CPA (ISC) • INFORMATION SYSTEMS

Evaluate IT Governance Structures And Responsibilities

Understanding how organizations align IT decision-making with strategic objectives to safeguard stakeholder value.

Historical Context & Motivation

The concept of IT governance did not emerge in a vacuum; it evolved in direct response to a series of corporate failures, regulatory mandates, and the rapid digitization of business processes. In the 1990s, organizations began to recognize that information technology was no longer a back-office support function but rather a strategic asset capable of creating or destroying shareholder value. As enterprises invested billions of dollars in enterprise resource planning systems, data warehouses, and internet-based platforms, boards of directors and C-suite executives found themselves ill-equipped to oversee the risks and returns associated with these investments. The absence of formal governance mechanisms led to spectacular failures—cost overruns, security breaches, and compliance violations—that eroded investor confidence and triggered regulatory scrutiny.

1996
COBIT 1.0 Released
The Information Systems Audit and Control Association (ISACA) published the first edition of COBIT, establishing a framework for IT audit and control that laid the groundwork for formal IT governance.
2002
Sarbanes-Oxley Act (SOX)
In the wake of Enron and WorldCom, SOX mandated that public companies establish internal controls over financial reporting—including IT controls—elevating IT governance from best practice to legal requirement.
2005
ISO/IEC 38500 Development Begins
The International Organization for Standardization began developing the first international standard dedicated to corporate governance of information technology, codifying board-level responsibilities.
2012
COBIT 5 Integrates Governance & Management
ISACA released COBIT 5, which explicitly separated governance processes (Evaluate, Direct, Monitor) from management processes, providing a comprehensive enterprise IT governance model.
2019
COBIT 2019 and Modern Risk Frameworks
COBIT 2019 introduced design factors and focus areas to tailor governance structures to enterprise-specific needs, reflecting the growing complexity of cloud computing, AI, and cybersecurity.

The central question that IT governance seeks to answer remains deceptively simple: Who makes IT decisions, how are those decisions made, and how are decision-makers held accountable? For CPA candidates preparing for the ISC exam, understanding these governance structures is essential because auditors must evaluate whether an organization's IT environment supports reliable financial reporting, regulatory compliance, and effective risk management.

Core Principles & Definitions

At its foundation, IT governance rests on several interrelated principles that distinguish it from day-to-day IT management. While IT management deals with planning, building, running, and monitoring IT activities, IT governance operates at the board and executive level, establishing the policies, structures, and accountability mechanisms that ensure IT supports strategic objectives. The ISO/IEC 38500 standard distills governance into three core activities: Evaluate, Direct, and Monitor (EDM). These three activities form a continuous cycle that the governing body uses to oversee IT's contribution to enterprise value.

1

Strategic Alignment

IT investments and activities must be aligned with the organization's strategic goals. The governance structure ensures that IT priorities are derived from—and traceable to—business objectives.
2

Value Delivery

IT governance ensures that IT investments deliver measurable value by optimizing costs, managing benefits realization, and confirming that projects yield their intended outcomes within acceptable risk parameters.
3

Risk Management

A governance framework integrates IT risk into the enterprise risk management process, ensuring that cybersecurity threats, system failures, and compliance gaps are identified, assessed, and mitigated systematically.
4

Resource Optimization

Governance structures define how IT resources—people, technology, data, and budget—are acquired, allocated, and utilized to achieve maximum efficiency and effectiveness across the enterprise.
5

Performance Measurement

Through balanced scorecards, key performance indicators, and maturity models, governance mechanisms track IT performance and provide transparency to stakeholders including auditors and regulators.
KEY TAKEAWAY
KEY TAKEAWAY

Visual Explanation — IT Governance Structure

The diagram illustrates the hierarchical IT governance structure from the Board of Directors at the top, through the IT Strategy Committee and IT Steering Committee, down to operational roles. Policy flows downward while accountability flows upward.

