Skip to content

Evidence request lists

COBIT 2019

Evidence request list. 68 controls, 68 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

APO - Align, Plan and Organize

COBIT-APO01
Managed IT management framework

Managed IT management framework. Control from COBIT 2019 framework, domain: APO - Align, Plan and Organize.

Artefacts an auditor will ask for
  • IT strategy document
  • Portfolio register
  • Risk register
  • Security policy
Where this commonly fails
  • Strategy not aligned to business
  • Portfolio unmanaged
  • Risk register stale
COBIT-APO02
Managed strategy

Managed strategy. Control from COBIT 2019 framework, domain: APO - Align, Plan and Organize.

Artefacts an auditor will ask for
  • IT strategy document
  • Portfolio register
  • Risk register
  • Security policy
Where this commonly fails
  • Strategy not aligned to business
  • Portfolio unmanaged
  • Risk register stale
COBIT-APO03
Managed enterprise architecture

Managed enterprise architecture. Control from COBIT 2019 framework, domain: APO - Align, Plan and Organize.

Artefacts an auditor will ask for
  • IT strategy document
  • Portfolio register
  • Risk register
  • Security policy
Where this commonly fails
  • Strategy not aligned to business
  • Portfolio unmanaged
  • Risk register stale
COBIT-APO04
Managed innovation

Managed innovation. Control from COBIT 2019 framework, domain: APO - Align, Plan and Organize.

Artefacts an auditor will ask for
  • IT strategy document
  • Portfolio register
  • Risk register
  • Security policy
Where this commonly fails
  • Strategy not aligned to business
  • Portfolio unmanaged
  • Risk register stale
COBIT-APO05
Managed portfolio

Managed portfolio. Control from COBIT 2019 framework, domain: APO - Align, Plan and Organize.

Artefacts an auditor will ask for
  • IT strategy document
  • Portfolio register
  • Risk register
  • Security policy
Where this commonly fails
  • Strategy not aligned to business
  • Portfolio unmanaged
  • Risk register stale
COBIT-APO06
Managed budget and costs

Managed budget and costs. Control from COBIT 2019 framework, domain: APO - Align, Plan and Organize.

Artefacts an auditor will ask for
  • IT strategy document
  • Portfolio register
  • Risk register
  • Security policy
Where this commonly fails
  • Strategy not aligned to business
  • Portfolio unmanaged
  • Risk register stale
COBIT-APO07
Managed human resources

Managed human resources. Control from COBIT 2019 framework, domain: APO - Align, Plan and Organize.

Artefacts an auditor will ask for
  • IT strategy document
  • Portfolio register
  • Risk register
  • Security policy
Where this commonly fails
  • Strategy not aligned to business
  • Portfolio unmanaged
  • Risk register stale
COBIT-APO08
Managed relationships

Managed relationships. Control from COBIT 2019 framework, domain: APO - Align, Plan and Organize.

Artefacts an auditor will ask for
  • IT strategy document
  • Portfolio register
  • Risk register
  • Security policy
Where this commonly fails
  • Strategy not aligned to business
  • Portfolio unmanaged
  • Risk register stale
COBIT-APO09
Managed service agreements

Managed service agreements. Control from COBIT 2019 framework, domain: APO - Align, Plan and Organize.

Artefacts an auditor will ask for
  • IT strategy document
  • Portfolio register
  • Risk register
  • Security policy
Where this commonly fails
  • Strategy not aligned to business
  • Portfolio unmanaged
  • Risk register stale
COBIT-APO10
Managed vendors

Managed vendors. Control from COBIT 2019 framework, domain: APO - Align, Plan and Organize.

Artefacts an auditor will ask for
  • IT strategy document
  • Portfolio register
  • Risk register
  • Security policy
Where this commonly fails
  • Strategy not aligned to business
  • Portfolio unmanaged
  • Risk register stale
COBIT-APO11
Managed quality

Managed quality. Control from COBIT 2019 framework, domain: APO - Align, Plan and Organize.

