The COBIT domains are the five groups into which COBIT 2019 sorts its 40 governance and management objectives, and the first letter of every objective identifier tells you which one it belongs to: EDM for Evaluate, Direct and Monitor; APO for Align, Plan and Organise; BAI for Build, Acquire and Implement; DSS for Deliver, Service and Support; MEA for Monitor, Evaluate and Assess. The split is not decorative. EDM is the governance domain — the five objectives that belong to the governing body — and the other four are management domains that follow the plan-build-run-monitor cycle every management model uses.
Reading an objective’s domain therefore tells you who owns it and where it sits in the cycle before you read what it says. This guide sets out the five COBIT domains and all 40 objectives by identifier and name, explains what distinguishes governance from management in the framework, shows how the domains relate to each other and to the design factors, and describes how to use the domain structure to scope a governance system that a real organisation can run.

The five COBIT domains at a glance
| Domain | Type | Objectives | Question it answers | Owner |
|---|---|---|---|---|
| EDM — Evaluate, Direct and Monitor | Governance | 5 | Is I&T delivering value at acceptable risk with optimised resources, and is that being directed and monitored? | The governing body (board or equivalent) |
| APO — Align, Plan and Organise | Management | 14 | Are strategy, architecture, portfolio, budget, people, suppliers, risk and security organised to deliver the direction? | Executive management, CIO |
| BAI — Build, Acquire and Implement | Management | 11 | Are solutions defined, built or acquired, changed and transitioned in a controlled way? | Delivery and change functions |
| DSS — Deliver, Service and Support | Management | 6 | Are services operated, supported, secured and kept continuous? | Operations |
| MEA — Monitor, Evaluate and Assess | Management | 4 | Is performance monitored, is internal control effective, are external requirements met, and is assurance provided? | Performance, compliance and assurance functions |
EDM: the governance domain among the COBIT domains
| Objective | Name | What the governing body does |
|---|---|---|
| EDM01 | Ensured Governance Framework Setting and Maintenance | Sets up the governance system itself: structures, principles, processes, and their maintenance |
| EDM02 | Ensured Benefits Delivery | Ensures I&T investments deliver value against strategy |
| EDM03 | Ensured Risk Optimisation | Sets risk appetite and ensures I&T risk is managed within it |
| EDM04 | Ensured Resource Optimisation | Ensures adequate and appropriate I&T capabilities — people, process, technology — at optimal cost |
| EDM05 | Ensured Stakeholder Engagement | Ensures stakeholders are identified, engaged and reported to transparently |
Every EDM objective’s practices follow the same three verbs — evaluate, direct, monitor — because that is what governance is in COBIT’s model: the governing body evaluates options and conditions, directs management, and monitors whether the direction was followed. Management does not perform EDM; it reports into it. Our guide to COBIT 2019 covers the governance–management distinction in full.
APO: Align, Plan and Organise
| Objective | Name |
|---|---|
| APO01 | Managed I&T Management Framework |
| APO02 | Managed Strategy |
| APO03 | Managed Enterprise Architecture |
| APO04 | Managed Innovation |
| APO05 | Managed Portfolio |
| APO06 | Managed Budget and Costs |
| APO07 | Managed Human Resources |
| APO08 | Managed Relationships |
| APO09 | Managed Service Agreements |
| APO10 | Managed Vendors |
| APO11 | Managed Quality |
| APO12 | Managed Risk |
| APO13 | Managed Security |
| APO14 | Managed Data |
APO is the largest domain because it holds the management-level counterparts of the governance concerns — strategy, portfolio, budget, risk, security — plus the organising functions. APO14 Managed Data was new in COBIT 2019. APO12 and APO13 are the management objectives most often set at the highest capability targets in regulated enterprises, because EDM03 and the compliance design factor push them.
BAI: Build, Acquire and Implement
| Objective | Name |
|---|---|
| BAI01 | Managed Programs |
| BAI02 | Managed Requirements Definition |
| BAI03 | Managed Solutions Identification and Build |
| BAI04 | Managed Availability and Capacity |
| BAI05 | Managed Organizational Change |
| BAI06 | Managed IT Changes |
| BAI07 | Managed IT Change Acceptance and Transitioning |
| BAI08 | Managed Knowledge |
| BAI09 | Managed Assets |
| BAI10 | Managed Configuration |
| BAI11 | Managed Projects |
COBIT 2019 split programmes (BAI01) from projects (BAI11), which COBIT 5 had held in one objective. BAI is where the agile and DevOps focus-area variants land, and where the ITIL practices for change, release, deployment and configuration deliver the objectives. Our guide to COBIT vs ITIL covers the mapping.
