COBIT 2019
Evidence request list. 68 controls, 68 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
APO - Align, Plan and Organize
Managed IT management framework. Control from COBIT 2019 framework, domain: APO - Align, Plan and Organize.
- IT strategy document
- Portfolio register
- Risk register
- Security policy
- Strategy not aligned to business
- Portfolio unmanaged
- Risk register stale
Managed strategy. Control from COBIT 2019 framework, domain: APO - Align, Plan and Organize.
- IT strategy document
- Portfolio register
- Risk register
- Security policy
- Strategy not aligned to business
- Portfolio unmanaged
- Risk register stale
Managed enterprise architecture. Control from COBIT 2019 framework, domain: APO - Align, Plan and Organize.
- IT strategy document
- Portfolio register
- Risk register
- Security policy
- Strategy not aligned to business
- Portfolio unmanaged
- Risk register stale
Managed innovation. Control from COBIT 2019 framework, domain: APO - Align, Plan and Organize.
- IT strategy document
- Portfolio register
- Risk register
- Security policy
- Strategy not aligned to business
- Portfolio unmanaged
- Risk register stale
Managed portfolio. Control from COBIT 2019 framework, domain: APO - Align, Plan and Organize.
- IT strategy document
- Portfolio register
- Risk register
- Security policy
- Strategy not aligned to business
- Portfolio unmanaged
- Risk register stale
Managed budget and costs. Control from COBIT 2019 framework, domain: APO - Align, Plan and Organize.
- IT strategy document
- Portfolio register
- Risk register
- Security policy
- Strategy not aligned to business
- Portfolio unmanaged
- Risk register stale
Managed human resources. Control from COBIT 2019 framework, domain: APO - Align, Plan and Organize.
- IT strategy document
- Portfolio register
- Risk register
- Security policy
- Strategy not aligned to business
- Portfolio unmanaged
- Risk register stale
Managed relationships. Control from COBIT 2019 framework, domain: APO - Align, Plan and Organize.
- IT strategy document
- Portfolio register
- Risk register
- Security policy
- Strategy not aligned to business
- Portfolio unmanaged
- Risk register stale
Managed service agreements. Control from COBIT 2019 framework, domain: APO - Align, Plan and Organize.
- IT strategy document
- Portfolio register
- Risk register
- Security policy
- Strategy not aligned to business
- Portfolio unmanaged
- Risk register stale
Managed vendors. Control from COBIT 2019 framework, domain: APO - Align, Plan and Organize.
- IT strategy document
- Portfolio register
- Risk register
- Security policy
- Strategy not aligned to business
- Portfolio unmanaged
- Risk register stale
Managed quality. Control from COBIT 2019 framework, domain: APO - Align, Plan and Organize.
- IT strategy document
- Portfolio register
- Risk register
- Security policy
- Strategy not aligned to business
- Portfolio unmanaged
- Risk register stale
Managed risk. Control from COBIT 2019 framework, domain: APO - Align, Plan and Organize.
- IT strategy document
- Portfolio register
- Risk register
- Security policy
- Strategy not aligned to business
- Portfolio unmanaged
- Risk register stale
Managed security. Control from COBIT 2019 framework, domain: APO - Align, Plan and Organize.
- IT strategy document
- Portfolio register
- Risk register
- Security policy
- Strategy not aligned to business
- Portfolio unmanaged
- Risk register stale
Managed data. Control from COBIT 2019 framework, domain: APO - Align, Plan and Organize.
- IT strategy document
- Portfolio register
- Risk register
- Security policy
- Strategy not aligned to business
- Portfolio unmanaged
- Risk register stale
Align, Plan and Organize
Implement a consistent I&T management approach that meets enterprise governance requirements.
- I&T policy catalog
- Process documentation
- Organizational charts
- Policies outdated
- No framework integration
- Process owners unassigned
Provide a holistic view of the current business and I&T environment, future direction, and initiatives required to migrate.
- IT strategy doc
- Multi-year roadmap
- Strategy alignment matrix
- Strategy not aligned with business
- Roadmap stale
- No review cadence
Provide a structured approach to ensure optimal structuring, placement, decision rights, and skills of human resources.
