COBIT 2019 IT Governance for Banking and Insurance Training Course
| Course code | SD-BI-035 |
|---|---|
| Duration | 5 days |
| Level | Foundation to Intermediate |
| Category | Banking & Insurance |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Banks and insurers must demonstrate that technology decisions, outsourced services, data controls and cyber investments support regulated business objectives—not merely that policies exist. Risk committees, internal audit teams, technology leaders and control owners need a shared way to connect IT processes with operational resilience, prudential requirements, customer-data protection, financial reporting and measurable risk appetite. COBIT 2019 provides that governance structure, but its value depends on tailoring it to the institution’s products, regulatory obligations, sourcing model and control environment.
This five-day course teaches participants how to apply COBIT 2019 to banking and insurance governance scenarios. Participants work with the COBIT governance and management objectives, design factors, goals cascade, capability levels and performance management approach. They learn to translate business priorities such as digital onboarding, claims-platform modernisation, payment-service resilience, third-party cloud risk and regulatory reporting into governance objectives, practices, metrics and accountable roles. The course also covers practical alignment with ISO/IEC 27001 and NIST Cybersecurity Framework controls.
Instruction combines facilitated framework teaching with banking and insurance case work, control-design workshops and small-group review sessions. Participants build a COBIT 2019 governance design for a fictional regulated financial institution, including a prioritised objective set, design-factor rationale, RACI assignments, performance measures, capability assessment and improvement roadmap. They leave with a reusable governance-design workbook and an action plan for applying COBIT methods to a live function, programme or control issue in their organisation.
The course is suited to foundation-to-intermediate professionals who influence technology risk, IT controls, digital transformation, internal audit, compliance or operational resilience in banks, insurers, lenders, payment firms and financial-services shared-service environments.
Course objectives
By the end of this course, participants will be able to:
- Apply the COBIT 2019 goals cascade to translate banking or insurance business priorities into governance and management objectives
- Assess COBIT 2019 design factors to scope a governance system for a regulated financial institution
- Prioritise COBIT governance and management objectives for scenarios involving cloud services, digital channels and third-party providers
- Map COBIT practices and components to operational resilience, cyber-risk and data-protection control requirements
- Define RACI accountability matrices for board, executive, risk, compliance, IT and control-owner responsibilities
- Measure governance performance using COBIT capability levels, metrics, targets and evidence sources
- Develop a risk-based improvement roadmap that addresses identified IT governance and control gaps
- Produce a COBIT 2019 governance-design workbook for a banking or insurance operating context
Benefits of attending
For you
- Build the ability to justify IT governance priorities in terms understood by risk committees, auditors and business executives
- Gain practical experience designing a COBIT-based control and accountability model for regulated financial services
- Improve credibility when contributing to audit remediation, operational resilience and technology-risk discussions
- Create reusable templates for goals cascades, design-factor assessments, RACI matrices and governance metrics
- Prepare for broader responsibilities in IT governance, technology risk, GRC, internal audit or digital-control leadership
For your organisation
- Establish a more consistent method for linking technology controls to banking or insurance business objectives and risk appetite
- Improve board and committee reporting through defined governance objectives, ownership and measurable performance indicators
- Reduce control gaps in cloud, outsourcing, data and digital-service initiatives through risk-based COBIT prioritisation
- Strengthen audit readiness by creating traceable links between governance practices, evidence sources and remediation actions
- Produce an actionable governance improvement roadmap rather than isolated policy or control updates
Target competencies
Who should attend
- IT Governance Managers — who need to design and maintain accountable technology governance arrangements
- Technology Risk Managers — who must connect IT risk treatment to risk appetite, control ownership and reporting
- Internal Auditors — who assess IT controls and need a structured basis for audit scoping and recommendations
- Information Security Managers — who align cyber controls, security metrics and executive oversight with enterprise governance
- Compliance and Operational Resilience Officers — who need traceable governance evidence for regulatory obligations and resilience testing
- Digital Transformation and Technology Leaders — who must govern cloud, platform and automation programmes without weakening control discipline
Requirements and prerequisites
This is a foundation-to-intermediate course. Participants should understand basic IT service, information-security or operational-risk concepts, such as controls, incidents, vendors, policies, risk assessments and management reporting. Familiarity with a bank or insurer’s three-lines model, risk appetite, audit process, or technology change lifecycle is helpful, but not essential. Participants should be comfortable reading process diagrams, simple RACI charts and spreadsheet-based metrics. No previous COBIT certification, coding ability, GRC-platform configuration experience, or detailed knowledge of ISO standards is required. Complete beginners should expect structured guidance through COBIT terminology before applying it in financial-services cases.
