7.2 Practices, Activities, and Metrics
Key Takeaways
- The Foundation stack is objective → process → practices → activities; practices group activities, and a practice is not an objective.
- Activities can be tagged to capability levels — higher capability means more complete, organized, and measured activities, not a new process ID.
- Each objective also has example metrics linked to alignment and enterprise goals; a metric measures, it is not a process.
- EDM03.02 Direct risk management is a practice with activities such as directing appetite communication and accept-or-treat decisions; APO12 sits underneath as the management process.
- The exam does not require memorizing about 1,202 activities; it requires recognizing the stack and refusing to treat a metric as a process.
Quick Answer: COBIT 2019 stacks work as objective → process → practices → activities. Practices group activities. Activities can be tagged to capability levels — higher capability needs more complete, organized, and measured work. Each objective also has example metrics tied to alignment and enterprise goals. The Foundation exam tests recognition of this stack, not memorization of about 1,202 activities.
The stack you must recognize closed-book
Candidates lose easy items when they flatten the stack. An objective is the outcome. The process is the organized work for that outcome. Inside the process, practices are the named chunks of work (EDM03.01, EDM03.02, EDM03.03). Inside each practice, activities are the concrete things people do. Metrics sit beside the stack as example measures; they are not a fifth layer of work and they are not a process.
Recite it once: objective, then process, then practices, then activities. A practice is not an objective. An activity is not a practice. A metric is not a process.
Practices exist so the process is teachable and assignable. “Manage risk” is too large to put on a RACI row. “Direct risk management” is a practice a governing body can own. “Maintain a risk profile” is a practice a risk function can own. Activities then unpack the practice into work a team can actually schedule: collect incidents, update the profile after a major change, brief the risk committee.
COBIT 2019 publishes on the order of 1,202 activities across the 40 processes. Foundation does not expect you to memorize them. If an item quotes an activity, your job is to place it: it belongs under a practice, inside a process, supporting an objective. If an item asks what you must memorize, the answer is the stack, the idea of capability-tagged activities, and the idea of example metrics — not the catalog.
Capability tags on activities
Performance management (Chapter 14) scores capability on the process. The process becomes more capable when its activities are more complete, more organized, and more measured.
A level-1 reading of a practice might include the essential activities — the work that means “we did it.” A level-2 or level-3 reading adds activities that plan the work, assign it, document it, and apply a standard way of working. Higher levels add measurement, prediction, and improvement activities. The practice ID does not change. EDM03.02 is still EDM03.02. What changes is how fully the activities under it are performed.
That is why “we have the practice on a slide” is not evidence of capability. Capability asks whether the activities actually happen in an organized, measured way. It is also why copying another firm’s practice list does not copy their capability. The IDs travel. The performed, managed, and established work does not.
Example metrics are not processes
Each objective offers example metrics. Those metrics are illustrative measures that show whether alignment goals and enterprise goals — and the process goals that support them — are moving. They are teaching aids, not a mandatory KPI standard and not a forty-first process.
A metric such as “percent of I&T risk exceeding agreed appetite” tells you whether EDM03 and APO12 are working. It is not the EDM03 process. It is not a practice. It does not have inputs and outputs. Confusing a metric with a process is a published Foundation trap: the number is a signal, the process is the work that produces outputs.
Metrics also do not replace the other six components. A green dashboard with no risk committee, no appetite policy, and no skilled analysts is decoration. And a metric is not an alignment goal. Alignment goals are the I&T-related goals in the cascade. Metrics are example ways to observe those goals.
Worked example: EDM03, with APO12 underneath
Use EDM03 Ensured Risk Optimization as the governance picture and APO12 Managed Risk as the management counterpart. Governance evaluates, directs, and monitors. Management collects data, analyzes risk, maintains a profile, articulates risk, defines a risk-action portfolio, and responds.
EDM03’s process typically groups three practices that match the EDM verbs:
| Practice (conceptual) | What the governing body is doing | Example activities — not a list to memorize |
|---|---|---|
| EDM03.01 Evaluate risk management | Judge whether the risk approach, appetite, and thresholds still fit stakeholder value | Review appetite against strategy; evaluate whether current risk information is decision-grade |
| EDM03.02 Direct risk management | Set direction for how management will treat I&T risk | Direct communication of appetite; direct which risks require treatment versus acceptance |
| EDM03.03 Monitor risk management | Watch whether risk stays inside directed limits | Monitor residual risk versus appetite; monitor whether treatments actually closed the exposure |
Take EDM03.02 Direct risk management. The practice is not the objective — the objective is ensured risk optimization. The practice is not a metric — “percent of risks with an explicit accept-or-treat decision” might be an example metric sitting beside the stack. The practice groups activities such as: communicate the approved appetite to management; require that material I&T risks come to the governing body with a recommended response; forbid silent acceptance of risk above threshold; and insist that risk direction is written so APO12 can execute it.
Those activities can be tagged to capability. At a low capability the board mentions risk once a year. At a higher capability the same EDM03.02 activities happen on a defined cadence, with recorded decisions, with escalation rules, and with measures that show whether direction was followed.
APO12 Managed Risk sits underneath that direction. Its practices conceptually include collecting data, analyzing risk, maintaining a risk profile, articulating risk, defining a risk-action portfolio, and responding to risk. APO12.03 Maintain a risk profile is a practice, not an objective and not a metric. Activities under it might include updating the profile after incidents, after major projects, and after vendor changes. The output is a current risk profile. The input often includes EDM03’s directed appetite plus incident and monitoring data from DSS or MEA processes.
Walk one sentence of the stack out loud: the objective is EDM03 Ensured Risk Optimization; the process is the related EDM03 process; EDM03.02 is a practice; “direct communication of appetite” is an activity; “percent of residual risk above appetite” is an example metric. If you can place those five nouns, you can place almost any Foundation item in this family.
Exam traps on the stack
Two traps dominate. Treating a metric as a process — the candidate sees a percentage and names it APO12. Treating a practice as an objective — the candidate sees EDM03.02 and calls it a governance objective, or sees “maintain a risk profile” and thinks it replaced APO12.
A third, quieter miss is treating the 1,202 activities as the study plan. You will not be asked to list them. You will be asked whether an activity belongs under a practice, whether a higher capability means more complete activities, and whether a metric is something other than work. Keep the units separate and the items become mechanical.
What is the correct COBIT 2019 work stack from outcome down to executable work?
Using EDM03 Ensured Risk Optimization, which statement correctly applies the practices-and-activities stack?
A candidate calls “percent of critical processes with a current risk assessment” a COBIT process. What did they confuse?