- Job descriptions
- Training plans
- Performance reviews
- No skills gap analysis
- Training budget cut
- Critical role single points
Manage the relationship between the business and IT in a formalized and transparent way.
- SLA documents
- BRM meeting minutes
- Satisfaction surveys
- No formal BRM function
- SLAs not reviewed
- Satisfaction not measured
Align IT-enabled services with enterprise needs through agreement on service definitions, levels, and reporting.
- Service catalog
- SLA register
- Service review reports
- No service catalog
- SLAs aspirational
- No service reviews
Manage I&T-related services and products provided by third parties to deliver enterprise requirements.
- Vendor register
- Contract repository
- Vendor performance reports
- No vendor risk tier
- Contracts not centrally tracked
- Performance unmeasured
Continually identify, assess, and reduce I&T-related risk within the levels of tolerance set by the enterprise.
- Risk methodology
- Risk register
- Risk treatment plans
- No quantitative methodology
- Register not maintained
- Treatments not tracked
Define, operate, and monitor a system for information security management.
- ISMS scope and policy
- Risk assessment
- Statement of Applicability
- No formal ISMS
- Policies not enforced
- Metrics absent
Achieve and sustain effective management of data assets across the data lifecycle.
- Data governance charter
- Data catalog
- Data quality metrics
- No data owners
- No data catalog
- Quality unmonitored
BAI - Build, Acquire and Implement
Managed programs. Control from COBIT 2019 framework, domain: BAI - Build, Acquire and Implement.
- Project charter
- Change advisory board minutes
- CMDB
- Asset inventory
- No project gates
- CAB bypassed
- CMDB inaccurate
Managed requirements definition. Control from COBIT 2019 framework, domain: BAI - Build, Acquire and Implement.
- Project charter
- Change advisory board minutes
- CMDB
- Asset inventory
- No project gates
- CAB bypassed
- CMDB inaccurate
Managed solutions identification and build. Control from COBIT 2019 framework, domain: BAI - Build, Acquire and Implement.
- Project charter
- Change advisory board minutes
- CMDB
- Asset inventory
- No project gates
- CAB bypassed
- CMDB inaccurate
Managed availability and capacity. Control from COBIT 2019 framework, domain: BAI - Build, Acquire and Implement.
- Project charter
- Change advisory board minutes
- CMDB
- Asset inventory
- No project gates
- CAB bypassed
- CMDB inaccurate
Managed organizational change. Control from COBIT 2019 framework, domain: BAI - Build, Acquire and Implement.
- Project charter
- Change advisory board minutes
- CMDB
- Asset inventory
- No project gates
- CAB bypassed
- CMDB inaccurate
Managed IT changes. Control from COBIT 2019 framework, domain: BAI - Build, Acquire and Implement.
- Project charter
- Change advisory board minutes
- CMDB
- Asset inventory
- No project gates
- CAB bypassed
- CMDB inaccurate
Managed IT change acceptance and transitioning. Control from COBIT 2019 framework, domain: BAI - Build, Acquire and Implement.
- Project charter
- Change advisory board minutes
- CMDB
- Asset inventory
- No project gates
- CAB bypassed
- CMDB inaccurate
Managed knowledge. Control from COBIT 2019 framework, domain: BAI - Build, Acquire and Implement.
- Project charter
- Change advisory board minutes
- CMDB
- Asset inventory
- No project gates
- CAB bypassed
- CMDB inaccurate
Managed assets. Control from COBIT 2019 framework, domain: BAI - Build, Acquire and Implement.
- Project charter
- Change advisory board minutes
- CMDB
- Asset inventory
- No project gates
- CAB bypassed
- CMDB inaccurate
Managed configuration. Control from COBIT 2019 framework, domain: BAI - Build, Acquire and Implement.
- Project charter
- Change advisory board minutes
- CMDB
- Asset inventory
- No project gates
- CAB bypassed
- CMDB inaccurate
Managed projects. Control from COBIT 2019 framework, domain: BAI - Build, Acquire and Implement.
- Project charter
- Change advisory board minutes
- CMDB
- Asset inventory
- No project gates
- CAB bypassed
- CMDB inaccurate
Build, Acquire and Implement
Manage all programs from the investment portfolio in alignment with enterprise strategy and in a coordinated way.
