COBIT 2019 Governance of Fintech Systems Training Course
| Course code | SD-FT-026 |
|---|---|
| Duration | 5 days |
| Level | Foundation to Intermediate |
| Category | Financial Technology |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Fintech organisations must govern payment platforms, digital lending engines, customer-data services, cloud-hosted core systems, API ecosystems and automated decision models without slowing product delivery. When ownership, controls and performance measures are unclear, firms face preventable incidents: failed payment reconciliations, weak third-party oversight, unmanaged regulatory obligations, duplicated controls and technology investments that do not support business priorities. This course equips participants to use COBIT 2019 as a practical governance system for these conditions.
Participants learn how to distinguish governance from management, apply the COBIT 2019 Core Model, and select relevant governance and management objectives for fintech services. They work with objectives including EDM03 Ensured Risk Optimization, APO12 Managed Risk, APO13 Managed Security, BAI03 Managed Solutions Identification and Build, DSS01 Managed Operations and MEA03 Managed Compliance With External Requirements. The course shows how to translate business goals, regulatory expectations and technology risks into a tailored governance design, RACI structure, metrics, control activities and improvement backlog.
Instruction combines guided COBIT 2019 interpretation with a running fintech case involving a cloud-based payments and lending provider. Participants map enterprise goals to alignment goals, assess design factors, identify governance gaps, draft performance measures and prioritise implementation actions. They leave with a completed COBIT-based Fintech Governance Improvement Pack: a scope statement, design-factor assessment, selected objectives, accountability matrix, KPI/KGI dashboard and 90-day implementation roadmap. A certificate of completion is issued at the end of the five-day course.
The programme suits professionals who need to govern technology-enabled financial products across business, risk, compliance, audit and IT teams. It is particularly valuable where a firm is scaling digital services, preparing for regulatory scrutiny, integrating third-party platforms or formalising controls after rapid growth.
Course objectives
By the end of this course, participants will be able to:
- Apply the COBIT 2019 governance system and Core Model to a fintech operating environment
- Map fintech enterprise goals to COBIT alignment goals and prioritised governance objectives
- Assess COBIT 2019 design factors to tailor a governance system for payments, lending or digital-asset services
- Define decision rights and accountability using COBIT RACI charts for fintech product, risk and technology teams
- Build a control and risk traceability matrix linking fintech risks to COBIT objectives and management practices
- Design KPIs, KGIs and capability measures for service reliability, security, compliance and delivery performance
- Evaluate governance gaps against selected COBIT objectives using a structured maturity and capability assessment
- Produce a 90-day COBIT governance implementation roadmap with owners, milestones and prioritised actions
Benefits of attending
For you
- Gain a repeatable method for framing fintech governance issues in COBIT 2019 terms rather than relying on ad hoc control lists
- Build credibility in discussions with risk, compliance, audit and technology leaders by using recognised COBIT objectives and practices
- Create governance artefacts that can support a move into fintech risk, IT governance, technology assurance or control leadership roles
- Learn to defend prioritisation decisions with design factors, risk evidence, accountability assignments and measurable outcomes
- Return with a portfolio-quality Fintech Governance Improvement Pack that demonstrates practical COBIT application
For your organisation
- Establish clearer accountability for product, technology, risk and compliance decisions across digital financial services
- Reduce control gaps by linking key fintech risks to selected COBIT objectives, practices, owners and evidence
- Prioritise governance investment using design factors instead of applying every COBIT objective indiscriminately
- Improve audit and regulatory readiness through traceable metrics, control mappings and documented governance decisions
- Create a practical 90-day improvement backlog for strengthening cloud, API, data, resilience and third-party oversight
Target competencies
Who should attend
- Fintech Governance Managers — who must establish decision rights, performance oversight and accountable technology controls
- Chief Risk Officers and Operational Risk Managers — who need to connect digital-service risks with governance objectives and control ownership
- IT Managers and Technology Directors — who oversee cloud platforms, integrations and delivery teams supporting financial products
- Compliance Managers and Regulatory Affairs Specialists — who must evidence governance over customer data, outsourced services and regulatory obligations
- Information Security Managers — who need to align security management with enterprise risk and fintech service priorities
- Internal Auditors and IT Auditors — who assess whether governance design, controls and assurance evidence are adequate
Requirements and prerequisites
Participants should understand the basic purpose of IT governance, operational risk and internal controls, and should be familiar with at least one fintech environment such as payments, digital banking, lending, wealth technology or financial-data services. Experience reading process maps, risk registers, audit findings or policy documents is useful. No prior COBIT certification is required, and participants do not need to be programmers, security engineers or regulatory lawyers. Complete beginners can attend, but should expect to work with governance terminology including enterprise goals, control objectives, RACI, KPIs, risk appetite and third-party risk.