The diagram above represents a typical IT governance hierarchy found in publicly traded companies. At the apex, the Board of Directors exercises its Evaluate, Direct, and Monitor responsibilities through a dedicated IT Strategy Committee—a board-level committee that includes senior executives and, ideally, at least one director with significant technology expertise. Below that sits the IT Steering Committee, which translates strategic directives into project priorities and resource allocations. The operational layer—comprising the Chief Information Officer, Chief Information Security Officer, and Internal Audit function—executes and monitors IT activities on a day-to-day basis, with clear reporting lines back up to the governing bodies. For CPA candidates, the critical observation is that Internal Audit maintains an independent reporting line to the audit committee of the board, preserving objectivity in its assessment of IT controls.

How IT Governance Works — The EDM Cycle & RACI Framework

IT governance operates through a structured decision-making cycle and clearly defined responsibilities. Two foundational mechanisms are the Evaluate-Direct-Monitor (EDM) cycle codified in ISO/IEC 38500 and the RACI matrix (Responsible, Accountable, Consulted, Informed) used extensively in COBIT to assign process-level roles. Understanding these mechanisms is essential because auditors evaluate whether the governance structure includes clear accountability and whether the right stakeholders are involved in IT decisions that affect financial reporting integrity.

The EDM Cycle

The Evaluate phase requires the governing body to assess the current and future use of IT, considering stakeholder needs, competitive pressures, and regulatory requirements. In the Direct phase, the board issues policies and guidelines that steer IT strategy, investment decisions, and risk tolerance thresholds. Finally, the Monitor phase involves reviewing performance metrics, audit reports, and compliance dashboards to verify that directives are being followed and objectives are being met. This cycle is continuous; the outputs of monitoring feed back into the next evaluation, creating a feedback loop similar to the Plan-Do-Check-Act cycle familiar from quality management.

The RACI Matrix

RACI Matrix — Defining Governance Roles and Responsibilities
RACI RoleDefinitionExample in IT Governance
Responsible (R)The person or group that performs the work to complete the activity.IT Security team implements firewall configuration changes.
Accountable (A)The single individual who is ultimately answerable for the activity; has authority to approve or reject outcomes.CISO is accountable for overall security posture and signs off on policy exceptions.
Consulted (C)Subject-matter experts whose input is sought before a decision is made; two-way communication.Legal counsel is consulted on data privacy implications before deploying a new CRM system.
Informed (I)Stakeholders who are kept updated on progress or decisions; one-way communication.The audit committee is informed of material IT incidents and remediation status.
CPA Exam Tip

Key IT Governance Frameworks — COBIT, ITIL, and ISO 38500

Several frameworks provide structured approaches to implementing IT governance, and CPA candidates should understand how they complement each other. The three most relevant frameworks for auditors are COBIT (Control Objectives for Information and Related Technologies), ITIL (Information Technology Infrastructure Library), and ISO/IEC 38500. While COBIT provides the most comprehensive governance and management framework, ITIL focuses on IT service management, and ISO 38500 addresses the board-level governance principles. In practice, organizations often layer multiple frameworks, using COBIT for governance processes, ITIL for service delivery, and ISO 38500 for board-level oversight standards.

This Venn-style diagram illustrates how COBIT provides the broadest governance and management coverage, ITIL specializes in service management, and ISO 38500 sets board-level governance principles. The overlap zone represents shared concerns: IT controls, risk management, and compliance.
Comparison of Major IT Governance and Related Frameworks
FrameworkIssuing BodyPrimary FocusCPA Exam Relevance
COBIT 2019ISACAEnd-to-end governance and management of enterprise IT; 40 objectives across 5 domainsHigh — Most frequently tested IT governance framework
ITIL 4Axelos / PeopleCertIT service management best practices; service value system and 34 management practicesModerate — Relevant to IT operations and change management controls
ISO/IEC 38500ISO / IECHigh-level governance principles for boards of directors; Evaluate-Direct-Monitor modelModerate — Tested as a conceptual governance model
COSO ERMCOSOEnterprise risk management framework that IT governance integrates with for risk alignmentHigh — COSO Internal Control framework is foundational to SOX compliance

Worked Example — Evaluating an IT Governance Structure

Consider the following scenario: you are a CPA performing an IT governance review for Apex Financial Corp., a mid-size publicly traded company. You have been provided with the company's IT organizational chart, committee charters, and recent board meeting minutes. Your task is to evaluate whether the governance structure is adequate to support reliable financial reporting and regulatory compliance.

