§60 · Lane 2 — AI Audit and Accountability

ISACA COBIT 2019 (AI & Enterprise Governance) the audit profession's control framework, applied to AI governance

ISACA (2019) · ISACA COBIT 2019

Standard Tier 1 Lane 2 Stable URL
Read on publisher · Stable URL

Bibliographic data

Title
ISACA COBIT 2019 — Governance and Management of Enterprise IT (control-objective framework)
Authors / Issuing body
ISACA (Information Systems Audit and Control Association)
Venue / Publisher
ISACA, Schaumburg, Illinois
Year
2019
Designation
Standard
Licence
Stable URL — refer to publisher for full licence terms.

How to cite

ISACA (2019). ISACA COBIT 2019 — Governance and Management of Enterprise IT (control-objective framework). ISACA, Schaumburg, Illinois. https://www.isaca.org/resources/cobit.

ISACA's enterprise-governance-of-IT framework: 40 governance and management objectives across five domains — the EDM governance domain (Evaluate, Direct and Monitor) plus four management domains (APO, BAI, DSS, MEA) — linked to enterprise goals through a goals cascade. The control framework the audit profession measures IT, and increasingly AI, governance against.

Why it matters for NETEVO

COBIT 2019 is the framework the audit profession actually tests governance against — the control-objective language ISACA, CISA-certified auditors, and internal audit functions apply when they examine how an enterprise governs its IT, and now its AI. For an organisation preparing for an AI assurance review, that makes COBIT the measuring stick, not a nice-to-have.

It completes the audit spine, from board to control. Where the Three Lines model names who is accountable, COBIT names what each line is measured against: governance and management objectives, each carrying practices, activities, and metrics. Its EDM domain (Evaluate, Direct and Monitor) is the established machinery on which a governing body's AI-specific duties actually run — the duties ISO/IEC 38507 overlays for AI. Citing the two together connects the AI-governance standard to the enterprise-governance framework boards already operate.

Its goals cascade is the recognised form of the NETEVO Law-to-Code Methodology. The cascade — enterprise goal to alignment goal to governance objective to practice to metric — is the same "encode obligations into auditable, evidenced controls" pattern, authored by the audit profession rather than asserted by us. NETEVO operationalises that cascade for AI: each AI obligation delivered as a control inside the COBIT machinery an organisation already runs, emitting the evidence an auditor expects rather than an attestation produced after the fact.

Where NETEVO applies this

Related audiences