17.2 Seven Implementation Phases

Key Takeaways

  • Memorize the seven official questions in order: drivers, current state, target, what to do, how to get there, did we get there, keep the momentum.
  • Phase 2 recognizes the current state; phase 3 defines the target, including capability targets that come from design.
  • Phase 4 plans the gap; phase 5 executes; phase 6 reviews benefits — do not treat documents as outcomes.
  • Phase 7 embeds continual improvement so the cycle does not die when the increment closes.
  • The high-yield traps are swapping phase 2 with phase 3, and ending the lifecycle at phase 5.
Last updated: August 2026

Quick Answer: Memorize the seven official questions in this order: (1) What are the drivers? (2) Where are we now? (3) Where do we want to be? (4) What needs to be done? (5) How do we get there? (6) Did we get there? (7) How do we keep the momentum going? Phase 2 is current state. Phase 3 is the designed target, including capability targets. Phase 5 executes. Phases 6 and 7 still remain. The exam traps are swapping 2 and 3 and ending at phase 5.

This is the highest-yield list in the 8% Implementation domain. If you can write the seven questions from memory, match each to its job, and refuse two swaps, you have most of the domain. Recognition, not a programme-manager simulation, is what Foundation tests.

The questions are the official phase titles. Under each question the enterprise does real work: recognize, define, plan, execute, review, embed. Learn the question first. Then learn what happens. Do not replace the official questions with homemade labels such as “assess / design / build / run” and hope ISACA will accept the paraphrase.

The seven questions, in order

PhaseOfficial questionWhat happensTypical output
1What are the drivers?Recognize why change is needed now; collect pain points and trigger events; start the programme and the case for sponsorshipDesire to change, outline business case, executive air cover
2Where are we now?Recognize the current state: issues, practices, and current capabilityHonest as-is picture, problem and opportunity list
3Where do we want to be?Define the target state, including capability targets from design, and a roadmap toward itTo-be profile, target capabilities, roadmap
4What needs to be done?Translate the gap into a prioritized plan of improvements — not all 40 objectives at onceProgramme plan, prioritized initiatives
5How do we get there?Execute the plan: change processes, structures, skills, culture, and servicesDelivered improvements, not only documents
6Did we get there?Review benefits against the target, not against the volume of bindersBenefits review, gap-to-target status
7How do we keep the momentum going?Embed continual improvement so the cycle restarts when pain or a trigger returnsSustained ownership, next-pass drivers

Read the middle column as a verb chain: recognize current → define target → plan → execute → review benefits → embed. That chain is the lifecycle. The left column is what you must recite on the exam.

Phase 1 — What are the drivers?

Phase 1 is not a capability assessment. It is the why now. The team gathers pain points and trigger events, turns them into a story the board can fund, and initiates a programme with an executive sponsor. Without this phase, later work is a hobby inside IT.

Aether’s driver story is a completed acquisition plus a supervisory letter plus shadow SaaS the board can no longer ignore. Northline’s driver story is a line-stopping near-miss plus unit cost the chair no longer believes. Both stories belong here. Neither story is “we should adopt COBIT because a peer did.”

Phase 1 also creates the political conditions for design and for later phases. A sponsor who will not attend phase 1 will not save phase 5.

Phase 2 — Where are we now?

Phase 2 is the as-is. Assess current EGIT, current management practices, current issues, and current capability. Be honest. Inflating the current state so the gap looks small is how programmes later claim success they did not earn.

This phase recognizes current state. It does not set the destination. Candidates who load target capability into phase 2 have already swapped 2 and 3.

Northline discovers that DSS01 Managed Operations is performed on some lines and incomplete on others, that BAI09 Managed Assets is a spreadsheet two quarters behind, and that APO06 Managed Budget and Costs cannot explain plant-IT spend. Aether discovers that APO13 and DSS05 are uneven across acquired banks, that APO14 Managed Data has no owner, and that release practices under BAI06 collide weekly. That is “where we are now.” It is not yet “where we want to be.”

