IT Governance for IT Managers Training Course
| Course code | SD-IT-008 |
|---|---|
| Duration | 5 days |
| Level | Intermediate to Advanced |
| Category | Information Technology |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
IT managers are routinely asked to deliver services faster, control technology risk, justify investment decisions, and prove that operational work supports business priorities. Without a clear governance model, decisions are escalated inconsistently, project portfolios become disconnected from strategy, service ownership is unclear, and risk reporting reaches executives too late. This course equips IT managers to establish practical governance mechanisms that work across infrastructure, applications, cloud services, cybersecurity, data, and supplier-managed environments.
Participants learn how to translate enterprise objectives into IT decision rights, policies, performance measures, risk controls, and management forums. The course applies COBIT 2019 governance and management objectives, ISO/IEC 38500 principles, ITIL 4 practices, and portfolio governance methods to real management situations. Participants develop skills in defining accountability with RACI matrices, building governance charters, setting service and investment metrics, evaluating technology risk, structuring executive dashboards, and escalating exceptions through defined decision pathways.
Delivery combines instructor-led briefings with governance design workshops, case analysis, facilitated peer review, and practical templates. Each participant works on a governance challenge relevant to their organisation, such as cloud oversight, project prioritisation, service performance, data accountability, or third-party risk. They leave with an IT Governance Action Pack containing a draft governance operating model, decision-rights matrix, committee charter, KPI/KRI dashboard design, and 90-day implementation roadmap.
The course is designed for experienced IT professionals who manage teams, services, programmes, platforms, vendors, or technology change and need to operate credibly with senior business stakeholders, risk functions, and executive governance boards.
Course objectives
By the end of this course, participants will be able to:
- Map enterprise objectives to COBIT 2019 governance and management objectives for an IT function
- Design an IT governance operating model with defined forums, decision rights, escalation routes, and accountabilities
- Create RACI matrices that clarify ownership for technology investments, services, risks, and policy exceptions
- Build a technology portfolio prioritisation scorecard using value, risk, cost, compliance, and strategic-alignment criteria
- Define KPI and KRI dashboards for service performance, investment delivery, technology risk, and control effectiveness
- Evaluate IT risks using risk appetite, control design, residual-risk assessment, and treatment planning methods
- Draft governance committee charters, agenda structures, decision logs, and action-tracking mechanisms
- Produce a 90-day IT governance implementation roadmap for a selected organisational challenge
Benefits of attending
For you
- Gain a repeatable framework for explaining IT governance decisions to executives, auditors, and business leaders
- Build credibility for senior IT management, service leadership, technology risk, or CIO-office roles
- Learn to replace informal escalation with documented decision rights, meeting structures, and decision logs
- Develop practical dashboard designs that connect operational metrics to business value and technology risk
- Leave with a tailored governance implementation pack that can be used in a current management role
For your organisation
- Creates clearer ownership for technology decisions, reducing duplicated approvals and unmanaged accountability gaps
- Improves prioritisation of projects and technology investments against strategy, value, risk, and available capacity
- Strengthens management visibility of service performance, control weaknesses, policy exceptions, and residual risk
- Provides reusable governance artefacts including committee charters, RACI models, scorecards, and escalation workflows
- Reduces exposure from poorly governed cloud, supplier, data, cybersecurity, and technology-change decisions
Target competencies
Who should attend
- IT Managers — who need to turn business priorities into governed technology decisions and measurable service outcomes
- Heads of IT Operations — who require clear accountability, performance reporting, and escalation mechanisms across service teams
- IT Service Delivery Managers — who must govern service quality, suppliers, changes, and operational risk
- Technology Programme and Project Managers — who need defensible portfolio prioritisation and investment-stage controls
- Infrastructure, Cloud, and Applications Managers — who oversee platforms with shared ownership, vendor dependencies, and security obligations
- IT Risk, Compliance, and Security Managers — who need to connect technical controls and risk evidence to executive governance
Requirements and prerequisites
Participants should have at least three years of experience managing IT services, technical teams, projects, platforms, suppliers, or technology risks. Familiarity with core concepts such as service levels, project business cases, IT risk registers, budgets, incident management, and stakeholder reporting is assumed. Participants should be able to discuss their organisation's current decision-making and escalation processes. Prior COBIT, ITIL, ISO/IEC 38500, audit, or formal compliance certification is not required. No programming, data analysis, or specialist governance software expertise is needed; templates and worked examples are provided during the course.
