IT Strategy and Steering Committees
In the CGEIT framework, effective Governance of Enterprise IT (GEIT) depends on governance structures that align IT with business objectives, deliver value, manage risk, and optimize resources. Two key structures are the IT Strategy Committee and the IT Steering Committee. They work together but op… In the CGEIT framework, effective Governance of Enterprise IT (GEIT) depends on governance structures that align IT with business objectives, deliver value, manage risk, and optimize resources. Two key structures are the IT Strategy Committee and the IT Steering Committee. They work together but operate at different levels and serve different purposes. The IT Strategy Committee operates at the board level. It is usually made up of board members and specialist non-board members, such as external IT experts. It advises the board, which keeps ultimate accountability for governance. Its focus is strategic. It ensures that IT strategy supports enterprise strategy, assesses whether IT is delivering value, oversees major IT risks and investments, and reviews IT's contribution to competitive advantage. It also gives the board insight into emerging technologies, regulatory concerns, and how well IT resources are being used. In short, it addresses the question: are we doing the right things? The IT Steering Committee operates at the executive or management level. It is typically chaired by a senior business executive. Members include the CIO, business unit leaders, and key advisors such as finance and risk representatives. Its focus is implementation and oversight. It prioritizes and approves IT-enabled investment programs, allocates resources, and monitors project delivery, costs, risks, and benefits realization. It also resolves resource conflicts between business units and ensures projects stay aligned with approved strategy. In short, it addresses the question: are we doing things the right way, and getting them done well? From a CGEIT perspective, these committees embody the principle of separating governance from management, as reflected in COBIT. Clear charters, defined roles, decision rights, and reporting lines are essential. The steering committee reports progress and issues to the strategy committee and the board. This creates accountability, transparency, and a continuous feedback loop. Together, the two committees ensure that IT investments support enterprise goals, balance risk and value, and help the organization achieve its strategic objectives.
IT Strategy and Steering Committees: A Complete CGEIT Guide (Governance of Enterprise IT)
Introduction
Within the CGEIT (Certified in the Governance of Enterprise IT) body of knowledge, Domain 1, Governance of Enterprise IT, sets the foundation for everything else. One of the most frequently tested topics in this domain is how an enterprise defines its IT strategy and the committees that oversee and steer it. This guide explains why the topic matters, what the structures are, how they work in practice, and how to answer exam questions about them.
1. Why IT Strategy and Steering Committees Are Important
IT is no longer a back-office cost center. It enables and often drives business strategy, so poor IT decisions can destroy value, expose the organization to risk and waste resources. Strategy and steering structures matter for six reasons:
Strategic alignment: IT investments and initiatives must support enterprise goals. Without a formal strategy and oversight body, IT tends to pursue technology for its own sake.
Value delivery: Steering committees make sure investments are prioritized and monitored so they deliver the benefits promised in the business case.
Accountability and decision rights: Governance structures clarify who decides what, so that business leaders, not just IT, own IT-enabled investments.
Risk optimization: Senior oversight puts IT-related risks in front of the people who can accept, mitigate or reject them, in line with risk appetite.
Resource optimization: Money, people and infrastructure are limited. Committees arbitrate competing demands across business units.
Stakeholder confidence: Boards, regulators and auditors expect evidence that IT is governed. Clear charters and minutes provide it.
In COBIT terms, these structures help the governing body Evaluate, Direct and Monitor (EDM). They are the bridge between governance and management.
2. What It Is: Key Concepts and Definitions
2.1 IT Strategy
An IT strategy is a long-term plan, typically covering 3 to 5 years, describing how IT will support and enable the enterprise strategy. It is derived from the business strategy, not the reverse. A good IT strategy covers:
• the current state (as-is) and the desired future state (to-be) of IT capabilities
• a gap analysis and a roadmap of initiatives to close the gaps
• alignment with enterprise goals, often traced through a goals cascade (stakeholder drivers, then enterprise goals, then alignment goals, then governance and management objectives)
• the investment, sourcing, architecture and resource plans needed to deliver the roadmap
• risks, constraints and success measures such as KPIs and the balanced scorecard
The IT strategic plan is then turned into tactical plans (annual budgets, project portfolios) and operational plans.
2.2 Governance vs. Management
This distinction is critical for CGEIT.
Governance (board level) evaluates stakeholder needs, sets direction through prioritization and decision making, and monitors performance and compliance.
Management (executive and operational level) plans, builds, runs and monitors activities in line with the direction set by governance.
Steering committees often sit at this boundary. Some act as governance bodies and others as management bodies, depending on their charter.