Artefacts an auditor will ask for
  • IT strategy document
  • Portfolio register
  • Risk register
  • Security policy
Where this commonly fails
  • Strategy not aligned to business
  • Portfolio unmanaged
  • Risk register stale
COBIT-APO12
Managed risk

Managed risk. Control from COBIT 2019 framework, domain: APO - Align, Plan and Organize.

Artefacts an auditor will ask for
  • IT strategy document
  • Portfolio register
  • Risk register
  • Security policy
Where this commonly fails
  • Strategy not aligned to business
  • Portfolio unmanaged
  • Risk register stale
COBIT-APO13
Managed security

Managed security. Control from COBIT 2019 framework, domain: APO - Align, Plan and Organize.

Artefacts an auditor will ask for
  • IT strategy document
  • Portfolio register
  • Risk register
  • Security policy
Where this commonly fails
  • Strategy not aligned to business
  • Portfolio unmanaged
  • Risk register stale
COBIT-APO14
Managed data

Managed data. Control from COBIT 2019 framework, domain: APO - Align, Plan and Organize.

Artefacts an auditor will ask for
  • IT strategy document
  • Portfolio register
  • Risk register
  • Security policy
Where this commonly fails
  • Strategy not aligned to business
  • Portfolio unmanaged
  • Risk register stale

Align, Plan and Organize

APO01
Managed I&T Management Framework

Implement a consistent I&T management approach that meets enterprise governance requirements.

Artefacts an auditor will ask for
  • I&T policy catalog
  • Process documentation
  • Organizational charts
Where this commonly fails
  • Policies outdated
  • No framework integration
  • Process owners unassigned
APO02
Managed Strategy

Provide a holistic view of the current business and I&T environment, future direction, and initiatives required to migrate.

Artefacts an auditor will ask for
  • IT strategy doc
  • Multi-year roadmap
  • Strategy alignment matrix
Where this commonly fails
  • Strategy not aligned with business
  • Roadmap stale
  • No review cadence
APO07
Managed Human Resources

Provide a structured approach to ensure optimal structuring, placement, decision rights, and skills of human resources.

Artefacts an auditor will ask for
  • Job descriptions
  • Training plans
  • Performance reviews
Where this commonly fails
  • No skills gap analysis
  • Training budget cut
  • Critical role single points
APO08
Managed Relationships

Manage the relationship between the business and IT in a formalized and transparent way.

Artefacts an auditor will ask for
  • SLA documents
  • BRM meeting minutes
  • Satisfaction surveys
Where this commonly fails
  • No formal BRM function
  • SLAs not reviewed
  • Satisfaction not measured
APO09
Managed Service Agreements

Align IT-enabled services with enterprise needs through agreement on service definitions, levels, and reporting.

Artefacts an auditor will ask for
  • Service catalog
  • SLA register
  • Service review reports
Where this commonly fails
  • No service catalog
  • SLAs aspirational
  • No service reviews
APO10
Managed Vendors

Manage I&T-related services and products provided by third parties to deliver enterprise requirements.

Artefacts an auditor will ask for
  • Vendor register
  • Contract repository
  • Vendor performance reports
Where this commonly fails
  • No vendor risk tier
  • Contracts not centrally tracked
  • Performance unmeasured
APO12
Managed Risk

Continually identify, assess, and reduce I&T-related risk within the levels of tolerance set by the enterprise.

Artefacts an auditor will ask for
  • Risk methodology
  • Risk register
  • Risk treatment plans
Where this commonly fails
  • No quantitative methodology
  • Register not maintained
  • Treatments not tracked
APO13
Managed Security

Define, operate, and monitor a system for information security management.

Artefacts an auditor will ask for
  • ISMS scope and policy
  • Risk assessment
  • Statement of Applicability
Where this commonly fails
  • No formal ISMS
  • Policies not enforced
  • Metrics absent
APO14
Managed Data

Achieve and sustain effective management of data assets across the data lifecycle.

Artefacts an auditor will ask for
  • Data governance charter
  • Data catalog
  • Data quality metrics
Where this commonly fails
  • No data owners
  • No data catalog
  • Quality unmonitored

BAI - Build, Acquire and Implement

COBIT-BAI01
Managed programs

Managed programs. Control from COBIT 2019 framework, domain: BAI - Build, Acquire and Implement.

