13.3 MEA Monitor, Evaluate, and Assess
Key Takeaways
- MEA Monitor, Evaluate, and Assess is a 4-objective MANAGEMENT domain; calling it a fifth governance domain because it begins with Monitor is the classic Foundation trap.
- Only EDM Evaluate, Direct and Monitor is governance. MEA is how management monitors performance, the control system, external compliance, and assurance.
- MEA01 Managed Performance and Conformance Monitoring collects, validates, and reports goals and metrics for performance and conformance.
- MEA02 Managed System of Internal Control evaluates the control environment; it does not embed the process controls that live in DSS06.
- MEA03 Managed Compliance With External Requirements assesses laws, regulations, and contracts; MEA04 Managed Assurance is new in 2019 and plans independent assurance initiatives.
Quick Answer: Monitor, Evaluate, and Assess (MEA) is a 4-objective MANAGEMENT domain. It is not a fifth governance domain. Only Evaluate, Direct and Monitor (EDM) is governance. MEA01 Managed Performance and Conformance Monitoring collects, validates, and evaluates goals and metrics and reports performance and conformance. MEA02 Managed System of Internal Control continuously monitors and evaluates the control environment. MEA03 Managed Compliance With External Requirements evaluates compliance with laws, regulations, and contractual requirements. MEA04 Managed Assurance is new in 2019 and plans, scopes, and executes independent assurance initiatives. Do not promote MEA to the board because the name starts with Monitor, and do not collapse MEA03, MEA04, and MEA01 into one “audit” title.
This is the last cluster in the 40-objective core model. You now hold EDM 5, APO 14, BAI 11, DSS 6, and MEA 4. 5+14+11+6+4 = 40. MEA is the smallest domain and one of the most trap-heavy, because its first word is Monitor and EDM’s last word is Monitor.
MEA is management monitoring, not EDM
Governance distinct from management is a governance-system principle. The board evaluates, directs, and monitors at enterprise altitude — value, risk, resources, stakeholders. Management plans, builds, runs, and monitors the work. MEA is that last management verb. It produces the evidence, assessments, compliance views, and assurance results that inform EDM. It does not become EDM.
| Lens | EDM Evaluate, Direct and Monitor | MEA Monitor, Evaluate, and Assess |
|---|---|---|
| Type | The only governance domain | A management domain |
| Count | 5 objectives, all titled Ensured | 4 objectives, all titled Managed |
| Owner | Board or other governing body | Executive and operational management, including control, compliance, and assurance functions |
| Altitude | Appetite, benefits, resources, stakeholder engagement, the governance system itself | Metrics, the internal-control system, external requirements, independent assurance initiatives |
| Name trap | Ends with Monitor | Begins with Monitor |
If a stem says the board reviews whether residual I&T risk still sits inside appetite, that is EDM03 Ensured Risk Optimization, possibly fed by MEA reports. If it says management collects process metrics and reports performance against agreed goals, that is MEA01. Same English verb, monitor. Different official domain, different title pattern, different owner.
Exam trap: calling MEA a fifth governance domain. There are five domains total, and only one of them is governance. MEA is the fourth management domain (APO, BAI, DSS, MEA), not a second governance domain and not a sixth domain. An option that says “EDM and MEA are the two governance domains” is wrong. An option that says “MEA replaced EDM in 2019” is wrong. An option that says “MEA01 is Ensured Performance Monitoring” invents a governance title.
The four official objectives
| ID | Official title | One-sentence purpose | 2019 note |
|---|---|---|---|
| MEA01 | Managed Performance and Conformance Monitoring | Collect, validate, and evaluate business, IT, and process goals and metrics; report systematic, timely performance and conformance. | Present in COBIT 5; still management. |
| MEA02 | Managed System of Internal Control | Continuously monitor and evaluate the control environment, including self-assessments and independent reviews, so management can fix deficiencies. | The system of internal control — not a single process edit. |
| MEA03 | Managed Compliance With External Requirements | Evaluate that I&T and I&T-supported business processes comply with laws, regulations, and contractual requirements. | External obligations, not internal policy-only conformance. |
| MEA04 | Managed Assurance | Plan, scope, and execute assurance initiatives that independently confirm processes and controls; report to relevant stakeholders. | New in 2019. |
MEA01 Managed Performance and Conformance Monitoring
MEA01 is the management dashboard objective. Collect, validate, and evaluate business, IT, and process goals and metrics. Monitor that processes perform against agreed performance and conformance goals. Provide reporting that is systematic and timely.
Performance asks whether we are achieving what we said we would achieve — cycle time, benefit hypotheses, service levels, quality. Conformance asks whether we are inside the internal rules we said we would keep — policy, agreed procedures, directed risk treatments. MEA01 is not the board’s EDM05 Ensured Stakeholder Engagement (the board ensuring stakeholders are engaged and that performance and conformance are reported to them). MEA01 is management building and running the monitoring system that makes those reports possible.
Northline’s weekly claims-cycle-time pack, the exception list against the “straight-through” rule, and the process-level scorecard that shows whether BAI07’s post-implementation promises still hold are MEA01. A colorful dashboard that nobody validates is not MEA01. Validate is in the official job: bad metrics are not monitoring.
MEA02 Managed System of Internal Control
MEA02 continuously monitors and evaluates the control environment, including self-assessments and independent assurance reviews. It enables management to identify control deficiencies and inefficiencies and to initiate improvement. It plans, organizes, and maintains standards for internal-control assessment.
This is the system view. DSS06 Managed Business Process Controls embeds maker-checker in the claims payment process. MEA02 asks whether the system of internal control — across processes, structures, and the other components — is still designed and operating as a system. A stem that says “add an input edit to the payment screen” is DSS06. A stem that says “management evaluates whether the internal-control system is adequate after the vendor took over overflow adjusting” is MEA02.
