Your organization has approved the AI tool.
Security has signed off. Legal has reviewed the contract. Procurement has negotiated the price. The business case has been approved.
So, is it a good technology decision?
Perhaps. But what about the wider consequences?
A tool may be secure, compliant, within budget, architecturally sound, supported by a compelling business case and still consume resources disproportionately, exclude intended users, create avoidable lifecycle impacts or produce consequences for employees and communities that nobody considered before approval.
The problem is not necessarily that organizations do not care about sustainability. It is that the questions are often siloed.
Security considers one part of the decision. Privacy considers another. Risk, legal, procurement, architecture and the business each bring their own lens. Environmental impacts may sit with sustainability teams. Accessibility may enter the conversation elsewhere. Workforce and societal consequences may emerge later still.
But the technology decision is one decision.
If its consequences are interconnected, the challenge, therefore, is not simply whether an organization should adopt technology. It is how it makes the decision.
This is the practical gap COMPASS is intended to address.
Why this matters now
This matters particularly as organizations make decisions about technologies whose consequences extend well beyond the IT function.
AI is an obvious example, but it is not the only one. Cloud migration, data centers, connected devices, automation, enterprise platforms and hardware procurement all create decisions about resources, lifecycle, accessibility, governance and people alongside the familiar questions of security, cost and performance.
The International Energy Agency’s work on AI and energy illustrates one part of this problem: efficiency at the level of an individual AI task does not necessarily translate into lower overall energy demand as adoption expands and more energy-intensive use cases emerge. Its 2026 analysis continues to highlight the rapid growth in electricity demand associated with data centres and AI.
At the same time, the United Nations’ Global Digital Compact calls for an inclusive and sustainable digital future, including attention to environmental impacts across the lifecycle of digital technologies, accessibility and meaningful stakeholder participation. The OECD similarly recognizes that technology can contribute to sustainable development while also creating risks involving workers, human rights, governance and the environment.
For governance professionals, the implication is important: Sustainability is becoming part of the technology governance conversation. The question is how to make it operational.
That shift is visible within ISACA itself. Writing in the ISACA Journal, Guy Pearce argues that Green IT should be subject to the same rigors of IT governance as other technology investments, including strategic alignment, risk management, benefits tracking and capability development. In a subsequent ISACA Now blog post on the evolving CIO role, he likewise places the sustainability of the IT ecosystem within contemporary technology leadership.
In an earlier ISACA blog post, I explored the sustainability implications of emerging technologies, such as blockchain and AI. Three years later, the question I find more pressing is not whether technology has sustainability implications – we know that it does. The practical question is how those considerations become part of the technology decision before approval.
One decision, seven questions
The COMPASS Model, developed in 2023, provides a holistic approach to navigating sustainability in technology. It brings environmental, social, economic and governance considerations together through seven interconnected dimensions: Circular Economy, Optimisation, Mindful Consumption, Policy and Regulation, Accessibility, Stakeholder Collaboration and Social Responsibility.
These considerations are not substitutes for security, privacy, risk or regulatory assessment. Nor does COMPASS attempt to turn technology professionals into sustainability specialists.
Its purpose is more practical: Before an organization commits to a technology decision, have the right sustainability questions been asked?
| Dimension | COMPASS Focus | The Question Before Approval |
|---|---|---|
| C |
Circular Economy |
What are we committing to across the technology's lifecycle? |
| O |
Optimisation |
Are the resources required proportionate to the value we expect? |
| M |
Mindful Consumption |
Do we need this technology or are we adopting capability because it is available? |
| P |
Policy and Regulation |
Do our governance arrangements cover how we intend to use it? |
| A |
Accessibility |
Who benefits and who might be excluded? |
| S |
Stakeholder Collaboration |
Who isn't in the room but will live with the consequences? |
| S |
Social Responsibility |
What consequences are we accepting for people and society by proceeding? |
The wording above translates the seven dimensions into questions that can be used at the point of decision.