Artefacts an auditor will ask for
  • Project charter
  • Change advisory board minutes
  • CMDB
  • Asset inventory
Where this commonly fails
  • No project gates
  • CAB bypassed
  • CMDB inaccurate
COBIT-BAI02
Managed requirements definition

Managed requirements definition. Control from COBIT 2019 framework, domain: BAI - Build, Acquire and Implement.

Artefacts an auditor will ask for
  • Project charter
  • Change advisory board minutes
  • CMDB
  • Asset inventory
Where this commonly fails
  • No project gates
  • CAB bypassed
  • CMDB inaccurate
COBIT-BAI03
Managed solutions identification and build

Managed solutions identification and build. Control from COBIT 2019 framework, domain: BAI - Build, Acquire and Implement.

Artefacts an auditor will ask for
  • Project charter
  • Change advisory board minutes
  • CMDB
  • Asset inventory
Where this commonly fails
  • No project gates
  • CAB bypassed
  • CMDB inaccurate
COBIT-BAI04
Managed availability and capacity

Managed availability and capacity. Control from COBIT 2019 framework, domain: BAI - Build, Acquire and Implement.

Artefacts an auditor will ask for
  • Project charter
  • Change advisory board minutes
  • CMDB
  • Asset inventory
Where this commonly fails
  • No project gates
  • CAB bypassed
  • CMDB inaccurate
COBIT-BAI05
Managed organizational change

Managed organizational change. Control from COBIT 2019 framework, domain: BAI - Build, Acquire and Implement.

Artefacts an auditor will ask for
  • Project charter
  • Change advisory board minutes
  • CMDB
  • Asset inventory
Where this commonly fails
  • No project gates
  • CAB bypassed
  • CMDB inaccurate
COBIT-BAI06
Managed IT changes

Managed IT changes. Control from COBIT 2019 framework, domain: BAI - Build, Acquire and Implement.

Artefacts an auditor will ask for
  • Project charter
  • Change advisory board minutes
  • CMDB
  • Asset inventory
Where this commonly fails
  • No project gates
  • CAB bypassed
  • CMDB inaccurate
COBIT-BAI07
Managed IT change acceptance and transitioning

Managed IT change acceptance and transitioning. Control from COBIT 2019 framework, domain: BAI - Build, Acquire and Implement.

Artefacts an auditor will ask for
  • Project charter
  • Change advisory board minutes
  • CMDB
  • Asset inventory
Where this commonly fails
  • No project gates
  • CAB bypassed
  • CMDB inaccurate
COBIT-BAI08
Managed knowledge

Managed knowledge. Control from COBIT 2019 framework, domain: BAI - Build, Acquire and Implement.

Artefacts an auditor will ask for
  • Project charter
  • Change advisory board minutes
  • CMDB
  • Asset inventory
Where this commonly fails
  • No project gates
  • CAB bypassed
  • CMDB inaccurate
COBIT-BAI09
Managed assets

Managed assets. Control from COBIT 2019 framework, domain: BAI - Build, Acquire and Implement.

Artefacts an auditor will ask for
  • Project charter
  • Change advisory board minutes
  • CMDB
  • Asset inventory
Where this commonly fails
  • No project gates
  • CAB bypassed
  • CMDB inaccurate
COBIT-BAI10
Managed configuration

Managed configuration. Control from COBIT 2019 framework, domain: BAI - Build, Acquire and Implement.

Artefacts an auditor will ask for
  • Project charter
  • Change advisory board minutes
  • CMDB
  • Asset inventory
Where this commonly fails
  • No project gates
  • CAB bypassed
  • CMDB inaccurate
COBIT-BAI11
Managed projects

Managed projects. Control from COBIT 2019 framework, domain: BAI - Build, Acquire and Implement.

Artefacts an auditor will ask for
  • Project charter
  • Change advisory board minutes
  • CMDB
  • Asset inventory
Where this commonly fails
  • No project gates
  • CAB bypassed
  • CMDB inaccurate

Build, Acquire and Implement

BAI01
Managed Programs

Manage all programs from the investment portfolio in alignment with enterprise strategy and in a coordinated way.

