COBIT 5
Definition
COBIT 5
COBIT 5 is the superseded edition of ISACA’s governance framework for enterprise information and technology. It has been replaced by COBIT 2019, so a requirement citing it today is usually quoting an old document rather than a current standard.
That matters practically. A tender demanding COBIT 5 alignment is often copying a policy written years ago, and the honest response is to ask whether the current edition would satisfy the requirement.
The framework’s purpose has not changed across editions. It separates governance, which sets direction and monitors it, from management, which plans and runs the work.
Its lasting contribution is that separation. Applied to outsourcing it produces a question buyers frequently skip — governance stays with you, and only management can be contracted out.
Key takeaways
- The edition is superseded, and the current one is COBIT 2019.
- Its core contribution is separating governance from management.
- Governance cannot be outsourced, even where the management activity is.
- Requirements still citing it usually reflect an outdated internal policy.
How it works
The framework organises enterprise technology into governance and management activities, each with objectives, and maps them to enablers such as processes, structures, people and information. Organisations select the parts that fit rather than adopting everything.
The publisher’s account of the succession is explicit. ISACA describes the current edition as an evolution of COBIT 5, containing everything you value about COBIT 5 while adding implementation resources and practical guidance.
Even the acronym’s expansion is unstable across sources. The United States National Institute of Standards and Technology glossary records it as Control Objectives for Information and Related Technologies.
That glossary cites several NIST publications for the expansion, while the publisher itself uses slightly different wording — a small inconsistency worth knowing before quoting either.
| Layer | Who owns it | Can it be outsourced |
|---|---|---|
| Governance | The board and executive | No — direction and accountability stay internal |
| Management planning | Internal technology leadership | Partly, with retained decision rights |
| Management execution | Delivery teams | Yes, this is the usual outsourcing scope |
| Monitoring | Internal assurance functions | Evidence can be produced externally, judgement cannot |
The framework is deliberately non-certifying at the organisational level. There is no audited badge for an organisation — a real difference from the security and quality standards buyers often mention in the same sentence.
The unflattering reality is that legacy citations create busywork. Providers write responses mapping their controls to a superseded model, buyers read them, and nobody involved believes the exercise improves the service.
Examples
The edition survives mainly inside documents that have outlived their review cycle, which is where buyers meet it. The situations below occur regularly, whatever a capability document chooses to put first.
A buyer’s tender template requires alignment with the older edition. The provider answers against the current one and explains the mapping, which everyone accepts.
An internal audit function still runs its control catalogue against the older model, because migrating the catalogue was never funded.
A compliance outsourcing provider maintains mappings to both editions, since its client base has not moved at a uniform pace.
A buyer discovers its policy cites the old edition and updates the policy rather than the requirement, which is the cheaper fix.
Related terms
Governance, security and assurance frameworks are routinely conflated, and the entries below separate them. Below, each term is narrowed to a single sense and walled off from its neighbours.
- ISO 27001: the information security management standard, which is independently audited.
- SOC 2: an attestation report on service organisation controls, not a framework.
- compliance outsourcing: contracting the compliance function, which uses frameworks like this one.
- risk outsourcing: contracting risk management activity while retaining risk ownership.
- IT transformation outsourcing: change programmes where governance models are usually revisited.
- service level agreement (SLA): the contractual layer where governance decisions become obligations.
- ESG: the wider reporting agenda that borrows governance language from frameworks like this.
FAQ
Is COBIT 5 still current?
No. ISACA describes the current edition, COBIT 2019, as an evolution of it, so the older edition should be treated as superseded.
Why does it still appear in tenders?
Because policy documents outlive their review cycles. A requirement citing it usually reflects a template that has not been refreshed.
Can an organisation be certified against it?
No. It is a governance framework rather than a certifiable management system, so there is no organisational audit or badge.
What does the acronym stand for?
Control Objectives for Information and Related Technologies, according to the NIST glossary. The publisher uses slightly different wording.
What is the governance and management split?
Governance sets direction and monitors outcomes; management plans and executes. The distinction determines what can be contracted out.
Should we update a policy that cites it?
Usually yes. Updating the policy is cheaper than maintaining mappings to a superseded model across every supplier response.
Search verified partners in the Outsource Accelerator directory and update the policy rather than the supplier requirement.







Independent