2.3 The Main Committees
IT Strategy Committee
• Level: board level
• Membership: board members plus specialist non-board members (for example, external IT experts); the CIO usually attends
• Focus: strategic direction; whether IT strategy is aligned with business strategy; whether IT delivers value and manages risk; advising the board on IT governance matters
• Authority: mainly advisory to the board; it does not run day-to-day projects
• Typical questions: Is the enterprise investing in IT appropriately? Is IT supporting competitive advantage? Are the major IT risks understood?
IT Steering Committee
• Level: executive or senior management level
• Membership: an executive sponsor (often the CEO, COO or CFO as chair), business unit heads, the CIO, key advisors from IT, finance, risk and security, and the PMO
• Focus: implementing the IT strategy; approving and prioritizing projects and the portfolio; allocating resources; monitoring project status, service levels and benefits; resolving conflicts between business units; escalating issues
• Authority: decision-making within its charter, such as approving, deferring or stopping projects and reallocating funds
• Typical questions: Which projects should we fund this year? Is project X on track? Should a failing project be terminated?
Other related bodies (names vary by organization)
• IT Architecture Review Board: sets and enforces enterprise architecture standards
• Project Steering Committee or Project Board: oversees a single major program or project
• Investment or Portfolio Committee: manages the IT-enabled investment portfolio (see Val IT concepts)
• Risk Committee and Audit Committee: board-level bodies with oversight of risk and assurance, including IT risk
• Information Security Steering Committee: coordinates security strategy and policy
• Technology Council or CIO Council: technical coordination among IT leaders
2.4 Committee Charter
Each committee should have a formal, approved charter that defines its:
• purpose and scope
• authority and decision rights
• membership and chair
• quorum rules and meeting frequency
• reporting lines and escalation paths
• responsibilities and deliverables
• performance review of the committee itself
The charter is usually approved by the board or by the body that creates the committee.
3. How It Works
3.1 Developing the IT Strategy
Step 1, understand enterprise direction: review the business strategy, mission, vision, stakeholder needs, regulatory environment and market drivers.
Step 2, assess the current state: review IT capabilities, architecture, portfolio, maturity and capability levels, risks and performance.
Step 3, define the target state: identify the IT capabilities, architecture and services needed to support future business goals.
Step 4, perform a gap analysis: compare the as-is with the to-be and identify initiatives.
Step 5, build the roadmap: sequence and prioritize initiatives by value, risk, dependencies and resource constraints.
Step 6, gain approval: the IT strategy committee or board endorses the strategy; the steering committee commits resources.
Step 7, communicate and implement: convert the strategy into portfolios, programs and projects, with clear ownership.
Step 8, monitor and adjust: track progress with a balanced scorecard and KPIs; review the strategy periodically or when business conditions change.
3.2 How the Steering Committee Operates
• Demand intake: business units submit proposals with business cases.
• Evaluation: proposals are scored against alignment with strategy, value (financial and non-financial), risk, cost, urgency and resource availability.
• Prioritization and portfolio decisions: approve, defer, reject or combine proposals. Portfolio management keeps the overall mix balanced.
• Monitoring: regular reviews of status, budget, schedule, risks and benefits realization, often using a stage-gate approach.
• Intervention: redirect, re-scope or terminate investments that are no longer viable. Sunk cost should not drive the decision.
• Reporting: summarized reports go up to the IT strategy committee or board, and decisions are communicated down to management.
• Documentation: minutes, decisions and action items are recorded for accountability and audit.
3.3 Relationship Between the Two Main Committees
The board's IT strategy committee sets and checks direction. The IT steering committee translates that direction into decisions about programs, projects and resources. Information flows upward (performance, risk, value) and direction flows downward (priorities, policies, risk appetite).
3.4 Supporting Frameworks
• COBIT 2019: EDM01 (Ensured Governance Framework Setting and Maintenance), EDM02 (Ensured Benefits Delivery), EDM03 (Ensured Risk Optimization), EDM04 (Ensured Resource Optimization), EDM05 (Ensured Stakeholder Engagement), APO02 (Managed Strategy) and APO05 (Managed Portfolio). COBIT also uses RACI charts to clarify roles, including those of steering committees.
• Val IT concepts: value governance, portfolio management and investment management.
• ISO/IEC 38500: the principles of responsibility, strategy, acquisition, performance, conformance and human behavior, together with the Evaluate-Direct-Monitor model.
• Balanced Scorecard (IT BSC): measures IT performance across corporate contribution, customer or user orientation, operational excellence and future orientation.
3.5 Common Problems
• The committee is dominated by IT and has little business participation, which leads to misalignment.
• Members lack the authority to make binding decisions.
• There is no charter, or the charter is unclear, which creates overlapping or conflicting decision rights.
• The committee focuses on operational detail instead of strategic issues.
• Meetings are infrequent or poorly attended, and decisions are not documented.