Artefacts an auditor will ask for
  • Program charters
  • PMO reports
  • Stage gate reviews
Where this commonly fails
  • No PMO oversight
  • Programs run independently
  • Stage gates skipped
BAI02
Managed Requirements Definition

Identify solutions and analyze requirements before acquisition or creation to ensure alignment with strategic requirements.

Artefacts an auditor will ask for
  • Requirements documents
  • Traceability matrix
  • Approval records
Where this commonly fails
  • Requirements informal
  • No traceability
  • Scope creep unmanaged
BAI03
Managed Solutions Identification and Build

Establish and maintain identified solutions in line with enterprise requirements covering design, development, procurement, and partnering.

Artefacts an auditor will ask for
  • Design documents
  • Build standards
  • Code review records
Where this commonly fails
  • No design review gate
  • Builds undocumented
  • Reviews skipped
BAI06
Managed IT Changes

Manage all changes in a controlled manner including standard, emergency, and operational changes to mitigate risk.

Artefacts an auditor will ask for
  • Change tickets
  • CAB minutes
  • Emergency change log
Where this commonly fails
  • Emergency changes routine
  • CAB rubber-stamps
  • No post-implementation review
BAI07
Managed IT Change Acceptance and Transitioning

Formally accept and operationalize new solutions including implementation planning, system conversion, and acceptance testing.

Artefacts an auditor will ask for
  • UAT sign-off
  • Go-live checklist
  • Hypercare plan
Where this commonly fails
  • UAT signed under pressure
  • No hypercare
  • Rollback plans missing
BAI08
Managed Knowledge

Maintain availability of relevant, current, validated, and reliable knowledge to support all process activities.

Artefacts an auditor will ask for
  • KB articles
  • Documentation standards
  • Review cycles
Where this commonly fails
  • KB stale
  • Tribal knowledge dominant
  • No review cadence
BAI09
Managed Assets

Manage IT assets through their life cycle to maximize value, control cost, manage risk, and support decision-making.

Artefacts an auditor will ask for
  • CMDB extract
  • Asset register
  • Disposal records
Where this commonly fails
  • CMDB inaccurate
  • Software unlicensed
  • Disposal informal
BAI10
Managed Configuration

Define and maintain definitions and relationships between key IT resources and capabilities required to deliver IT-enabled services.

Artefacts an auditor will ask for
  • CMDB schema
  • Baseline records
  • Audit reports
Where this commonly fails
  • No baseline definition
  • CMDB drift
  • Reconciliation absent

DSS - Deliver, Service and Support

COBIT-DSS01
Managed operations

Managed operations. Control from COBIT 2019 framework, domain: DSS - Deliver, Service and Support.

Artefacts an auditor will ask for
  • Operations procedures
  • Incident records
  • Problem management log
  • BC plan
Where this commonly fails
  • No problem management
  • BC plan untested
  • Operations undocumented
COBIT-DSS02
Managed service requests and incidents

Managed service requests and incidents. Control from COBIT 2019 framework, domain: DSS - Deliver, Service and Support.

Artefacts an auditor will ask for
  • Operations procedures
  • Incident records
  • Problem management log
  • BC plan
Where this commonly fails
  • No problem management
  • BC plan untested
  • Operations undocumented
COBIT-DSS03
Managed problems

Managed problems. Control from COBIT 2019 framework, domain: DSS - Deliver, Service and Support.

Artefacts an auditor will ask for
  • Operations procedures
  • Incident records
  • Problem management log
  • BC plan
Where this commonly fails
  • No problem management
  • BC plan untested
  • Operations undocumented
COBIT-DSS04
Managed continuity

Managed continuity. Control from COBIT 2019 framework, domain: DSS - Deliver, Service and Support.

Artefacts an auditor will ask for
  • Operations procedures
  • Incident records
  • Problem management log
  • BC plan
Where this commonly fails
  • No problem management
  • BC plan untested
  • Operations undocumented
COBIT-DSS05
Managed security services

Managed security services. Control from COBIT 2019 framework, domain: DSS - Deliver, Service and Support.

