15.2 The Eleven Design Factors

Key Takeaways

  • ISACA publishes eleven design factors: enterprise strategy, enterprise goals, risk profile, I&T-related issues, threat landscape, compliance requirements, role of IT, sourcing model for IT, IT implementation methods, technology adoption strategy, and enterprise size.
  • Typical strategy options are growth/acquisition, innovation, cost leadership, and client service; typical role-of-IT options are support, factory, turnaround, and strategic — do not swap those lists.
  • Initial scope commonly uses factors 1–4; refined scope uses factors 5–11.
  • Risk profile is weighted by risk rating; the other factors are weighted by importance.
  • A cost-leader manufacturer and a first-mover digital bank can both use COBIT 2019 and must not receive the same priority profile.
Last updated: August 2026

Quick Answer: ISACA publishes 11 design factors: (1) enterprise strategy, (2) enterprise goals, (3) risk profile, (4) I&T-related issues, (5) threat landscape, (6) compliance requirements, (7) role of IT, (8) sourcing model for IT, (9) IT implementation methods, (10) technology adoption strategy, and (11) enterprise size. Initial scope commonly uses factors 1–4. Refined scope uses factors 5–11. Risk profile is weighted by risk rating; the other factors are weighted by importance.

Memorize the names and the typical options. A Foundation stem will not ask you to operate the design-toolkit spreadsheet. It will ask whether “cloud” is a sourcing-model option, whether “factory” is a role of IT, whether initial scope is factors 1–4, or whether two enterprises with different factors should receive the same 40-objective profile. They should not.

Hold two enterprises in your head for the rest of this chapter.

Northline Castings makes metal components for industrial equipment. Strategy is cost leadership. IT keeps the plants running — a factory role — on mostly insourced systems with a few cloud tools. Methods are traditional with pockets of hybrid. Adoption is slow adopter / cautious follower. Threat landscape and compliance sit near normal. Size is a mid-size manufacturer, not a global bank.

Aether Digital Bank is a licensed digital bank racing to be a first mover in embedded payments. Strategy mixes innovation and client service, with growth behind a recent acquisition. IT is strategic. Sourcing is hybrid leaning cloud. Methods are Agile and DevOps. Threat landscape and compliance are high. Size is large enough for formal structures, but the culture is still product-team first.

Both can adopt COBIT 2019. Neither should get Northline’s profile stamped onto Aether, or Aether’s committee stack dumped onto Northline.

The official eleven

#Design factorTypical options you should recognizeWhat it tends to move
1Enterprise strategyGrowth/acquisition, innovation, cost leadership, client serviceWhich value bets I&T must serve
2Enterprise goalsThe enterprise’s balanced-scorecard goalsCascade into alignment goals, then into objectives
3Risk profileI&T-related risk categories rated for this enterpriseSecurity, risk, vendors, continuity — weighted by risk rating
4I&T-related issuesCurrent problems: failed projects, shadow IT, audit findings, fragile operationsObjectives already hurting stakeholders
5Threat landscapeNormal or highSecurity services, continuity, risk optimization
6Compliance requirementsLow, normal, or highCompliance, assurance, and control objectives
7Role of ITSupport, factory, turnaround, strategicStrategy, architecture, innovation, relationships
8Sourcing model for ITInsourced, outsourced, cloud, hybridVendors, service agreements, continuity
9IT implementation methodsAgile, DevOps, traditional, hybridChange, projects, configuration, knowledge
10Technology adoption strategyFirst mover, follower, slow adopterInnovation and architecture versus operational stability
11Enterprise sizeLarge, or small and mediumFormality of structures and which variants are realistic

Recite the eleven in that order. ISACA’s design workflow uses the numbering: 1–4 first, then 5–11. Inventing a twelfth factor, dropping enterprise size, or treating “Agile” as a strategy option is how candidates lose easy marks.

Factors 1–4: who we are and what hurts

These four commonly set the initial scope of the governance system.