Phase 3 — Where do we want to be?

Phase 3 is the to-be. The target is not a slogan (“world-class IT”). It is a designed profile: which of the 40 objectives matter more, and at what target capability. Those targets come from the Design Guide workflow — conclude the design, including capability — and are used here as the destination the lifecycle aims at.

Aether’s target may raise security, data, vendors, and architecture above Northline’s, with different capability numbers on the same objective IDs. Northline’s target may raise operations, assets, and budget. Capability 5 on every row is not a phase-3 answer. It is the equal-implementation trap wearing a roadmap badge.

If a stem asks which phase uses design’s capability targets, the answer is phase 3 — where do we want to be? — not phase 2.

Phase 4 — What needs to be done?

Phase 4 turns the gap into a plan. What initiatives will close the distance between phase 2 and phase 3? In what order? With which owners, components, and funding? This is where boiling the ocean is refused. A designed system that prioritized twelve objectives does not become a forty-workstream programme at the planning table.

Phase 4 is still planning. It is not execution. Writing a plan is not “how do we get there?” Getting there is phase 5.

Phase 5 — How do we get there?

Phase 5 executes. Process owners change work. Structures meet. Skills are hired or built. Culture is confronted. Services and tools are adjusted. The seven components move, not only the process narratives.

This is the phase energetic sponsors love, and it is why the exam traps you into stopping here. Execution feels like the finish. It is not. You can execute the wrong plan, execute without measuring benefits, or execute once and then drift. Phases 6 and 7 exist because phase 5 is necessary and insufficient.

Phase 6 — Did we get there?

Phase 6 is a benefits review, not a deliverable count. Compare outcomes to the phase-3 target. Did capability actually move? Did the pain that started phase 1 recede? Did the merger, the outage, or the supervisory letter get a governance response that stuck?

Aether shipped a policy pack and a new committee. If incidents, data ownership, and vendor risk did not move, phase 6’s answer is no — even if the PMO’s dashboard is green. Northline published an asset procedure. If the line still cannot see what is running, phase 6’s answer is no.

Phase 7 — How do we keep the momentum going?

Phase 7 embeds continual improvement. Ownership stays with process owners and the governing body, not with a departing consultant. The next pain or trigger is allowed to restart phase 1. Design factors that changed — a new sourcing model, a new regulation, another acquisition — send the enterprise back through design and then around the cycle again.

Ending at phase 5 skips this on purpose. Treating phase 7 as “write a lessons-learned slide and close the project forever” also skips it. Momentum is the difference between a COBIT project and EGIT as a system.

Exam traps: swap 2 with 3, or stop at 5

Wrong instincts:

  • “Where do we want to be?” comes before “Where are we now?” because strategy is more important than assessment.
  • Phase 2 is where you set target capability.
  • Phase 5 is the last official question, so the lifecycle ends at execution.
  • Phase 6 is optional if the plan was delivered on time.
  • Phase 7 is a close-out meeting, not a return to the cycle.
  • The seven questions are the same as the four-step design workflow.

Right instincts:

  1. Drivers first.
  2. Current state next.
  3. Target — including design’s capability targets — after you know the as-is.
  4. Plan the gap.
  5. Execute.
  6. Review benefits.
  7. Keep momentum and circle again.

If a stem puts the target before the current state, reject the swap. If it treats a delivered plan as “we got there,” reject the stop at 5. If it offers the seven questions in the official order and uses phase 3 for the designed to-be, take it.

Loading diagram...
Seven official questions: current state, designed target, then execute and sustain
Test Your Knowledge

What is the official order of the seven COBIT 2019 implementation-lifecycle questions?

A
B
C
D
Test Your Knowledge

How should phase 2 be distinguished from phase 3?

A
B
C
D
Test Your Knowledge

Why is ending the lifecycle at phase 5 an exam trap?

A
B
C
D