COBIT 2019 IT Governance for Banking and Insurance Training Course

5 days Banking & Insurance Certificate on completion
Course codeSD-BI-035
Duration5 days
LevelFoundation to Intermediate
CategoryBanking & Insurance
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Banks and insurers must demonstrate that technology decisions, outsourced services, data controls and cyber investments support regulated business objectives—not merely that policies exist. Risk committees, internal audit teams, technology leaders and control owners need a shared way to connect IT processes with operational resilience, prudential requirements, customer-data protection, financial reporting and measurable risk appetite. COBIT 2019 provides that governance structure, but its value depends on tailoring it to the institution’s products, regulatory obligations, sourcing model and control environment.

This five-day course teaches participants how to apply COBIT 2019 to banking and insurance governance scenarios. Participants work with the COBIT governance and management objectives, design factors, goals cascade, capability levels and performance management approach. They learn to translate business priorities such as digital onboarding, claims-platform modernisation, payment-service resilience, third-party cloud risk and regulatory reporting into governance objectives, practices, metrics and accountable roles. The course also covers practical alignment with ISO/IEC 27001 and NIST Cybersecurity Framework controls.

Instruction combines facilitated framework teaching with banking and insurance case work, control-design workshops and small-group review sessions. Participants build a COBIT 2019 governance design for a fictional regulated financial institution, including a prioritised objective set, design-factor rationale, RACI assignments, performance measures, capability assessment and improvement roadmap. They leave with a reusable governance-design workbook and an action plan for applying COBIT methods to a live function, programme or control issue in their organisation.

The course is suited to foundation-to-intermediate professionals who influence technology risk, IT controls, digital transformation, internal audit, compliance or operational resilience in banks, insurers, lenders, payment firms and financial-services shared-service environments.

Course objectives

By the end of this course, participants will be able to:

  • Apply the COBIT 2019 goals cascade to translate banking or insurance business priorities into governance and management objectives
  • Assess COBIT 2019 design factors to scope a governance system for a regulated financial institution
  • Prioritise COBIT governance and management objectives for scenarios involving cloud services, digital channels and third-party providers
  • Map COBIT practices and components to operational resilience, cyber-risk and data-protection control requirements
  • Define RACI accountability matrices for board, executive, risk, compliance, IT and control-owner responsibilities
  • Measure governance performance using COBIT capability levels, metrics, targets and evidence sources
  • Develop a risk-based improvement roadmap that addresses identified IT governance and control gaps
  • Produce a COBIT 2019 governance-design workbook for a banking or insurance operating context

Benefits of attending

For you

  • Build the ability to justify IT governance priorities in terms understood by risk committees, auditors and business executives
  • Gain practical experience designing a COBIT-based control and accountability model for regulated financial services
  • Improve credibility when contributing to audit remediation, operational resilience and technology-risk discussions
  • Create reusable templates for goals cascades, design-factor assessments, RACI matrices and governance metrics
  • Prepare for broader responsibilities in IT governance, technology risk, GRC, internal audit or digital-control leadership

For your organisation

  • Establish a more consistent method for linking technology controls to banking or insurance business objectives and risk appetite
  • Improve board and committee reporting through defined governance objectives, ownership and measurable performance indicators
  • Reduce control gaps in cloud, outsourcing, data and digital-service initiatives through risk-based COBIT prioritisation
  • Strengthen audit readiness by creating traceable links between governance practices, evidence sources and remediation actions
  • Produce an actionable governance improvement roadmap rather than isolated policy or control updates

Target competencies

COBIT goals cascadeGovernance system designControl accountability mappingCapability assessmentRisk-based prioritisationGovernance metrics design

Who should attend

  • IT Governance Managers — who need to design and maintain accountable technology governance arrangements
  • Technology Risk Managers — who must connect IT risk treatment to risk appetite, control ownership and reporting
  • Internal Auditors — who assess IT controls and need a structured basis for audit scoping and recommendations
  • Information Security Managers — who align cyber controls, security metrics and executive oversight with enterprise governance
  • Compliance and Operational Resilience Officers — who need traceable governance evidence for regulatory obligations and resilience testing
  • Digital Transformation and Technology Leaders — who must govern cloud, platform and automation programmes without weakening control discipline

Requirements and prerequisites

This is a foundation-to-intermediate course. Participants should understand basic IT service, information-security or operational-risk concepts, such as controls, incidents, vendors, policies, risk assessments and management reporting. Familiarity with a bank or insurer’s three-lines model, risk appetite, audit process, or technology change lifecycle is helpful, but not essential. Participants should be comfortable reading process diagrams, simple RACI charts and spreadsheet-based metrics. No previous COBIT certification, coding ability, GRC-platform configuration experience, or detailed knowledge of ISO standards is required. Complete beginners should expect structured guidance through COBIT terminology before applying it in financial-services cases.

Training methodology

The instructor leads short, focused COBIT 2019 explanations followed by guided application to a bank-and-insurer case environment. Participants use the COBIT 2019 Design Toolkit to assess design factors, select priority objectives and build ownership models for issues such as cloud outsourcing, customer-data controls and critical-service resilience. Small groups review evidence, score capability, challenge proposed metrics and present improvement recommendations as if reporting to a technology-risk committee. The final session converts the case work into an individual application plan for a real governance issue or programme.

