Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

COBIT 2019 governance system principles guide cover

COBIT 2019 Governance System Principles Explained 2026

COBIT 2019 governance system principles set out the ideas that shape how an enterprise designs its governance of information and technology. ISACA groups its principles into two categories, principles for the governance system and principles for the governance framework, and the six governance system principles tell you what a good system should look like. Understanding them helps you decide how far to adapt COBIT to your own organization, instead of copying its process list into a policy binder.

This guide names the six principles, explains what changed from COBIT 5 and shows how to apply each one. It builds on our overview of COBIT 2019 and our guides to IT governance frameworks and COBIT 2019 implementation.

Free gap assessment

How much of your service management system could you evidence?

Score every clause of ISO/IEC 20000-1, free, including the service management plan, service reporting and knowledge requirements generic checklists miss.

Run the free ISO 20000 gap assessment →  or  View premium report sample

The six COBIT 2019 governance system principles

Training providers who summarise ISACA’s material list the six principles as follows.

#PrincipleWhat it means in practice
1Provide stakeholder valueGovernance exists to create value for stakeholders, balancing benefits, risk and resources
2Holistic approachConsider all the components that work together, not one control or process alone
3Dynamic governance systemThe system changes as design factors change, and it needs regular review
4Governance distinct from managementKeep the two separate: governance sets direction and oversight, management plans and runs
5Tailored to enterprise needsCustomise the system using design factors rather than adopting a generic model
6End-to-end governance systemCover the whole enterprise, not only the IT function

Read the explanation of each principle in ISACA’s own publications before you cite it in a policy. The descriptions here are summaries.

What changed from COBIT 5

ISACA’s comparison of the two versions notes that COBIT 2019 has six governance system principles compared with five in COBIT 5, with revised terminology. It also adds governance framework principles covering a conceptual model, openness and flexibility, and alignment with major standards and regulations, which COBIT 5 did not have. Other changes include 40 governance and management objectives instead of 37 processes, a performance management scheme based on CMMI with capability levels 0 to 5, and 11 design factors. Enablers were renamed components.

The split of objectives between governance and management follows the fourth principle. Five objectives sit in the evaluate, direct and monitor domain, and 35 management objectives sit in the four management domains, according to one summary. Our guide to the COBIT domains explains the structure.

Principle 1: provide stakeholder value

Every governance decision should trace to value for stakeholders. That means asking what benefits the enterprise seeks from technology, what risks it will accept and what resources it will commit. A practical step is to link each IT initiative to a stakeholder need in your portfolio review, and to record the expected benefit. Use the goals cascade to show how enterprise goals translate into governance and management objectives.

Principle 2: holistic approach

A holistic approach reflects that governance depends on several parts working together: processes, structures, policies, information, culture, skills and services. Fixing one component in isolation rarely works. If you roll out a new incident process but leave roles, tooling and training unchanged, the process will not stick. When you plan a change, list which components it touches and who owns each.

Principle 3: dynamic governance system

The system is not fixed. When a design factor changes, such as strategy, risk profile, regulatory environment or technology adoption, you should reconsider the design. Build a review cycle, for example annually, and add triggers for events such as a merger, a major incident or entry into a regulated market. Record the outcome, even if you decide no change is needed.

Principle 4: governance distinct from management

Governance is about evaluating, directing and monitoring. Management is about planning, building, running and monitoring activities. Keep them distinct in role descriptions, committee charters and reporting lines. The board or a governance committee sets direction and reviews performance, and management executes. When the same group does both without distinction, oversight weakens because nobody is challenging plans independently.

Principle 5: tailored to enterprise needs

Tailoring is where COBIT 2019 differs most in practice. Instead of implementing every objective, use the design factors to decide which objectives and components matter most for your enterprise. Our guide to COBIT design factors walks through the factors and how to score them. A small company with modest risk needs a lighter system than a global bank, and the principle supports that.

Principle 6: end-to-end governance system

An end-to-end system covers all technology and information processing the enterprise uses to achieve its goals, wherever it sits. That includes shadow IT, outsourced services, cloud platforms and operational technology. Include business units in the scope of governance, and make business leaders accountable for technology decisions in their area.

