§60 · Lane 2 — AI Audit and Accountability
ISACA COBIT 2019 (AI & Enterprise Governance) the audit profession's control framework, applied to AI governance
ISACA (2019) · ISACA COBIT 2019
Bibliographic data
- Title
- ISACA COBIT 2019 — Governance and Management of Enterprise IT (control-objective framework)
- Authors / Issuing body
- ISACA (Information Systems Audit and Control Association)
- Venue / Publisher
- ISACA, Schaumburg, Illinois
- Year
- 2019
- Designation
- Standard
- Licence
- Stable URL — refer to publisher for full licence terms.
- Canonical link
- https://www.isaca.org/resources/cobit
How to cite
ISACA (2019). ISACA COBIT 2019 — Governance and Management of Enterprise IT (control-objective framework). ISACA, Schaumburg, Illinois. https://www.isaca.org/resources/cobit.
ISACA's enterprise-governance-of-IT framework: 40 governance and management objectives across five domains — the EDM governance domain (Evaluate, Direct and Monitor) plus four management domains (APO, BAI, DSS, MEA) — linked to enterprise goals through a goals cascade. The control framework the audit profession measures IT, and increasingly AI, governance against.
Why it matters for NETEVO
COBIT 2019 is the framework the audit profession actually tests governance against — the control-objective language ISACA, CISA-certified auditors, and internal audit functions apply when they examine how an enterprise governs its IT, and now its AI. For an organisation preparing for an AI assurance review, that makes COBIT the measuring stick, not a nice-to-have.
It completes the audit spine, from board to control. Where the Three Lines model names who is accountable, COBIT names what each line is measured against: governance and management objectives, each carrying practices, activities, and metrics. Its EDM domain (Evaluate, Direct and Monitor) is the established machinery on which a governing body's AI-specific duties actually run — the duties ISO/IEC 38507 overlays for AI. Citing the two together connects the AI-governance standard to the enterprise-governance framework boards already operate.
Its goals cascade is the recognised form of the NETEVO Law-to-Code Methodology. The cascade — enterprise goal to alignment goal to governance objective to practice to metric — is the same "encode obligations into auditable, evidenced controls" pattern, authored by the audit profession rather than asserted by us. NETEVO operationalises that cascade for AI: each AI obligation delivered as a control inside the COBIT machinery an organisation already runs, emitting the evidence an auditor expects rather than an attestation produced after the fact.
Where NETEVO applies this
- AI Governance in ANZ Whitepaper — supporting — governance-of-IT framing where it meets APRA CPS 230/234