The COBIT goals cascade is the mechanism in COBIT 2019 that translates what stakeholders want from the enterprise into a short list of governance and management objectives that deserve your attention first. Instead of asking a team to implement every process in the framework, the cascade gives a traceable path from business strategy, through enterprise goals and alignment goals, down to the objectives that support them.
This guide explains each step of the cascade, shows how to run it in a workshop, gives a worked example, and covers the mistakes that make the result unconvincing. It assumes you know the basics of the framework, and if you do not, our overview of COBIT 2019 is the place to begin.
Free gap assessment
How much of your service management system could you evidence?
Score every clause of ISO/IEC 20000-1, free, including the service management plan, service reporting and knowledge requirements generic checklists miss.
Run the free ISO 20000 gap assessment → or View premium report sample
What the COBIT goals cascade is
ISACA describes the cascade as a prioritization mechanism: it supports the translation of enterprise goals into priorities for alignment goals, which in turn point to the governance and management objectives. COBIT 2019 contains 13 enterprise goals, 13 alignment goals and 40 governance and management objectives, organized across five domains. In ISACA’s own summary, the 2019 edition simplified and consolidated the goals used in COBIT 5. You can read ISACA’s overview of the goals cascade in this ISACA article on COBIT 2019 and enterprise governance strategy.
| Level | Question it answers | Count in COBIT 2019 |
|---|---|---|
| Stakeholder drivers and needs | What does the business want and why? | Not fixed, set by context |
| Enterprise goals | What must the enterprise achieve? | 13 |
| Alignment goals | What must IT achieve to support those goals? | 13 |
| Governance and management objectives | Which processes and practices deliver that? | 40 |
The four steps of the COBIT goals cascade
Step 1: Start with stakeholder needs
Every cascade begins with the enterprise context: strategy, regulation, market pressure, risk appetite, technology change. Stakeholders may want growth, cost control, resilience, compliance or better customer experience, and often several at once. Capture these needs in plain language first, before you touch any framework vocabulary.
Step 2: Select enterprise goals
Choose the enterprise goals that reflect those needs. The framework provides a standard set of 13, so you pick from the list rather than invent new ones. Rank them by importance to your organization and be strict: if everything is a top priority, the cascade produces nothing useful.
Step 3: Map to alignment goals
Alignment goals describe what information and technology must achieve to support the enterprise goals. COBIT provides mapping tables that show how strongly each enterprise goal relates to each alignment goal, usually as primary or secondary. Use the tables in the published COBIT 2019 documentation and record the mapping you used in your workshop notes.
Step 4 of the COBIT goals cascade: Select governance and management objectives
The alignment goals in turn map to the 40 governance and management objectives. The objectives are divided across five domains: Evaluate, Direct and Monitor (EDM) for governance, and Align, Plan and Organize (APO), Build, Acquire and Implement (BAI), Deliver, Service and Support (DSS) and Monitor, Evaluate and Assess (MEA) for management. Our overview of the COBIT domains describes what each one contains. The output of this step is a ranked list of objectives to implement or improve first.
A worked example
The example below is hypothetical and simplified, to show how the reasoning flows. It does not reproduce the official mapping tables, which you should take from the COBIT publications.
A regional insurer is under pressure from its regulator and has suffered two outages in a year. Its stakeholders want reliable service, compliance and controlled risk. In the workshop the team selects three enterprise goals, one about managed business risk, one about compliance with external requirements and one about service continuity or customer experience. Working through the mapping tables, they find that these goals relate most strongly to alignment goals about managed IT-related risk, security and compliance, and reliable service delivery. Those alignment goals point toward objectives in risk management, security management, incident and continuity management and monitoring of compliance. The team ends with a shortlist of eight objectives, ranks them, and moves on to assess their current capability.
The value lies in the traceability. When the board asks why the IT plan focuses on risk and continuity instead of a new digital channel, the answer is a documented chain from stakeholder needs to objectives, not a preference.
