COBIT 2019 IT Governance Implementation Training Course
| Course code | SD-IT-013 |
|---|---|
| Duration | 5 days |
| Level | Intermediate |
| Category | Information Technology |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Organisations often have IT controls, risk registers, architecture standards and performance dashboards, yet still struggle to show how technology decisions support enterprise strategy. COBIT 2019 provides a structured way to design, implement and sustain an IT governance system that is proportionate to the organisation’s objectives, risk profile, regulatory obligations and delivery model. This course addresses the practical challenge of moving from isolated control activities to an integrated governance approach with accountable decision rights, measurable objectives and prioritised improvement initiatives.
Participants work through the COBIT 2019 governance system and framework, including governance and management objectives, the goals cascade, components of a governance system, design factors, focus areas, capability considerations and the COBIT implementation lifecycle. They learn to translate stakeholder needs into enterprise and alignment goals, select relevant COBIT objectives, assess current-state practices, identify design gaps and define target governance arrangements. The course also covers how COBIT can be applied alongside ITIL, ISO/IEC 27001, ISO/IEC 38500, enterprise risk management and assurance activities without creating duplicate controls.
Instruction combines facilitated explanation with structured workshops based on a realistic organisational case. Participants build a COBIT governance design workbook containing a stakeholder-needs analysis, goals cascade, design-factor profile, prioritised governance and management objectives, component recommendations, improvement roadmap, metrics and ownership model. The final day concludes with an implementation planning session that converts the design into sequenced actions, decision points and reporting measures. Participants receive a certificate on completion.
The course is suited to IT leaders, governance, risk, compliance, assurance and transformation professionals who need to establish or improve an enterprise IT governance system rather than simply understand COBIT terminology.
Course objectives
By the end of this course, participants will be able to:
- Apply the COBIT 2019 goals cascade to translate stakeholder needs into enterprise, alignment and governance objectives
- Assess organisational design factors using the COBIT 2019 Design Guide methodology
- Select and prioritise relevant COBIT governance and management objectives for a defined business context
- Define governance system components covering processes, structures, policies, information, culture, people and services
- Map decision rights, accountability and performance measures using COBIT RACI and management-practice structures
- Conduct a current-state gap assessment against selected COBIT objectives and management practices
- Build a risk-based COBIT implementation roadmap using the seven-phase implementation lifecycle
- Produce a governance system design workbook with target-state recommendations, metrics and improvement actions
Benefits of attending
For you
- Gain a repeatable method for designing governance systems rather than relying on generic control checklists
- Develop evidence-based recommendations for IT governance improvement initiatives and executive steering groups
- Strengthen credibility when linking technology risk, investment, security and performance to enterprise goals
- Build practical capability to facilitate COBIT design-factor and goals-cascade workshops with stakeholders
- Create a portfolio-ready governance design workbook that demonstrates implementation planning competence
For your organisation
- Establish clearer technology decision rights, ownership structures and escalation paths
- Prioritise governance improvements according to enterprise strategy, risk profile and regulatory requirements
- Reduce duplicated controls by aligning COBIT with existing ITIL, security, risk and assurance practices
- Improve board and executive reporting through defined governance objectives, metrics and accountability
- Create an actionable roadmap for closing governance gaps with sequenced initiatives and measurable outcomes
Target competencies
Who should attend
- IT Governance Managers — who must design, operate or refresh governance arrangements across technology services
- CIOs and Heads of IT — who need traceable links between business priorities, technology investments and accountability
- IT Risk Managers — who need to embed technology risk treatment within governance objectives and management practices
- Information Security Managers — who must align security governance with enterprise objectives and assurance requirements
- IT Audit and Assurance Professionals — who assess the adequacy of governance controls and management practices
- Digital Transformation and PMO Leaders — who need governance structures that support controlled change and benefits realisation
Requirements and prerequisites
Participants should have practical exposure to IT service delivery, information security, technology risk, audit, portfolio management or digital transformation. They should understand basic concepts such as business objectives, controls, risk appetite, policies, KPIs, accountability and the distinction between governance and management. Familiarity with ITIL, ISO/IEC 27001, internal audit or enterprise risk management is useful but not essential. No prior COBIT qualification is required, and participants do not need to be programmers, auditors or experienced framework implementers. A laptop with spreadsheet and document-editing software is recommended for workshop activities.