Artefacts an auditor will ask for
  • Operations procedures
  • Incident records
  • Problem management log
  • BC plan
Where this commonly fails
  • No problem management
  • BC plan untested
  • Operations undocumented
COBIT-DSS06
Managed business process controls

Managed business process controls. Control from COBIT 2019 framework, domain: DSS - Deliver, Service and Support.

Artefacts an auditor will ask for
  • Operations procedures
  • Incident records
  • Problem management log
  • BC plan
Where this commonly fails
  • No problem management
  • BC plan untested
  • Operations undocumented

Deliver, Service and Support

DSS01
Managed Operations

Coordinate and execute the activities and operational procedures required to deliver internal and outsourced IT services.

Artefacts an auditor will ask for
  • Operations runbooks
  • Monitoring dashboards
  • Shift handover logs
Where this commonly fails
  • Runbooks outdated
  • No formal handovers
  • Monitoring gaps
DSS02
Managed Service Requests and Incidents

Provide timely and effective response to user requests and resolution of all types of incidents.

Artefacts an auditor will ask for
  • Ticket system reports
  • MTTR metrics
  • Priority matrix
Where this commonly fails
  • Priorities inconsistent
  • No SLA tracking
  • Major incident reviews absent
DSS05
Managed Security Services

Protect enterprise information to maintain the level of risk acceptable in accordance with the security policy.

Artefacts an auditor will ask for
  • SOC reports
  • Endpoint coverage reports
  • Vulnerability scans
Where this commonly fails
  • SOC alerts unactioned
  • Endpoint coverage incomplete
  • Scan remediation slow

EDM - Evaluate, Direct and Monitor

COBIT-EDM01
Ensured governance framework setting and maintenance

Ensured governance framework setting and maintenance. Control from COBIT 2019 framework, domain: EDM - Evaluate, Direct and Monitor.

Artefacts an auditor will ask for
  • Governance framework charter
  • Benefits realisation log
  • Risk appetite statement
  • Resource plan
Where this commonly fails
  • No governance framework
  • Benefits not tracked
  • Risk appetite undefined
COBIT-EDM02
Ensured benefits delivery

Ensured benefits delivery. Control from COBIT 2019 framework, domain: EDM - Evaluate, Direct and Monitor.

Artefacts an auditor will ask for
  • Governance framework charter
  • Benefits realisation log
  • Risk appetite statement
  • Resource plan
Where this commonly fails
  • No governance framework
  • Benefits not tracked
  • Risk appetite undefined
COBIT-EDM03
Ensured risk optimization

Ensured risk optimization. Control from COBIT 2019 framework, domain: EDM - Evaluate, Direct and Monitor.

Artefacts an auditor will ask for
  • Governance framework charter
  • Benefits realisation log
  • Risk appetite statement
  • Resource plan
Where this commonly fails
  • No governance framework
  • Benefits not tracked
  • Risk appetite undefined
COBIT-EDM04
Ensured resource optimization

Ensured resource optimization. Control from COBIT 2019 framework, domain: EDM - Evaluate, Direct and Monitor.

Artefacts an auditor will ask for
  • Governance framework charter
  • Benefits realisation log
  • Risk appetite statement
  • Resource plan
Where this commonly fails
  • No governance framework
  • Benefits not tracked
  • Risk appetite undefined
COBIT-EDM05
Ensured stakeholder engagement

Ensured stakeholder engagement. Control from COBIT 2019 framework, domain: EDM - Evaluate, Direct and Monitor.

Artefacts an auditor will ask for
  • Governance framework charter
  • Benefits realisation log
  • Risk appetite statement
  • Resource plan
Where this commonly fails
  • No governance framework
  • Benefits not tracked
  • Risk appetite undefined

Evaluate, Direct and Monitor

EDM01
Ensured Governance Framework Setting and Maintenance

Establish and maintain a governance framework that aligns enterprise governance of I&T with overall enterprise governance.

Artefacts an auditor will ask for
  • Governance framework doc
  • Board charter
  • RACI matrix
Where this commonly fails
  • No board-approved I&T governance
  • RACI undefined
  • No periodic review
EDM02
Ensured Benefits Delivery

Optimize value contribution to the business from I&T-enabled investments, services, and assets.