- Program charters
- PMO reports
- Stage gate reviews
- No PMO oversight
- Programs run independently
- Stage gates skipped
Identify solutions and analyze requirements before acquisition or creation to ensure alignment with strategic requirements.
- Requirements documents
- Traceability matrix
- Approval records
- Requirements informal
- No traceability
- Scope creep unmanaged
Establish and maintain identified solutions in line with enterprise requirements covering design, development, procurement, and partnering.
- Design documents
- Build standards
- Code review records
- No design review gate
- Builds undocumented
- Reviews skipped
Manage all changes in a controlled manner including standard, emergency, and operational changes to mitigate risk.
- Change tickets
- CAB minutes
- Emergency change log
- Emergency changes routine
- CAB rubber-stamps
- No post-implementation review
Formally accept and operationalize new solutions including implementation planning, system conversion, and acceptance testing.
- UAT sign-off
- Go-live checklist
- Hypercare plan
- UAT signed under pressure
- No hypercare
- Rollback plans missing
Maintain availability of relevant, current, validated, and reliable knowledge to support all process activities.
- KB articles
- Documentation standards
- Review cycles
- KB stale
- Tribal knowledge dominant
- No review cadence
Manage IT assets through their life cycle to maximize value, control cost, manage risk, and support decision-making.
- CMDB extract
- Asset register
- Disposal records
- CMDB inaccurate
- Software unlicensed
- Disposal informal
Define and maintain definitions and relationships between key IT resources and capabilities required to deliver IT-enabled services.
- CMDB schema
- Baseline records
- Audit reports
- No baseline definition
- CMDB drift
- Reconciliation absent
DSS - Deliver, Service and Support
Managed operations. Control from COBIT 2019 framework, domain: DSS - Deliver, Service and Support.
- Operations procedures
- Incident records
- Problem management log
- BC plan
- No problem management
- BC plan untested
- Operations undocumented
Managed service requests and incidents. Control from COBIT 2019 framework, domain: DSS - Deliver, Service and Support.
- Operations procedures
- Incident records
- Problem management log
- BC plan
- No problem management
- BC plan untested
- Operations undocumented
Managed problems. Control from COBIT 2019 framework, domain: DSS - Deliver, Service and Support.
- Operations procedures
- Incident records
- Problem management log
- BC plan
- No problem management
- BC plan untested
- Operations undocumented
Managed continuity. Control from COBIT 2019 framework, domain: DSS - Deliver, Service and Support.
- Operations procedures
- Incident records
- Problem management log
- BC plan
- No problem management
- BC plan untested
- Operations undocumented
Managed security services. Control from COBIT 2019 framework, domain: DSS - Deliver, Service and Support.
- Operations procedures
- Incident records
- Problem management log
- BC plan
- No problem management
- BC plan untested
- Operations undocumented
Managed business process controls. Control from COBIT 2019 framework, domain: DSS - Deliver, Service and Support.
- Operations procedures
- Incident records
- Problem management log
- BC plan
- No problem management
- BC plan untested
- Operations undocumented
Deliver, Service and Support
Coordinate and execute the activities and operational procedures required to deliver internal and outsourced IT services.
- Operations runbooks
- Monitoring dashboards
- Shift handover logs
- Runbooks outdated
- No formal handovers
- Monitoring gaps
Provide timely and effective response to user requests and resolution of all types of incidents.
- Ticket system reports
- MTTR metrics
- Priority matrix
- Priorities inconsistent
- No SLA tracking
- Major incident reviews absent
Protect enterprise information to maintain the level of risk acceptable in accordance with the security policy.
- SOC reports
- Endpoint coverage reports
- Vulnerability scans
- SOC alerts unactioned
- Endpoint coverage incomplete
- Scan remediation slow
EDM - Evaluate, Direct and Monitor
Ensured governance framework setting and maintenance. Control from COBIT 2019 framework, domain: EDM - Evaluate, Direct and Monitor.
- Governance framework charter
- Benefits realisation log
- Risk appetite statement
- Resource plan
- No governance framework
- Benefits not tracked
- Risk appetite undefined
Ensured benefits delivery. Control from COBIT 2019 framework, domain: EDM - Evaluate, Direct and Monitor.
