Enterprise Architecture

IT governance is diagnosed by the decisions that truly move value

A useful IT governance diagnostic reconstructs concrete decisions, measures five dimensions of the decision cycle and translates each gap into economic exposure. Counting committees describes intent. The decisions reveal what governs margin, deadline and risk.

A useful IT governance diagnostic reconstructs decisions, identifies economic exposure and defines where to expand autonomy, control or transparency, rather than counting committees.

IT governance is the system by which an organization evaluates options, sets direction, delegates authority, tracks results and corrects decisions about technology. Committees, policies and approvals are instruments of that system, not its sum. When the system works, the company decides with clarity and executes at the velocity that matches the risk. When it fails, competing priorities, permanent exceptions, immobilized capital and diffuse accountability emerge.

ISO/IEC 38500 guides governing bodies on the effective, efficient and acceptable use of technology. COBIT 2019 treats governance and management as a system adaptable to the context, strategy, risk profile and priorities of the organization. The common point is direct. Governance cannot be assessed only by its formal design. It has to be observed in the quality of decisions and in the capacity to monitor their consequences.

That is why an IT governance diagnostic starts better when it reconstructs concrete decisions. Not to disqualify org charts or responsibility matrices, but to test whether the declared model shows up in operation.

Governance appears on the path between decision and result

There is almost always some distance between designed governance and practiced governance. The policy defines who should decide. Execution reveals who influences, who approves, who takes the risk, who receives the information and who can interrupt an initiative. That space is not automatic proof of dysfunction. It has to be measured.

An exception can be rational when it protects a relevant opportunity. An additional forum can be adequate in the face of regulatory risk. A centralized decision can reduce exposure on a critical topic. The problem begins when the exception has no deadline, the approval has no materiality, accountability does not follow authority or the result never returns to the table that decided.

The diagnostic does not seek to eliminate all variation. It verifies whether the variation is conscious, proportional and reviewable.

Five dimensions reveal the quality of the decision cycle

WatchZ uses five dimensions as a practical frame. They do not replace COBIT, ISO, audit or regulatory requirements. They organize the investigation and can be expanded according to the company context.

Decision rights

Who decides what, in which domain and within which limit. Portfolio, architecture, security, data, vendors and continuity require different decision classes. A strong diagnostic identifies authority, thresholds, escalation criteria and decisions left with no owner.

Accountability

Authority without responsibility produces approval without consequence. For each relevant decision, there must be a person or body that answers for the result, the accepted risk and the need for correction. Accountability does not concentrate blame. It keeps the connection between choice, result and learning.

Evidence and visibility

Every important decision starts from a thesis. That thesis needs indicators, reliable sources and a review cadence. The diagnostic verifies whether the information used to decide was sufficient, whether the indicators were defined before execution and whether they returned to the responsible body.

Decision velocity

Velocity is completing the decision within the economic window and the applicable level of risk, not deciding fast in every situation. Time has to be measured by decision class, from the identification of the need to the competent authority taking a direction. Delays come from excess approval, but also from dependencies, low information quality, budget, capacity or regulation.

Reversibility and learning

Mature governance creates conditions to detect error, limit exposure and change direction, without assuming perfect decisions. The diagnostic looks for stop criteria, progressive tests, post-implementation reviews, exception handling and mechanisms to discontinue initiatives whose thesis has lost validity.

Control and assurance cut across the five dimensions. Controls should be proportional to risk and, whenever possible, embedded in the flow. Independent assurance should test whether the system works as declared, without taking over management responsibility. The Three Lines Model reinforces the need for clear roles, coordination and independent assessment of governance, risk and controls.

The framework organizes the investigation into three movements

WatchZ infographic for an IT governance diagnostic, titled governance is diagnosed in the decisions that truly move value. A governance decision map links three columns. On the left, the real evidence: portfolio and investment, architecture and exceptions, risk and security, data and vendors, under the note to start from concrete decisions and not from org charts. In the center, the diagnostic in five dimensions: decision, accountability, evidence, velocity and reversal, each with the question that tests it. On the right, the executive output: decision map, economic exposure, priorities by value and risk, and review cadence. At the base, the foundations of trust: proportional control, independent verification and value metrics.
The governance diagnostic reads from left to right: decisions and real evidence come in, five dimensions test the decision cycle and the output becomes map, exposure, priorities and cadence

The asset above represents the method in three movements. On the left, decisions and real evidence form the input. In the center, five dimensions test the quality of the decision cycle. On the right, the diagnostic produces map, exposure, priorities and cadence. At the base, proportional controls, independent verification and value metrics sustain trust.