1
Step 1 — Identify the Governance StructureReview the organizational chart to identify the key governance bodies. Apex has a Board Audit Committee, an IT Strategy Committee chaired by the CFO, and an IT Steering Committee chaired by the CIO. The CISO reports to the CIO. There is no separate IT Risk Committee.
Three governance bodies identified; CISO reporting line noted as potential concern.
2
Step 2 — Assess Roles and Responsibilities Using RACIMap key IT governance activities to RACI roles. For IT investment decisions: the IT Steering Committee is Responsible, the CFO (as IT Strategy Committee chair) is Accountable, business unit leaders are Consulted, and the Board Audit Committee is Informed. For cybersecurity risk: the CISO is Responsible, but the CIO—not an independent risk function—is Accountable. This creates a potential segregation of duties issue because the CIO also manages IT operations that generate the risks the CISO is supposed to mitigate.
Deficiency: CISO reporting to CIO may compromise independent risk oversight.
3
Step 3 — Evaluate Against Framework Criteria (COBIT EDM Domain)Check whether each EDM process is addressed. EDM01 (Ensure Governance Framework Setting and Maintenance): Apex has committee charters but they have not been updated in three years. EDM02 (Ensure Benefits Delivery): Post-implementation reviews are not consistently performed. EDM03 (Ensure Risk Optimization): IT risk is not formally integrated into enterprise risk management. EDM04 (Ensure Resource Optimization): IT budgets are reviewed annually by the IT Strategy Committee. EDM05 (Ensure Stakeholder Engagement): Board receives quarterly IT updates.
Gaps found in EDM01 (stale charters), EDM02 (no post-implementation reviews), and EDM03 (IT risk not integrated into ERM).
4
Step 4 — Formulate Findings and RecommendationsDocument findings with their potential impact on financial reporting. The CISO reporting line increases the risk that security vulnerabilities affecting financial systems may not be escalated independently. Stale charters mean that governance roles may not reflect current regulatory requirements (e.g., new SEC cybersecurity disclosure rules). The absence of ERM integration means that IT risks may not be appropriately weighted in the entity's overall risk assessment.
Recommendations: (1) CISO should report directly to the Board Audit Committee or CEO; (2) Update committee charters annually; (3) Integrate IT risk into the COSO ERM framework.

Strengths and Limitations of Common Governance Structures

No single IT governance structure is universally optimal. Organizations must weigh the strengths and limitations of different structural approaches based on their size, industry, regulatory environment, and risk profile. Understanding these trade-offs is vital for CPA candidates, who must not only identify governance structures but also assess their effectiveness in a given context.

Comparison of IT Governance Structural Approaches
Governance StructureStrengthsLimitations
Centralized IT GovernanceConsistent policies and standards; strong control environment; economies of scale in procurement; clearer accountability lines.Slower response to local business unit needs; potential bottlenecks in decision-making; reduced innovation at the operational level.
Decentralized IT GovernanceHigh responsiveness to individual business unit requirements; encourages innovation; empowers local management.Inconsistent policies and controls; duplication of resources; higher risk of control gaps; challenging for enterprise-wide compliance.
Federated (Hybrid) IT GovernanceBalances standardization with flexibility; central policies with local execution; commonly adopted by large enterprises.Complex to implement and manage; requires mature communication channels; risk of ambiguous accountability if roles are not clearly defined.
Board-Level IT CommitteeEnsures board-level oversight; aligns IT with fiduciary responsibilities; demonstrates 'tone at the top' for technology risk.Requires directors with sufficient IT expertise; may create additional governance overhead; effectiveness depends on committee composition.
KEY TAKEAWAY
KEY TAKEAWAY