MEA02 uses self-assessment and independent review as inputs. It is still a management objective. Independent assurance as its own planned initiative is MEA04. Do not merge them just because both words sound like audit.
MEA03 Managed Compliance With External Requirements
MEA03 evaluates that I&T processes and I&T-supported business processes comply with laws, regulations, and contractual requirements. Obtain assurance that those external requirements have been identified and complied with, and integrate I&T compliance with overall enterprise compliance.
The object is external. Privacy law, insurance conduct rules, contractual data-processing clauses, and industry obligations live here. Internal policy conformance that is not an external obligation is closer to MEA01’s conformance monitoring. The exam will offer MEA03 as a distractor for any monitoring stem. Ask: is the requirement external?
Northline’s review that the claims engine and the overflow vendor still meet the privacy statute and the regulator’s conduct rules is MEA03. Integrating that work with the enterprise compliance function is part of the official purpose — I&T compliance is not a private IT hobby.
MEA03 is not MEA04. Compliance assessment against external requirements can feed assurance. It is not itself the independent assurance program.
MEA04 Managed Assurance
MEA04 Managed Assurance is new in COBIT 2019. COBIT 5’s MEA domain stopped at three processes. 2019 added a fourth management objective so assurance has its own planned home.
Official job: plan, scope, and execute assurance initiatives that independently confirm I&T processes, controls, and the system of internal control are designed and operating effectively, then report results to relevant stakeholders. Use a road map based on accepted assurance approaches.
Independent is the tell. MEA01 is management’s own metrics. MEA02 is management evaluating the control system, including using independent reviews as an input. MEA04 is the objective that plans and executes those independent assurance initiatives — internal audit-style, third-party, or other independent confirmations — so the enterprise is not marking its own homework as the only line of evidence.
If a stem says “new in 2019” and the options include a MEA title, look at MEA04 Managed Assurance first (and remember BAI11 Managed Projects and APO14 Managed Data are the other famous 2019 additions). If a stem says “independent confirmation that controls operate effectively,” prefer MEA04 over MEA01’s dashboard and over MEA03’s external-requirement assessment.
High-yield split: MEA01 versus MEA03 versus MEA04
| Official objective | Object of work | Independence | Typical stem language |
|---|---|---|---|
| MEA01 Managed Performance and Conformance Monitoring | Goals and metrics; performance and internal conformance | Management’s own monitoring | Scorecard, KPI, validated metrics, timely reporting |
| MEA03 Managed Compliance With External Requirements | Laws, regulations, contracts | Compliance evaluation, integrated with enterprise compliance | Regulator, statute, contractual clause |
| MEA04 Managed Assurance | Independent confirmation of processes and controls | Independent assurance initiatives, planned and scoped | Internal audit plan, independent review program, new in 2019 |
MEA02 sits beside them as the system of internal control evaluation. Keep it in the DSS06 contrast you already learned: controls in the process versus assessment of the system.
Scenario: Northline’s first quarter after go-live
The claims engine has been live for a quarter. The board still owns EDM. Management now has to monitor.
MEA01 collects and validates cycle-time, straight-through rate, defect leakage, and conformance to the internal “no payment without maker-checker” rule. The pack is systematic and timely — not a one-off slide after a complaint.
MEA02 evaluates the control environment as a system. Overflow adjusting is now outsourced. Self-assessments plus an independent review show a segregation-of-duties gap the DSS06 process control did not catch across the vendor boundary. Management initiates improvement. That evaluation is MEA02, not a new DSS ticket.
MEA03 maps the privacy statute, the conduct regulator, and the engine vendor’s contractual processing clauses, then evaluates whether I&T-supported claims processes still comply. Findings feed the enterprise compliance function. This is not a metrics dashboard and not an audit plan.
MEA04 — the 2019 objective — plans an independent assurance initiative on the new cloud landing zone and the outsourced overflow controls. Scope, execution, and reporting to relevant stakeholders sit here. The board may use that report under EDM03 and EDM05. Using the report is governance. Planning and executing the independent initiative is MEA04.
A candidate who answers every one of those stems with “MEA, because it is governance monitoring” has fallen for the name trap. None of the four titles is Ensured. None is owned by the board. All four are Managed.
Closing the 40
You can now walk the whole core model:
- EDM (5) — board Ensured governance.
- APO (14) — management plans.
- BAI (11) — management builds, including BAI11 projects.
- DSS (6) — management runs.
- MEA (4) — management monitors, including MEA04 assurance.
Forty objectives. Five domains. One governance domain. Four management domains. Recite the MEA four by official title. Refuse to promote them to the board. Refuse to merge metrics, control-system evaluation, external compliance, and independent assurance.
Exam traps
- MEA is a fifth governance domain. False. MEA is management. Only EDM is governance.
- Monitor in the name = EDM. EDM ends with Monitor; MEA begins with it. Owner and title pattern decide.
- MEA01 = MEA03 = MEA04. Metrics versus external compliance versus independent assurance.
- MEA02 = DSS06. System of internal control versus business process controls.
- Forgetting MEA04. It is new in 2019.
- Inventing Ensured titles in MEA, or dropping MEA to three because you memorized COBIT 5.
- Calling MEA01 the board pack. EDM05 ensures stakeholder reporting; MEA01 is management’s monitoring system.
Prefer the answer that keeps all four official titles, keeps Managed not Ensured, keeps MEA under management, and keeps MEA04 as the 2019 independent-assurance objective.
A Foundation stem calls MEA the fifth governance domain because the name begins with Monitor. What is the error?
Which statement correctly separates the four MEA objectives?