The reading goes from left to right. The framework assigns no fictional score and does not replace market standards. It organizes the investigation and helps turn scattered signals into executive decisions.

Reconstruct decisions before interviewing structures

The diagnostic gains quality when it starts from a deliberate sample of decisions from the last twelve months. Instead of picking only successful projects or serious incidents, combine decisions of value, risk and operation.

  • Investments and portfolio prioritization.
  • Architecture, modernization and exceptions to standards.
  • Acceptance of security and continuity risks.
  • Quality, use and sharing of data.
  • Vendor selection, renewal and concentration.
  • Operational changes, relevant incidents and capacity.

A sample of ten to fifteen decisions is usually enough to start the investigation, without becoming a universal standard. The volume should consider size, diversity of domains, materiality and the level of confidence desired.

For each decision, reconstruct eight elements. Problem, options considered, authority, participants, evidence used, decision time, expected result and review mechanism. Collect documents, approval records, business cases, architecture decisions, exceptions, indicators, minutes, contracts and post-implementation reviews. ISO/IEC 38503 recognizes the importance of criteria, evidence and maturity methods in governance assessments.

Interviews remain important, but they should confront perception with evidence. Ask the board, executive leadership and operational teams how the same decision happened. Divergence between versions is a signal to go deeper into authority, information and accountability, not automatic proof of failure.

Measure maturity without turning the score into absolute truth

A simple scale helps compare decisions and domains. The score does not replace judgment. It makes the criterion explicit and allows evidence to be discussed.

  • Level 1, ad hoc. The decision depends on people, memory and influence. Roles, criteria and review vary.
  • Level 2, defined. There are documented rules and responsibilities, but application is irregular.
  • Level 3, operated. The flow works consistently, produces evidence and tracks results.
  • Level 4, adaptive. The organization adjusts thresholds, guardrails and metrics based on risk, result and learning.

Useful metrics include coverage of owners, decision time by class, age of exceptions, share of decisions with a defined indicator, benefit review coverage, time to correct a decision and concentration of authority. No target is universal. The baseline, materiality and risk determine what needs to change.

Translate gaps into economic exposure without inventing precision

Governance enters the executive agenda when the organization understands the consequence of keeping the gap. That does not require converting every problem into an exact number. It requires demonstrating materiality and making uncertainty explicit.

  • Opportunity cost caused by a decision beyond the market window.
  • Rework generated by a recurring exception or an ambiguous standard.
  • Executive time consumed by decisions without authority or sufficient information.
  • Capital stuck in initiatives with no stop criterion.
  • Exposure to incidents, fines, downtime or loss of trust.
  • Vendor dependency and cost of exit.

Use ranges, scenarios and a confidence level. Distinguish observed value, estimate and hypothesis. When monetization is fragile, present risk, obligation, strategic option or operational impact. The goal is to make the decision comparable and defensible, not to produce artificial precision.

Proportional control raises trust without paralyzing the operation

Weak governance is not fixed by more approval nor by removing controls indiscriminately. The answer is to differentiate decision classes and apply the right mechanism.

  • Routine and reversible decisions operate with autonomy and clear guardrails.
  • Material or hard-to-reverse decisions require more robust evidence and adequate authority.
  • Exceptions need an owner, a justification, a deadline and an exit criterion.
  • Repetitive controls should be automated when technology allows.
  • Assurance assesses the system without replacing whoever decides or executes.

This architecture reduces two losses at once. It prevents low-risk topics from consuming executive attention and stops material decisions from passing without responsibility, evidence or review.

The diagnostic should end in priority and cadence

A usable diagnostic does not deliver only findings. It organizes decisions about where to intervene first. The minimum output contains five artifacts.