Training methodology
The instructor introduces each COBIT concept through short, structured teaching segments and then applies it to a running case of a cloud-based fintech provider. Participants use the COBIT 2019 Core Model and Design Toolkit to make scope decisions, complete design-factor assessments, map risks and draft RACI assignments. Small groups compare governance choices for payments, lending, customer-data and outsourced-service scenarios. Daily workshops build sections of one governance pack, while the final session converts findings into an owned 90-day action plan suitable for workplace review.
Course outline
Day 1: COBIT 2019 foundations for fintech governance
- Governance and management distinction in COBIT 2019
- COBIT principles for governance systems and governance frameworks
- COBIT 2019 Core Model domains and objectives
- Fintech value streams for payments, lending and digital onboarding
- Enterprise goals, alignment goals and goal cascade logic
- Governance stakeholders across product, risk, compliance and technology
- COBIT terminology: components, practices, activities and work products
Workshop: Participants map a fintech payment-service scenario from enterprise goals to alignment goals and identify an initial set of relevant COBIT objectives.
Day 2: Tailoring a governance system with design factors
- COBIT 2019 design factors and their tailoring purpose
- Enterprise strategy and business-model design factors
- Risk profile assessment for customer data, fraud, outages and model risk
- Threat landscape analysis for cloud, API and third-party dependencies
- Technology adoption strategy and sourcing-model assessment
- Compliance requirements and regulatory landscape considerations
- Using the COBIT 2019 Design Toolkit to prioritise objectives
Workshop: Working in groups, participants complete a design-factor assessment for a growing digital lender and produce a prioritised objective shortlist.
Day 3: Risk, controls and accountable decision-making
- EDM03 Ensured Risk Optimization for board and executive oversight
- APO12 Managed Risk and fintech risk-register integration
- APO13 Managed Security for data protection and cyber-risk governance
- DSS01 Managed Operations for service availability and incident resilience
- MEA03 Managed Compliance With External Requirements
- RACI charts for governance and management practices
- Risk-control traceability matrices and control evidence design
Workshop: Participants build a risk-control traceability matrix and RACI chart for an API outage and customer-data exposure scenario.
Day 4: Performance, assurance and delivery governance
- BAI03 Managed Solutions Identification and Build for regulated product change
- BAI06 Managed IT Changes and release-control governance
- APO10 Managed Vendors and third-party fintech oversight
- DSS04 Managed Continuity and operational resilience planning
- KGI, KPI and metric cascade design
- COBIT performance management and capability-level assessment
- Assurance reporting for executives, regulators and internal audit
Workshop: Participants design a governance dashboard and assess capability gaps for a cloud payment platform's vendor, change and resilience controls.
Day 5: Implementing the fintech governance improvement plan
- COBIT 2019 implementation lifecycle and continual improvement approach
- Governance scope statements and target-state definition
- Gap analysis against prioritised governance and management objectives
- Improvement initiative prioritisation using risk, value and feasibility criteria
- Ninety-day roadmap sequencing and milestone planning
- Executive governance reporting and decision-paper structure
- Change adoption, ownership and benefits-realisation monitoring
Workshop: Participants consolidate their work into a Fintech Governance Improvement Pack and present a 90-day COBIT implementation roadmap for executive approval.
Tools & standards covered
COBIT 2019 Framework: Governance and Management Objectives, COBIT 2019 Design Toolkit, Jira Software, Microsoft Excel
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Financial Technology
Power BI Financial Technology Analytics Training Course
Financial technology teams generate high-volume data from payment gateways, digital wallets, lending platforms, core banking systems, fraud …
Digital Payment Controls for Internal Auditors Training Course
Digital payment environments create audit exposures that do not fit neatly into traditional cash, accounts receivable, or IT general control…
Islamic Digital Finance Products and Shariah Controls Training Course
Islamic digital finance teams must turn Shariah principles into controls that work inside mobile onboarding, payment journeys, financing eng…
Fintech Regulatory Compliance for Compliance Officers Training Course
Compliance officers in fintech firms must control risks created by rapid product releases, outsourced technology, cross-border payments, dig…