Our guide to COBIT 2019 implementation covers what happens to the design next.

Frequently asked questions

What are the COBIT design factors?
Eleven inputs in COBIT 2019’s Design Guide — enterprise strategy, enterprise goals, risk profile, I&T-related issues, threat landscape, compliance requirements, role of IT, sourcing model, IT implementation methods, technology adoption strategy and enterprise size — that determine which of the 40 objectives an enterprise prioritises, at what capability, and with which focus-area variants.

Do you have to use all eleven?
The Design Guide’s workflow uses all of them across its four stages, but their influence differs: the first four set the initial scope through the goals cascade and the risk and issues mappings; the remaining seven refine it. Skipping a factor leaves an objective’s priority unjustified.

What is the goals cascade?
The mechanism behind design factor 2: enterprise goals map to alignment goals, which map to governance and management objectives, so a rated enterprise goal raises the priority of the objectives that support it.

What does the design produce?
A tailored governance system: the objectives in scope, a target capability level for each, the focus areas applied, and the documented reasoning. It is the input to the seven-phase implementation lifecycle.

Do the design factors change in COBIT 7?
ISACA has announced COBIT 7 certificates replacing the 2019 certificates from 27 October 2026, with the 2019 certificates sunset on 26 April 2027, but has not yet published the framework’s content. Until it does, the eleven factors and the four-stage workflow are the current design method.

Where this leaves you

Use the COBIT design factors as the framework intends: take the strategy, goals, risks and issues from the enterprise rather than the workshop, let the mappings produce the initial scope, refine it with the seven contextual factors and the focus areas, set capability targets that vary, and write the reasoning down. A governance system with fourteen justified objectives will be run; one with forty asserted ones will be shelved.

References

More on COBIT

The design factor workbook with the eleven factors and their mapping to objectives, the governance system design document template, the goals cascade worksheet and the target capability register are in the COBIT 2019 IT Governance Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.