Governance System Design Factors
In CGEIT and the governance of enterprise IT (GEIT), governance system design factors come from COBIT 2019. They are contextual factors that shape how an enterprise designs a governance system that fits its needs, rather than adopting a one-size-fits-all model. COBIT 2019 defines eleven design fact… In CGEIT and the governance of enterprise IT (GEIT), governance system design factors come from COBIT 2019. They are contextual factors that shape how an enterprise designs a governance system that fits its needs, rather than adopting a one-size-fits-all model. COBIT 2019 defines eleven design factors. 1. Enterprise strategy: the primary strategic archetype, such as growth/acquisition, innovation/differentiation, cost leadership or client service/stability. 2. Enterprise goals: the goals that support the strategy, which cascade to alignment goals through the COBIT goals cascade. 3. Risk profile: the IT-related risk categories the enterprise faces and their likelihood and impact. 4. I&T-related issues: current pain points, such as frustration between business and IT, frequent incidents, regulatory findings or poor IT investment returns. 5. Threat landscape: whether the enterprise operates in a normal or high-threat environment, for example because of geopolitics or its industry. 6. Compliance requirements: low, normal or high regulatory and contractual demands. 7. Role of IT: support, factory, turnaround or strategic, based on the McFarlan grid. 8. Sourcing model for IT: outsourcing, cloud, insourced or hybrid. 9. IT implementation methods: Agile, DevOps, traditional or hybrid approaches. 10. Technology adoption strategy: first mover, follower or slow adopter. 11. Enterprise size: large versus small and medium enterprises, which have a dedicated focus area. These factors influence the governance system in three ways. They set the priority and target capability levels of the 40 governance and management objectives. They determine which variants of components, such as processes, structures, policies, culture, information, skills and services, should be emphasized. They also identify relevant focus areas, such as DevSecOps, cybersecurity or small and medium enterprises. Applying the factors follows the COBIT design workflow. First, understand the enterprise context and strategy. Next, determine the initial scope of the governance system. Then refine that scope. Finally, resolve conflicts between factors and conclude the design. COBIT design toolkits help quantify how much each factor matters. For CGEIT professionals, design factors are essential because they make sure governance is tailored, proportionate and aligned with business value creation. They also help optimize risk and resources and support stakeholder needs and accountability.
Governance System Design Factors (CGEIT): A Complete Guide to Tailoring Enterprise I&T Governance
Introduction
Governance System Design Factors are a core concept in the CGEIT domain Governance of Enterprise IT. The concept comes from COBIT 2019. It reflects a simple idea: no single governance system fits every enterprise. Design factors are the contextual and strategic variables an enterprise uses to tailor its governance system for information and technology (I&T). That system covers governance and management objectives, components and capability or performance targets.
Why Governance System Design Factors Are Important
1. One size does not fit all. A global bank, a start-up and a public hospital face different risks, regulations, strategies and technology choices. A generic governance model would be too heavy for some and too light for others.
2. Alignment with strategy. Design factors help governance support what the enterprise is actually trying to achieve, such as growth, innovation, cost leadership or stability. This is the essence of strategic alignment, a central CGEIT theme.
3. Efficient use of resources. Prioritising the governance and management objectives that matter most avoids wasted effort on low-value processes. It also concentrates investment where risk or value is highest.
4. Defensible, evidence-based decisions. Boards and executives get a structured, repeatable rationale for why certain objectives get higher capability targets.
5. Supports value delivery, risk optimisation and resource optimisation. These are the three components of the governance objective of value creation. Tailoring through design factors balances all three.
6. Adaptability. As context changes, revisiting the design factors keeps governance relevant. Examples include a merger, a move to the cloud, new regulation or a rising threat level.
What Governance System Design Factors Are
COBIT 2019 defines eleven design factors. They fall into two groups: the first four are often called the core context factors, and the remaining seven are additional or specific factors.
1. Enterprise Strategy
The strategic archetype the enterprise pursues:
- Growth/Acquisition: focus on expanding revenue and market.
- Innovation/Differentiation: offering new and differentiated products and services.
- Cost Leadership: minimising short-term costs.
- Client Service/Stability: providing stable, client-oriented service.
Enterprises usually have a primary strategy and sometimes a secondary one.
2. Enterprise Goals
The enterprise goals (EG01 to EG13) from the COBIT goals cascade support the strategy. Examples are a portfolio of competitive products and services, managed business risk, compliance with laws, and quality of financial information. Through the goals cascade, these map to alignment goals (AG01 to AG13), which map to governance and management objectives.
