Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

COBIT domains explained

COBIT Domains: EDM, APO, BAI, DSS and MEA Explained (2026 Guide)

The COBIT domains are the five groups into which COBIT 2019 sorts its 40 governance and management objectives, and the first letter of every objective identifier tells you which one it belongs to: EDM for Evaluate, Direct and Monitor; APO for Align, Plan and Organise; BAI for Build, Acquire and Implement; DSS for Deliver, Service and Support; MEA for Monitor, Evaluate and Assess. The split is not decorative. EDM is the governance domain — the five objectives that belong to the governing body — and the other four are management domains that follow the plan-build-run-monitor cycle every management model uses.

Reading an objective’s domain therefore tells you who owns it and where it sits in the cycle before you read what it says. This guide sets out the five COBIT domains and all 40 objectives by identifier and name, explains what distinguishes governance from management in the framework, shows how the domains relate to each other and to the design factors, and describes how to use the domain structure to scope a governance system that a real organisation can run.

The five COBIT domains and 40 objectives
EDM (5) governance: evaluate, direct, monitor · APO (14) align, plan, organise · BAI (11) build, acquire, implement · DSS (6) deliver, service, support · MEA (4) monitor, evaluate, assess.

The five COBIT domains at a glance

Domain Type Objectives Question it answers Owner
EDM — Evaluate, Direct and Monitor Governance 5 Is I&T delivering value at acceptable risk with optimised resources, and is that being directed and monitored? The governing body (board or equivalent)
APO — Align, Plan and Organise Management 14 Are strategy, architecture, portfolio, budget, people, suppliers, risk and security organised to deliver the direction? Executive management, CIO
BAI — Build, Acquire and Implement Management 11 Are solutions defined, built or acquired, changed and transitioned in a controlled way? Delivery and change functions
DSS — Deliver, Service and Support Management 6 Are services operated, supported, secured and kept continuous? Operations
MEA — Monitor, Evaluate and Assess Management 4 Is performance monitored, is internal control effective, are external requirements met, and is assurance provided? Performance, compliance and assurance functions

EDM: the governance domain among the COBIT domains

Objective Name What the governing body does
EDM01 Ensured Governance Framework Setting and Maintenance Sets up the governance system itself: structures, principles, processes, and their maintenance
EDM02 Ensured Benefits Delivery Ensures I&T investments deliver value against strategy
EDM03 Ensured Risk Optimisation Sets risk appetite and ensures I&T risk is managed within it
EDM04 Ensured Resource Optimisation Ensures adequate and appropriate I&T capabilities — people, process, technology — at optimal cost
EDM05 Ensured Stakeholder Engagement Ensures stakeholders are identified, engaged and reported to transparently

Every EDM objective’s practices follow the same three verbs — evaluate, direct, monitor — because that is what governance is in COBIT’s model: the governing body evaluates options and conditions, directs management, and monitors whether the direction was followed. Management does not perform EDM; it reports into it. Our guide to COBIT 2019 covers the governance–management distinction in full.

APO: Align, Plan and Organise

Objective Name
APO01 Managed I&T Management Framework
APO02 Managed Strategy
APO03 Managed Enterprise Architecture
APO04 Managed Innovation
APO05 Managed Portfolio
APO06 Managed Budget and Costs
APO07 Managed Human Resources
APO08 Managed Relationships
APO09 Managed Service Agreements
APO10 Managed Vendors
APO11 Managed Quality
APO12 Managed Risk
APO13 Managed Security
APO14 Managed Data

APO is the largest domain because it holds the management-level counterparts of the governance concerns — strategy, portfolio, budget, risk, security — plus the organising functions. APO14 Managed Data was new in COBIT 2019. APO12 and APO13 are the management objectives most often set at the highest capability targets in regulated enterprises, because EDM03 and the compliance design factor push them.

BAI: Build, Acquire and Implement

Objective Name
BAI01 Managed Programs
BAI02 Managed Requirements Definition
BAI03 Managed Solutions Identification and Build
BAI04 Managed Availability and Capacity
BAI05 Managed Organizational Change
BAI06 Managed IT Changes
BAI07 Managed IT Change Acceptance and Transitioning
BAI08 Managed Knowledge
BAI09 Managed Assets
BAI10 Managed Configuration
BAI11 Managed Projects

COBIT 2019 split programmes (BAI01) from projects (BAI11), which COBIT 5 had held in one objective. BAI is where the agile and DevOps focus-area variants land, and where the ITIL practices for change, release, deployment and configuration deliver the objectives. Our guide to COBIT vs ITIL covers the mapping.