Connection to Advanced Theory — IT Governance in Cloud and Digital Transformation

As organizations increasingly adopt cloud computing, artificial intelligence, and third-party managed services, IT governance must evolve to address new complexities. Traditional governance structures assumed that the organization owned and operated most of its IT infrastructure, but cloud computing introduces a shared responsibility model where the cloud service provider manages infrastructure-level controls while the customer retains responsibility for data classification, access management, and application-layer controls. This shared model demands that governance structures explicitly assign accountability for each layer of the technology stack and that audit procedures verify whether the division of responsibilities is clearly documented and monitored.

Traditional vs. Cloud-Era IT Governance Considerations
Governance DimensionTraditional On-PremiseCloud / Digital Transformation
Control over InfrastructureFull internal control; physical and logical access managed by the organization.Shared responsibility; reliance on SOC 2 reports from cloud providers for infrastructure controls.
Vendor GovernanceLimited third-party dependency; vendor management focused on hardware and software licensing.Extensive third-party risk management; governance must include vendor due diligence, SLA monitoring, and exit strategies.
Data GovernanceData resides within the organization's perimeter; location and sovereignty are straightforward.Data may reside in multiple jurisdictions; governance must address data residency, privacy regulations (GDPR, CCPA), and encryption requirements.
Change ManagementFormal change advisory boards with scheduled release windows.Continuous deployment pipelines; governance must adapt to DevOps and CI/CD practices while maintaining control.

For CPA candidates, the takeaway is that evaluating IT governance in the modern environment requires an understanding of how complementary user entity controls (CUECs) operate in conjunction with a service organization's controls, and how SOC 1 and SOC 2 reports provide assurance about third-party governance. As you progress in your career, expect IT governance evaluation to increasingly intersect with topics like AI ethics governance, data privacy impact assessments, and resilience planning for systemic technology risks.

Practice Problems

PROBLEM 1CONCEPTUAL
An IS auditor is evaluating internal controls over financial reporting (ICFR) at a publicly traded company. During planning, the auditor identifies several observations. For each observation below, select whether it represents an IT Governance issue, an IT Management issue, or Both.
PROBLEM 2BASIC CALCULATION
A company's IT Steering Committee approved five projects with the following budgets: ERP Upgrade ($2.4M), Cybersecurity Enhancement ($800K), Cloud Migration ($1.6M), Data Analytics Platform ($1.2M), and Regulatory Compliance System ($600K). If the governance policy requires that at least 20% of the total IT investment portfolio be allocated to risk mitigation projects (cybersecurity and compliance combined), does the current portfolio comply?
PROBLEM 3INTERMEDIATE
You are reviewing the RACI chart for a company's change management process. The chart shows that the CIO is both Responsible and Accountable for approving emergency changes to production systems, while the IT Steering Committee is only Informed. Identify the governance weakness and explain how it could affect financial reporting.
PROBLEM 4APPLIED
GlobalTech Inc. recently migrated its financial reporting system to a major public cloud provider. During your IT governance evaluation, you discover that (a) the company relies on the cloud provider's SOC 2 Type II report for infrastructure controls but has not reviewed the report's complementary user entity controls (CUECs), (b) there is no vendor governance policy, and (c) the board has not been briefed on the shared responsibility model. Assess the governance risks and recommend corrective actions.
PROBLEM 5CRITICAL THINKING
A mid-size financial services firm operates with a fully decentralized IT governance model: each of its four business units maintains its own IT infrastructure, security policies, and change management processes. The firm recently failed a regulatory examination due to inconsistent access controls across business units. The CEO proposes moving to a fully centralized governance model. As a CPA advisor, critically evaluate this proposal. What alternative governance design might better serve the organization, and what factors should the board consider?
Varsity Tutors • CPA (ISC) • Evaluate IT Governance Structures And Responsibilities