Turning the COBIT 2019 governance system principles into a checklist

  1. List your stakeholders and the value each expects from technology.
  2. Map components (processes, roles, policies, information, skills, services) to each priority objective.
  3. Set a review cycle and trigger events for the governance design.
  4. Separate governance and management roles in charters and job descriptions.
  5. Score your design factors and choose a tailored set of objectives.
  6. Extend scope to all technology, including outsourced and shadow IT.
  7. Report to the board on stakeholder value, risk and resource use.

Applying COBIT 2019 governance system principles in a board setting

Boards rarely read framework documents, so translate the principles into questions they can ask. Does each major technology investment show the value stakeholders expect? Are all the components needed to deliver it in place, including people and information? When did we last review the design of our governance system, and what triggered the review? Who is accountable for governance, and who for management? Is our scope the whole enterprise? Asking these questions each quarter turns COBIT 2019 governance system principles into practical oversight. Record the answers in board papers so that the trail of decisions is visible to auditors and regulators.

Support the board with a short dashboard: value delivered against plan, top technology risks, capability levels for priority objectives and open audit actions. Keep it to one page, and explain movements from the previous period, so that directors can focus on decisions instead of decoding metrics.

Linking principles to performance management

COBIT 2019 adopted a performance management scheme based on CMMI, with capability levels from 0 to 5 for processes and a maturity concept for focus areas, according to ISACA’s comparison. Use these levels to set targets for the objectives you have selected, and to check that improvement is happening. Our guide to COBIT capability levels explains how to assess them. Targets should follow from the tailoring principle: not every objective needs the highest level, and chasing level 5 everywhere wastes resources.

Sequencing your first year

  1. Quarter 1. Confirm sponsors, list stakeholders and score design factors.
  2. Quarter 2. Select priority objectives, assess current capability and set targets.
  3. Quarter 3. Address the largest gaps and separate governance and management responsibilities in charters.
  4. Quarter 4. Review results with the board, refresh the design and plan the next cycle.

Treat the first year as a pilot. You will learn which objectives matter, which metrics are useful and where ownership is unclear.

A hypothetical example

A hypothetical regional insurer wants to strengthen IT governance. It starts by listing stakeholders: policyholders, regulators, the board and staff. It scores design factors, finds that regulatory pressure and data sensitivity are high and that technology adoption is moderate, and selects a focused set of objectives. It creates a technology committee to give governance oversight, separate from the management-level architecture board. Six months after a cloud migration, the committee revisits the design because the risk profile changed. The example is invented for illustration.

Finally, remember that principles guide judgement. They do not replace it. When a design choice is unclear, return to the six principles and ask which option best serves stakeholder value, fits the enterprise and keeps governance separate from management.

Common mistakes with COBIT 2019 governance system principles

  • Treating COBIT as a checklist of 40 objectives to implement in full.
  • Blurring governance and management in committee charters.
  • Ignoring shadow IT and outsourced services.
  • Designing the system once and never reviewing it.
  • Focusing on processes while neglecting culture, skills and information.

ISACA’s article on COBIT 2019 and COBIT 5 gives a short comparison. For a comparison with service management, see our guide to COBIT versus ITIL.

Templates for COBIT 2019 governance system principles

If you want ready-made documents for governance charters, design factor scoring and objective selection, the COBIT 2019 Toolkit provides materials you can adapt. Review them against ISACA’s current publications.

COBIT 2019 governance system principles FAQ

How many governance system principles are there?

Six, according to summaries of ISACA’s material, compared with five principles in COBIT 5.

Are the governance framework principles different?

Yes. They concern how the framework itself is built, including a conceptual model, openness and flexibility, and alignment with major standards.

Do we have to implement all 40 objectives?

No. The tailoring principle and design factors help you choose the objectives that matter most.

Why keep governance and management separate?

Separation provides independent oversight. Governance sets direction and evaluates results, while management delivers.

How often should we review the design?

The dynamic principle calls for review as design factors change. Many organizations do so annually and after major events.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.