Acquisition of Resources and Make-Versus-Buy Decisions
In the CGEIT framework, the acquisition of resources falls under the Resource Optimization domain. Its goal is to ensure the enterprise has adequate, appropriate and cost-effective IT capabilities, including people, processes, applications, infrastructure and information, to meet current and future… In the CGEIT framework, the acquisition of resources falls under the Resource Optimization domain. Its goal is to ensure the enterprise has adequate, appropriate and cost-effective IT capabilities, including people, processes, applications, infrastructure and information, to meet current and future strategic objectives. Governance is less about operational buying and more about ensuring acquisition decisions align with enterprise strategy, deliver value, optimize risk and use resources efficiently. COBIT 2019 supports this through objectives such as EDM04 (Ensured Resource Optimization), APO07 (Managed Human Resources), APO10 (Managed Vendors) and BAI03 (Managed Solutions Identification and Build). The make-versus-buy decision is central to resource acquisition. Leaders must choose among several sourcing options: developing a solution in-house, purchasing commercial off-the-shelf software, subscribing to cloud or SaaS services, outsourcing to third parties, or combining these in a hybrid model. Key evaluation criteria include: 1. **Strategic importance:** Capabilities that provide competitive differentiation or represent core competencies are often built or tightly controlled. Commodity functions are usually bought. 2. **Total cost of ownership:** This covers acquisition, implementation, licensing, maintenance, support, upgrades and exit costs over the full life cycle. 3. **Time to market:** Buying usually speeds deployment, while building may delay benefits. 4. **Skills and capacity:** The decision depends on whether internal staff have the expertise and availability to develop and maintain the solution. 5. **Control, customization and intellectual property:** Building offers flexibility and ownership. Buying may require adapting business processes to the product. 6. **Risk:** Relevant risks include vendor viability, lock-in, security, regulatory compliance, data sovereignty and project delivery risk. 7. **Scalability and integration:** The solution must fit the enterprise architecture. Effective governance requires a formal business case that compares alternatives objectively, using techniques such as cost-benefit analysis and NPV. It also requires clear decision rights, often exercised through an IT steering or investment committee, and alignment with sourcing policies and enterprise architecture standards. When the choice is to buy or outsource, governance extends to vendor selection, contract management, service level agreements, performance monitoring and exit strategies. Ultimately, the board and executives remain accountable for outcomes, even when execution is outsourced. Decisions should be revisited periodically as business needs, technology and markets evolve.
Acquisition of Resources and Make-Versus-Buy Decisions (CGEIT – IT Resources)
Overview
In the ISACA CGEIT (Certified in the Governance of Enterprise IT) framework, IT Resources is one of the core domains. It covers how the enterprise makes sure it has the right capabilities (people, information, infrastructure, applications and services) to deliver on its strategy. A central part of this domain is how resources are acquired and the strategic choice between making (building or developing in-house) and buying (purchasing, outsourcing, subscribing or partnering).
This guide explains why the topic matters, what it involves, how the process works in a governed enterprise, and how to approach exam questions on it.
1. Why It Is Important
Strategic alignment: Every acquisition decision commits money, people and time. If those commitments do not support enterprise objectives, value is destroyed. Governance makes sure sourcing choices reflect business strategy, not just IT preference.
Value delivery: Make-versus-buy decisions directly affect whether IT-enabled investments realise their expected benefits. A poor choice can lead to cost overruns, late delivery, poor fit, or dependence on an unreliable supplier.
Risk optimisation: Each sourcing option carries different risks, including:
- vendor lock-in
- loss of internal knowledge
- data protection and regulatory exposure
- project failure
- skills gaps
- supplier insolvency
Resource optimisation: Enterprises have limited capital and skilled staff. Sourcing decisions determine where scarce internal talent is focused, ideally on capabilities that create competitive differentiation.
Accountability and transparency: Stakeholders and regulators expect sourcing decisions to be justified, documented and traceable to business cases and policies.
Long-term capability: Decisions taken today shape the enterprise architecture, the skills base and supplier dependencies for years. Governance takes a lifecycle view, not a short-term cost view.
2. What It Is
Acquisition of resources is the governed process by which an enterprise obtains the IT resources it needs. These include:
- People and skills: hiring, contracting, training, consultants, managed services.
- Applications: custom development, commercial off-the-shelf (COTS) software, Software as a Service (SaaS), open source.
- Infrastructure: on-premises hardware, colocation, Infrastructure as a Service (IaaS), Platform as a Service (PaaS).
- Information: internally generated data or externally purchased data sets.
- Services: internal shared services, outsourcing, offshoring, nearshoring, multi-sourcing.
The make-versus-buy decision (also called the sourcing decision or build-versus-buy) is the structured evaluation of whether a capability should be:
- Made: developed, built or operated internally using enterprise staff and assets.
