COBIT Framework

How to implement COBIT 2019: A step-by-step guide

Implementing COBIT 2019 does not mean applying all 40 governance and management objectives to your organization at once. The COBIT framework is designed to be tailored to your business strategy, risk profile, regulatory environment, technology needs, and other organizational factors.

 

A better approach is to start with the problem you need to solve, understand where your governance system stands today, define where you need it to be, and then build a practical roadmap to close the gaps.

 

COBIT 2019 organizes this work into a seven-phase implementation life cycle. The phases take you from identifying the reason for change through implementation, measurement, and continuous improvement.

 

 

What does COBIT 2019 implementation involve?

 

Consider COBIT implementation as a cycle, not a one-time framework rollout. You first identify the business or governance driver. Then you examine the current state, define the desired state, determine what needs to change, implement those changes, measure the results, and use what you learn to further improve the governance system.

 

The first three phases also connect closely with COBIT 2019’s governance system design approach. This matters because you should tailor the governance system before you start rolling out processes.

 

How to implement COBIT 2019 in seven phases

 

COBIT 2019 breaks implementation into seven phases, and each phase answers a practical question about your governance needs. Use these questions to move from identifying a governance need to implementing, measuring, and continuously improving your governance system.

 

Phase 1: What are the drivers?

 

Don’t start by opening the COBIT Core Model and selecting objectives. First, identify the business problem or trigger that requires action.

 

For example, suppose your organization has experienced several security incidents and senior leadership wants better visibility into technology risk. Your implementation driver could be:

 

“The organization needs stronger oversight of cyber security risk, clearer accountability, and consistent reporting to senior leadership.”

 

That statement gives you something concrete to work with. It also helps you avoid implementing COBIT simply because someone decided that the organization needs COBIT.

 

Bring the right stakeholders into this discussion. Depending on the issue, that could include the CIO, CISO, risk and compliance leaders, business representatives, and members of the governing body.

 

Your output: A clearly documented business case for improving I&T governance and a defined reason for the initiative.

 

Phase 2: Where are we now?

 

Next, document your current state. Look at how your organization currently makes I&T decisions, manages risk, assigns accountability, operates processes, and measures performance. Review existing policies, procedures, controls, audit findings, risk assessments, reports, and other evidence.

 

Suppose your security governance already includes a risk register, incident process, security policies, and quarterly reporting. You don’t need to rebuild these from scratch. Instead, determine how well they currently work and where they fall short.

 

You might discover, for example, that:

 

  • Security responsibilities exist but overlap between IT and risk teams.
  • Risk assessments happen, but management receives inconsistent reporting.
  • Incident procedures exist, but lessons learned do not consistently feed back into risk management.
  • Security performance metrics focus on technical activity rather than business risk.

 

Those findings give you a much more useful starting point than simply saying your organization is at a “low maturity” level.

 

COBIT implementation guidance also recommends assessing the capability of relevant processes and documenting the current situation before defining the target state.

 

Your output: A documented current-state assessment, including existing capabilities, gaps, blockers, and evidence.

 

Phase 3: Where do we want to be?

 

Now define the governance system you actually need. Consider your enterprise strategy, goals, risk profile, I&T-related issues, technology adoption approach, regulatory requirements, organizational size, and the role I&T plays in your business. Return to the problem you identified in Phase 1.

 

If cyber security risk is the driver, you might prioritize COBIT objectives such as APO12 managed risk, APO13 managed security, DSS05 managed security services, and EDM03 ensured risk optimization.

 

But don’t automatically assign the highest possible capability target to every objective. A process that directly affects a critical business service may need a more advanced target than a low-risk supporting process.

 

Your output: A tailored target state with prioritized objectives, desired outcomes, and appropriate capability targets.

 


 

Phase 4: What needs to change?

 

With the current and target states defined, identify the gaps between them. This is where you turn COBIT from a framework into an improvement plan.

 

Suppose your current security risk process identifies risks and assigns owners, but it does not consistently connect risk ratings to business impact or provide management with consolidated reporting.

 

Your gap is not simply that APO12 is missing. You need to improve how the organization assesses, reports, monitors, and acts on risk. For each significant gap, determine:

 

Current state → required change → owner → priority → expected outcome

 

For example:

 

  • Current: Security risks are maintained separately by different teams.
  • Required change: Establish a common risk assessment and reporting process.
  • Owner: Enterprise risk and security teams.
  • Outcome: Management receives a consolidated view of I&T risk.

 

At this stage, also look for opportunities to reuse existing processes and controls. If ISO 27001, NIST, or another framework already gives you a functioning security process, use it as part of your COBIT governance system rather than creating a duplicate process.

 

Your output: A prioritized gap analysis and list of improvement initiatives.

 

Phase 5: How do we get there?

 

Group related improvements into a roadmap and sequence them according to business importance, dependencies, resources, and expected value. 