3. Risk Profile
This covers the I&T-related risk the enterprise faces and its current exposure. COBIT uses 19 generic IT risk categories, for example IT investment decision making, programme and project lifecycle management, IT operational infrastructure incidents, unauthorised actions, and logical attacks. Each category is rated for impact and likelihood.
4. I&T-Related Issues
These are current pain points, using a list of 20 generic issues. Examples include frustration between IT and business, significant IT-related incidents, service delivery problems by outsourcers, failure to meet regulatory requirements, and duplication or overlap of initiatives.
5. Threat Landscape
The general threat environment the enterprise operates in:
- Normal: a normal threat level.
- High: a highly exposed environment, such as one driven by geopolitical situation, industry sector or particular profile.
6. Compliance Requirements
The degree of regulatory and contractual obligation:
- Low: minimal requirements.
- Normal: average for the sector.
- High: heavily regulated, as in banking, healthcare or pharma.
7. Role of IT
Based on the McFarlan strategic grid:
- Support: IT is not crucial for running or innovating business processes.
- Factory: failure of IT has immediate business impact, but IT is not key to innovation.
- Turnaround: IT drives innovation but is not yet critical for current operations.
- Strategic: IT is critical for both operations and innovation.
8. Sourcing Model for IT
Options include outsourcing, cloud, insourced, or hybrid. A heavy reliance on outsourcing and cloud raises the priority of objectives such as APO09 Managed Service Agreements and APO10 Managed Vendors.
9. IT Implementation Methods
Options include agile, DevOps, traditional (waterfall) or hybrid. For example, DevOps increases emphasis on build, deploy and operate objectives such as BAI03, BAI06, BAI07 and DSS01.
10. Technology Adoption Strategy
- First mover: adopts emerging technology early.
- Follower: waits for technologies to become mainstream and proven.
- Slow adopter: very late adoption.
First movers place greater emphasis on innovation management (APO04) and on risk.
11. Enterprise Size
- Large enterprise: more than 250 full-time equivalents (the default assumption of COBIT 2019).
- Small and medium enterprise: 50 to 250 FTEs, with simpler structures. ISACA has published a separate COBIT focus area for SMEs.
How Governance System Design Factors Work
What the factors influence
Design factors shape the governance system in three main ways:
1. Management objective priority and target capability levels. Some of the 40 governance and management objectives become more important than others. Capability targets range from level 0 to 5.
2. Component variations. Components may need to be adapted, for example simpler organisational structures in an SME. The seven components are processes; organisational structures; principles, policies and procedures; information; culture, ethics and behaviour; people, skills and competencies; and services, infrastructure and applications.
3. Need for specific focus areas. Some contexts call for focus-area guidance such as DevOps, cybersecurity, cloud, SME, privacy or digital transformation.
The Four-Step Design Workflow (COBIT 2019 Design Guide)
Step 1: Understand the enterprise context and strategy.
- 1.1 Understand enterprise strategy.
- 1.2 Understand enterprise goals.
- 1.3 Understand the risk profile.
- 1.4 Understand current I&T-related issues.
This step uses the first four design factors.
Step 2: Determine the initial scope of the governance system.
The step 1 inputs are translated through mapping tables and the goals cascade. The result is an initial prioritised set of governance and management objectives.
Step 3: Refine the scope of the governance system.
The remaining seven design factors are considered: threat landscape, compliance requirements, role of IT, sourcing model, implementation methods, technology adoption strategy and enterprise size. They adjust priorities, capability targets, component variations and focus areas.
Step 4: Conclude the governance system design.
- 4.1 Resolve inherent priority conflicts. For example, a cost-leadership strategy may conflict with a high threat landscape that demands security investment.
- 4.2 Conclude the design, including final capability levels and the components to be addressed.
Stakeholder agreement and sign-off are essential here.
The Design Toolkit
COBIT provides a spreadsheet toolkit. Each design factor's values are entered and weighted. The toolkit produces a relative importance score for each objective, roughly between -100 and +100, relative to a baseline. The scores are then translated into suggested target capability levels:
- A score of 75 or above suggests level 4.
- A score of 50 or above suggests level 3.
- A score of 25 or above suggests level 2.
- Lower scores suggest level 1.
Professional judgement is always applied on top of the toolkit output.
