A useful IT governance diagnostic reconstructs decisions, identifies economic exposure and defines where to expand autonomy, control or transparency, rather than counting committees.
IT governance is the system by which an organization evaluates options, sets direction, delegates authority, tracks results and corrects decisions about technology. Committees, policies and approvals are instruments of that system, not its sum. When the system works, the company decides with clarity and executes at the velocity that matches the risk. When it fails, competing priorities, permanent exceptions, immobilized capital and diffuse accountability emerge.
ISO/IEC 38500 guides governing bodies on the effective, efficient and acceptable use of technology. COBIT 2019 treats governance and management as a system adaptable to the context, strategy, risk profile and priorities of the organization. The common point is direct. Governance cannot be assessed only by its formal design. It has to be observed in the quality of decisions and in the capacity to monitor their consequences.
That is why an IT governance diagnostic starts better when it reconstructs concrete decisions. Not to disqualify org charts or responsibility matrices, but to test whether the declared model shows up in operation.
Governance appears on the path between decision and result
There is almost always some distance between designed governance and practiced governance. The policy defines who should decide. Execution reveals who influences, who approves, who takes the risk, who receives the information and who can interrupt an initiative. That space is not automatic proof of dysfunction. It has to be measured.
An exception can be rational when it protects a relevant opportunity. An additional forum can be adequate in the face of regulatory risk. A centralized decision can reduce exposure on a critical topic. The problem begins when the exception has no deadline, the approval has no materiality, accountability does not follow authority or the result never returns to the table that decided.
The diagnostic does not seek to eliminate all variation. It verifies whether the variation is conscious, proportional and reviewable.
Five dimensions reveal the quality of the decision cycle
WatchZ uses five dimensions as a practical frame. They do not replace COBIT, ISO, audit or regulatory requirements. They organize the investigation and can be expanded according to the company context.
Decision rights
Who decides what, in which domain and within which limit. Portfolio, architecture, security, data, vendors and continuity require different decision classes. A strong diagnostic identifies authority, thresholds, escalation criteria and decisions left with no owner.
Accountability
Authority without responsibility produces approval without consequence. For each relevant decision, there must be a person or body that answers for the result, the accepted risk and the need for correction. Accountability does not concentrate blame. It keeps the connection between choice, result and learning.
Evidence and visibility
Every important decision starts from a thesis. That thesis needs indicators, reliable sources and a review cadence. The diagnostic verifies whether the information used to decide was sufficient, whether the indicators were defined before execution and whether they returned to the responsible body.
Decision velocity
Velocity is completing the decision within the economic window and the applicable level of risk, not deciding fast in every situation. Time has to be measured by decision class, from the identification of the need to the competent authority taking a direction. Delays come from excess approval, but also from dependencies, low information quality, budget, capacity or regulation.
Reversibility and learning
Mature governance creates conditions to detect error, limit exposure and change direction, without assuming perfect decisions. The diagnostic looks for stop criteria, progressive tests, post-implementation reviews, exception handling and mechanisms to discontinue initiatives whose thesis has lost validity.
Control and assurance cut across the five dimensions. Controls should be proportional to risk and, whenever possible, embedded in the flow. Independent assurance should test whether the system works as declared, without taking over management responsibility. The Three Lines Model reinforces the need for clear roles, coordination and independent assessment of governance, risk and controls.
The framework organizes the investigation into three movements

The asset above represents the method in three movements. On the left, decisions and real evidence form the input. In the center, five dimensions test the quality of the decision cycle. On the right, the diagnostic produces map, exposure, priorities and cadence. At the base, proportional controls, independent verification and value metrics sustain trust.
The reading goes from left to right. The framework assigns no fictional score and does not replace market standards. It organizes the investigation and helps turn scattered signals into executive decisions.
Reconstruct decisions before interviewing structures
The diagnostic gains quality when it starts from a deliberate sample of decisions from the last twelve months. Instead of picking only successful projects or serious incidents, combine decisions of value, risk and operation.
- Investments and portfolio prioritization.
- Architecture, modernization and exceptions to standards.
- Acceptance of security and continuity risks.
- Quality, use and sharing of data.
- Vendor selection, renewal and concentration.
- Operational changes, relevant incidents and capacity.
A sample of ten to fifteen decisions is usually enough to start the investigation, without becoming a universal standard. The volume should consider size, diversity of domains, materiality and the level of confidence desired.
For each decision, reconstruct eight elements. Problem, options considered, authority, participants, evidence used, decision time, expected result and review mechanism. Collect documents, approval records, business cases, architecture decisions, exceptions, indicators, minutes, contracts and post-implementation reviews. ISO/IEC 38503 recognizes the importance of criteria, evidence and maturity methods in governance assessments.
