What is IT governance and how do you set it up properly?

An IT project is delayed. Deadlines are missed. The business wants one thing, IT delivers something else. No one knows exactly who is authorized to make the decision. The cause is almost always the same: IT governance that is not set up properly.
IT governance is the entirety of agreements, roles, and processes that determines how decisions about IT are made, who is responsible for them, and how IT aligns with the goals of the organization. In this article, you will read what IT governance entails, why it so often goes wrong, and how to set it up properly step-by-step.
What is IT governance?
IT governance regulates decision-making about IT within an organization. Who has the mandate to make which choices? How are IT investments accounted for? And how does IT ensure that it contributes to the goals of the organization instead of standing apart from them?
It is not just about technology. IT governance touches on strategy, organization, and culture. It determines how business and IT collaborate, how priorities are set, and who is responsible when things go wrong.
Many large organizations have set something up for this. Processes, roles, consultation structures. But whether that actually works in practice is another question.
Why is IT governance important?
MIT research among 250 organizations worldwide shows that organizations with good IT governance achieve more than 25% higher profits than organizations with poor governance under the same strategic objectives.
Yet, IT governance remains neglected in many large organizations. Projects run over budget because no one dares to make a decision. Budgets grow without it being clear what they deliver. IT and business work on different priorities without anyone correcting it. Compliance requirements such as GDPR or NIS2 become a risk instead of a manageable part of business operations.
Good IT governance prevents this.
Where does it go wrong in practice?
IT governance rarely fails due to a lack of frameworks or documentation. IT governance falters not because of technology, but because of leadership. The structure exists on paper, but does not work in practice.
That is also what the figures show. Fewer than twenty percent of organizations effectively apply methods like COBIT and ITIL, according to KPMG research. The vast majority of large organizations have introduced frameworks that are barely used in practice.
Why? Because many IT governance frameworks originate from the accounting corner and are often quite complex and do not align with operational practice. A direct translation into practice then results in bureaucracy instead of governance.
This translates into recognizable situations. No one knows who is allowed to make a decision about an IT investment. There are consultation structures, but the mandate is missing. Decisions are postponed, passed on, or made by the wrong people. IT reports on systems and capacity, business wants to know what it delivers. As long as that translation is not made, structural misunderstandings arise. And in large organizations with multiple suppliers and outsourced services, this only becomes more complex: the intention to have control is present, but concrete control over data flows and IT dependencies is virtually non-existent everywhere.
The conclusion is immediate: governance that is too heavy for the organization is bypassed. Governance that is too light offers no guidance. The art lies in the balance.
A new governance issue that comes on top of this is AI. You can read why existing IT frameworks fall short for this in our article on AI governance.

How do you set up IT governance properly?
There is no universal approach that works for every organization. What works depends on the size of your organization, the sector in which you operate, and the maturity of your IT function. But there are three things that are decisive in almost every situation.
Make clear who decides on what
The basis of IT governance is decision-making. Who has the mandate for which IT choices? Who is involved, who has the right to advise, and who ultimately decides? As long as this is not clear, the problems from the previous chapter will keep reoccurring.
This does not have to be an extensive document. A simple decision-making matrix that is widely known and actually used does more than an extensive framework that is still unknown to a large part of the organization.
Choose a framework that fits your organization
The most famous frameworks are COBIT, ITIL, and BiSL. They each have a different area of application and are not interchangeable.
COBIT is more relevant for large companies, as they often place higher demands on compliance. ITIL is particularly important when setting up IT processes and strategies. Both frameworks complement each other: ITIL describes how IT processes are set up, COBIT ensures that those processes are demonstrably aligned with laws, regulations, and business objectives.
BiSL has a different starting point. BiSL focuses on the demand side of IT service delivery and emphasizes the business and the user organization, while ITIL focuses on how IT can technically realize these needs. For organizations that want to improve the alignment between business and IT, BiSL is therefore a logical choice, often alongside ITIL.
Important: it is wiser to first determine what one wants to achieve and how one can apply IT governance, before choosing a framework. A framework is a tool.
Ensure IT and business speak the same language
Governance does not work if IT remains in its own world. At FedEx, this was exactly the problem. After the takeover of TNT, hundreds of thousands of customer records had to be migrated globally. The project had the highest priority within the organization, but stalled due to a large gap between IT and business. No one understood what the other side did or needed.
Koodin brought structure by redefining the project, structurally involving stakeholders, and translating technology into business language. What started as a stalled project grew into a collaboration that was internally described as excellent.
Keep it workable
Governance that is too complex will be bypassed. Choose frameworks that fit the scale and maturity of your organization. Adapt them based on what works. And ensure that the people who have to work with it know why the structure is there.
You can read more about how governance and decision-making relate on our page about governance and decision-making.
How do we approach this?
We start by listening. What is really going on? Where is the friction? What needs to be done now and what can wait? We take the time to understand your situation before coming up with solutions.
1. We listen and understand
We talk to the people who do it daily and to the stakeholders who have to approve it. We ask the difficult questions that others skip, and thus get a clear picture of where the bottlenecks are.
2. We define the demand sharply
Together, we determine what is achievable, where risks lie, and what choices need to be made. We help you bring focus and maintain it throughout the project.
3. We execute with seniority
Our consultants step directly into your team and take responsibility. They not only work on the solution, but also ensure that stakeholders are on board and that quality is guaranteed.
4. We transfer knowledge
We do not build something that only we understand. Your team grows stronger during the project and can continue independently afterwards. That is what truly sustainable results are about.
5. We conclude with a hand-over
Once the project is finished, we hand everything over properly. This way, your organization can continue under its own power.
Can we help you?
Do you recognize this in your organization and want to know what is needed? Contact Maarten.
Anything to amaze you.
Frequently asked questions about IT governance
What is the difference between IT governance and IT management?
IT management is about the daily operations within IT. IT governance is about the structure within which decisions are made: who has the mandate, how investments are accounted for, and how IT aligns with the organization's strategy.
Which IT governance framework fits my organization?
That depends on what you want to achieve. COBIT is suitable for large organizations with compliance requirements, ITIL for setting up IT processes, and BiSL for improving the alignment between business and IT. The choice does not start with the framework, but with the question of what is currently not going well.
How long does it take to set up IT governance?
An initial assessment takes a few weeks and provides insight into where the bottlenecks are and which decision-making is lacking. A full implementation, in which roles, processes, and consultation structures are set up and anchored in the organization, often takes three to six months. The exact lead time depends on the size of the organization and how mature the IT function already is.
What does poor IT governance cost an organization?
Research from MIT shows that organizations with good IT governance achieve over 25% higher profits than those with poor governance, even with the same strategic objectives. On top of that are indirect costs: delayed decision-making, missed opportunities, and IT investments that fail to deliver what they were supposed to.
Is IT governance only relevant for large organizations?
The core is relevant to every organization, but in large organizations with complex IT landscapes and many suppliers, the lack of governance becomes visible more quickly and is more painful.