- Governance framework charter
- Benefits realisation log
- Risk appetite statement
- Resource plan
- No governance framework
- Benefits not tracked
- Risk appetite undefined
Ensured risk optimization. Control from COBIT 2019 framework, domain: EDM - Evaluate, Direct and Monitor.
- Governance framework charter
- Benefits realisation log
- Risk appetite statement
- Resource plan
- No governance framework
- Benefits not tracked
- Risk appetite undefined
Ensured resource optimization. Control from COBIT 2019 framework, domain: EDM - Evaluate, Direct and Monitor.
- Governance framework charter
- Benefits realisation log
- Risk appetite statement
- Resource plan
- No governance framework
- Benefits not tracked
- Risk appetite undefined
Ensured stakeholder engagement. Control from COBIT 2019 framework, domain: EDM - Evaluate, Direct and Monitor.
- Governance framework charter
- Benefits realisation log
- Risk appetite statement
- Resource plan
- No governance framework
- Benefits not tracked
- Risk appetite undefined
Evaluate, Direct and Monitor
Establish and maintain a governance framework that aligns enterprise governance of I&T with overall enterprise governance.
- Governance framework doc
- Board charter
- RACI matrix
- No board-approved I&T governance
- RACI undefined
- No periodic review
Optimize value contribution to the business from I&T-enabled investments, services, and assets.
- Business case templates
- Benefits tracking reports
- Portfolio dashboards
- No benefits realization tracking
- Investment decisions not value-based
- Stale business cases
Ensure that I&T-related risk does not exceed risk appetite and tolerance, and that impact is identified and managed.
- Risk appetite statement
- Risk register
- Board risk reports
- No risk appetite statement
- Risk tolerance undefined
- Risk reporting absent at board
Ensure adequate and sufficient business and IT-related resources (people, process, technology) are available to support enterprise objectives.
- Resource plans
- Capacity reports
- Skills inventory
- No skills inventory
- Resource conflicts unresolved
- Capacity reactive only
Ensure stakeholders are identified, engaged, and that performance and conformance reporting meets their needs.
- Stakeholder map
- Reporting calendar
- Communication plan
- Stakeholders not mapped
- Reporting one-directional
- No feedback loop
MEA - Monitor, Evaluate and Assess
Managed performance and conformance monitoring. Control from COBIT 2019 framework, domain: MEA - Monitor, Evaluate and Assess.
- Performance dashboard
- Internal control matrix
- Compliance register
- Assurance plan
- No performance monitoring
- Controls untested
- Compliance unmapped
Managed system of internal control. Control from COBIT 2019 framework, domain: MEA - Monitor, Evaluate and Assess.
- Performance dashboard
- Internal control matrix
- Compliance register
- Assurance plan
- No performance monitoring
- Controls untested
- Compliance unmapped
Managed compliance with external requirements. Control from COBIT 2019 framework, domain: MEA - Monitor, Evaluate and Assess.
- Performance dashboard
- Internal control matrix
- Compliance register
- Assurance plan
- No performance monitoring
- Controls untested
- Compliance unmapped
Managed assurance. Control from COBIT 2019 framework, domain: MEA - Monitor, Evaluate and Assess.
- Performance dashboard
- Internal control matrix
- Compliance register
- Assurance plan
- No performance monitoring
- Controls untested
- Compliance unmapped
Monitor, Evaluate and Assess
Collect, validate, and evaluate enterprise and alignment goals and metrics; monitor that processes perform against agreed objectives.
- Balanced scorecard
- KPI reports
- Variance analysis
- No goals cascade
- KPIs vanity metrics
- Variance not actioned
Continually monitor and evaluate the control environment and effectiveness of internal controls.
- Control matrix
- Test results
- Remediation tracking
- Controls untested
- No tracking of failures
- Self-assessment only
Evaluate that IT processes and IT-supported business processes are compliant with laws, regulations, and contractual requirements.
- Regulatory mapping
- External audit reports
- Compliance attestations
- Regulatory inventory stale
- No horizon scanning
- Findings unremediated
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the COBIT 2019 framework page.