The Plain English Version

COBIT is ISACA's framework for governing and managing enterprise IT. Where ISO 27001 asks "is information secure" and ITIL asks "are IT services run well", COBIT asks the board-level question: "does IT actually deliver value, at acceptable risk, and how would we know?"

Its defining idea is separating governance from management. Governance evaluates, directs, and monitors; management plans, builds, runs, and monitors. Boards govern, executives manage, and COBIT gives each a defined set of objectives.

Who Uses COBIT?

Internal audit, IT governance and risk teams, CIOs answering to boards, and regulated enterprises that need a defensible bridge between business goals and IT controls. Auditors in financial services lean on it heavily, and it is a common lens for SOX IT controls.

How COBIT Is Structured

  • Governance objectives - Evaluate, Direct and Monitor: ensuring stakeholder value, risk optimisation, and resource optimisation
  • Management objectives - Four domains covering planning, building, running, and monitoring IT
  • Components - Each objective is achieved through processes, structures, information flows, people and skills, culture, and services
  • Design factors - The framework is tailored to your size, risk profile, and role of IT rather than applied wholesale

Why This Matters for SMEs

Few SMEs adopt COBIT end to end, and few should. Its value at smaller scale is the vocabulary: when an enterprise client's audit team asks how IT risk reaches your leadership, a COBIT-shaped answer, clear accountability, defined objectives, measured performance, is what they are listening for.

Getting Prepared

Start from business goals, not IT processes: which few IT objectives genuinely matter to what your organisation is trying to achieve? Assign each an accountable owner, define what good looks like, and measure it. COBIT rewards selective, tailored adoption far more than checkbox coverage of every objective.