 

For example, your cyber security governance roadmap might start with:

 

  • Quarter 1: Establish ownership and a common risk methodology.
  • Quarter 2: Standardize risk reporting and connect security risks to enterprise risk management.
  • Quarter 3: Introduce consistent performance metrics and management reporting.
  • Quarter 4: Reassess process capability and address remaining gaps.

 

The exact timeline will depend on the organization. The key is to define who does what, when, with which resources, and how you will know the change worked.

 

COBIT implementation guidance recommends using a project plan with defined resources, milestones, deliverables, and quick wins, while monitoring progress and escalating high-cost, resource, quality, or schedule issues.

 

Your output: An implementation roadmap with owners, milestones, resources, dependencies, and measurable outcomes.

 

Phase 6: Did we get there?

 

If you wanted consistent cyber security risk reporting, check whether risk owners now use the defined methodology, whether reports contain the information management needs, and whether leadership actually uses those reports to make decisions.

 

You can also assess the capability of the relevant processes using COBIT’s performance management approach.

 

For example, you might find that your security risk process moved from a managed but inconsistent state toward a standardized and more predictable process.

 

Collect evidence rather than relying on self-reported completion. Review process records, reports, approvals, metrics, assessments, and other evidence that demonstrates how the process operates in practice.

 

Your output: An assessment of whether the implemented changes achieved the intended outcomes and where capability gaps remain.

 

Phase 7: How do we keep the momentum going?

 

COBIT implementation should not end when the project plan reaches its final milestone. A process that worked well two years ago may no longer support the organization’s needs.

 

Use the results from Phase 6 to start the next improvement cycle.

 

For example, after improving cyber security risk reporting, you might discover that third-party technology risk still receives inconsistent treatment. That becomes a new improvement priority.

 

This continuous cycle is one of the important ideas behind COBIT 2019 implementation: assess where you are, improve what matters, measure the result, and repeat.

 

Your output: Lessons learned, updated priorities, and the next improvement cycle.

 

Common mistakes to avoid when implementing COBIT

 

A few patterns show up repeatedly in organizations struggling with COBIT implementation:

 

  • Trying to implement all 40 objectives at once: COBIT’s design factors exist specifically so organizations don’t have to do this. Prioritization is a feature, not a shortcut.

 

  • Treating this as a one-time project: Organizations that stop after phase 6 often see governance practices erode within a year, since phase 7’s ongoing monitoring is what sustains the gains.

 

  • Underinvesting in change enablement: Technical design tends to get most of the attention, but resistance from IT and business teams is one of the most common reasons implementations stall.

 

  • No clear ownership: Without a defined RACI structure for key activities, accountability gaps often appear at handoff points between phases.

 

Implement COBIT 2019 without the spreadsheet sprawl

 

Walking through the seven phases on paper is one thing. Running them for real, across multiple objectives, owners, and evidence sources, is where most implementations start to strain. 

 

By Phase 2, teams are usually juggling assessment documents. By Phase 4, gap analysis lives in a separate tracker. By Phase 6, someone is manually chasing down evidence to prove the change actually worked. None of it talks to each other, and the thread connecting a Phase 1 driver to a Phase 6 outcome gets harder to see with every phase.

 

CyberArrow GRC is built to keep that thread intact. With CyberArrow, you can:

 

  • Track capability gaps: See current and target compliance state in one place, instead of scattered assessment documents.

 

  • Assign clear ownership: Give every initiative and control a named owner, so accountability gaps don’t appear between phases.

 

  • Cross-map as you go: Reuse control work across COBIT, ISO 27001, SOC 2, and NIST rather than starting from scratch for each framework, exactly the kind of reuse we called out in Phase 4.

 

  • Automate evidence collection: Connect your tech stack through 80+ integrations so Phase 6 monitoring produces evidence automatically, not manually.

 

 

Whether you’re just identifying your Phase 1 drivers or already mid-implementation, CyberArrow gives you one place to see where every objective stands.

 

Book a free demo with CyberArrow today!

 


 

FAQs

 

How long does it take to implement COBIT 2019?

It depends on scope and organization size. A focused implementation covering a handful of priority objectives might take a few months, while a full enterprise-wide rollout across most of the 40 objectives commonly takes 12 to 18 months or more.

 

Do you need to complete all 7 phases before seeing value?

No. Because the life cycle is iterative, organizations often see meaningful improvement after closing gaps on a small set of priority objectives, well before completing a full cycle across every objective.

 

Who should be involved in a COBIT implementation?

Successful implementations typically involve executive sponsors (often from the governing body for EDM-related work), IT management, process owners for the objectives in scope, and often internal audit or risk teams who rely on the resulting evidence and controls.

 

What’s the difference between COBIT implementation and COBIT design?

Design refers to using COBIT’s design factors to tailor which objectives matter most and how much rigor to apply to each one. Implementation is the operational process- the seven phases- of actually closing the gap between current and target capability for those objectives.

Avatar photo
CyberArrow team