Training methodology
The instructor leads short, focused COBIT 2019 explanations followed by guided application to a bank-and-insurer case environment. Participants use the COBIT 2019 Design Toolkit to assess design factors, select priority objectives and build ownership models for issues such as cloud outsourcing, customer-data controls and critical-service resilience. Small groups review evidence, score capability, challenge proposed metrics and present improvement recommendations as if reporting to a technology-risk committee. The final session converts the case work into an individual application plan for a real governance issue or programme.
Course outline
Day 1: COBIT 2019 foundations for regulated financial institutions
- Banking and insurance governance challenges: resilience, conduct, data and third-party risk
- COBIT 2019 principles for governance systems and governance frameworks
- Governance versus management under the EDM and APO, BAI, DSS and MEA domains
- COBIT governance and management objectives structure
- COBIT components: processes, organisational structures, policies, information and culture
- Financial-services business goals and stakeholder needs analysis
- Introduction to the COBIT 2019 goals cascade
Workshop: Participants map a retail bank or insurer’s strategic priorities to enterprise goals, alignment goals and candidate COBIT objectives.
Day 2: Designing a tailored COBIT governance system
- COBIT 2019 design workflow and governance system scope
- Enterprise strategy design factor for growth, innovation and client service
- Enterprise goals and risk profile design factors
- Threat landscape and regulatory compliance requirement design factors
- IT-related issues and sourcing-model design factors
- Technology adoption strategy and enterprise-size design factors
- Using the COBIT 2019 Design Toolkit to prioritise objectives
Workshop: Teams complete a Design Toolkit assessment for an insurer adopting a cloud-based claims and customer-service platform.
Day 3: Controls, accountability and risk integration
- EDM objectives for governance oversight, benefits, risk and resources
- APO objectives for enterprise architecture, risk, security and supplier management
- BAI objectives for programme governance, change enablement and solution delivery
- DSS objectives for operations, continuity, security services and incident management
- MEA objectives for performance monitoring, internal control and assurance
- RACI responsibility design across board, executive, risk, compliance and IT functions
- Mapping COBIT practices to ISO/IEC 27001 and NIST Cybersecurity Framework outcomes
Workshop: Participants produce a RACI matrix and control mapping for a payment-service provider outage and outsourced recovery scenario.
Day 4: Performance management, evidence and assurance
- COBIT performance management concepts and capability levels
- Process purpose statements, practices and activities
- Setting governance metrics, targets, thresholds and reporting frequency
- Selecting evidence for internal audit and second-line challenge
- Control testing versus capability assessment
- Issue logging, root-cause analysis and remediation tracking
- Technology-risk dashboards for executive and board committees
Workshop: Participants assess the capability of a critical-service continuity process and create a metric dashboard with escalation thresholds.
Day 5: Governance improvement roadmap for banking and insurance
- Interpreting COBIT assessment findings and prioritising governance gaps
- Risk-based sequencing of quick wins, control uplift and operating-model changes
- Building improvement initiatives for cloud governance and third-party oversight
- Embedding governance in digital onboarding, claims automation and core-system change
- Stakeholder engagement and committee approval planning
- Governance roadmap milestones, owners, dependencies and success measures
- Preparing a COBIT governance-design workbook and executive narrative
Workshop: Each participant finalises and presents a COBIT 2019 governance improvement roadmap for a selected banking or insurance use case.
Tools & standards covered
COBIT 2019 Framework, COBIT 2019 Design Toolkit, ISO/IEC 27001:2022, NIST Cybersecurity Framework 2.0
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Banking & Insurance
Advanced Bank Risk and Insurance Portfolio Management Training Course
Banks and insurers face a connected portfolio-management problem: credit deterioration, market shocks, liquidity pressure, interest-rate mov…
Insurance Claims Handling for Claims Adjusters Training Course
Claims adjusters must reach defensible coverage, liability, reserve, and settlement decisions while managing claimant expectations, policyho…
Insurance Underwriting and Risk Selection Training Course
Insurance underwriting decisions must balance growth targets, pricing discipline, regulatory requirements, and the insurer’s appetite for re…
Liquidity Risk Management for Bank Treasury Managers Training Course
Bank treasury managers must maintain sufficient liquidity through normal conditions, market stress, rating pressure, deposit outflows and fu…