1. Enterprise strategy. Typical options are growth/acquisition, innovation, cost leadership, and client service (sometimes phrased as client service/stability). Northline is cost leadership: raise APO06 Managed Budget and Costs, BAI09 Managed Assets, DSS01 Managed Operations. Aether is innovation plus client service, with a growth/acquisition overlay: raise APO04 Managed Innovation, APO02 Managed Strategy, APO03 Managed Enterprise Architecture, APO08 Managed Relationships, and the benefits-delivery side of EDM02.

Do not confuse strategy options with role of IT options. Growth is a strategy. Strategic is a role of IT. They often travel together — Aether is both innovative and strategic — but they are different factors with different typical lists.

2. Enterprise goals. These are the enterprise’s own goals, usually through the balanced scorecard language of the goals cascade. Strategy is the bet. Goals are the scored outcomes. Northline’s goals cluster on cost, quality, and reliable delivery. Aether’s goals cluster on customer experience, growth, and regulated-product speed. The cascade then points at different alignment goals and therefore different governance and management objectives. If a stem says “which design factor uses the enterprise’s documented goals,” the answer is enterprise goals, not a vague appeal to culture.

3. Risk profile. This factor asks where I&T-related risk is concentrated and how severe it is. Weighting is based on risk rating, not on a generic “importance” slider. Aether’s profile is heavy on cyber, third-party/cloud, conduct, and resilience. That rating raises APO12 Managed Risk, APO13 Managed Security, APO10 Managed Vendors, DSS05 Managed Security Services, DSS04 Managed Continuity, and EDM03 Ensured Risk Optimization. Northline still has plant-floor and availability risk, but the rating on digital-channel cyber is lower, so the toolkit should not copy Aether’s security-heavy profile just because both firms “have IT risk.”

4. I&T-related issues. This is the current-pain factor: what is already going wrong or frustrating stakeholders. Failed programs, shadow IT, recurring incidents, audit findings, and brittle change all point at specific objectives. Northline’s issues might be aging plant systems, weak asset records, and cost overruns on a warehouse upgrade — BAI09, BAI11 Managed Projects, APO06. Aether’s issues might be product teams buying SaaS on corporate cards, release collisions, and a messy data estate after the acquisition — APO10, BAI06 Managed IT Changes, APO14 Managed Data, APO03. Issues make the initial scope concrete. They do not replace strategy or risk; they show where the generic model is already failing here.

Factors 5–11: refine the picture

These seven commonly refine the scope after the first four have drawn the outline.

5. Threat landscape — normal or high. Aether is high; Northline is closer to normal. High threat pushes security, continuity, and risk optimization further up than strategy alone would.

6. Compliance requirements — low, normal, or high. Aether is a licensed bank: high. That raises MEA03 Managed Compliance With External Requirements, MEA02 Managed System of Internal Control, MEA04 Managed Assurance, and related security and data objectives. Northline has ordinary industrial and privacy duties — real, but not Aether’s supervisory stack. Do not invent a “zero compliance” enterprise as an official option; the published range is low / normal / high.

7. Role of ITsupport, factory, turnaround, strategic. Support: IT is not crucial for running or innovating the business. Factory: crucial for running, not for innovating. Turnaround: not crucial for current running, crucial for future innovation. Strategic: crucial for both. Northline is factory: keep operations, assets, availability, and changes reliable. Aether is strategic: strategy, architecture, innovation, data, and business relationships must be first-class. A stem that lists support / factory / turnaround / strategic is pointing at role of IT, not at enterprise strategy.

8. Sourcing model for ITinsourced, outsourced, cloud, hybrid. Northline is mostly insourced. Aether is hybrid/cloud. Cloud and outsourcing raise APO09 Managed Service Agreements, APO10 Managed Vendors, and continuity/security around third parties. Insourcing does not make vendor objectives disappear — it lowers their relative weight.

9. IT implementation methodsAgile, DevOps, traditional, hybrid. Methods change how change, projects, configuration, and knowledge should be governed. Aether cannot copy a stage-gate-only reading of BAI06 / BAI11 and call it tailored. Northline cannot pretend a DevOps overlay is required because a consultant likes the focus-area publication. Methods refine how build-and-change objectives are realized, including through variants.

