COBIT Controversies

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

Heavy framework

40 objectives × multiple practices × multiple activities × capability levels:

  • Substantial documentation burden.
  • Implementation complexity.
  • Overhead disproportionate for smaller orgs.

ITIL overlap

ITIL and COBIT both touch IT service management:

  • Combined implementations double overhead.
  • Some confusion on responsibilities.
  • COBIT design factors help but don't fully resolve.

Governance-management distinction in practice

EDM (governance) vs APO/BAI/DSS/MEA (management) distinction:

  • Practically often blurred.
  • Smaller orgs collapse governance to management.

Procurement signal limited

Compared to ISO 27001 / SOC 2:

  • COBIT alignment less commonly procurement-requested.
  • Implementation more strategic than procurement-driven.

ISACA certification ecosystem complexity

CISA / CISM / CRISC / CGEIT / CDPSE / COBIT certs:

  • Multiple credential paths.
  • Continuing education obligations.
  • Cost over time accumulates.

Update cadence

COBIT 2019 published 2018. Major revisions infrequent:

  • Cloud / DevOps / AI evolution outpaces.
  • Focus areas partially address.

Counterpoint

  • Genuinely useful governance framework.
  • Cross-framework mapping reduces fragmentation.
  • ISACA backing legitimate.
  • Design factors and focus areas modernize approach.

See also