Evaluate, Direct and Monitor (EDM) Applied to IT Strategic Planning: A CGEIT Guide
Introduction
Evaluate, Direct and Monitor (EDM) is the core governance model behind ISO/IEC 38500 and the COBIT governance domain. For the CGEIT exam (Domain 1: Governance Framework for Enterprise IT, and Domain 2: IT Resources and Strategy), you must understand how the board and executive management use EDM to govern IT strategic planning. Management, in turn, plans, builds, runs and monitors IT (PBRM). This guide explains why EDM matters, what it is, how it works in IT strategic planning, and how to answer exam questions on it.
Why It Is Important
1. It separates governance from management. EDM defines what the governing body (the board) does, as distinct from what management executes. CGEIT tests this distinction heavily.
2. It aligns IT with enterprise goals. IT strategic planning without governance oversight often produces technology-driven plans that do not deliver business value. EDM keeps the IT strategy tied to enterprise objectives, stakeholder needs and risk appetite.
3. It supports value delivery, risk optimization and resource optimization. These are the three components of governance objectives in COBIT, and they map to EDM02, EDM03 and EDM04.
4. It creates accountability. The board stays accountable for IT-enabled outcomes even when responsibility for execution is delegated to management.
5. It enables continual adjustment. The monitoring part creates a feedback loop. The strategy can then be re-evaluated when business conditions, technology or risks change.
What It Is
Evaluate: The governing body examines current and future use of IT. It considers internal and external pressures such as business needs, competition, regulation, technology trends and risk. It assesses strategic options, proposals and plans put forward by management. The key question is: Are we doing the right things?
Direct: The governing body sets direction and assigns responsibility for preparing and carrying out plans and policies. Typical outputs are:
- Strategic priorities and principles
- Investment priorities
- Risk appetite
- Policies and decision rights
Directing means guiding, not managing day-to-day activity.
Monitor: The governing body checks performance and conformance against the plans, policies and objectives it approved. This is done through measurement systems such as balanced scorecards, KPIs, KGIs, assurance reports and audit findings. The key question is: Are we getting the benefits, and are we compliant?
Relationship to COBIT 2019
The COBIT governance objectives are:
- EDM01 Ensured Governance Framework Setting and Maintenance
- EDM02 Ensured Benefits Delivery
- EDM03 Ensured Risk Optimization
- EDM04 Ensured Resource Optimization
- EDM05 Ensured Stakeholder Engagement
IT strategic planning itself is a management activity: APO02 Managed Strategy, supported by APO01, APO03, APO05 and APO06. EDM governs APO02. Management performs the planning; the board evaluates, directs and monitors it.
How It Works in IT Strategic Planning
Step 1 - Evaluate the context and options.
- The board, often through an IT strategy committee, reviews the enterprise strategy, stakeholder needs, the current IT capability and the external environment.
- It evaluates alternative IT strategies, roadmaps and investment portfolios that management proposes.
- Tools include gap analysis, SWOT, enterprise architecture baselines, business cases, risk assessments and the COBIT goals cascade, which runs from stakeholder drivers to enterprise goals to alignment goals.
Step 2 - Direct the strategy.
- The board approves the IT strategic plan and investment priorities.
- It sets guiding principles, such as cloud-first or security by design.
- It defines decision rights, for example who approves investments above a threshold.
- It sets the risk appetite and allocates resources.
- It communicates expectations and assigns accountability to the CIO and executive management.
Step 3 - Management executes (APO/BAI/DSS).
Management translates the direction into tactical plans, programs, projects and operations.
Step 4 - Monitor results.
- The board reviews strategic KPIs, benefits realization reports, portfolio status, risk profile changes and independent assurance from internal audit.
- Where deviations exist, it re-evaluates and issues new direction.
Step 5 - Feedback loop.
Monitoring feeds evaluation, so EDM is continuous rather than a one-time annual event.
Key Structures and Roles
- Board of directors: ultimately accountable for governance of enterprise IT.
- IT strategy committee (board level): advises the board on strategic alignment and IT direction.
- IT steering committee (executive level): manages the portfolio, prioritizes projects and monitors delivery. This is a management body, not a governance body.
- CIO: responsible for developing and executing the IT strategy.
- Internal audit: provides independent assurance that supports monitoring.
Common Success Factors
- Strong business involvement and executive sponsorship
- A clear link between enterprise goals and IT goals
- Portfolio management with value-based prioritization
- Agreed metrics and transparent reporting
- A defined risk appetite
- Periodic strategy refresh
Common Pitfalls
- The board micromanages IT projects (confusing directing with managing).
- The IT strategy is developed in isolation by IT.
- There are no benefit metrics, so monitoring is impossible.
- Approval happens without later monitoring.
- Plans are static and ignore changes in the environment.
Exam Tips: Answering Questions on Evaluate, Direct and Monitor Applied to IT Strategic Planning
1. Identify whose perspective the question takes. If it asks what the board or governing body should do, choose an EDM-type answer (evaluate, approve, set direction, monitor). If it asks about the CIO or IT management, choose a plan, build, run or monitor activity.
2. Business alignment usually wins. The best answer typically ties IT strategy to enterprise strategy and goals, not to technology preferences, cost cutting alone or IT best practices.
3. Watch for the word FIRST. The first step in IT strategic planning is usually to understand the enterprise strategy, objectives and stakeholder needs (evaluate) before choosing technologies or approving projects.
4. The governing body does not execute. Reject options where the board develops detailed project plans, selects vendors or manages operations. The board approves, directs and holds management accountable.
5. Monitoring means measurement against approved objectives. Prefer answers involving KPIs, balanced scorecards, benefits realization reviews and independent assurance over informal status updates.
6. Know the committees. IT strategy committee = board level, strategic advice (governance). IT steering committee = executive level, prioritization and oversight of projects (management). A frequent trap is swapping their roles.
7. Value, risk and resources. When asked what governance must ensure, think benefits delivery, risk optimization within appetite, and resource optimization. These map to EDM02, EDM03 and EDM04.
8. Strategy is iterative. If the business environment changes, the best answer is to re-evaluate and update the IT strategy through governance. Do not simply continue the existing plan or let IT adjust unilaterally.
9. Accountability cannot be delegated. Responsibility can be delegated to management, but the board retains accountability.
10. Choose the most strategic, holistic option. CGEIT questions favor enterprise-wide, sustainable and governance-level answers over tactical fixes. When two answers seem correct, choose the one that addresses root cause and alignment.
11. Stakeholder engagement matters. Transparency and reporting to stakeholders (EDM05) is part of governance. Answers that improve communication of IT performance to the board and stakeholders are often correct.
12. Distinguish frameworks. ISO/IEC 38500 uses Evaluate-Direct-Monitor with six principles: Responsibility, Strategy, Acquisition, Performance, Conformance and Human Behaviour. COBIT applies EDM as its governance domain. Recognize either terminology.
Sample Question Approach
Question: The board is concerned that IT investments are not delivering expected value. What should it do FIRST?
Reasoning: This is a governance-level concern, so the starting point is evaluation. The board should evaluate whether IT investments align with enterprise strategy, using benefits realization data and portfolio review. Then it should direct corrective priorities. Answers such as replacing the CIO, cutting the IT budget or adopting a new technology are premature or tactical.
Summary
EDM is how the governing body ensures that the IT strategic plan creates value, manages risk and uses resources wisely:
- Evaluate needs and options.
- Direct through approved strategy, priorities, principles and policies.
- Monitor performance and conformance, then feed results back into evaluation.
On the exam, always keep the board and management roles distinct, anchor answers in business alignment, and prefer measurable, strategic and accountable governance actions.