DSS: Deliver, Service and Support
| Objective | Name |
|---|---|
| DSS01 | Managed Operations |
| DSS02 | Managed Service Requests and Incidents |
| DSS03 | Managed Problems |
| DSS04 | Managed Continuity |
| DSS05 | Managed Security Services |
| DSS06 | Managed Business Process Controls |
DSS is the smallest management domain and the one operations teams recognise: incidents, problems, continuity, security operations and the controls embedded in business processes. DSS06 is the objective SOX and internal-control programmes map to.
MEA: Monitor, Evaluate and Assess
| Objective | Name |
|---|---|
| MEA01 | Managed Performance and Conformance Monitoring |
| MEA02 | Managed System of Internal Control |
| MEA03 | Managed Compliance with External Requirements |
| MEA04 | Managed Assurance |
MEA closes the management loop and feeds EDM’s monitoring: performance and conformance data (MEA01), the effectiveness of internal control (MEA02), compliance with laws, regulations and contracts (MEA03) and independent assurance (MEA04). Audit and compliance functions live here.
Using the COBIT domains to scope a governance system
- Take EDM as given. Every governance system needs the five EDM objectives at some level; a design that omits them has no governance layer. The capability target can be modest.
- Let the design factors pick from APO, BAI, DSS and MEA. The eleven factors — strategy, goals, risk, issues, threat landscape, compliance, role of IT, sourcing, methods, adoption, size — raise and lower objectives across the four management domains; a typical first scope is ten to fifteen management objectives. Our guide to COBIT design factors covers the method.
- Check each domain has an owner. APO to the CIO and executive team, BAI to delivery, DSS to operations, MEA to performance, compliance and audit — a domain without an accountable executive is a domain that will not reach its target.
- Set targets per objective, not per domain. Capability is measured per process; a domain-level target hides the variation the design factors produce. Our guide to COBIT capability levels covers the scale.
- Map existing frameworks into the domains. ITIL into BAI and DSS, ISO 27001 into APO13 and DSS05, ISO 31000 into APO12, SOX into DSS06 and MEA02 — components, not duplicates.
- Read ISACA’s transition notices. COBIT 7 certificates replace the 2019 certificates from 27 October 2026; whether the domain structure changes is for ISACA to publish, and the 40-objective model above is current until it does.
Frequently asked questions
What are the five COBIT domains?
EDM (Evaluate, Direct and Monitor) — the governance domain with 5 objectives; and four management domains: APO (Align, Plan and Organise, 14), BAI (Build, Acquire and Implement, 11), DSS (Deliver, Service and Support, 6) and MEA (Monitor, Evaluate and Assess, 4). Together they hold COBIT 2019’s 40 governance and management objectives.
What is the difference between EDM and the other domains?
EDM belongs to the governing body and its practices are to evaluate, direct and monitor; the other four belong to management and follow the plan, build, run and monitor cycle. Governance sets direction and checks it was followed; management executes within it.
Do you implement all five domains?
All five EDM objectives at some level, yes; from the management domains, the objectives the design factors prioritise — typically ten to fifteen in a first cycle. Implementing all 40 is neither expected nor advisable.
Which domain does ITIL map to?
Mainly BAI and DSS — change, release, configuration, incidents, problems, continuity, service agreements (APO09). Governance in EDM and the assurance objectives in MEA have no ITIL counterpart.
What changed in the domains between COBIT 5 and COBIT 2019?
The five domains kept their names. COBIT 2019 added APO14 Managed Data, BAI11 Managed Projects (split from programmes in BAI01) and MEA04 Managed Assurance, taking the objective count from 37 to 40, and renamed ‘processes’ as governance and management objectives with seven components each.
Where this leaves you
Read the COBIT domains as ownership and sequence: EDM for the board, then align and plan, build and acquire, deliver and support, and monitor and assess for management — with the objective identifier telling you which. Keep all five EDM objectives, let the design factors choose from the other 35, give every domain an accountable owner, and set targets objective by objective.
References
- ISACA — COBIT 2019 Framework: Governance and Management Objectives — The 40 objectives by domain with purpose statements, practices and activities (ISACA publication page).
- ISACA — COBIT Foundation certificate — Exam domains include governance and management objectives; COBIT 7 transition notice.
More on COBIT
- The COBIT domains — you are here
- COBIT 2019: the complete guide
- COBIT design factors: all eleven
- COBIT capability levels: the 0–5 scale
- COBIT vs ITIL
- COBIT 2019 implementation: the seven phases
The document set for each of the five domains — objective definitions, process descriptions, RACI charts and metrics for EDM, APO, BAI, DSS and MEA — with the governance framework manual and the cross-mapping appendix are in the COBIT 2019 IT Governance Toolkit, or start with the free templates.