Link to Implementation
The tailored design from the Design Guide feeds the COBIT 2019 Implementation Guide, which uses a seven-phase lifecycle for continual improvement:
1. What are the drivers?
2. Where are we now?
3. Where do we want to be?
4. What needs to be done?
5. How do we get there?
6. Did we get there?
7. How do we keep the momentum going?
Design factors are reassessed when the context changes.
Illustrative Examples
- A heavily regulated bank with a High compliance requirement and a Strategic IT role will raise priority and capability targets for:
- MEA03 Managed Compliance with External Requirements
- APO12 Managed Risk
- APO13 Managed Security
- DSS05 Managed Security Services
- EDM03 Ensured Risk Optimisation
- A start-up with an innovation strategy, first-mover adoption, cloud sourcing and agile delivery will prioritise:
- APO04 Managed Innovation
- BAI03 Managed Solutions Identification and Build
- APO10 Managed Vendors
- APO09 Managed Service Agreements
It may also use lighter organisational structures suited to its size.
- An enterprise whose IT role is Support generally needs lower capability targets across many objectives. Its governance can be leaner.
Related Principles
Design factors operate within the COBIT principles.
The six governance system principles are:
1. Provide stakeholder value.
2. Holistic approach.
3. Dynamic governance system.
4. Governance distinct from management.
5. Tailored to enterprise needs.
6. End-to-end governance system.
The three governance framework principles are:
1. Based on a conceptual model.
2. Open and flexible.
3. Aligned to major standards.
Design factors are the practical mechanism behind the principles Tailored to enterprise needs and Dynamic governance system.
Exam Tips: Answering Questions on Governance System Design Factors
1. Think tailoring first. When a question asks how an enterprise should establish or improve I&T governance, prefer answers that tailor governance to the enterprise context. Avoid answers that adopt a framework wholesale or copy another organisation.
2. Strategy and goals come first. Questions often ask what should be done first. The correct answer is usually to understand enterprise strategy and goals, which is step 1. Selecting tools, processes or controls comes later.
3. Know the four steps and their order. The order is: understand context, determine initial scope, refine scope, then conclude the design. Know which factors belong to which step: the first four in step 1 and the other seven in step 3.
4. Memorise all eleven factors and their typical values. Distractors may list items that are not design factors, such as budget, CIO preference or vendor recommendations.
5. Link factors to objectives logically.
- High compliance points to MEA03 and APO12.
- Outsourcing or cloud points to APO09 and APO10.
- A high threat landscape points to APO13 and DSS05.
- Innovation and first-mover adoption point to APO04.
- Agile or DevOps points to BAI03 and BAI06.
6. Watch for conflict resolution. A scenario may show conflicting factors, such as cost leadership combined with a high threat environment. The best answer usually involves balancing through stakeholder agreement and risk appetite, as in step 4.1. Ignoring one factor is rarely correct.
7. Governance versus management. The board and executives are accountable for approving the tailored design and the risk appetite. Management executes it. Choose answers that keep accountability at the governance level.
8. Dynamic reassessment. Significant changes should trigger a re-evaluation of design factors and capability targets. Examples include an acquisition, new regulation, a cloud migration or a major incident.
9. Do not chase maximum capability everywhere. Level 5 for all objectives is almost never the right answer. Targets should be proportionate to the importance given by the design factors, which reflects resource optimisation.
10. Role of IT matters. For Strategic or Factory roles, expect stronger governance on availability, continuity (DSS04) and performance. For a Support role, leaner governance is acceptable.
11. Toolkit output is advisory. If a question asks about the design toolkit results, remember that professional judgement and stakeholder validation are still required.
12. Use the CGEIT mindset. Pick the answer that delivers business value, optimises risk and resources, and keeps I&T aligned with enterprise objectives. Avoid purely technical answers. When two answers both look correct, choose the one that is more strategic, enterprise-wide and stakeholder-driven.
Summary
Governance System Design Factors are the eleven contextual variables COBIT 2019 uses to customise an enterprise's I&T governance system. They are applied through the four-step design workflow to:
- prioritise governance and management objectives,
- set target capability levels,
- adapt components, and
- choose focus areas.
Mastering them helps you answer CGEIT questions on strategic alignment, value delivery, risk optimisation and the design of a governance framework that truly fits the enterprise.
Unlock Premium Access
Certified in the Governance of Enterprise IT
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2995 Superior-grade Certified in the Governance of Enterprise IT practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CGEIT: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!