Components of a Governance Framework
In the CGEIT (Certified in the Governance of Enterprise IT) context, a governance framework is the structure that ensures enterprise IT creates value, optimizes risk and uses resources wisely in line with stakeholder needs. ISACA's COBIT 2019 is the main reference. It describes seven components tha… In the CGEIT (Certified in the Governance of Enterprise IT) context, a governance framework is the structure that ensures enterprise IT creates value, optimizes risk and uses resources wisely in line with stakeholder needs. ISACA's COBIT 2019 is the main reference. It describes seven components that work together as a governance system. Processes are organized practices and activities that achieve objectives, such as evaluating, directing and monitoring (EDM) or managing IT budgets and risk. Organizational structures are the key decision-making bodies, such as the board, an IT steering committee, an architecture board or a risk committee. Each has a defined mandate, authority and accountability. Principles, policies and procedures turn desired behavior into practical guidance for day-to-day management. Information covers the data produced and used across the enterprise, including the reports, dashboards and metrics that support governance decisions. Culture, ethics and behavior reflect individual and collective conduct, which often decides whether governance succeeds or fails. People, skills and competencies are needed to make good decisions, take corrective action and complete activities. Services, infrastructure and applications are the technology and services that support governance and management, such as GRC tools and monitoring platforms. CGEIT candidates should also understand the related framework elements. Clear roles and responsibilities are often documented in RACI charts. Decision rights clarify who decides and who is consulted. Performance measurement uses goals cascades, KPIs, balanced scorecards and capability levels. Design factors such as enterprise strategy, risk profile, compliance needs and sourcing model allow the framework to be tailored. Focus areas address specific topics such as cybersecurity or DevOps. A good framework separates governance (evaluate, direct, monitor) from management (plan, build, run, monitor). It aligns with standards like ISO/IEC 38500, ITIL and COSO, and it is improved continuously. Together, these components give leaders a holistic, adaptable way to align IT with business goals, deliver benefits, manage risk and keep stakeholder trust.
Components of a Governance Framework (CGEIT – Governance of Enterprise IT)
Introduction
The Components of a Governance Framework topic sits at the heart of CGEIT Domain 1, Governance of Enterprise IT. ISACA expects a CGEIT candidate to know what a governance framework is made of. It also expects you to know how those parts work together to create value, optimize risk and optimize resources. This guide explains why the topic matters, what the components are, how they work in practice, and how to approach exam questions on it.
1. Why It Is Important
A governance framework turns stakeholder needs into decisions, direction and oversight that management can act on. Without a defined framework, organizations tend to suffer from:
• IT investments that do not support business strategy.
• Unclear accountability, where nobody owns decisions or outcomes.
• Inconsistent risk-taking and missed compliance obligations.
• Poor value delivery and wasted resources.
• Weak communication between the board, executives and IT.
A well-designed framework provides:
• Strategic alignment between IT and enterprise goals.
• Value delivery from IT-enabled investments.
• Risk optimization within the approved risk appetite.
• Resource optimization across people, information, infrastructure and applications.
• Performance measurement, so that leaders can monitor progress and correct course.
• Transparency and accountability to stakeholders, regulators and shareholders.
For the CGEIT exam, this topic is foundational. Almost every scenario question assumes you know who sets direction, who executes and how oversight happens.
2. What It Is
An enterprise governance framework is a structured set of principles, structures, processes, policies, roles, information flows and enablers. Together they make sure that:
• stakeholder needs are evaluated,
• direction is set through prioritization and decision-making, and
• performance and compliance are monitored against agreed direction and objectives.
This is the EDM model (Evaluate, Direct, Monitor). It comes from ISO/IEC 38500 and is embedded in COBIT.
Governance vs. Management
A core concept is separating governance from management:
• Governance is the responsibility of the board of directors, under the leadership of the chair. It covers evaluating, directing and monitoring.
• Management is the responsibility of executive management, under the leadership of the CEO. It covers planning, building, running and monitoring (PBRM) in line with the direction set by governance.
Key Components of a Governance Framework
Using COBIT 2019 terminology, which is aligned with CGEIT, the framework is built from the following components.
a) Principles, Policies and Procedures
• Principles are high-level guiding statements, such as "IT investments must be justified by a business case."
• Policies are formal directives that translate principles into rules for behavior.
• Procedures and standards are the detailed, operational steps that implement policies.
