Centralized, Decentralized and Shared-Service IT Resourcing
In the CGEIT framework, IT resource optimization is a core governance objective. It ensures that people, infrastructure, applications and information are sourced, organized and allocated so that they deliver business value efficiently. The resourcing model an enterprise chooses (centralized, decent… In the CGEIT framework, IT resource optimization is a core governance objective. It ensures that people, infrastructure, applications and information are sourced, organized and allocated so that they deliver business value efficiently. The resourcing model an enterprise chooses (centralized, decentralized or shared-service) shapes accountability, cost, agility and alignment with strategy. The board and executive management must select and oversee that model. Centralized IT resourcing places IT staff, budgets, infrastructure and decision rights under a single corporate IT function, typically led by the CIO. Its strengths are economies of scale, standardized architecture, consistent security and compliance controls, stronger negotiating power with vendors, and clear enterprise-wide visibility of IT spending and risk. Its weaknesses include slower responsiveness to individual business units, a perception of IT as bureaucratic, and weaker alignment with local needs. Decentralized IT resourcing distributes IT resources and decision authority to business units, divisions or geographic regions. Each unit controls its own systems and staff. This model offers close business alignment, faster local decision-making and greater ownership by business leaders. However, it often leads to duplicated investments, inconsistent standards, fragmented data, higher total cost of ownership and increased risk because governance oversight is harder to enforce. The shared-service model is a hybrid. Common, non-differentiating services such as data centers, networks, help desks, ERP support and procurement are consolidated into a service organization. That organization operates like an internal provider, often with service level agreements (SLAs), chargeback or showback mechanisms, and a service catalog. Business units keep control over strategic, differentiating capabilities. This approach balances efficiency with responsiveness and supports a customer-oriented, performance-measured IT culture. From a CGEIT perspective, no single model is inherently correct. Governance requires choosing the model that fits enterprise strategy, culture, risk appetite and maturity. It also requires defining clear decision rights (for example, through RACI charts), establishing portfolio and investment oversight, monitoring performance and benefits, and periodically reassessing the model as business conditions change.
Centralized, Decentralized and Shared-Service IT Resourcing (CGEIT – IT Resources Domain)
Overview
In the CGEIT (Certified in the Governance of Enterprise IT) exam, the IT Resources domain tests whether you can make sure the enterprise has the right IT capabilities (people, information, infrastructure and applications) to meet its current and future needs. A key part of this is the resourcing model: how IT resources are organized, owned, funded and delivered. The three main models are centralized, decentralized and shared-service resourcing. Hybrid or federated mixes of these are also common. This guide explains why the topic matters, what each model is, how it works in practice and how to answer exam questions on it.
Why It Is Important
The resourcing model is a governance decision, not just an IT operations decision. It shapes:
• Value delivery: whether IT investments support enterprise strategy or only local business unit goals.
• Cost optimization: economies of scale, duplication of effort and total cost of ownership.
• Risk management: consistency of security controls, compliance, data protection and resilience.
• Agility and responsiveness: how quickly IT can respond to business unit and market needs.
• Accountability: who owns IT decisions, budgets and outcomes.
• Standardization and architecture: whether there is one coherent enterprise architecture or a patchwork of platforms.
Boards and executive management must pick a model that fits the enterprise's strategy, culture, regulatory environment, size and geography. A poor fit leads to wasted spending, shadow IT, inconsistent controls, slow service and frustrated stakeholders. CGEIT expects you to judge which model best balances benefits realization, risk optimization and resource optimization, the three governance objectives found in COBIT.
What It Is: The Three Models
1. Centralized IT Resourcing
All or most IT resources (staff, budget, infrastructure, applications, decision rights) sit in a single corporate IT function, usually led by the CIO. Business units consume services from this one function.
Advantages:
• Economies of scale and stronger negotiating power with vendors.
• Standardized architecture, platforms and processes.
• Consistent security, compliance and risk controls.
• Clear accountability and easier enterprise-wide governance.
• Less duplication and lower overall cost.
• Easier enterprise-wide data integration and reporting.
Disadvantages:
• Can be slow to respond to local business needs.
• Seen as bureaucratic or out of touch with the business.
• Risk of shadow IT when business units go around central IT.
