COBIT 2019 design factors and tailoring
By Sam Rivera, Founder, SentinelPanda · May 19, 2026 · 3 min read · COBIT 2019
Trying to run all 40 COBIT objectives at full intensity is how programs die quietly. The design factors are how the framework was designed to be scaled down to your context.
Why the design factors exist
COBIT 2019 covers a wide range of enterprise sizes, industries, and risk profiles. Running every objective at the same level of rigour in every organisation would be enormously wasteful. The 11 design factors are inputs you weight to produce a tailored design: which objectives are priorities, at what capability target, and with what tailoring of the focus areas.
In ISACA terminology, the output is a "designed system of governance for I&T" — a slimmed and prioritised view of the 40 objectives that reflects your specific organisational context.
The 11 design factors
- <strong>1. Enterprise strategy.</strong> Growth, stability, client-service, innovation, cost leadership — the strategic stance the organisation is pursuing.
- <strong>2. Enterprise goals.</strong> The specific enterprise-level objectives the strategy decomposes into.
- <strong>3. Risk profile.</strong> The enterprise's current risk exposure across IT-related risk categories.
- <strong>4. I&T-related issues.</strong> Specific issues the organisation is grappling with — security incidents, regulatory pressure, technical debt, integration challenges.
- <strong>5. Threat landscape.</strong> The current threat environment the organisation operates in (normal, elevated, or sector-specific).
- <strong>6. Compliance requirements.</strong> External regulatory and contractual obligations.
- <strong>7. Role of IT.</strong> Whether IT is a support function, a factory, a turnaround function, or strategic to the business.
- <strong>8. Sourcing model.</strong> Insourced, outsourced, hybrid, or cloud-first.
- <strong>9. IT implementation methods.</strong> Agile, DevOps, traditional, or mixed.
- <strong>10. Technology adoption strategy.</strong> First mover, follower, or slow adopter.
- <strong>11. Enterprise size.</strong> Large, medium, or small.
How tailoring works in practice
Each design factor influences a different set of objectives. ISACA publishes the canonical influence mapping, and tooling typically automates the calculation. For example, a high "compliance requirements" weighting raises the priority of MEA03 (compliance with external requirements) and APO13 (managed security); a high "innovation" enterprise strategy raises BAI11 (managed projects) and APO04 (managed innovation).
The output is a prioritised view of the 40 objectives, often with target capability levels per priority objective. You do not get to skip objectives — every COBIT objective applies to some degree — but you do get to spend the most rigour where it matters most.
A worked example
A mid-size cloud-native SaaS company with: enterprise strategy = innovation + growth; risk profile = elevated cyber; I&T-related issues = rapid scaling; threat landscape = elevated; compliance requirements = SOC 2 + GDPR; role of IT = strategic; sourcing = cloud-first; methods = DevOps; technology adoption = first mover; size = medium.
The tailoring will heavily prioritise APO13 (security), APO12 (risk), DSS05 (security services), BAI11 (projects), MEA03 (compliance), and BAI06 (changes) — the objectives that directly support a fast-moving, cloud-native, security-conscious business. APO02 (strategy) and APO04 (innovation) sit in the second tier. Pure-IT objectives like DSS06 (business process controls) and BAI09 (assets) sit lower in priority — they exist and need basic capability, but they are not where the program should concentrate effort first.
What this means for assessment
A COBIT 2019 assessment that ignores tailoring tends to produce a flat scorecard — every objective at low or middling capability, no clear story for executives. A tailored assessment produces a prioritised view: here are the eight objectives that matter most for our context, here is where each one is today, here is the target, here is the year-one plan. The latter is what a board can actually decide on.
The tailoring is also defensible: if a critical audit raises the question "why is BAI09 only at capability 2?", the answer "because our design factors place it in the second tier and BAI06 / APO13 are first-tier priorities for our risk profile" is an actual answer, not a deflection.