Training methodology
The instructor uses short, focused teaching sessions to introduce governance principles, then moves participants into structured application. Teams analyse a multi-service IT organisation with conflicting investment, cloud-risk, and service-performance issues; they use COBIT 2019 objectives, RACI templates, risk registers, scorecards, and committee-charter formats to resolve them. Individual work is anchored in each participant's own governance challenge. Peer review sessions test whether proposed controls, reporting, and decision routes are workable, before participants complete a prioritised 90-day implementation plan.
Course outline
Day 1: IT governance foundations and operating context
- Distinguishing governance from IT management and operational administration
- ISO/IEC 38500 principles for responsible technology oversight
- COBIT 2019 governance system components and design factors
- Enterprise goals cascade from business objectives to IT objectives
- Governance operating model layers: boards, executives, management, and delivery teams
- Stakeholder analysis for business, risk, finance, audit, and technology functions
- Current-state governance maturity assessment and pain-point identification
Workshop: Participants assess a case organisation's governance gaps and produce a current-state governance heat map with prioritised issues.
Day 2: Decision rights, accountability, and governance forums
- Decision-rights categories for investment, architecture, risk, service, and sourcing decisions
- RACI matrix design for cross-functional technology accountability
- Governance committee structures and terms of reference
- Executive steering committee agendas and decision-log practices
- Delegated authority thresholds and escalation pathways
- Policy exception management and documented risk acceptance
- Integrating architecture review boards, change advisory boards, and portfolio forums
Workshop: Participants create a decision-rights map, RACI matrix, and draft charter for a governance forum addressing a selected IT issue.
Day 3: Performance, value, and portfolio governance
- Linking IT services and investment portfolios to business outcomes
- Balanced KPI design for value, delivery, resilience, cost, and customer experience
- KRI selection for technology debt, cyber exposure, supplier dependence, and control failure
- Service-level governance using ITIL 4 service value concepts
- Technology investment business cases and benefits-realisation ownership
- Portfolio prioritisation scoring across strategic alignment, cost, risk, value, and capacity
- Executive dashboard design and management-reporting cadence
Workshop: Participants build a portfolio prioritisation scorecard and a one-page executive KPI/KRI dashboard for the case organisation.
Day 4: Risk, compliance, and supplier governance
- Technology risk appetite statements and tolerance thresholds
- Inherent risk, control effectiveness, and residual-risk assessment
- Risk treatment plans, control owners, and assurance evidence
- Governance of cloud services, shared responsibility, and data accountability
- Third-party due diligence, contract controls, and supplier performance reviews
- Mapping governance controls to cybersecurity, privacy, and regulatory obligations
- Internal audit engagement, control testing, and remediation tracking
Workshop: Participants complete a technology risk register and supplier-governance review, producing treatment actions and executive escalation recommendations.
Day 5: Implementing and sustaining IT governance
- Selecting a governance implementation scope and sequencing quick wins
- Change-impact analysis for managers, delivery teams, executives, and suppliers
- Governance communications plans and stakeholder engagement tactics
- Measuring adoption, decision quality, control effectiveness, and business outcomes
- Handling resistance to new approval routes and accountability structures
- Continuous improvement using maturity reviews and governance retrospectives
- Ninety-day implementation roadmap and executive sponsorship plan
Workshop: Participants present their IT Governance Action Pack and produce a 90-day roadmap with milestones, owners, measures, and sponsor actions.
Tools & standards covered
COBIT 2019, ITIL 4, ISO/IEC 38500, ServiceNow Integrated Risk Management
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
-
21 – 25 Sep 2026Book
Live Online · USD 1,500 -
28 Sep – 02 Oct 2026Book
Nairobi · USD 3,000 -
19 – 23 Oct 2026Book
Live Online · USD 1,500 -
19 – 23 Oct 2026Book
Dar es Salaam · USD 3,500 -
26 – 30 Oct 2026Book
Dar es Salaam · USD 3,500 -
26 – 30 Oct 2026Book
Kigali · USD 3,500 -
02 – 06 Nov 2026Book
Live Online · USD 1,500 -
09 – 13 Nov 2026Book
Nairobi · USD 3,000
49 more dates — ask us.
Group of 5+?
Request in-house delivery or group rates →Related courses in Information Technology
IT Asset Lifecycle Management for Asset Managers Training Course
IT asset managers are expected to produce reliable answers to questions that often sit across disconnected systems: what technology the orga…
IT Controls Testing for Internal Auditors Training Course
Internal auditors are increasingly expected to provide assurance over access management, change control, IT operations, cloud services and a…
Docker Container Deployment and Management Training Course
Docker deployments often become fragile when teams rely on manually built images, inconsistent environment variables, untracked container ch…
COBIT 2019 IT Governance Implementation Training Course
Organisations often have IT controls, risk registers, architecture standards and performance dashboards, yet still struggle to show how tech…