COBIT 2019
Definition
COBIT 2019
COBIT 2019 is the current edition of ISACA’s governance framework for enterprise information and technology. It carries 40 governance and management objectives, and ISACA describes it as an evolution of the COBIT 5 edition that came just before it.
The naming convention changed with this edition — moving from a version number to a year signals a framework meant to be updated continuously rather than released in numbered generations.
Its most useful addition for outsourcing is the idea of design factors. Rather than adopting everything, an organisation tailors the framework to its own risk profile, regulatory exposure and sourcing model.
That tailoring matters because a heavily outsourced organisation needs a different governance design from one running everything in house — the objectives are the same, and the emphasis is not.
Key takeaways
- It is the current edition of ISACA’s technology governance framework.
- It defines 40 governance and management objectives.
- Design factors tailor the framework to an organisation’s own context, including sourcing.
- Focus areas provide targeted guidance for domains such as security and DevOps.
How it works
The framework sets out governance and management objectives, each with practices and metrics. Design factors then determine which objectives matter most for a given organisation, producing a tailored governance system rather than a uniform checklist.
The publisher describes the scope directly. ISACA’s guidance sets out 40 governance and management objectives and positions the edition as an evolution of its predecessor, adding implementation resources and practical guidance.
Targeted extensions sit alongside the core. ISACA publishes focus area guidance covering DevOps, information security, and information and technology risk, each applying the framework to a specific domain.
| Component | What it does | Why it matters when outsourcing |
|---|---|---|
| Governance objectives | Direction, oversight, accountability | Cannot be delegated to a provider |
| Management objectives | Planning, building, running, monitoring | The layer usually contracted out |
| Design factors | Tailor the framework to context | Sourcing model is one of the inputs |
| Focus areas | Domain-specific guidance | Useful for security and delivery scope |
| Metrics | Measures attached to each objective | Source material for contractual reporting |
The acronym is recorded differently across authorities. The United States National Institute of Standards and Technology glossary expands it as Control Objectives for Information and Related Technologies.
That entry cites several NIST publications, while the publisher phrases the expansion slightly differently — worth checking before you quote it in a policy document.
The candid limitation is that tailoring invites selective adoption. An organisation can design a governance system that quietly omits the objectives it finds inconvenient — and nothing in the framework prevents that.
Examples
The framework reaches outsourcing through how a buyer designs oversight rather than through anything a provider is certified against. What follows are engagements in progress, rather than engagements somebody might one day win.
A bank tailors its governance design around heavy outsourcing, weighting objectives on third-party risk and supplier performance far above internal build activity.
A buyer derives its contractual reporting pack from the framework’s metrics, so provider reporting maps to internal governance rather than to the provider’s own dashboard.
An organisation applies the information security focus area to define what it requires from a cybersecurity outsourcing partner, rather than writing requirements from scratch.
An internal audit team uses design factors to justify why certain objectives are out of scope, which is legitimate when documented and convenient when not.
Related terms
Governance frameworks, audited standards and attestations do different jobs, and the entries below keep them apart. Each entry here defines one idea, with the nearest alternative deliberately ruled out.
- ISO 27001: an auditable security management standard, unlike this non-certifiable framework.
- SOC 2: an attestation report produced by an auditor on a provider’s controls.
- compliance outsourcing: contracting the compliance function that operates these frameworks.
- risk outsourcing: contracting risk activity while retaining ownership of the risk itself.
- cybersecurity outsourcing: the domain covered by the security focus area guidance.
- IT transformation outsourcing: programmes where governance design is usually rebuilt.
- ESG: the reporting agenda that draws on similar governance vocabulary.
FAQ
How many objectives does COBIT 2019 have?
Forty governance and management objectives, each with associated practices and metrics that can be tailored to an organisation’s context.
What are design factors?
Inputs such as risk profile, regulatory environment and sourcing model that determine which objectives an organisation should emphasise.
Can an organisation be certified against it?
No. It is a governance framework, not a certifiable management system. Individuals can be certified; organisations cannot.
How does it differ from COBIT 5?
ISACA describes it as an evolution of the earlier edition, retaining its substance while adding design factors, focus areas and implementation guidance.
What are focus areas?
Domain-specific guidance applying the framework to particular subjects, including DevOps, information security, and information and technology risk.
How does it apply to outsourced services?
Management activity can be contracted out while governance stays internal. Design factors let you weight objectives toward third-party oversight.
Compare verified partners in the Outsource Accelerator directory and derive your reporting pack from the objectives that matter.







Independent