Running the COBIT goals cascade as a workshop
- Prepare. Collect the strategy, risk register, recent audit findings and incident history.
- Invite the right people. Include business leaders, risk, security, IT operations and internal audit, not just IT managers.
- Agree stakeholder needs. Write them on a wall and combine duplicates.
- Score enterprise goals. Vote or rate, then challenge the top and bottom of the list.
- Map and shortlist. Use the official mapping tables to reach alignment goals and objectives.
- Record and sign off. Capture the reasoning, and have an executive sponsor approve the shortlist.
Two to four hours is usually enough for the first pass if the preparation was done. The output should be a one-page summary, with the full working kept as an appendix.
How the COBIT goals cascade connects to the design factors
The cascade is one input to tailoring a governance system, not the whole design. COBIT 2019 also describes design factors, such as enterprise strategy, risk profile, compliance requirements and technology adoption strategy, which adjust the priority of the objectives further. Use the cascade to get a first ranking, then refine it with the COBIT design factors. If the two approaches disagree, discuss why, because the disagreement often exposes a hidden assumption about strategy or risk.
Reporting the results to leadership
Executives rarely want the full mapping. Give them a single page that shows the stakeholder needs on the left, the chosen enterprise goals in the middle, and the priority objectives on the right, with a line of reasoning under each. Add the current and target capability for each priority objective, the owner, and the next milestone. A picture of that kind lets a board member see at a glance what the IT governance program is for, what it will not do, and what decisions the executive team is being asked to take.
Keeping the cascade alive
Treat the output as a living record. Assign one person to own it, schedule a review whenever the strategy is refreshed, and log any change to the shortlist with the reason. When an audit or a regulator asks how you decided your governance priorities, the record shows a deliberate, repeatable method and not an accumulation of habits. It also makes new team members productive faster, since they can read why the program looks the way it does.
Common mistakes with the COBIT goals cascade
- Choosing goals to fit a plan. Selecting enterprise goals to justify a project already decided defeats the point.
- Too many priorities. A shortlist of 25 objectives is a list of the framework, not a priority list.
- IT-only workshops. Enterprise goals belong to the business, so IT staff cannot select them alone.
- No record of reasoning. Without notes, the result cannot be reviewed or refreshed later.
- One-off exercise. Strategy and risk change, so repeat the cascade annually or after a major change.
From the shortlist to an implementation plan
Once you have the priority objectives, assess how well each is performed today using the capability levels described in COBIT capability levels, set target levels, and plan the work to close the gaps. Sequence quick wins first to show progress, and give every objective an owner. Our guide to COBIT 2019 implementation covers the wider program, including change and communication. Keep the cascade record in the program file, because it justifies the scope every time someone asks why a process was included or left out.
Documenting your COBIT governance system
After the cascade, you need governance documents that turn objectives into working policies, roles and reviews. The COBIT 2019 IT Governance Toolkit provides a set of templates you can adapt for that purpose. Whether you use it or your own format, keep the link between each document and the objective it supports, so that the chain from stakeholder need to evidence stays visible.
COBIT goals cascade FAQ
How many enterprise goals does COBIT 2019 have?
COBIT 2019 has 13 enterprise goals and 13 alignment goals, which lead to 40 governance and management objectives.
Is the goals cascade mandatory?
COBIT is a framework and not a certifiable standard, so nothing forces you to use it. The cascade is the recommended way to prioritize the objectives, and it helps to justify scope to executives and auditors.
How often should we repeat it?
Repeat it when strategy, risk profile or regulation changes materially, and review it at least once a year as part of governance planning.
Where do I find the mapping tables?
They are in the official COBIT 2019 publications from ISACA. Use the published tables rather than copies from third parties, and check that they match the edition you are using.
Who should lead the cascade workshop?
An executive sponsor should own the outcome, and a facilitator with COBIT experience should run the session, ideally from governance, risk or enterprise architecture and not from a single IT team.