17.3 Roles, Pain Points, and Challenges

Key Takeaways

  • A board or executive sponsor must own the mandate; consultant-only ownership is a failure mode, not a staffing model.
  • Internal audit and assurance advise and give independent assurance — they do not own EGIT.
  • Process owners, business stakeholders, the implementation team, and the PMO each have a job; COBIT is not an IT-only workshop.
  • Pain points are current burns; trigger events are discrete windows — learn both with examples.
  • Classic challenges are no sponsorship, IT-only scope, boiling the ocean, culture resistance, no benefits tracking, and binders with no behavior change.
Last updated: August 2026

Quick Answer: Implementation needs a board or executive sponsor, an implementation team, process owners, business stakeholders, and usually a PMO. Internal audit and assurance advise; they do not own EGIT. Pain points are current burns; trigger events are discrete windows. Classic challenges are no sponsorship, IT-only COBIT, boiling the ocean, culture resistance, no benefits tracking, and consultant-only ownership that produces binders and no behavior change.

The seven questions tell you what the lifecycle asks. This section tells you who has to show up and why programmes die anyway. Foundation will give you short scenarios. Name the missing role or the named challenge. Do not invent a rule that “audit should run COBIT because COBIT used to sound like control objectives.”

Who has to be in the room

EGIT is part of corporate governance. The governing body still evaluates, directs, and monitors. An implementation programme that never reaches the board is a management project wearing a governance badge.

RoleJob in the lifecycleFailure if missing
Board / executive sponsorMandate, resources, visible direction, air cover when culture pushes backThe programme becomes optional the first time a line manager is busy
Implementation teamCoordinate the seven phases, keep design and implementation connected, chase decisionsWork fragments into local tools and unofficial side projects
Process ownersChange the actual work under in-scope objectives; accept capability targetsNarratives update; behavior does not
Business stakeholdersKeep outcomes in business language — value, risk, cost, customers, plants, productsCOBIT collapses into an IT-only workshop
PMOProgramme discipline: plan, dependencies, reporting, increment controlPhase 4 and phase 5 turn into an unmanaged pile of initiatives
Internal audit / assuranceAdvise, provide independent assurance, later assess whether EGIT worksIf they own EGIT, independence and accountability both break

Read the last row twice. Assurance as advisor, not owner is a Foundation favorite. Audit can be a driver (findings are pain). Audit can be a reviewer (phase 6 and MEA-style assurance). Audit cannot be the executive sponsor, the process owner of APO and DSS, and the independent assurer of the same system.

The implementation team is a coordinator, not a permanent shadow IT department that “does COBIT” so everyone else can ignore it. The PMO is useful. The PMO does not replace process owners. Business stakeholders are not optional guests at an IT kickoff. If only the CIO shop is in the room, you have already hit the IT-only challenge.

Pain points versus trigger events, with examples

Section 17.1 introduced the pair. Here you must be able to classify a stem.

Pain points — already true this quarter, even if nobody launched a programme:

  • Failed or chronically late I&T programmes
  • Recurring incidents or a standing problem backlog
  • Audit findings that reopen every year
  • I&T cost the board cannot connect to value
  • Business and I&T talking past each other on priorities
  • Shadow IT / shadow SaaS
  • Security or data issues that never quite become a crisis

Trigger events — a discrete event that opens a window:

  • Merger or acquisition
  • Regulatory shock or a new supervisory letter
  • Major outage that reaches the board
  • New CIO, CEO, or chair
  • Published digital or transformation strategy
  • IPO, new market, or a hard board mandate
StoryClassify asWhy
Northline’s unit-cost reports have been unexplained for six quartersPain pointCurrent, ongoing dissatisfaction
Northline’s line stops for a shift after a near-miss, and the chair demands a responseTrigger eventDiscrete event that opens a window
Aether’s acquired banks still run colliding release trainsPain pointCurrent operating problem
Aether closes the acquisition and receives a supervisory letterTrigger eventDiscrete event plus external shock
Internal audit repeats the same access finding for the third yearPain pointStanding issue; also a possible later trigger if the chair finally refuses it

A programme can have both. Aether often will: pain in data and releases, trigger in the acquisition and the letter. Phase 1 collects both. It does not treat them as the same noun.

Challenges that kill the lifecycle

Know these by name. Stems will describe them without labeling them.

  1. Lack of sponsorship. No executive will spend political capital. Phase 1 never really happens. Later phases become evenings-and-weekends work inside architecture.
  2. Treating COBIT as IT-only. The CIO shop “implements COBIT” for systems it owns. OT, digital products, vendor platforms, and business data sit outside the tent. That also violates end-to-end coverage and the I&T-versus-IT-function idea from earlier chapters.
  3. Boiling the ocean. No design, no prioritization. All 40 objectives, capability 5, this year. Phase 4 becomes a fantasy programme. Phase 5 drowns.
  4. Culture, ethics, and behavior resistance. Process narratives change; incentives and habits do not. The culture component was taught for a reason. A lifecycle that ignores it will look complete and change nothing.
  5. No benefits tracking. Phase 6 is skipped. The PMO reports activity. The board never sees whether pain receded.
  6. Consultant-only ownership. The firm writes the system, presents the binders, and leaves. Process owners never accepted the work. When the contract ends, EGIT ends.

These challenges stack. A sponsor-free, IT-only, consultant-led, forty-objective programme with no benefits measures is not six separate unlucky events. It is one failed pattern.

Scenario: binders, no behavior change

Aether hires a firm to “implement COBIT” in ninety days after the acquisition. There is no lasting executive sponsor — the CIO attends the kickoff and then disappears into integration meetings. The firm photocopies generic process narratives for all 40 objectives, prints RACI charts nobody negotiated, and stacks them in branded binders. Internal audit is told it now “owns COBIT” because the word control appears in the framework’s history. Process owners are invited to a readout, not to change a decision right. The PMO closes the project on time. Six months later the audit committee asks what behavior changed in releases, data ownership, or vendor risk. Nothing has. Shadow SaaS grew. The supervisory letter is still open.

That programme hit almost every challenge in one story: weak sponsorship, IT-only framing, boiling the ocean, culture ignored, no benefits tracking, consultant-only ownership, and assurance asked to own EGIT. It produced binders. It did not produce a governance system.

The repair is not a thicker binder. The repair is a sponsor, a designed subset of objectives with capability targets, process owners who change work, business stakeholders in the room, audit back in an assurance seat, and phases 6 and 7 that ask whether Aether actually moved.

Northline can fail the same way at smaller scale: a plant-IT lead buys a “COBIT in a box” pack, labels it implementation, and never involves operations or finance. The pack is still a binder.

Exam instincts

Wrong instincts:

  • “Internal audit should own EGIT because COBIT is about controls.”
  • “If consultants delivered the documents, implementation succeeded.”
  • “Pain points and trigger events are two names for the same start.”
  • “Business stakeholders are optional once IT has a PMO.”
  • “Doing all 40 objectives proves commitment.”

Right instincts:

  • Sponsor first.
  • Audit advises; it does not own.
  • Process owners and the business must change work.
  • Pain is current; a trigger is a window.
  • Binders without behavior change are a failed COBIT project, not a conservative start.

If a stem offers a sponsored, designed, business-inclusive programme with assurance on the side, take it. If it offers a consultant binder that audit is told to own, reject it.

Loading diagram...
Implementation roles: sponsor owns the mandate; audit advises, not owns
Test Your Knowledge

What is the correct role of internal audit or assurance in a COBIT implementation?

A
B
C
D
Test Your Knowledge

Which scenario is a classic failed COBIT implementation?

A
B
C
D