13.3 MEA Monitor, Evaluate, and Assess

Key Takeaways

  • MEA Monitor, Evaluate, and Assess is a 4-objective MANAGEMENT domain; calling it a fifth governance domain because it begins with Monitor is the classic Foundation trap.
  • Only EDM Evaluate, Direct and Monitor is governance. MEA is how management monitors performance, the control system, external compliance, and assurance.
  • MEA01 Managed Performance and Conformance Monitoring collects, validates, and reports goals and metrics for performance and conformance.
  • MEA02 Managed System of Internal Control evaluates the control environment; it does not embed the process controls that live in DSS06.
  • MEA03 Managed Compliance With External Requirements assesses laws, regulations, and contracts; MEA04 Managed Assurance is new in 2019 and plans independent assurance initiatives.
Last updated: August 2026

Quick Answer: Monitor, Evaluate, and Assess (MEA) is a 4-objective MANAGEMENT domain. It is not a fifth governance domain. Only Evaluate, Direct and Monitor (EDM) is governance. MEA01 Managed Performance and Conformance Monitoring collects, validates, and evaluates goals and metrics and reports performance and conformance. MEA02 Managed System of Internal Control continuously monitors and evaluates the control environment. MEA03 Managed Compliance With External Requirements evaluates compliance with laws, regulations, and contractual requirements. MEA04 Managed Assurance is new in 2019 and plans, scopes, and executes independent assurance initiatives. Do not promote MEA to the board because the name starts with Monitor, and do not collapse MEA03, MEA04, and MEA01 into one “audit” title.

This is the last cluster in the 40-objective core model. You now hold EDM 5, APO 14, BAI 11, DSS 6, and MEA 4. 5+14+11+6+4 = 40. MEA is the smallest domain and one of the most trap-heavy, because its first word is Monitor and EDM’s last word is Monitor.

MEA is management monitoring, not EDM

Governance distinct from management is a governance-system principle. The board evaluates, directs, and monitors at enterprise altitude — value, risk, resources, stakeholders. Management plans, builds, runs, and monitors the work. MEA is that last management verb. It produces the evidence, assessments, compliance views, and assurance results that inform EDM. It does not become EDM.

LensEDM Evaluate, Direct and MonitorMEA Monitor, Evaluate, and Assess
TypeThe only governance domainA management domain
Count5 objectives, all titled Ensured4 objectives, all titled Managed
OwnerBoard or other governing bodyExecutive and operational management, including control, compliance, and assurance functions
AltitudeAppetite, benefits, resources, stakeholder engagement, the governance system itselfMetrics, the internal-control system, external requirements, independent assurance initiatives
Name trapEnds with MonitorBegins with Monitor

If a stem says the board reviews whether residual I&T risk still sits inside appetite, that is EDM03 Ensured Risk Optimization, possibly fed by MEA reports. If it says management collects process metrics and reports performance against agreed goals, that is MEA01. Same English verb, monitor. Different official domain, different title pattern, different owner.

Exam trap: calling MEA a fifth governance domain. There are five domains total, and only one of them is governance. MEA is the fourth management domain (APO, BAI, DSS, MEA), not a second governance domain and not a sixth domain. An option that says “EDM and MEA are the two governance domains” is wrong. An option that says “MEA replaced EDM in 2019” is wrong. An option that says “MEA01 is Ensured Performance Monitoring” invents a governance title.

The four official objectives

IDOfficial titleOne-sentence purpose2019 note
MEA01Managed Performance and Conformance MonitoringCollect, validate, and evaluate business, IT, and process goals and metrics; report systematic, timely performance and conformance.Present in COBIT 5; still management.
MEA02Managed System of Internal ControlContinuously monitor and evaluate the control environment, including self-assessments and independent reviews, so management can fix deficiencies.The system of internal control — not a single process edit.
MEA03Managed Compliance With External RequirementsEvaluate that I&T and I&T-supported business processes comply with laws, regulations, and contractual requirements.External obligations, not internal policy-only conformance.
MEA04Managed AssurancePlan, scope, and execute assurance initiatives that independently confirm processes and controls; report to relevant stakeholders.New in 2019.

MEA01 Managed Performance and Conformance Monitoring

MEA01 is the management dashboard objective. Collect, validate, and evaluate business, IT, and process goals and metrics. Monitor that processes perform against agreed performance and conformance goals. Provide reporting that is systematic and timely.

Performance asks whether we are achieving what we said we would achieve — cycle time, benefit hypotheses, service levels, quality. Conformance asks whether we are inside the internal rules we said we would keep — policy, agreed procedures, directed risk treatments. MEA01 is not the board’s EDM05 Ensured Stakeholder Engagement (the board ensuring stakeholders are engaged and that performance and conformance are reported to them). MEA01 is management building and running the monitoring system that makes those reports possible.

Northline’s weekly claims-cycle-time pack, the exception list against the “straight-through” rule, and the process-level scorecard that shows whether BAI07’s post-implementation promises still hold are MEA01. A colorful dashboard that nobody validates is not MEA01. Validate is in the official job: bad metrics are not monitoring.

MEA02 Managed System of Internal Control

MEA02 continuously monitors and evaluates the control environment, including self-assessments and independent assurance reviews. It enables management to identify control deficiencies and inefficiencies and to initiate improvement. It plans, organizes, and maintains standards for internal-control assessment.

This is the system view. DSS06 Managed Business Process Controls embeds maker-checker in the claims payment process. MEA02 asks whether the system of internal control — across processes, structures, and the other components — is still designed and operating as a system. A stem that says “add an input edit to the payment screen” is DSS06. A stem that says “management evaluates whether the internal-control system is adequate after the vendor took over overflow adjusting” is MEA02.

