Human Resource Competency Assessment
In the CGEIT framework, Human Resource Competency Assessment belongs to the IT Resources domain. It is the structured process of evaluating whether the enterprise's IT workforce has the knowledge, skills, behaviors and capacity needed to deliver business value and support strategic objectives. Gove… In the CGEIT framework, Human Resource Competency Assessment belongs to the IT Resources domain. It is the structured process of evaluating whether the enterprise's IT workforce has the knowledge, skills, behaviors and capacity needed to deliver business value and support strategic objectives. Governance professionals treat people as a critical IT resource, alongside information, applications and infrastructure, and ensure that human capabilities are optimized, developed and aligned with enterprise goals. The assessment begins with defining required competencies. These are derived from the enterprise strategy, the IT strategic plan, and architecture roadmaps. Frameworks such as SFIA (Skills Framework for the Information Age), the e-Competence Framework (e-CF), and COBIT practices (for example, APO07 Managed Human Resources) provide standardized competency definitions and proficiency levels. Each role is mapped to a profile of required technical, managerial and soft skills. Next, current competencies are measured using methods such as self-assessments, manager evaluations, certifications, performance reviews, skills inventories and 360-degree feedback. Comparing current capabilities against required profiles produces a gap analysis. The analysis highlights shortages, surpluses, key-person dependencies and succession risks. Governance oversight ensures that the results drive decisions. These include training and development programs, recruitment, outsourcing or sourcing strategies, job rotation, mentoring, and succession planning. The board and executive management should receive reports showing whether IT human resources are sufficient to execute the portfolio of programs and manage risk. Key governance considerations include: - Aligning competency requirements with business strategy. - Ensuring assessments are objective, repeatable and periodically refreshed. - Integrating results into resource planning and investment decisions. - Managing risks from skill gaps or reliance on critical individuals. - Measuring effectiveness through metrics such as training completion, staff retention, skill coverage and project success rates. Ultimately, competency assessment allows the enterprise to optimize its investment in people. It sustains capabilities for innovation and operations and ensures that IT can reliably deliver value, which is a core CGEIT objective of resource optimization.
Human Resource Competency Assessment (CGEIT - IT Resources)
Human Resource Competency Assessment: A Complete CGEIT Guide
Human Resource Competency Assessment belongs to the CGEIT domain on IT Resources. In CGEIT terms, people are the most important enabler of IT-related value. Technology, processes and information can only produce benefits if the right people, with the right skills, are in the right roles at the right time.
1. What Is Human Resource Competency Assessment?
Human Resource Competency Assessment is the structured, ongoing process of evaluating the knowledge, skills, abilities and behaviours of IT staff and business stakeholders. The assessment compares these against the competencies the enterprise needs to achieve its IT-related and business objectives.
It answers three core questions:
• What competencies do we need? These are the required competencies, derived from strategy, architecture, roadmap and service requirements.
• What competencies do we currently have? This is the current-state inventory of skills and capabilities.
• What is the gap, and how do we close it? This is the gap analysis and remediation plan: training, hiring, sourcing, succession and so on.
From a governance perspective, the assessment is not just an HR administrative task. It is a governance mechanism that ensures resource optimization, one of the core governance objectives alongside benefits realization and risk optimization.
2. Why Is It Important?
• Strategic alignment: IT strategy cannot be executed if staff lack the needed skills. Examples include cloud, cybersecurity, data analytics and AI. Competency assessment links workforce capability to strategic goals.
• Resource optimization: Boards and executives must ensure IT resources, including people, are used efficiently and effectively. Knowing staff competencies avoids over-hiring, underutilization and misallocation.
• Risk management: Skill gaps create operational, security and project risks. Other people-related risks include key-person dependency, single points of failure, loss of institutional knowledge and inadequate segregation of duties.
• Value delivery: Competent staff deliver projects on time and on budget and run services reliably. These are prerequisites for benefits realization.
• Sourcing decisions: Assessment informs the decision on whether to build (train internally), buy (hire) or borrow (outsource or contract).
• Succession planning and continuity: It identifies critical roles and potential successors, ensuring business continuity.
• Compliance and accountability: Some regulations and frameworks require evidence that personnel are competent. Examples include security certifications and segregation-of-duties knowledge.
• Motivation and retention: Clear competency frameworks support career paths, objective performance management and employee engagement.
3. Key Frameworks and Concepts
• COBIT 2019: People, Skills and Competencies is one of the seven governance components (enablers). Relevant objectives include:
- EDM04 Ensured Resource Optimization, which evaluates, directs and monitors resource adequacy, including people.
- APO07 Managed Human Resources, which covers acquiring and maintaining adequate staff, identifying key personnel, maintaining skills and competencies, assessing and recognizing performance, planning and tracking usage, and managing contract staff.
• SFIA (Skills Framework for the Information Age): This is a common reference model describing IT skills across seven levels of responsibility.
• e-CF (European e-Competence Framework, EN 16234): This framework defines ICT competencies across five proficiency levels.
• RACI charts: These define who is Responsible, Accountable, Consulted and Informed. The competency requirements for each role should be clear.
• Competency vs. skill vs. knowledge:
- Knowledge is what one knows.
- Skill is the ability to apply that knowledge.
- Competency combines knowledge, skills, behaviours and attitudes demonstrated in a work context.
4. How It Works: The Competency Assessment Lifecycle
Step 1: Understand strategic and operational requirements.
Start from enterprise goals, the IT strategy, the enterprise architecture, the project portfolio and service catalog. Determine which capabilities will be needed now and in the future.