DSS: Deliver, Service and Support

Objective Name
DSS01 Managed Operations
DSS02 Managed Service Requests and Incidents
DSS03 Managed Problems
DSS04 Managed Continuity
DSS05 Managed Security Services
DSS06 Managed Business Process Controls

DSS is the smallest management domain and the one operations teams recognise: incidents, problems, continuity, security operations and the controls embedded in business processes. DSS06 is the objective SOX and internal-control programmes map to.

MEA: Monitor, Evaluate and Assess

Objective Name
MEA01 Managed Performance and Conformance Monitoring
MEA02 Managed System of Internal Control
MEA03 Managed Compliance with External Requirements
MEA04 Managed Assurance

MEA closes the management loop and feeds EDM’s monitoring: performance and conformance data (MEA01), the effectiveness of internal control (MEA02), compliance with laws, regulations and contracts (MEA03) and independent assurance (MEA04). Audit and compliance functions live here.

Using the COBIT domains to scope a governance system

  1. Take EDM as given. Every governance system needs the five EDM objectives at some level; a design that omits them has no governance layer. The capability target can be modest.
  2. Let the design factors pick from APO, BAI, DSS and MEA. The eleven factors — strategy, goals, risk, issues, threat landscape, compliance, role of IT, sourcing, methods, adoption, size — raise and lower objectives across the four management domains; a typical first scope is ten to fifteen management objectives. Our guide to COBIT design factors covers the method.
  3. Check each domain has an owner. APO to the CIO and executive team, BAI to delivery, DSS to operations, MEA to performance, compliance and audit — a domain without an accountable executive is a domain that will not reach its target.
  4. Set targets per objective, not per domain. Capability is measured per process; a domain-level target hides the variation the design factors produce. Our guide to COBIT capability levels covers the scale.
  5. Map existing frameworks into the domains. ITIL into BAI and DSS, ISO 27001 into APO13 and DSS05, ISO 31000 into APO12, SOX into DSS06 and MEA02 — components, not duplicates.
  6. Read ISACA’s transition notices. COBIT 7 certificates replace the 2019 certificates from 27 October 2026; whether the domain structure changes is for ISACA to publish, and the 40-objective model above is current until it does.

Frequently asked questions

What are the five COBIT domains?
EDM (Evaluate, Direct and Monitor) — the governance domain with 5 objectives; and four management domains: APO (Align, Plan and Organise, 14), BAI (Build, Acquire and Implement, 11), DSS (Deliver, Service and Support, 6) and MEA (Monitor, Evaluate and Assess, 4). Together they hold COBIT 2019’s 40 governance and management objectives.

What is the difference between EDM and the other domains?
EDM belongs to the governing body and its practices are to evaluate, direct and monitor; the other four belong to management and follow the plan, build, run and monitor cycle. Governance sets direction and checks it was followed; management executes within it.

Do you implement all five domains?
All five EDM objectives at some level, yes; from the management domains, the objectives the design factors prioritise — typically ten to fifteen in a first cycle. Implementing all 40 is neither expected nor advisable.

Which domain does ITIL map to?
Mainly BAI and DSS — change, release, configuration, incidents, problems, continuity, service agreements (APO09). Governance in EDM and the assurance objectives in MEA have no ITIL counterpart.

What changed in the domains between COBIT 5 and COBIT 2019?
The five domains kept their names. COBIT 2019 added APO14 Managed Data, BAI11 Managed Projects (split from programmes in BAI01) and MEA04 Managed Assurance, taking the objective count from 37 to 40, and renamed ‘processes’ as governance and management objectives with seven components each.

Where this leaves you

Read the COBIT domains as ownership and sequence: EDM for the board, then align and plan, build and acquire, deliver and support, and monitor and assess for management — with the objective identifier telling you which. Keep all five EDM objectives, let the design factors choose from the other 35, give every domain an accountable owner, and set targets objective by objective.

References

More on COBIT

The document set for each of the five domains — objective definitions, process descriptions, RACI charts and metrics for EDM, APO, BAI, DSS and MEA — with the governance framework manual and the cross-mapping appendix are in the COBIT 2019 IT Governance Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.