- Bought: acquired from external parties through purchase, licence, subscription, outsourcing or partnership.
- Hybrid: for example, buying a COTS package and customising it, co-sourcing, or building on a cloud platform.
Key governance concepts linked to this topic:
- Sourcing strategy: a board-approved, high-level direction stating which capabilities are core (keep in-house) and which are context or commodity (candidates to buy).
- Business case: the justification document that includes options analysis, costs, benefits, risks and the recommended option.
- Total Cost of Ownership (TCO): all costs across the lifecycle, including acquisition, implementation, integration, operation, support, upgrades, exit and decommissioning.
- Vendor and supplier management: selection, contracting, performance monitoring and relationship management.
- Contracts and SLAs: service level agreements, right-to-audit clauses, exit and transition clauses, intellectual property ownership, and data protection terms.
- Enterprise architecture: the reference that confirms any acquired resource fits standards and the target state.
- COBIT 2019 alignment: relevant objectives include APO02 Managed Strategy, APO05 Managed Portfolio, APO06 Managed Budget and Costs, APO07 Managed Human Resources, APO10 Managed Vendors, APO03 Managed Enterprise Architecture, BAI03 Managed Solutions Identification and Build, and EDM04 Ensured Resource Optimization.
3. How It Works
A well-governed acquisition and make-versus-buy process typically follows these stages.
Step 1: Establish direction (Evaluate, Direct, Monitor).
- The board and executive committee set the resource management principles and sourcing strategy.
- Under EDM04, governance bodies evaluate current and future resource needs, direct how resources are to be obtained, and monitor whether resource goals are met.
- Policies define approval thresholds, preferred suppliers, cloud-first or cloud-appropriate positions, and risk appetite.
Step 2: Identify the business need.
- The requirement starts with a business objective, not a technology.
- Requirements cover functional needs, non-functional needs (security, performance, availability) and compliance needs.
- Stakeholders and the business sponsor are identified, and accountability is clearly assigned (often via a RACI chart).
Step 3: Analyse options.
Each option is evaluated against common criteria:
- Strategic importance: Is the capability a source of competitive advantage? Core differentiating capabilities favour make. Commodity capabilities favour buy.
- Internal capability and capacity: Do we have the skills, time and maturity to build and maintain it?
- Time to market: Buying is often faster.
- Total cost of ownership: Look beyond the purchase price to the full lifecycle.
- Fit with enterprise architecture: integration, standards and technical debt.
- Risk: vendor viability, lock-in, security, data sovereignty, regulatory constraints, project delivery risk.
- Flexibility and control: Custom builds offer control. Bought solutions may limit customisation but bring vendor innovation.
- Market availability: Are mature solutions available? How many credible suppliers exist?
- Intellectual property: Who will own what is created?
Step 4: Build the business case.
- Document the options, financial analysis (NPV, ROI, payback, TCO), non-financial benefits, risks and assumptions.
- Include a do nothing baseline.
- The business sponsor owns the business case and the expected benefits, not IT alone.
Step 5: Decide and approve through governance.
- Investment and portfolio committees, or the IT strategy committee, review the business case against strategic priorities and portfolio balance.
- The decision follows defined decision rights and is documented.
Step 6: Execute the acquisition.
- If buy: issue a request for information (RFI), request for proposal (RFP) or request for quotation (RFQ); evaluate vendors using predefined weighted criteria; carry out due diligence (financial stability, security posture, references, certifications such as SOC 2 or ISO 27001); negotiate contracts with SLAs, right-to-audit, exit strategy, escrow and data return provisions.
- If make: secure skilled resources, apply SDLC controls, follow the architecture, and plan for ongoing maintenance and knowledge retention.
Step 7: Transition and integrate.
- Plan the implementation and organisational change.
- Arrange knowledge transfer and integrate operations into service management.
Step 8: Monitor, measure and review.
- Track supplier performance against SLAs and KPIs.
- Carry out benefits realisation reviews and post-implementation reviews.
- Reassess the sourcing decision periodically, because markets, technology and strategy change.
- Maintain exit and contingency plans.
Typical guidance on when to make versus buy:
- Favour make when the capability is a core differentiator, requirements are highly unique, IP retention is critical, internal skills exist, or regulatory constraints limit third-party use.
- Favour buy when the capability is a commodity, mature market solutions exist, speed is important, internal skills are lacking, or economies of scale lower costs.
- Consider hybrid when a package meets most needs but some differentiation is required, or when transitional skills are needed.
Important governance reminders:
- Outsourcing a service does not outsource accountability. The enterprise remains accountable for risk, compliance and outcomes.
- Heavy customisation of COTS software often erodes the benefits of buying, because it complicates upgrades and raises TCO.
- Cloud adoption is a buy decision that requires the same governance rigour: shared responsibility, data location, exit and audit rights.
4. Common Pitfalls Governance Should Prevent
- Deciding on price alone rather than TCO and value.