• Possible bottlenecks in prioritization.
Best suited to: heavily regulated enterprises, organizations with similar business units, cost-focused strategies, and strategies that need strong integration and standardization.
2. Decentralized IT Resourcing
IT resources and decision rights are spread across business units, divisions or regions. Each unit has its own IT staff, budget and often its own systems.
Advantages:
• High responsiveness and close alignment with local business needs.
• Business units feel ownership of, and accountability for, IT.
• Faster local decisions and innovation.
• Better fit for diverse business models or geographies.
Disadvantages:
• Duplicated systems, licenses, skills and infrastructure.
• Higher total cost and weaker economies of scale.
• Inconsistent security and compliance, which raises enterprise risk.
• Difficult enterprise-wide integration, data sharing and reporting.
• Fragmented architecture and weak enterprise-level governance visibility.
Best suited to: conglomerates with very different businesses, enterprises that value local autonomy and speed, and growth by acquisition where units run independently.
3. Shared-Service IT Resourcing
Common IT services (data centers, networks, service desk, ERP support, procurement and so on) are consolidated into a shared service organization or center. This unit serves multiple business units like an internal service provider. It typically works under service level agreements (SLAs), a service catalog and chargeback or showback mechanisms. Business-specific or strategic IT may stay inside the business units.
Advantages:
• Combines centralized efficiency with a customer-focused, market-like orientation.
• Standardized, repeatable services with measurable performance.
• Transparent costs through chargeback, which encourages responsible consumption.
• Business units can focus on their core capabilities.
• Can be a step toward outsourcing or a benchmark against external providers.
Disadvantages:
• Needs mature service management (for example ITIL), costing and SLA practices.
• Business units may dispute chargeback rates or service quality.
• Can drift toward a cost focus at the expense of innovation.
• Setup costs and organizational change resistance.
Best suited to: large, multi-unit enterprises that want efficiency and accountability for commodity services while keeping some local flexibility.
Hybrid / Federated Models
Most large enterprises use a federated approach. Infrastructure, security, architecture standards and enterprise applications are centralized or delivered as shared services, while business-specific applications and relationship management are decentralized. CGEIT often favors a balanced, fit-for-purpose answer over a pure model.
How It Works in Practice
1. Start from enterprise strategy
The resourcing model should follow from business strategy, operating model and governance principles. An enterprise pursuing synergy and standardization leans toward centralization or shared services. A diversified holding company leans toward decentralization.
2. Define decision rights
Using frameworks such as Weill and Ross's IT governance archetypes (business monarchy, IT monarchy, federal, duopoly, feudal, anarchy), the enterprise decides who makes which decisions in five areas: IT principles, architecture, infrastructure, business application needs and investment prioritization. Centralized models put more decisions with corporate or IT leadership. Decentralized models give business units more rights. Federated models share them.
3. Establish governance structures
• IT strategy committee at board level.
• IT steering committee for investment prioritization.
• Architecture review board for standards.
• Business relationship managers to link shared or central IT with business units.
• Clear policies, standards and RACI charts.
4. Set up funding and cost allocation
Options include:
• Corporate overhead funding (common in centralized models).
• Business unit budgets (decentralized).
• Chargeback or showback based on consumption (shared services).
Transparent cost allocation drives accountability and informed demand.
5. Manage service delivery and performance
Use SLAs, OLAs, service catalogs, KPIs and balanced scorecards to monitor performance, customer satisfaction and value. Shared services in particular depend on mature service management.
6. Manage people and skills
The model affects career paths, skills, culture and retention. Centralization can build deep specialist pools. Decentralization builds business-domain knowledge. Workforce planning, competency frameworks and sourcing strategy (in-house, outsourced, cloud) must line up with the chosen model.
7. Review and adapt
Resourcing models should be revisited when strategy shifts, after mergers and acquisitions, during digital transformation, or when performance and risk indicators show problems.
Relationship to COBIT and Related Concepts
• COBIT EDM04 (Ensure Resource Optimization): the board evaluates, directs and monitors that adequate and sufficient IT capabilities are available and used effectively.
• APO07 (Managed Human Resources) and APO10 (Managed Vendors) support resourcing.