Interviews remain important, but they should confront perception with evidence. Ask the board, executive leadership and operational teams how the same decision happened. Divergence between versions is a signal to go deeper into authority, information and accountability, not automatic proof of failure.
Measure maturity without turning the score into absolute truth
A simple scale helps compare decisions and domains. The score does not replace judgment. It makes the criterion explicit and allows evidence to be discussed.
- Level 1, ad hoc. The decision depends on people, memory and influence. Roles, criteria and review vary.
- Level 2, defined. There are documented rules and responsibilities, but application is irregular.
- Level 3, operated. The flow works consistently, produces evidence and tracks results.
- Level 4, adaptive. The organization adjusts thresholds, guardrails and metrics based on risk, result and learning.
Useful metrics include coverage of owners, decision time by class, age of exceptions, share of decisions with a defined indicator, benefit review coverage, time to correct a decision and concentration of authority. No target is universal. The baseline, materiality and risk determine what needs to change.
Translate gaps into economic exposure without inventing precision
Governance enters the executive agenda when the organization understands the consequence of keeping the gap. That does not require converting every problem into an exact number. It requires demonstrating materiality and making uncertainty explicit.
- Opportunity cost caused by a decision beyond the market window.
- Rework generated by a recurring exception or an ambiguous standard.
- Executive time consumed by decisions without authority or sufficient information.
- Capital stuck in initiatives with no stop criterion.
- Exposure to incidents, fines, downtime or loss of trust.
- Vendor dependency and cost of exit.
Use ranges, scenarios and a confidence level. Distinguish observed value, estimate and hypothesis. When monetization is fragile, present risk, obligation, strategic option or operational impact. The goal is to make the decision comparable and defensible, not to produce artificial precision.
Proportional control raises trust without paralyzing the operation
Weak governance is not fixed by more approval nor by removing controls indiscriminately. The answer is to differentiate decision classes and apply the right mechanism.
- Routine and reversible decisions operate with autonomy and clear guardrails.
- Material or hard-to-reverse decisions require more robust evidence and adequate authority.
- Exceptions need an owner, a justification, a deadline and an exit criterion.
- Repetitive controls should be automated when technology allows.
- Assurance assesses the system without replacing whoever decides or executes.
This architecture reduces two losses at once. It prevents low-risk topics from consuming executive attention and stops material decisions from passing without responsibility, evidence or review.
The diagnostic should end in priority and cadence
A usable diagnostic does not deliver only findings. It organizes decisions about where to intervene first. The minimum output contains five artifacts.
- Decision map. Shows domains, decision classes, authority, thresholds and escalation.
- Gap scorecard. Records evidence, maturity, exposure and confidence of the assessment.
- Executive exposure. Translates materiality into value, risk, obligation or strategic option.
- Prioritized roadmap. Orders interventions by impact, urgency, dependency, effort and reversibility.
- Review cadence. Defines when results, exceptions, risks and benefits return to governance.
Prioritization separates structural actions from local fixes. Clarifying decision rights, defining materiality criteria and instituting benefit review tend to have cross-cutting effect. Fixing a specific forum or closing an exception resolves a point exposure. Both types are needed, but they should not compete at the same level. Prioritization by economic criteria sets the sequence.
Questions the board should ask
- Which technology decisions carry the highest materiality for the current strategy?
- Who holds authority and who answers for the result of each decision class?
- What evidence supports the choice and which indicator will confirm or invalidate the thesis?
- Does the decision time fit the economic window and the risk appetite?
- Which decisions can be reversed and which require additional protection?
- Which exceptions remain open, for how long and with what exposure?
- Where does control raise trust and where does it only shift responsibility?
Conclusion
IT governance does not improve when the organization multiplies rituals without revising the decision system. It improves when authority, responsibility, evidence, velocity and reversibility work as a cycle.
The most useful diagnostic asks how a relevant decision was born, who took the direction, which risk was accepted, how the result was measured and what would happen if the thesis were wrong, not only whether a policy, committee or matrix exists.
When those answers are clear, governance stops being an internal IT agenda. It becomes the capacity to allocate capital, protect value and adapt the company with more confidence. A structured capability assessment turns that cycle into a priority before the next investment. Which relevant technology decision could you reconstruct today, from problem to review, without discovering a governance gap?
Sources
- WatchZ. "IT governance diagnostic in practice". Published on May 27, 2026.
- ISO. "ISO/IEC 38500:2024, Information technology, Governance of IT for the organization". https://www.iso.org/standard/81684.html
- ISO. "ISO/IEC 38503:2022, Assessment of the governance of IT". https://www.iso.org/standard/75547.html
- ISACA. "COBIT 2019 Framework, Introduction and Methodology". https://www.isaca.org/resources/cobit
- The Institute of Internal Auditors. "Three Lines Model". https://www.theiia.org/en/resources/statements-of-position