Training methodology
The five-day programme uses instructor-led walkthroughs of COBIT 2019 publications, followed by guided application to a realistic enterprise scenario. Participants complete design-factor assessments, goals-cascade mappings, governance-objective selection matrices, RACI exercises and capability gap reviews in small groups. Facilitated case discussions test decisions against risk, regulatory and stakeholder constraints. Each day adds to a governance design workbook, and the final workshop converts findings into a practical implementation roadmap with owners, milestones, measures and review points.
Course outline
Day 1: COBIT 2019 foundations and governance context
- COBIT 2019 principles for a governance system and governance framework
- Distinction between governance objectives and management objectives
- The COBIT Core Model and its 40 governance and management objectives
- Enterprise governance of information and technology concepts
- Governance system components and their interdependencies
- Stakeholder needs, value creation and enterprise objectives
- Relationships between COBIT, ITIL, ISO/IEC 27001 and ISO/IEC 38500
Workshop: Participants analyse a case organisation’s governance symptoms and produce an initial stakeholder-needs statement and problem definition.
Day 2: Goals cascade and tailored governance design
- COBIT goals cascade structure and mapping logic
- Enterprise goals and alignment goals selection
- Design factor 1: enterprise strategy
- Design factors for enterprise goals, risk profile and threat landscape
- Design factors for compliance requirements and role of IT
- Design factors for sourcing model, implementation methods and technology adoption strategy
- Focus areas and their use in tailoring a governance system
Workshop: Participants complete a goals cascade and design-factor profile for the case organisation, producing a tailored governance context summary.
Day 3: Selecting objectives and defining governance components
- Prioritisation of COBIT governance and management objectives
- Governance objectives EDM01 through EDM05 and board-level accountability
- Management domains APO, BAI, DSS and MEA
- Process purpose statements, practices and activities
- Organisational structures and decision-making bodies
- Policies, procedures, information flows and reporting artefacts
- People, skills, culture, ethics and behaviour components
Workshop: Participants select priority COBIT objectives and create a target governance-component model with named accountabilities.
Day 4: Performance, capability and assurance integration
- COBIT performance management concepts and capability levels
- Defining governance and management performance metrics
- RACI charts for governance and management practices
- Current-state assessment methods and evidence sources
- Gap analysis against target practices and component requirements
- Integrating technology risk management and control assurance
- Using COBIT with internal audit, compliance testing and management reporting
Workshop: Participants perform a current-state assessment and produce a prioritised gap register with measures, owners and evidence requirements.
Day 5: Implementation roadmap and sustained improvement
- COBIT 2019 implementation lifecycle and continual improvement approach
- Identifying drivers, pain points and desired change outcomes
- Building the business case for governance improvement
- Prioritising initiatives by value, risk, dependency and organisational readiness
- Change enablement, communications and stakeholder engagement
- Roadmap milestones, governance checkpoints and benefit measures
- Monitoring, review and adaptation of the governance system
Workshop: Participants consolidate their workbook into a 90-day and 12-month COBIT implementation roadmap for presentation to an executive steering group.
Tools & standards covered
COBIT 2019 Framework: Introduction and Methodology, COBIT 2019 Framework: Governance and Management Objectives, COBIT 2019 Design Guide: Designing an Information and Technology Governance Solution, COBIT 2019 Implementation Guide: Implementing and Optimiz
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
-
21 – 25 Sep 2026Book
Dubai · USD 4,500 -
21 – 25 Sep 2026Book
Dar es Salaam · USD 3,500 -
28 Sep – 02 Oct 2026Book
Nairobi · USD 3,000 -
12 – 16 Oct 2026Book
Live Online · USD 1,500 -
12 – 16 Oct 2026Book
Dubai · USD 4,500 -
19 – 23 Oct 2026Book
Nairobi · USD 3,000 -
19 – 23 Oct 2026Book
Live Online · USD 1,500 -
26 – 30 Oct 2026Book
Live Online · USD 1,500
49 more dates — ask us.
Group of 5+?
Request in-house delivery or group rates →Related courses in Information Technology
IT Risk Management for Banking Professionals Training Course
Banks depend on technology for payments, lending, customer onboarding, trading, treasury, regulatory reporting and digital channels. A contr…
Education Technology Infrastructure Management Training Course
Education providers depend on reliable identity, connectivity, devices, learning platforms and data services to keep teaching, assessment an…
Docker Container Deployment and Management Training Course
Docker deployments often become fragile when teams rely on manually built images, inconsistent environment variables, untracked container ch…
IT Asset Lifecycle Management for Asset Managers Training Course
IT asset managers are expected to produce reliable answers to questions that often sit across disconnected systems: what technology the orga…