← Back to articles
Article 64Draft

Cobit 2019

Working draft. Statistics without a confirmed source have been removed from this companion article in a fact-audit. It is still being finalised.
The short versionRead the three-minute post: Cobit 2019

Theory: COBIT 2019 | Template: The Case File | Words: 1,405

# COBIT 2019: Governance for EdTech and AI

In 2021, the University of Amsterdam faced a familiar challenge for any modern institution: managing an explosion of digital research data. This wasn't just about storage; it was about protecting sensitive information, ensuring regulatory compliance, and maintaining academic integrity. They needed a robust system to oversee how data was handled, from its creation to its eventual archiving. The stakes were high, especially with stringent regulations like GDPR looming over every data point. What they realized was that their existing approach, while well-intentioned, wasn't built for the scale and complexity of today's digital landscape. It was a classic case of management trying to do the job of governance, and the cracks were starting to show.

The Problem

Many institutions, especially in education, operate under a fundamental misunderstanding of what "governance" truly means for technology. They often see it as a checklist for the IT department, a bureaucratic hurdle focused on compliance reports and audit trails. The common thought is: "COBIT? That's for big corporations, too rigid for our academic freedom." This perspective misses the forest for the trees. The real issue is not about technology itself, but about accountability.

Consider the typical scenario: the IT director identifies a new adaptive learning platform, champions its purchase, oversees its implementation, and then reports on its effectiveness. This person is both the decision-maker and the primary evaluator. It's like asking a chef to review their own cooking for a Michelin star. The incentive for an unbiased assessment is, understandably, compromised.

This conflation of roles creates a closed loop where critical questions often go unasked. With IT risks increasing for 63% of organizations (ISACA 2021 IT Risk/Reward Barometer), and the average cost of a data breach standing at $4.35 million (Ponemon Institute 2022), this oversight isn't just inefficient; it's dangerous. The lack of clear separation between those who direct and those who execute leaves institutions vulnerable, not just to data breaches, but to misaligned investments and missed opportunities for true value.

The Approach

The University of Amsterdam, like many forward-thinking organizations, began to look beyond the superficial understanding of frameworks like COBIT 2019. They recognized that the core value wasn't a rigid checklist, but a set of principles for how decisions are made and overseen. COBIT 2019, as the research shows, is actually designed to be highly flexible and customizable, allowing organizations to tailor governance objectives to their specific needs (ISACA 2018). It’s not a one-size-fits-all straitjacket, but a adaptable blueprint.

Instead of focusing on what technology to use, the focus shifted to how technology decisions are made and who is accountable for them. This is the heart of COBIT 2019: the distinction between governance and management. Governance evaluates, directs, and monitors. Management plans, builds, runs, and monitors. Imagine a board of directors (governance) setting the strategic direction for a company, while the CEO and their team (management) execute that vision day-to-day. The board doesn't get involved in daily operations, but they ensure those operations align with the overall strategy and deliver value (De Haes & Van Grembergen 2004).

Applying this, the university didn't just ask their IT department to "implement COBIT." Instead, they established clear roles and responsibilities, ensuring that the people making strategic decisions about research data management were distinct from those implementing the technical solutions. This structured approach helps ensure that IT investments contribute directly to organizational success (Van Grembergen & De Haes 2009). It's about bridging the gap between institutional risks, control needs, and technical realities (Kress & Dickinson 2003), making sure that everyone involved understands their part in the larger picture. This meant actively involving leadership, not just the IT team, in defining the governance structure, a crucial step for effectiveness (Simonsson & Johnson 2006).

What Happened

The University of Amsterdam's adoption of a COBIT 2019-aligned governance framework for its research data yielded tangible results. By clearly separating the governance function from the management function, they achieved a significant improvement in their data security posture. The outcome wasn't just theoretical compliance; it was measurable. The university reported a 30% reduction in security incidents (University of Amsterdam 2021).

This reduction wasn't magic. It stemmed from a clearer understanding of who was responsible for what. With governance providing oversight and strategic direction, and management focusing on efficient implementation, risks were identified and mitigated more proactively. Data security improved, and transparency in research data management was enhanced. It's a testament to the idea that frameworks like COBIT can be successfully applied in higher education institutions, particularly for critical areas like information security (Soomro, Shah, & Ahmed 2016).

The success wasn't about imposing corporate rules, but about adopting a universal principle of accountability. It demonstrated that when leadership is actively involved in defining and overseeing technology strategy, the entire institution benefits. In an era where 58% of higher education institutions are prioritizing cybersecurity initiatives (Educause 2022), the University of Amsterdam's experience offers a concrete example of how structured governance can directly contribute to these goals. It’s a practical demonstration that a well-defined governance structure isn't an obstacle to academic freedom, but a safeguard for it.

Why It Matters

The University of Amsterdam’s experience isn't an isolated incident; it's a blueprint for a broader shift. The deeper truth about COBIT 2019 is that it’s not primarily about IT. It's about the governance of information and technology – who makes decisions, who benefits, and critically, who is accountable. The core insight is that the people who make decisions about technology should not be the same people who implement and manage that technology. This separation isn't bureaucratic overhead; it's foundational to genuine oversight.

This distinction becomes even more critical with the rapid integration of Artificial Intelligence (AI) into education. AI systems are often opaque, operating with complex algorithms that even their creators struggle to fully explain. The claims made about AI's capabilities can be highly technical, making independent evaluation challenging. When the same individuals who champion and deploy an AI system are also solely responsible for assessing its performance, ethical implications, and potential biases, oversight becomes a performance, not a genuine inquiry.

For instance, 73% of executives believe AI is critically important to their organization's future (Deloitte 2021). But with that importance comes immense responsibility. Without a clear separation of governance and management, who truly holds the AI accountable? Who ensures transparency, fairness, and ethical deployment (Gonzalez & Sharma 2023)? The growing need for governance frameworks to manage AI risks and ethical considerations is widely recognized (de Boer, de Jong, & van Bemmel 2019). COBIT 2019, with its emphasis on distinct roles and accountability, offers a powerful model for navigating these uncharted waters. It's about ensuring that the promise of AI in education is realized responsibly, with checks and balances firmly in place.

The Takeaway Framework

Here are the critical lessons from this investigative dive into governance and technology:

1. Governance is Not Management: These are distinct functions. Governance sets direction, evaluates outcomes, and monitors performance. Management plans, builds, and runs the operations. Conflating them creates accountability gaps. 2. COBIT 2019 is Flexible, Not Rigid: Forget the old image of a corporate straitjacket. COBIT 2019 is a customizable framework designed to adapt to specific organizational contexts and needs, including the unique environment of educational institutions. 3. Focus on Value and Strategic Alignment: True governance isn't just about compliance; it's about ensuring technology investments deliver strategic value and align with the institution's overarching mission and objectives. 4. AI Demands Separation of Duties: The opacity and complexity of AI systems make the separation of governance and management not just beneficial, but essential. Independent oversight is the only way to ensure ethical, transparent, and accountable AI deployment in education. 5. Leadership Engagement is Non-Negotiable: Effective governance requires active involvement from institutional leadership, not just the IT department. It’s a strategic imperative, not a technical one.

The Transfer Question

The principles demonstrated by the University of Amsterdam are not unique to research data or European regulations. They apply to any institution grappling with complex technology decisions, especially as AI becomes more prevalent in classrooms and administrative offices. The core question is about who decides, who acts, and who is truly accountable. Could your institution benefit from a clearer separation of governance and management in its technology initiatives?

Can educational institutions afford to ignore the separation of governance and management in the age of AI?