Policies should be approved at the right level, communicated, enforced and periodically reviewed.
b) Processes
Processes are organized sets of practices and activities that achieve objectives. COBIT 2019 defines 40 governance and management objectives:
• EDM (Evaluate, Direct and Monitor) is the governance domain. It includes EDM01 Ensured Governance Framework Setting and Maintenance, EDM02 Ensured Benefits Delivery, EDM03 Ensured Risk Optimization, EDM04 Ensured Resource Optimization, and EDM05 Ensured Stakeholder Engagement.
• APO covers Align, Plan and Organize.
• BAI covers Build, Acquire and Implement.
• DSS covers Deliver, Service and Support.
• MEA covers Monitor, Evaluate and Assess.
c) Organizational Structures
These are the key decision-making entities, for example:
• Board of directors
• IT strategy committee, which operates at board level and advises on strategic IT direction
• IT steering committee, which operates at executive level and prioritizes and oversees programs and projects
• Executive committee, CIO, CRO, CISO and CFO
• Architecture board, project management office (PMO) and value management office
• Audit committee and the internal audit function
d) Information Flows and Items
Information is required for governance decisions. Examples include IT strategy documents, risk profiles, performance dashboards, balanced scorecards, business cases and audit reports. Reporting must be accurate, timely and relevant to the intended audience.
e) People, Skills and Competencies
Good decisions and execution depend on capable people. This includes board IT literacy, skills frameworks such as SFIA and e-CF, training, and succession planning.
f) Culture, Ethics and Behavior
Culture is often underestimated, yet it is critical to whether governance succeeds. Relevant elements include tone at the top, risk-aware culture, ethical conduct, and attitudes toward compliance and innovation.
g) Services, Infrastructure and Applications
These are the technology services and tools that support governance, such as GRC platforms, portfolio management tools and monitoring systems.
Other Framework Elements CGEIT Expects You to Know
• Roles and responsibilities, documented using RACI charts (Responsible, Accountable, Consulted, Informed).
• Decision rights, meaning who decides on IT principles, architecture, infrastructure, business application needs and investment. Weill and Ross's IT governance archetypes describe common patterns: business monarchy, IT monarchy, feudal, federal, duopoly and anarchy.
• Performance management, including KPIs, KGIs, balanced scorecards and maturity or capability assessments.
• Strategic alignment mechanisms, such as the COBIT goals cascade, which runs from stakeholder drivers to enterprise goals, then alignment goals, then governance and management objectives.
• Design factors (COBIT 2019), which are used to tailor the governance system. They include enterprise strategy, enterprise goals, risk profile, I&T-related issues, threat landscape, compliance requirements, role of IT, sourcing model, IT implementation methods, technology adoption strategy and enterprise size.
• Focus areas, such as small and medium enterprises, cybersecurity, cloud, DevOps and privacy.
Relevant Standards and Frameworks
• COBIT 2019 is the primary reference for CGEIT.
• ISO/IEC 38500 sets out six principles: Responsibility, Strategy, Acquisition, Performance, Conformance and Human Behaviour.
• Val IT and Risk IT have been integrated into COBIT.
• Supporting frameworks include ITIL, ISO/IEC 27001, COSO, TOGAF and PMBOK/PRINCE2.
3. How It Works
Step 1 – Understand stakeholder needs. Governance starts by identifying stakeholder drivers and needs. Examples include shareholder returns, regulatory compliance, customer expectations and competitive pressure.
Step 2 – Evaluate. The board, or the IT strategy committee on its behalf, evaluates current and future business needs, IT capabilities, risks and options.
Step 3 – Direct. The board sets direction through principles, policies, the risk appetite, investment priorities and strategy. It also assigns accountability and decision rights.
Step 4 – Management executes. Executive management plans, builds, runs and monitors IT activities within the direction set. The IT steering committee prioritizes portfolios, and the PMO manages delivery.
Step 5 – Monitor. Performance, conformance and risk are measured with KPIs, scorecards, audits and assurance reviews. Results go back to the board.
Step 6 – Continual improvement. The framework is reviewed and adjusted through maturity or capability assessments, lessons learned, and changes in strategy or the environment. This is the purpose of EDM01, which ensures the governance framework is set and maintained.
Implementing a Governance Framework
COBIT describes a seven-phase implementation lifecycle:
1. What are the drivers?
2. Where are we now?
3. Where do we want to be?
4. What needs to be done?
5. How do we get there?
6. Did we get there?
7. How do we keep the momentum going?
These phases run alongside three supporting tracks: program management, change enablement and the continual improvement lifecycle.