MEA02 uses self-assessment and independent review as inputs. It is still a management objective. Independent assurance as its own planned initiative is MEA04. Do not merge them just because both words sound like audit.

MEA03 Managed Compliance With External Requirements

MEA03 evaluates that I&T processes and I&T-supported business processes comply with laws, regulations, and contractual requirements. Obtain assurance that those external requirements have been identified and complied with, and integrate I&T compliance with overall enterprise compliance.

The object is external. Privacy law, insurance conduct rules, contractual data-processing clauses, and industry obligations live here. Internal policy conformance that is not an external obligation is closer to MEA01’s conformance monitoring. The exam will offer MEA03 as a distractor for any monitoring stem. Ask: is the requirement external?

Northline’s review that the claims engine and the overflow vendor still meet the privacy statute and the regulator’s conduct rules is MEA03. Integrating that work with the enterprise compliance function is part of the official purpose — I&T compliance is not a private IT hobby.

MEA03 is not MEA04. Compliance assessment against external requirements can feed assurance. It is not itself the independent assurance program.

MEA04 Managed Assurance

MEA04 Managed Assurance is new in COBIT 2019. COBIT 5’s MEA domain stopped at three processes. 2019 added a fourth management objective so assurance has its own planned home.

Official job: plan, scope, and execute assurance initiatives that independently confirm I&T processes, controls, and the system of internal control are designed and operating effectively, then report results to relevant stakeholders. Use a road map based on accepted assurance approaches.

Independent is the tell. MEA01 is management’s own metrics. MEA02 is management evaluating the control system, including using independent reviews as an input. MEA04 is the objective that plans and executes those independent assurance initiatives — internal audit-style, third-party, or other independent confirmations — so the enterprise is not marking its own homework as the only line of evidence.

If a stem says “new in 2019” and the options include a MEA title, look at MEA04 Managed Assurance first (and remember BAI11 Managed Projects and APO14 Managed Data are the other famous 2019 additions). If a stem says “independent confirmation that controls operate effectively,” prefer MEA04 over MEA01’s dashboard and over MEA03’s external-requirement assessment.

High-yield split: MEA01 versus MEA03 versus MEA04

Official objectiveObject of workIndependenceTypical stem language
MEA01 Managed Performance and Conformance MonitoringGoals and metrics; performance and internal conformanceManagement’s own monitoringScorecard, KPI, validated metrics, timely reporting
MEA03 Managed Compliance With External RequirementsLaws, regulations, contractsCompliance evaluation, integrated with enterprise complianceRegulator, statute, contractual clause
MEA04 Managed AssuranceIndependent confirmation of processes and controlsIndependent assurance initiatives, planned and scopedInternal audit plan, independent review program, new in 2019

MEA02 sits beside them as the system of internal control evaluation. Keep it in the DSS06 contrast you already learned: controls in the process versus assessment of the system.

Scenario: Northline’s first quarter after go-live

The claims engine has been live for a quarter. The board still owns EDM. Management now has to monitor.

MEA01 collects and validates cycle-time, straight-through rate, defect leakage, and conformance to the internal “no payment without maker-checker” rule. The pack is systematic and timely — not a one-off slide after a complaint.

MEA02 evaluates the control environment as a system. Overflow adjusting is now outsourced. Self-assessments plus an independent review show a segregation-of-duties gap the DSS06 process control did not catch across the vendor boundary. Management initiates improvement. That evaluation is MEA02, not a new DSS ticket.

MEA03 maps the privacy statute, the conduct regulator, and the engine vendor’s contractual processing clauses, then evaluates whether I&T-supported claims processes still comply. Findings feed the enterprise compliance function. This is not a metrics dashboard and not an audit plan.

MEA04 — the 2019 objective — plans an independent assurance initiative on the new cloud landing zone and the outsourced overflow controls. Scope, execution, and reporting to relevant stakeholders sit here. The board may use that report under EDM03 and EDM05. Using the report is governance. Planning and executing the independent initiative is MEA04.

A candidate who answers every one of those stems with “MEA, because it is governance monitoring” has fallen for the name trap. None of the four titles is Ensured. None is owned by the board. All four are Managed.

Closing the 40

You can now walk the whole core model:

  • EDM (5) — board Ensured governance.
  • APO (14) — management plans.
  • BAI (11) — management builds, including BAI11 projects.
  • DSS (6) — management runs.
  • MEA (4) — management monitors, including MEA04 assurance.

Forty objectives. Five domains. One governance domain. Four management domains. Recite the MEA four by official title. Refuse to promote them to the board. Refuse to merge metrics, control-system evaluation, external compliance, and independent assurance.

Exam traps

  • MEA is a fifth governance domain. False. MEA is management. Only EDM is governance.
  • Monitor in the name = EDM. EDM ends with Monitor; MEA begins with it. Owner and title pattern decide.
  • MEA01 = MEA03 = MEA04. Metrics versus external compliance versus independent assurance.
  • MEA02 = DSS06. System of internal control versus business process controls.
  • Forgetting MEA04. It is new in 2019.
  • Inventing Ensured titles in MEA, or dropping MEA to three because you memorized COBIT 5.
  • Calling MEA01 the board pack. EDM05 ensures stakeholder reporting; MEA01 is management’s monitoring system.

Prefer the answer that keeps all four official titles, keeps Managed not Ensured, keeps MEA under management, and keeps MEA04 as the 2019 independent-assurance objective.

Loading diagram...
MEA is management monitoring, not a fifth governance domain
Test Your Knowledge

A Foundation stem calls MEA the fifth governance domain because the name begins with Monitor. What is the error?

A
B
C
D
Test Your Knowledge

Which statement correctly separates the four MEA objectives?

A
B
C
D