  • Decision map. Shows domains, decision classes, authority, thresholds and escalation.
  • Gap scorecard. Records evidence, maturity, exposure and confidence of the assessment.
  • Executive exposure. Translates materiality into value, risk, obligation or strategic option.
  • Prioritized roadmap. Orders interventions by impact, urgency, dependency, effort and reversibility.
  • Review cadence. Defines when results, exceptions, risks and benefits return to governance.

Prioritization separates structural actions from local fixes. Clarifying decision rights, defining materiality criteria and instituting benefit review tend to have cross-cutting effect. Fixing a specific forum or closing an exception resolves a point exposure. Both types are needed, but they should not compete at the same level. Prioritization by economic criteria sets the sequence.

Questions the board should ask

  • Which technology decisions carry the highest materiality for the current strategy?
  • Who holds authority and who answers for the result of each decision class?
  • What evidence supports the choice and which indicator will confirm or invalidate the thesis?
  • Does the decision time fit the economic window and the risk appetite?
  • Which decisions can be reversed and which require additional protection?
  • Which exceptions remain open, for how long and with what exposure?
  • Where does control raise trust and where does it only shift responsibility?

Conclusion

IT governance does not improve when the organization multiplies rituals without revising the decision system. It improves when authority, responsibility, evidence, velocity and reversibility work as a cycle.

The most useful diagnostic asks how a relevant decision was born, who took the direction, which risk was accepted, how the result was measured and what would happen if the thesis were wrong, not only whether a policy, committee or matrix exists.

When those answers are clear, governance stops being an internal IT agenda. It becomes the capacity to allocate capital, protect value and adapt the company with more confidence. A structured capability assessment turns that cycle into a priority before the next investment. Which relevant technology decision could you reconstruct today, from problem to review, without discovering a governance gap?

Sources

Common questions about this insight

What is an IT governance diagnostic?

It investigates how concrete technology decisions were made over the last twelve months, not only whether a policy, committee or responsibility matrix exists. It reconstructs a sample of portfolio, architecture, security, data and vendor decisions and tests who held authority, who answered for the result, what evidence supported the choice, how long it took and how the result returned to the table. ISO/IEC 38500 and COBIT 2019 treat governance as a system of decision and monitoring, not as formal design. That is why the diagnostic observes practice, not the org chart.

What are the pillars of IT governance?

Five dimensions organize the investigation. Decision rights, which define who decides what, in which domain and within which limit. Accountability, which keeps the connection between authority, result and correction. Evidence and visibility, which verify whether the information to decide was sufficient and whether indicators returned to the responsible body. Decision velocity, which measures whether the decision was completed within the economic window and the applicable risk. And reversibility, which assesses the capacity to detect error, limit exposure and change direction. Control and independent assurance cut across all five.

How do you measure IT governance maturity?

By using a simple scale that makes the criterion explicit without replacing judgment. Level 1, ad hoc, when the decision depends on people and influence. Level 2, defined, when there are documented rules but irregular application. Level 3, operated, when the flow works consistently and produces evidence. Level 4, adaptive, when the organization adjusts thresholds, guardrails and metrics based on risk and learning. Metrics such as decision time by class, age of exceptions and benefit review coverage help compare domains. No target is universal. Baseline, materiality and risk determine what needs to change.

How do you connect IT governance to financial result?

By translating the gap into economic exposure with explicit materiality and uncertainty. A decision beyond the market window creates opportunity cost. A recurring exception creates rework. Decisions without authority consume executive time. Capital gets stuck in initiatives with no stop criterion. When monetization is fragile, the gap appears as risk, regulatory obligation, strategic option or operational impact. Use ranges and a confidence level, distinguishing observed value, estimate and hypothesis. The goal is to make the decision comparable and defensible, not to produce artificial precision.

Does more control improve IT governance?

Not always. Weak governance is not fixed by more approval nor by removing controls indiscriminately. The answer is to differentiate decision classes and apply the right mechanism. Routine and reversible decisions operate with autonomy and clear guardrails. Material or hard-to-reverse decisions require more robust evidence and adequate authority. Exceptions need an owner, a deadline and an exit criterion. Assurance assesses the system without replacing whoever decides. Proportional control keeps low-risk topics from consuming executive attention and stops material decisions from passing without responsibility or review.

Want clarity on where to invest first?

A complete technology capability assessment with an evolution roadmap connected to financial result.