Critical Success Factors
• Executive sponsorship and board commitment (tone at the top)
• Alignment with enterprise strategy and culture
• Clear roles, responsibilities and decision rights
• Tailoring the framework to the enterprise rather than adopting it "out of the box"
• Effective communication and change management
• Measurable objectives and regular reporting
4. How to Answer Exam Questions on This Topic
CGEIT questions are scenario-based and usually ask for the BEST, MOST, FIRST or PRIMARY answer. Several options are often technically correct. You must choose the one that best reflects a governance perspective, as opposed to an operational one.
Common Question Types
• Who is accountable? For example: who is ultimately accountable for IT governance? Answer: the board of directors.
• What should be done first? For example: when establishing a governance framework, the first step is usually to understand the enterprise strategy and stakeholder needs, or to obtain executive sponsorship.
• Which structure fits? For example: which body prioritizes IT investments across business units? Usually the IT steering committee. Which body advises the board on IT strategy? The IT strategy committee.
• What is the purpose of a component? For example: the PRIMARY purpose of a policy is to communicate management's intent and direction.
• Which is the BEST indicator of effectiveness? Usually something that shows business value or alignment, such as achievement of enterprise goals. Technical metrics are less likely to be correct.
Sample Question
An enterprise is implementing an IT governance framework. Which of the following should be done FIRST?
A. Select a governance tool
B. Define IT performance metrics
C. Obtain senior management commitment and understand enterprise objectives
D. Draft detailed IT procedures
Answer: C. Governance must begin with business drivers and leadership sponsorship. Options A, B and D are later, more operational steps.
Exam Tips: Answering Questions on Components of a Governance Framework
Tip 1 – Think like a board member, not a technician. CGEIT rewards strategic, business-oriented answers. If one option sounds technical and another sounds governance-focused, the governance-focused option is usually correct.
Tip 2 – Separate governance from management. Remember that governance means EDM and is done by the board, while management means PBRM and is done by executives. Answers that blur this distinction are often wrong.
Tip 3 – Business strategy drives everything. When asked what comes first, or what a framework should be based on, choose answers that point to enterprise strategy, objectives or stakeholder needs.
Tip 4 – Know the committees.
• IT strategy committee: board level, advisory, focused on strategic direction.
• IT steering committee: executive level, focused on prioritizing and overseeing projects and resources.
• Audit committee: oversees assurance and controls.
Tip 5 – Accountability vs. responsibility. Accountability cannot be delegated, but responsibility can. In a RACI chart there should be only one Accountable party per activity.
Tip 6 – Tailor, don't copy. Frameworks such as COBIT must be adapted to the enterprise using design factors. Be suspicious of answers suggesting a framework should be implemented "in full" without customization.
Tip 7 – Culture and people matter. If a scenario shows that a framework exists but isn't followed, the root cause is often culture, awareness, sponsorship or unclear accountability. A missing tool is rarely the answer.
Tip 8 – Look for value, risk and resource optimization. The ultimate objective of governance is value creation, which means realizing benefits while optimizing risk and resources. Answers framed around these outcomes are strong candidates.
Tip 9 – Policies come before procedures. The hierarchy runs from principles, to policies, to standards, to procedures and guidelines. Higher-level direction must exist before detailed controls.
Tip 10 – Monitoring closes the loop. When asked how the board knows governance is effective, think of performance measurement, balanced scorecards, independent assurance (internal audit) and reporting to the board.
Tip 11 – Watch keywords. FIRST points to the starting point or root activity. BEST points to the most comprehensive, strategic option. PRIMARY points to the main purpose rather than secondary benefits. MOST LIKELY points to the root cause.
Tip 12 – Eliminate extremes. Discard options that are too narrow, too technical, or that bypass governance structures. An example is an IT manager making enterprise investment decisions alone.
Summary
A governance framework is a coordinated system with these parts:
• principles, policies and procedures
• processes
• organizational structures
• information
• culture
• people and skills
• services, infrastructure and applications
It is guided by the EDM model and tailored to the enterprise's context. Its purpose is to ensure IT delivers value, manages risk and uses resources wisely. For the exam, anchor every answer in business strategy, board accountability, the separation of governance from management, and continual monitoring and improvement.
Unlock Premium Access
Certified in the Governance of Enterprise IT
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2995 Superior-grade Certified in the Governance of Enterprise IT practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CGEIT: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!