The questions are deliberately simple, but they are not superficial. Optimisation, for example, asks organizations to distinguish technical efficiency from proportionality: a solution can be efficient and still consume more resources than its value justifies. Mindful Consumption goes further by asking whether the technology is necessary in the first place. This is not anti-innovation; it is disciplined adoption.
From Questions to Evidence
Asking the questions is only the beginning. For governance, risk and assurance professionals, an answer without evidence has limited value. A practical assessment should therefore establish the organization’s position, the evidence supporting it, any gap identified and ownership of the resulting action.
Consider Accessibility. A project team might state that a new platform is accessible. The assessment should not end there. The next question is: What evidence demonstrates that?
Was accessibility tested? Against what standard? With whom? Which issues were identified? Which remain unresolved?
The same principle applies to Optimisation. If a project claims its infrastructure is appropriately sized, what usage, capacity or performance evidence supports that conclusion?
And if the organization concludes that affected stakeholders were adequately involved, where is that involvement demonstrated?
This is where COMPASS becomes relevant to assurance rather than remaining a statement of good intentions.
Applying COMPASS to a Generative AI Decision
Suppose an organization wants to deploy a generative AI assistant across its workforce.
Security has assessed data exposure. Privacy has considered personal data. Legal has reviewed contractual and regulatory requirements. The business expects productivity gains.
Those assessments remain important. The sustainability lens asks what may still be missing.
Circular Economy: What infrastructure sits behind the service, and what lifecycle commitments are being created?
Optimisation: Is the chosen model and supporting infrastructure proportionate to the task?
Mindful Consumption: Does this problem require generative AI?
Policy and Regulation: Does existing governance cover the proposed use rather than AI merely in principle?
Accessibility: Can the whole intended workforce use and benefit from it?
Stakeholder Collaboration: Were employees and other affected groups involved before the decision?
Social Responsibility: Which human decisions, roles or relationships might change as a result?
None of those questions automatically produces a “no.” Rather, the answers may affect the conditions under which the technology is approved, implemented and subsequently reviewed.
Put COMPASS inside governance, not beside it
This matters at a time when organizations are already dealing with framework proliferation. Writing recently on ISACA Now, Mark Thomas cautions against responding to each emerging risk with another standalone model, describing “framework sprawl” as a source of fragmentation and advocating an “extend, don’t duplicate” approach.
The same principle applies here. It is not proposed as a replacement governance framework or as another governance layer. Rather, it provides a sustainability lens that can be incorporated into the technology governance processes an organization already uses.
If sustainability is genuinely part of technology governance, its questions should enter the processes organizations already use to make decisions.
A COMPASS question might appear in a technology business case. It might become part of architecture review. It could inform procurement requirements and supplier due diligence. It could provide criteria for project approval. And it could give internal audit additional questions when assessing whether technology governance reflects an organization’s stated sustainability commitments.
That same principle applies to established approaches such as the NIST AI Risk Management Framework, which addresses AI risk management across the lifecycle. The seven decision questions can sit within such existing governance and assurance processes rather than creating a parallel program.
The objective is not another governance layer. It is a broader definition of a good technology decision.
Before the Next Approval
Think about the last major technology decision your organization approved.
You may be able to produce the business case, security assessment, privacy review, risk register, architecture decision and procurement record. But could you demonstrate that sustainability considerations were part of that decision before approval—not considered separately or retrospectively, but incorporated into the decision itself?
If that is difficult to demonstrate, the organization may not have a sustainability problem as much as a technology decision-making problem.
COMPASS offers a practical lens for exposing that gap. It does not tell an organization whether to buy the system, migrate to the cloud, automate the process or deploy an AI solution. It asks whether the organization knows enough about the consequences to make that decision well.
And as technology decisions become more consequential, that should increasingly be part of what good governance means.
About the Author: Abigael Okikijesu Dumbiri (formerly Abigael Okikijesu Bada) is a Certified Information Systems Auditor (CISA), technology entrepreneur and Founder of Fortini Tech. She serves on the ISACA London Chapter Board as Marketing Director and writes on cybersecurity, technology governance and sustainable technology. Her previous work with ISACA was published under the name Abigael Okikijesu Bada.