- IT selecting solutions without business ownership.
- Shadow IT purchases bypassing governance, such as departments signing SaaS contracts directly.
- No exit strategy, which leads to lock-in.
- Inadequate vendor due diligence.
- Losing critical internal knowledge after outsourcing.
- Failing to revisit sourcing decisions over time.
- Ignoring architecture, which leads to integration failures and technical debt.
5. Exam Tips: Answering Questions on Acquisition of Resources and Make-Versus-Buy Decisions
Tip 1: Think like a governance professional, not a technician. CGEIT answers favour board-level and strategic perspectives. When options include technical detail versus alignment with strategy or business objectives, the strategic answer is usually correct.
Tip 2: Strategy and business need come first. If a question asks what should be done first or what is most important before an acquisition, look for answers such as:
- aligning with enterprise strategy
- defining business requirements
- consulting the sourcing strategy
- developing a business case
Tip 3: Accountability cannot be outsourced. Any option suggesting the vendor becomes accountable for compliance, risk or business outcomes is wrong. The enterprise, and ultimately the board or senior management, remains accountable.
Tip 4: Prefer TCO and value over cost. When choosing between the lowest price and the best value or lowest total cost of ownership aligned with objectives, choose value or TCO.
Tip 5: Business case ownership belongs to the business. The business sponsor owns the business case and benefits realisation. IT supports it with cost, risk and technical input.
Tip 6: Core versus commodity. If the scenario stresses competitive advantage, uniqueness or strategic IP, lean towards make or retaining control. If it stresses standard functionality, speed or a lack of skills, lean towards buy.
Tip 7: Contracts must protect the enterprise. In outsourcing or cloud scenarios, strong answers include:
- right-to-audit clauses
- SLAs with measurable metrics
- exit and transition clauses
- data ownership and protection terms
- escrow for critical software
- clarity on the shared responsibility model
Tip 8: Watch for shadow IT and policy bypass. If a department bought a solution independently, the best governance response usually involves enforcing or establishing acquisition policies and bringing the solution under portfolio and architecture governance. Simply banning it, or ignoring it, is rarely the best answer.
Tip 9: Monitoring is part of governance. After acquisition, look for answers involving performance monitoring, benefits realisation reviews and periodic reassessment of sourcing decisions.
Tip 10: Identify the governance body or role. Questions may ask who should approve. Typical mapping:
- The board or IT strategy committee approves the sourcing strategy and major investments.
- Investment or portfolio committees prioritise and approve business cases.
- The CIO executes and manages delivery.
- Procurement and legal support contracting.
- Risk and compliance functions advise on risk.
Tip 11: Read for keywords such as BEST, MOST, FIRST and PRIMARY. Several options may be correct. Choose the one with the greatest strategic impact or the one that is a logical prerequisite.
Tip 12: Use COBIT thinking. Remember the EDM (Evaluate, Direct, Monitor) role of governance versus the Plan-Build-Run-Monitor role of management. Governance sets the direction and resource principles. Management carries out acquisitions.
Tip 13: Risk appetite matters. When a sourcing option introduces risk, the right answer usually involves assessing it against the enterprise risk appetite and documenting risk acceptance at the appropriate level. Do not automatically eliminate all risk.
Tip 14: Do not forget people resources. Make-versus-buy also applies to skills. Possible responses to skills gaps include training, hiring, contracting or managed services. Governance-oriented answers consider knowledge retention, key-person dependency and long-term capability.
6. Sample Exam-Style Reasoning
Scenario: An enterprise is considering outsourcing its customer analytics platform to reduce costs. Analytics is a key differentiator in its market strategy. What should the IT steering committee do FIRST?
Reasoning: Because analytics is a differentiator, the first step is to evaluate the proposal against the enterprise strategy and sourcing principles. This includes considering whether outsourcing could erode competitive advantage or IP. Selecting a vendor or negotiating SLAs comes later.
Scenario: After outsourcing IT operations, a regulator finds data protection breaches by the provider. Who is accountable?
Reasoning: The enterprise remains accountable. The provider may be contractually responsible, but accountability to regulators and stakeholders stays with the enterprise's governance bodies.
7. Quick Summary
- Acquisition and sourcing decisions must be driven by strategy, business need and value.
- Use structured options analysis, TCO and a business-owned business case.
- Make for core differentiators, buy for commodities, and use hybrid approaches where appropriate.
- Govern through defined decision rights, policies, architecture and risk appetite.
- Protect the enterprise through due diligence, strong contracts, SLAs, audit rights and exit plans.
- Accountability is never outsourced.
- Monitor performance and benefits, and revisit sourcing decisions over time.
Unlock Premium Access
Certified in the Governance of Enterprise IT
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2995 Superior-grade Certified in the Governance of Enterprise IT practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CGEIT: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!