• 4,000 firms
  • Independent
  • Trusted
Save up to 70% on staff

Home » Glossary » COBIT 5

COBIT 5

Definition

COBIT 5

COBIT 5 is the superseded edition of ISACA’s governance framework for enterprise information and technology. It has been replaced by COBIT 2019, so a requirement citing it today is usually quoting an old document rather than a current standard.

That matters practically. A tender demanding COBIT 5 alignment is often copying a policy written years ago, and the honest response is to ask whether the current edition would satisfy the requirement.

The framework’s purpose has not changed across editions. It separates governance, which sets direction and monitors it, from management, which plans and runs the work.

Its lasting contribution is that separation. Applied to outsourcing it produces a question buyers frequently skip — governance stays with you, and only management can be contracted out.

Key takeaways

  • The edition is superseded, and the current one is COBIT 2019.
  • Its core contribution is separating governance from management.
  • Governance cannot be outsourced, even where the management activity is.
  • Requirements still citing it usually reflect an outdated internal policy.

How it works

The framework organises enterprise technology into governance and management activities, each with objectives, and maps them to enablers such as processes, structures, people and information. Organisations select the parts that fit rather than adopting everything.

The publisher’s account of the succession is explicit. ISACA describes the current edition as an evolution of COBIT 5, containing everything you value about COBIT 5 while adding implementation resources and practical guidance.

Even the acronym’s expansion is unstable across sources. The United States National Institute of Standards and Technology glossary records it as Control Objectives for Information and Related Technologies.

That glossary cites several NIST publications for the expansion, while the publisher itself uses slightly different wording — a small inconsistency worth knowing before quoting either.

LayerWho owns itCan it be outsourced
GovernanceThe board and executiveNo — direction and accountability stay internal
Management planningInternal technology leadershipPartly, with retained decision rights
Management executionDelivery teamsYes, this is the usual outsourcing scope
MonitoringInternal assurance functionsEvidence can be produced externally, judgement cannot

The framework is deliberately non-certifying at the organisational level. There is no audited badge for an organisation — a real difference from the security and quality standards buyers often mention in the same sentence.

The unflattering reality is that legacy citations create busywork. Providers write responses mapping their controls to a superseded model, buyers read them, and nobody involved believes the exercise improves the service.

Examples

The edition survives mainly inside documents that have outlived their review cycle, which is where buyers meet it. The situations below occur regularly, whatever a capability document chooses to put first.

A buyer’s tender template requires alignment with the older edition. The provider answers against the current one and explains the mapping, which everyone accepts.

An internal audit function still runs its control catalogue against the older model, because migrating the catalogue was never funded.

A compliance outsourcing provider maintains mappings to both editions, since its client base has not moved at a uniform pace.

A buyer discovers its policy cites the old edition and updates the policy rather than the requirement, which is the cheaper fix.

Related terms

Governance, security and assurance frameworks are routinely conflated, and the entries below separate them. Below, each term is narrowed to a single sense and walled off from its neighbours.

  • ISO 27001: the information security management standard, which is independently audited.
  • SOC 2: an attestation report on service organisation controls, not a framework.
  • compliance outsourcing: contracting the compliance function, which uses frameworks like this one.
  • risk outsourcing: contracting risk management activity while retaining risk ownership.
  • IT transformation outsourcing: change programmes where governance models are usually revisited.
  • service level agreement (SLA): the contractual layer where governance decisions become obligations.
  • ESG: the wider reporting agenda that borrows governance language from frameworks like this.

FAQ

Is COBIT 5 still current?

No. ISACA describes the current edition, COBIT 2019, as an evolution of it, so the older edition should be treated as superseded.

Why does it still appear in tenders?

Because policy documents outlive their review cycles. A requirement citing it usually reflects a template that has not been refreshed.

Can an organisation be certified against it?

No. It is a governance framework rather than a certifiable management system, so there is no organisational audit or badge.

What does the acronym stand for?

Control Objectives for Information and Related Technologies, according to the NIST glossary. The publisher uses slightly different wording.

What is the governance and management split?

Governance sets direction and monitors outcomes; management plans and executes. The distinction determines what can be contracted out.

Should we update a policy that cites it?

Usually yes. Updating the policy is cheaper than maintaining mappings to a superseded model across every supplier response.

Search verified partners in the Outsource Accelerator directory and update the policy rather than the supplier requirement.

Companies you might be interested in

Get Inside Outsourcing

An insider's view on why remote and offshore staffing is radically changing the future of work.

Order now

Start your
journey today

  • Independent
  • Secure
  • Transparent

About OA

Outsource Accelerator is the trusted source of independent information, advisory and expert implementation of Business Process Outsourcing (BPO).

The #1 outsourcing authority

Outsource Accelerator offers the world’s leading aggregator marketplace for outsourcing. It specifically provides the conduit between world-leading outsourcing suppliers and the businesses – clients – across the globe.

The Outsource Accelerator website has over 5,000 articles, 450+ podcast episodes, and a comprehensive directory with 4,700+ BPO companies… all designed to make it easier for clients to learn about – and engage with – outsourcing.

About Derek Gallimore

Derek Gallimore has been in business for 20 years, outsourcing for over eight years, and has been living in Manila (the heart of global outsourcing) since 2014. Derek is the founder and CEO of Outsource Accelerator, and is regarded as a leading expert on all things outsourcing.

“Excellent service for outsourcing advice and expertise for my business.”

Learn more
Banner Image
Get 3 Free Quotes Verified Outsourcing Suppliers
4,000 firms.Just 2 minutes to complete.
SAVE UP TO
70% ON STAFF COSTS
Learn more

Connect with over 4,000 outsourcing services providers.

Banner Image

Transform your business with skilled offshore talent.

  • 4,000 firms
  • Simple
  • Transparent
Banner Image