Step 2: Define the competency framework and role profiles.
Create or adopt a competency model, such as SFIA. Then define job roles, their required competencies and the proficiency levels for each role.
Step 3: Assess current competencies.
Common methods include:
• self-assessments;
• manager assessments;
• 360-degree feedback;
• skills inventories;
• certifications and qualifications;
• practical tests or simulations;
• performance reviews;
• interviews.
Using multiple methods improves objectivity.
Step 4: Perform gap analysis.
Compare required competencies against current competencies, at the individual, team and enterprise level. Prioritize gaps based on strategic importance and risk.
Step 5: Develop remediation and workforce plans.
Options include:
• training and certification;
• mentoring and coaching;
• job rotation;
• recruitment;
• contracting or outsourcing;
• restructuring;
• succession planning;
• knowledge transfer and documentation.
Step 6: Implement and integrate with HR processes.
Link the assessment to recruitment, onboarding, performance management, rewards, career development and termination procedures.
Step 7: Monitor, measure and report.
Use metrics such as:
• percentage of staff meeting role competency requirements;
• skill gap closure rate;
• training effectiveness;
• turnover in critical roles;
• percentage of critical roles with identified successors;
• dependency on key individuals.
Report these to IT management and governance bodies.
Step 8: Review periodically.
Competency needs change with strategy and technology, so assessment must be continuous, not a one-off event.
5. Roles and Responsibilities
• Board / Governance body: Ensures resources, including people, are adequate to support strategy (EDM04). It sets direction and monitors outcomes.
• Executive management / CIO: Owns the IT workforce strategy and ensures the competency framework aligns with business goals.
• HR function: Provides methods, tools and processes. It partners with IT; it does not own IT competency requirements alone.
• IT line managers: Conduct assessments, identify gaps and support development.
• Employees: Participate in self-assessment and development.
• IT steering committee / Strategy committee: Considers resource capability when prioritizing investments.
6. Common Challenges
• Assessments that are not linked to strategy, which become mere checklists.
• Reliance solely on self-assessment, which introduces bias.
• Rapid technology change making competency models outdated.
• Lack of senior management sponsorship.
• Siloed HR and IT functions.
• Ignoring competencies of business stakeholders, such as business relationship management, benefits ownership and governance literacy.
• Overlooking third-party and contractor competencies.
7. Exam Tips: Answering Questions on Human Resource Competency Assessment
Tip 1: Think like a governance professional, not a technician or HR clerk.
CGEIT questions favour answers that align people capability with enterprise strategy and value. When in doubt, choose the option that links competencies to business objectives.
Tip 2: Strategy comes first.
If asked what to do FIRST when assessing competencies, the best answer is usually to understand strategic requirements and define needed competencies. Assessing staff or launching training comes later. You cannot measure a gap without knowing the target.
Tip 3: Gap analysis before solutions.
Training, hiring or outsourcing are remedies. They are rarely the best FIRST step. Look for answers that identify gaps before prescribing actions.
Tip 4: Recognize key-person risk.
Scenarios may describe a single expert holding critical knowledge. The best governance responses include:
• succession planning;
• cross-training;
• knowledge documentation;
• job rotation.
Do not pick answers like 'give the person a raise' as the primary governance control.
Tip 5: Board vs. management roles.
The board directs and monitors resource adequacy. Management executes assessments and development. Choose answers that keep these roles distinct.
Tip 6: Continuous, not one-time.
Prefer answers describing periodic, ongoing assessment integrated into HR processes over one-time audits.
Tip 7: Objectivity and multiple sources.
Answers that combine methods (manager review, certifications, 360 feedback) beat answers relying only on self-assessment.
Tip 8: Connect to sourcing decisions.
When a question involves outsourcing, remember that the enterprise must retain competencies to manage and govern the vendor. Examples include contract management, vendor oversight and architecture. Outsourcing does not outsource accountability.
Tip 9: Use COBIT vocabulary.
Recognize the following:
• APO07 (Managed Human Resources);
• EDM04 (Ensured Resource Optimization);
• People, Skills and Competencies as a governance component.
Answers referencing alignment, value, risk and resource optimization are usually correct.
Tip 10: Watch for 'MOST', 'BEST', 'PRIMARY' keywords.
Several options may be partially correct. Select the one with the broadest governance impact and strongest strategic linkage.
Tip 11: Metrics matter.
If asked how to measure effectiveness, prefer outcome-oriented metrics over activity metrics. For example, 'percentage of critical roles filled by staff meeting competency requirements' is better than 'number of training hours delivered'.
8. Sample Exam-Style Question
An enterprise is adopting a cloud-first strategy. The CIO is concerned that current IT staff may not be able to support the transition. What should be done FIRST?
A. Send all staff to cloud certification training
B. Outsource cloud operations to a managed service provider
C. Define required cloud competencies and assess current staff against them
D. Hire experienced cloud architects
Answer: C. Defining required competencies and performing a gap analysis must precede any remediation. A, B and D are possible remedies, but each is premature without understanding the gap.
9. Key Takeaways
• Competency assessment is a governance tool for resource optimization, risk reduction and value delivery.
• Always begin with strategy-derived requirements, then assess, analyze gaps, remediate and monitor.
• Integrate it with HR processes and make it continuous.
• Address key-person dependency and retained competencies when outsourcing.
• In the exam, choose answers that are strategic, structured, objective and accountability-aware.
Unlock Premium Access
Certified in the Governance of Enterprise IT
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2995 Superior-grade Certified in the Governance of Enterprise IT practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CGEIT: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!