COBIT 2019 MEA domain (Monitor, Evaluate, Assess)
By Sam Rivera, Founder, SentinelPanda · June 20, 2026 · 1 min read · COBIT 2019
MEA is the domain that checks the others — performance, internal control, and compliance. It is how COBIT closes the loop and feeds governance with evidence.
The monitoring domain
MEA — Monitor, Evaluate and Assess — is the management domain that checks whether everything else is working. It monitors IT performance and conformance, assesses the system of internal control, and manages compliance with external requirements. It is the feedback loop of the governance system.
What it covers
MEA's objectives cover monitoring performance and conformance (are we meeting goals and following our own rules), managing the system of internal control (is the control environment effective), and managing compliance with external requirements (laws, regulations, contracts). It is assurance and oversight at the management level.
It feeds governance
MEA produces the evidence that EDM — the board's governance domain — needs to monitor. Governance cannot evaluate and direct without information on how things are actually going, and MEA supplies it. The two close the loop: MEA assesses, EDM governs based on the assessment.
Where it meets compliance
MEA's compliance objective is where COBIT connects most directly to the regulatory and security compliance work an organisation does — the monitoring and assurance that frameworks like ISO 27001 and SOC 2 also require. SentinelPanda's evidence and monitoring feed exactly this kind of conformance assessment.