10. Technology adoption strategyfirst mover, follower, slow adopter. Aether is a first mover: more APO04 and APO03, more appetite for new platforms, more need to govern experiments. Northline is a slow adopter: more operational stability, less innovation machinery. Follower sits in the middle. Adoption strategy is not the same as role of IT, even though first movers are often strategic.

11. Enterprise size — large, or small and medium. Size changes whether a three-tier committee stack is realistic, how formal policies must be, and which variants a small enterprise should use. Aether can staff architecture and risk forums. A 90-person Northline cousin should not invent a Metro-bank governance factory just to look complete. Size is a design factor, not an excuse to skip COBIT.

Initial scope versus refined scope

ISACA’s design workflow — taught in the next section — uses a two-pass read of these eleven:

  • Initial scope: factors 1–4 (strategy, goals, risk profile, I&T-related issues).
  • Refined scope: factors 5–11 (threat, compliance, role of IT, sourcing, methods, adoption, size).

That split is a Foundation fact. Candidates lose it by shoving sourcing or Agile into the initial four because those words feel modern, or by scoring all eleven in one undifferentiated dump so “initial” and “refined” mean nothing. The first four describe the enterprise’s intent and pain. The last seven describe the environment and the way IT is actually run. Both passes matter. They are not optional decorations.

How weighting works

The toolkit does not treat every factor as a similar slider.

  • For risk profile, weighting is based on risk rating — how severe and relevant each I&T-related risk is for this enterprise.
  • For the other design factors, weighting is based on importance — how strongly that factor characterizes the enterprise.

Northline’s cost-leadership strategy is important; that importance lifts cost, asset, and operations objectives. Aether’s cyber risk is highly rated; that rating lifts risk and security objectives even if someone on the product team would rather talk only about innovation. Equal weighting of all eleven “to stay neutral” is not neutrality. It is a refusal to use the published method.

Two profiles, one core model

LensNorthline CastingsAether Digital Bank
StrategyCost leadershipInnovation, client service, growth/acquisition
Role of ITFactoryStrategic
SourcingMostly insourcedHybrid / cloud
MethodsTraditional / hybridAgile / DevOps
AdoptionSlow adopter / followerFirst mover
Threat / complianceNormal / normalHigh / high
Objectives that riseAPO06, BAI09, DSS01, BAI11, EDM04APO02, APO03, APO04, APO08, APO12, APO13, APO14, DSS05, MEA03, EDM02, EDM03

Same 40-objective spine. Different priorities. Different target capabilities. Different variants. That is what “eleven design factors” is for.

Exam traps on the named list

  • Swapping option lists. Growth / innovation / cost leadership / client service is enterprise strategy. Support / factory / turnaround / strategic is role of IT. Insourced / outsourced / cloud / hybrid is sourcing. First mover / follower / slow adopter is technology adoption. Agile / DevOps / traditional / hybrid is implementation methods.
  • Putting factors 5–11 in the initial-scope set. Initial is 1–4. Refined is 5–11.
  • Weighting everything the same way. Risk profile uses risk rating. The others use importance.
  • Copying one famous company’s profile. Northline is not a failed Aether. Aether is not a flashy Northline. Both can be faithful.

If a stem lists “enterprise strategy, risk profile, and sourcing model,” you are looking at design factors, not at a secret twelfth system principle. If it asks which factors open the design, answer 1–4. If it asks how risk is weighted, answer risk rating.

Loading diagram...
Eleven design factors: initial scope then refined scope
Test Your Knowledge

Which set lists the typical COBIT 2019 options for the enterprise-strategy design factor?

A
B
C
D
Test Your Knowledge

In the official COBIT 2019 design workflow, which design factors commonly determine the initial scope of the governance system?

A
B
C
D
Test Your Knowledge

How does the COBIT 2019 design approach typically apply weighting to design factors?

A
B
C
D