• APO09 (Managed Service Agreements) underpins shared service SLAs.
• APO06 (Managed Budget and Costs) covers chargeback and cost allocation.
• Design factors in COBIT 2019 (enterprise strategy, size, sourcing model, IT implementation methods) influence the governance system design.
Exam Tips: Answering Questions on Centralized, Decentralized and Shared-Service IT Resourcing
1. Think like a governance professional, not a technician.
CGEIT answers favor alignment with enterprise strategy, value delivery, risk optimization and resource optimization. Pick the option that addresses the enterprise-wide view and board-level accountability.
2. Strategy alignment comes first.
If a question asks what should be done FIRST or what MOST influences the choice of model, the answer is usually to align with or understand business strategy and objectives. It is rarely a technical or cost factor considered alone.
3. Match clues to models.
• Clues such as duplication, high costs, inconsistent security, integration problems, lack of standards point to too much decentralization. Remedies are centralizing, adopting shared services or setting enterprise standards.
• Clues such as slow response, business frustration, shadow IT, lack of business alignment point to over-centralization. Remedies are business relationship management, federated decision rights or more local involvement.
• Clues such as internal customers, SLAs, chargeback, service catalog, economies of scale with accountability point to shared services.
4. Know the main benefit of each model.
• Centralized: economies of scale, standardization, control, consistent risk management.
• Decentralized: responsiveness, business ownership, flexibility.
• Shared services: efficiency plus cost transparency and service accountability.
5. Know the main risk of each model.
• Centralized: poor responsiveness and misalignment with business units.
• Decentralized: duplication, higher cost, fragmented controls and compliance risk.
• Shared services: disputes over chargeback, focus on cost over value, and dependence on service management maturity.
6. Prefer balanced or hybrid answers when the scenario is complex.
For large, diverse enterprises, an option describing a federated model (central standards and infrastructure, local application ownership) is often the BEST answer.
7. Watch for governance enablers.
Strong answers often mention defined decision rights, an IT steering committee, SLAs, cost allocation, enterprise architecture and performance measurement. Without these, no model succeeds.
8. Chargeback questions.
The main governance benefit of chargeback is accountability and informed demand management, through transparency of IT costs to consumers. Its purpose is not to generate profit.
9. Mergers and acquisitions scenarios.
After an acquisition, the best first step is usually to assess the current resourcing, architecture and capabilities against the combined enterprise strategy before consolidating.
10. Avoid extreme or tactical answers.
Options such as 'outsource all IT immediately,' 'fire business unit IT staff' or 'buy a new tool' are rarely correct. CGEIT rewards structured, stakeholder-inclusive, strategy-driven approaches.
11. Remember stakeholder involvement.
Any change in resourcing model needs business stakeholder buy-in, change management and communication. Answers that include business leadership tend to beat IT-only approaches.
12. Read qualifiers carefully.
Words like BEST, MOST, PRIMARY and FIRST matter. Eliminate options that are true but secondary, and choose the one with the broadest governance impact.
Sample Question Walkthrough
Question: A global enterprise with autonomous business units finds that each unit runs its own data center and security tools. This causes high costs and inconsistent compliance. Which approach would BEST address this while preserving business responsiveness?
A. Fully centralize all IT functions under corporate IT
B. Establish shared services for infrastructure and security, with business units retaining application ownership
C. Allow each unit to continue but require annual audits
D. Outsource all IT to a single vendor
Answer: B. It achieves economies of scale and consistent controls for commodity services (resource and risk optimization) while keeping business alignment (value delivery). A sacrifices responsiveness, C does not fix the root cause, and D is extreme and ignores strategy.
Key Takeaways
• The resourcing model must follow enterprise strategy and governance principles.
• Centralized means control and efficiency. Decentralized means agility and ownership. Shared services means efficiency with service accountability.
• Most enterprises benefit from a hybrid or federated approach.
• Success depends on clear decision rights, funding mechanisms, SLAs, architecture standards and performance monitoring.
• In the exam, choose answers that balance benefits, risks and resources from an enterprise-wide, board-level perspective.
Unlock Premium Access
Certified in the Governance of Enterprise IT
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2995 Superior-grade Certified in the Governance of Enterprise IT practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CGEIT: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!