Artefacts an auditor will ask for
  • Business case templates
  • Benefits tracking reports
  • Portfolio dashboards
Where this commonly fails
  • No benefits realization tracking
  • Investment decisions not value-based
  • Stale business cases
EDM03
Ensured Risk Optimization

Ensure that I&T-related risk does not exceed risk appetite and tolerance, and that impact is identified and managed.

Artefacts an auditor will ask for
  • Risk appetite statement
  • Risk register
  • Board risk reports
Where this commonly fails
  • No risk appetite statement
  • Risk tolerance undefined
  • Risk reporting absent at board
EDM04
Ensured Resource Optimization

Ensure adequate and sufficient business and IT-related resources (people, process, technology) are available to support enterprise objectives.

Artefacts an auditor will ask for
  • Resource plans
  • Capacity reports
  • Skills inventory
Where this commonly fails
  • No skills inventory
  • Resource conflicts unresolved
  • Capacity reactive only
EDM05
Ensured Stakeholder Engagement

Ensure stakeholders are identified, engaged, and that performance and conformance reporting meets their needs.

Artefacts an auditor will ask for
  • Stakeholder map
  • Reporting calendar
  • Communication plan
Where this commonly fails
  • Stakeholders not mapped
  • Reporting one-directional
  • No feedback loop

MEA - Monitor, Evaluate and Assess

COBIT-MEA01
Managed performance and conformance monitoring

Managed performance and conformance monitoring. Control from COBIT 2019 framework, domain: MEA - Monitor, Evaluate and Assess.

Artefacts an auditor will ask for
  • Performance dashboard
  • Internal control matrix
  • Compliance register
  • Assurance plan
Where this commonly fails
  • No performance monitoring
  • Controls untested
  • Compliance unmapped
COBIT-MEA02
Managed system of internal control

Managed system of internal control. Control from COBIT 2019 framework, domain: MEA - Monitor, Evaluate and Assess.

Artefacts an auditor will ask for
  • Performance dashboard
  • Internal control matrix
  • Compliance register
  • Assurance plan
Where this commonly fails
  • No performance monitoring
  • Controls untested
  • Compliance unmapped
COBIT-MEA03
Managed compliance with external requirements

Managed compliance with external requirements. Control from COBIT 2019 framework, domain: MEA - Monitor, Evaluate and Assess.

Artefacts an auditor will ask for
  • Performance dashboard
  • Internal control matrix
  • Compliance register
  • Assurance plan
Where this commonly fails
  • No performance monitoring
  • Controls untested
  • Compliance unmapped
COBIT-MEA04
Managed assurance

Managed assurance. Control from COBIT 2019 framework, domain: MEA - Monitor, Evaluate and Assess.

Artefacts an auditor will ask for
  • Performance dashboard
  • Internal control matrix
  • Compliance register
  • Assurance plan
Where this commonly fails
  • No performance monitoring
  • Controls untested
  • Compliance unmapped

Monitor, Evaluate and Assess

MEA01
Managed Performance and Conformance Monitoring

Collect, validate, and evaluate enterprise and alignment goals and metrics; monitor that processes perform against agreed objectives.

Artefacts an auditor will ask for
  • Balanced scorecard
  • KPI reports
  • Variance analysis
Where this commonly fails
  • No goals cascade
  • KPIs vanity metrics
  • Variance not actioned
MEA02
Managed System of Internal Control

Continually monitor and evaluate the control environment and effectiveness of internal controls.

Artefacts an auditor will ask for
  • Control matrix
  • Test results
  • Remediation tracking
Where this commonly fails
  • Controls untested
  • No tracking of failures
  • Self-assessment only
MEA03
Managed Compliance with External Requirements

Evaluate that IT processes and IT-supported business processes are compliant with laws, regulations, and contractual requirements.

Artefacts an auditor will ask for
  • Regulatory mapping
  • External audit reports
  • Compliance attestations
Where this commonly fails
  • Regulatory inventory stale
  • No horizon scanning
  • Findings unremediated
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the COBIT 2019 framework page.