Course outline

Day 1: COBIT 2019 foundations for regulated financial institutions

  • Banking and insurance governance challenges: resilience, conduct, data and third-party risk
  • COBIT 2019 principles for governance systems and governance frameworks
  • Governance versus management under the EDM and APO, BAI, DSS and MEA domains
  • COBIT governance and management objectives structure
  • COBIT components: processes, organisational structures, policies, information and culture
  • Financial-services business goals and stakeholder needs analysis
  • Introduction to the COBIT 2019 goals cascade

Workshop: Participants map a retail bank or insurer’s strategic priorities to enterprise goals, alignment goals and candidate COBIT objectives.

Day 2: Designing a tailored COBIT governance system

  • COBIT 2019 design workflow and governance system scope
  • Enterprise strategy design factor for growth, innovation and client service
  • Enterprise goals and risk profile design factors
  • Threat landscape and regulatory compliance requirement design factors
  • IT-related issues and sourcing-model design factors
  • Technology adoption strategy and enterprise-size design factors
  • Using the COBIT 2019 Design Toolkit to prioritise objectives

Workshop: Teams complete a Design Toolkit assessment for an insurer adopting a cloud-based claims and customer-service platform.

Day 3: Controls, accountability and risk integration

  • EDM objectives for governance oversight, benefits, risk and resources
  • APO objectives for enterprise architecture, risk, security and supplier management
  • BAI objectives for programme governance, change enablement and solution delivery
  • DSS objectives for operations, continuity, security services and incident management
  • MEA objectives for performance monitoring, internal control and assurance
  • RACI responsibility design across board, executive, risk, compliance and IT functions
  • Mapping COBIT practices to ISO/IEC 27001 and NIST Cybersecurity Framework outcomes

Workshop: Participants produce a RACI matrix and control mapping for a payment-service provider outage and outsourced recovery scenario.

Day 4: Performance management, evidence and assurance

  • COBIT performance management concepts and capability levels
  • Process purpose statements, practices and activities
  • Setting governance metrics, targets, thresholds and reporting frequency
  • Selecting evidence for internal audit and second-line challenge
  • Control testing versus capability assessment
  • Issue logging, root-cause analysis and remediation tracking
  • Technology-risk dashboards for executive and board committees

Workshop: Participants assess the capability of a critical-service continuity process and create a metric dashboard with escalation thresholds.

Day 5: Governance improvement roadmap for banking and insurance

  • Interpreting COBIT assessment findings and prioritising governance gaps
  • Risk-based sequencing of quick wins, control uplift and operating-model changes
  • Building improvement initiatives for cloud governance and third-party oversight
  • Embedding governance in digital onboarding, claims automation and core-system change
  • Stakeholder engagement and committee approval planning
  • Governance roadmap milestones, owners, dependencies and success measures
  • Preparing a COBIT governance-design workbook and executive narrative

Workshop: Each participant finalises and presents a COBIT 2019 governance improvement roadmap for a selected banking or insurance use case.

Tools & standards covered

COBIT 2019 Framework, COBIT 2019 Design Toolkit, ISO/IEC 27001:2022, NIST Cybersecurity Framework 2.0

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

No. The course introduces COBIT 2019 terminology, structure and design workflow before participants use them in exercises. Experience in IT risk, audit, security, compliance, operations or technology delivery will help participants relate the framework to their work.

A laptop is recommended for completing the Design Toolkit exercises and retaining the workbook templates. No GRC platform configuration is required; the course uses spreadsheet-based COBIT design and assessment materials rather than a specific enterprise system.

It is designed for both. Cases address common regulated-financial-services concerns including third-party dependency, critical-service resilience, customer data, digital channels, regulatory reporting and change governance, with examples adapted to banking and insurance operating models.

This course applies COBIT through financial-services scenarios rather than treating the framework as an abstract set of concepts. Participants tailor objectives using regulatory, risk-profile, sourcing and technology-adoption design factors relevant to banks and insurers.

You can use the goals cascade to frame governance discussions, the design factors to prioritise objectives, and RACI and metrics templates to strengthen a live control area. Typical applications include audit remediation, cloud governance, operational resilience, supplier oversight and technology-risk reporting.

Participants leave with a completed COBIT governance-design workbook containing objective priorities, design-factor rationale, accountability assignments, assessment outputs and proposed metrics. They also develop a risk-based improvement roadmap for a real or simulated financial-services governance challenge.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Banking & Insurance

5 Days Certificate

Advanced Bank Risk and Insurance Portfolio Management Training Course

Banks and insurers face a connected portfolio-management problem: credit deterioration, market shocks, liquidity pressure, interest-rate mov…

5 Days Certificate

Insurance Claims Handling for Claims Adjusters Training Course

Claims adjusters must reach defensible coverage, liability, reserve, and settlement decisions while managing claimant expectations, policyho…

5 Days Certificate

Insurance Underwriting and Risk Selection Training Course

Insurance underwriting decisions must balance growth targets, pricing discipline, regulatory requirements, and the insurer’s appetite for re…

5 Days Certificate

Liquidity Risk Management for Bank Treasury Managers Training Course

Bank treasury managers must maintain sufficient liquidity through normal conditions, market stress, rating pressure, deposit outflows and fu…