• Benefits are not tracked after projects are approved.
• The IT strategy is created once and never revisited.
4. Exam Tips: Answering Questions on IT Strategy and Steering Committees
Tip 1: Think like a governance professional, not a technician. CGEIT questions reward answers that emphasize alignment, value, accountability and stakeholder needs. Technical fixes are rarely the best answer.
Tip 2: Business strategy drives IT strategy. If a question asks what should be done FIRST when developing or updating an IT strategy, look for options such as understanding the enterprise strategy and objectives, identifying stakeholder needs, or assessing business drivers. Distractors often start with technology assessments or vendor selection.
Tip 3: Know which committee does what.
• Board-level direction, oversight and advice on IT strategy point to the IT strategy committee.
• Prioritizing projects, allocating resources, monitoring project status and resolving cross-business-unit conflicts point to the IT steering committee.
• Technical standards and architecture compliance point to the architecture review board.
• Independent assurance points to the audit committee.
Tip 4: Composition matters. The best steering committee includes senior business representatives with decision authority, chaired by a business executive. If a question describes a committee made up only of IT staff, the problem is lack of business involvement and ownership.
Tip 5: Look for the charter. When a question describes confusion over roles, overlapping decisions or ineffective committees, a well-defined charter that specifies authority, responsibilities and membership is often the correct answer.
Tip 6: Decision rights and accountability. The business owns IT-enabled investments and is accountable for benefits realization. The CIO is accountable for delivering IT services and solutions. Choose answers that place accountability with the business.
Tip 7: Value and the business case. Steering committees approve investments based on a sound business case that includes benefits, costs and risks, and they track benefits after implementation. Answers that mention benefits realization tracking or portfolio-level evaluation are usually strong.
Tip 8: Do not fall for sunk cost. If a project no longer supports strategy or deliver value, the governance answer is to re-evaluate and possibly stop or redirect it, regardless of how much has already been spent.
Tip 9: Separate governance from management. Questions may ask who should set direction (governance: board or strategy committee) versus who should execute (management). Avoid answers in which the board performs management tasks or management sets enterprise risk appetite.
Tip 10: Watch keywords such as BEST, MOST, PRIMARY and FIRST. Several options may be partially correct. Choose the one with the broadest, most strategic, preventive and business-aligned impact.
Tip 11: Monitoring and continuous alignment. IT strategy must be reviewed periodically and when business conditions change, such as mergers, new regulations or market shifts. Answers that promote periodic review and use of performance metrics (balanced scorecard, KPIs) are typically preferred over one-time activities.
Tip 12: Prefer enabling over controlling. CGEIT favors governance that enables value creation while optimizing risk and resources. An answer that only adds controls or bureaucracy without supporting value is often a distractor.
5. Sample Question Walkthrough
Question: An enterprise's IT steering committee approves most project requests submitted by the IT department, yet business units complain that IT does not meet their needs. What is the MOST likely root cause?
A. Insufficient IT budget
B. Lack of business representation on the steering committee
C. Inadequate project management methodology
D. Outdated technology infrastructure
Answer: B. The scenario signals misalignment. When the committee lacks senior business members, decisions reflect IT priorities rather than enterprise needs. Budget, methodology and technology are secondary issues.
Question: Which of the following is the PRIMARY responsibility of a board-level IT strategy committee?
A. Approving individual project budgets
B. Monitoring daily IT service levels
C. Advising the board on the alignment of IT with business strategy
D. Selecting technology vendors
Answer: C. The IT strategy committee operates at board level and provides strategic advice and oversight. Options A, B and D are management or steering-level activities.
6. Quick Revision Summary
• IT strategy is derived from enterprise strategy, covers 3 to 5 years, includes as-is, to-be, gap analysis and roadmap, and is reviewed regularly.
• The IT strategy committee is board level and advisory, focused on strategic direction, alignment, value and risk.
• The IT steering committee is executive level, makes decisions, and handles prioritization, resource allocation, monitoring and conflict resolution.
• Effective committees need a formal charter, senior business participation, clear decision rights, documented decisions and benefits tracking.
• The key frameworks are COBIT 2019 (EDM domain, APO02, APO05), ISO/IEC 38500, Val IT concepts and the IT balanced scorecard.
• For exam strategy, choose answers that are business-driven, accountable, value-focused, risk-aware and strategic rather than technical or operational.
Mastering the roles, composition and operation of IT strategy and steering committees will help you answer a large share of Domain 1 questions and will reinforce your understanding of governance across the whole CGEIT exam.
Unlock Premium Access
Certified in the Governance of Enterprise IT
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2995 Superior-grade Certified in the Governance of Enterprise IT practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CGEIT: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!