COBIT 2019
COBIT 2019 is a framework created by ISACA for managing and governing an organization's information technology. It helps organizations align their IT activities with business goals, and is designed to work alongside other industry standards, guidelines, and regulations. In many organizations it is used as a reference model for structuring IT governance and management responsibilities.
COBIT 2019 is ISACA's framework for the governance and management of enterprise IT. According to the evidence, it is business-focused and is structured around a set of principles, enablers, and governance and management objectives (the evidence describes six principles, seven enablers, and 40 governance and management objectives organized across five domains). It is intended to be integrated with other standards, guidelines, and regulations rather than to replace them. As a voluntary framework, its adoption and scope of application vary by organization; specific structural details and edition-specific terminology should be verified against ISACA's primary publications.
Why it matters
As enterprises grow more dependent on information technology, the boundary between IT decisions and business outcomes has effectively disappeared. COBIT 2019 matters because it gives organizations a structured, business-focused reference model for who holds decision rights over IT, how IT objectives connect to enterprise objectives, and how governance responsibilities are separated from day-to-day management activities. For governance professionals, this distinction is central: COBIT positions the governance of enterprise IT as a board- and executive-level accountability, not merely an operational IT concern.
A further reason COBIT 2019 is significant is its explicit design to work alongside, rather than replace, other standards, guidelines, and regulations. Many organizations operate under overlapping obligations and frameworks, and a common reference model that can be integrated with existing requirements helps reduce fragmentation and duplicated effort across IT governance, risk, and compliance activities. This integrative intent is one of the characteristics ISACA emphasizes for the 2019 edition.
Because COBIT is a voluntary framework rather than a binding legal requirement, its value depends on how deliberately an organization tailors and adopts it. It does not, on its own, guarantee compliance with any regulation or eliminate IT-related risk; rather, it offers a way to organize governance and management objectives so that IT activities can be directed, monitored, and held accountable in a consistent manner. Organizations should confirm structural details and terminology against ISACA's primary publications before relying on them.
Who it's relevant to
Inside COBIT
Common questions
Answers to the questions practitioners most commonly ask about COBIT.

