Every enterprise is carrying governance debt, and most don’t know the balance is due.
We talk constantly about technical debt: the shortcuts in code and architecture that compound quietly until the system buckles. Governance debt works the same way. Organizations layer new technology, new policy and new urgency onto old structures, the same committees, the same decision rights, the same evidence mechanisms, without ever modernizing the foundation. It feels like progress. It looks like progress. Then a regulator, an incident, or a board member asks one hard question, and the brittleness shows.
That gap, between how fast technology moves and how slowly governance adapts, is the governance challenge of 2026 and beyond. The encouraging news is that closing it doesn’t require a new framework. It requires using one we already have, the way it was designed to be used.
Thirty years of keeping up
In a recent piece, 30 Things COBIT Taught Us About Governing Technology, I reflected on how much one framework has absorbed over three decades. Look at the arc and a pattern emerges: COBIT has never really been about technology. It has always been about the questions leadership must answer as technology changes.
Figure 1—COBIT and the moving terrain

The map keeps getting redrawn because the terrain keeps changing. What stays constant is the discipline of asking who decides, who is accountable and how we would prove it.
Where the gap opens today
Governance debt isn’t abstract. It surfaces in patterns I see in nearly every engagement.
What ties these gaps together is fragmentation. Every new pressure, new regulation, new technology or new assurance demand tends to arrive with its own policy, its own committee, and its own binder, stacked alongside everything that came before. The result is not more governance but more surface area, and the gaps open in the seams between all those disconnected parts.
Those seams are where the real gaps live. Strip away the labels and the same handful show up in nearly every enterprise: where each one opens, why it persists and how COBIT closes it.
| The gap | Why it persists | How COBIT closes it |
|---|---|---|
|
Policy theater: more policy than control |
Documents feel like governance |
Components model ties policy to processes, structures and evidence |
|
The enforcement era: “show us,” not “tell us” |
Programs built to assert, not demonstrate |
EDM and MEA objectives make oversight evidential, not declarative |
|
AI accountability: borrowed models, owned risk |
Vendors transfer operation, not accountability |
Design factors integrate AI risk without a parallel program |
|
Resilience vs. recovery |
Recovery metrics mistaken for resilience |
End-to-end coverage links continuity to enterprise objectives |
|
Framework sprawl: a new model for every domain |
Each emerging risk arrives with its own standard, team and tooling |
COBIT sits above them as the integrating umbrella, so you extend rather than duplicate |
|
Value blind spot: activity mistaken for value |
Effort and spend are measured; outcomes are assumed |
The goals cascade ties every objective to enterprise value and performance management measures what was realized |
|
Trust deficit: compliant but not trusted |
Trust is treated as a by-product of compliance, not a designed outcome |
COBIT and the DTEF make digital trust a governed objective, with owners, controls and evidence |
Read down the last column and the through-line is unmistakable. Every one of these gaps is a governance problem wearing a technology costume, and none of them is solved by adopting a new framework. It took me a while, and a very cluttered desk, to see it.
I learned this the hard way, long before I sat on this side of the table. As a CIO, I once faced a stack of frameworks and models that would have buried my desk if I had printed them all. Every one arrived with the same promise: adopt me, and I will save your organization. Security had its models, service management had its own, and so did project delivery, architecture, risk, and quality, each with passionate champions and a thick manual. I did not have a framework problem. I had a framework overload problem and no honest way to decide which parts of which model actually mattered to the enterprise.
That is when COBIT became, in my own words, my framework to manage frameworks. It did two things nothing else did. It linked enterprise governance to the governance of enterprise I&T, so the board’s intent and the technology function were finally speaking the same language. And it let me filter the sprawl, pulling from each model only the parts that helped the enterprise meet its goals and support its strategy, leaving the rest on the shelf. I stopped asking which framework wins. I started asking which parts of each one earn their place.
Figure 2—COBIT as the framework to manage frameworks.

COBIT closes the gap by refusing to treat each pressure as a new island. Its components model, the interplay of processes, organizational structures, policies, information flows, culture, and skills, turns a written policy into something that actually operates and produces evidence. That is the difference between a control that lives on paper and one an interested party can watch working. The Evaluate, Direct and Monitor (EDM) and Monitor, Evaluate and Assess (MEA) domains move oversight from assertion (decorative) to demonstration (load bearing), so when the request shifts from tell us to show us, the evidence already exists.
Just as important is how COBIT absorbs what is new. Its design factors let an enterprise fold emerging risks, AI, privacy, digital trust, into the governance system it already runs, rather than standing up a parallel program for each. That is the working meaning of extend, don’t duplicate. And because COBIT covers the enterprise end to end, it ties operational concerns like resilience back to enterprise objectives, so continuity is judged by whether the business can keep its promises, not merely by whether a system was restored.
Seen whole, that is what COBIT gives you: one integrated system that balances performance and conformance, and turns a pile of disconnected frameworks into value the enterprise can actually show.
From the Field: When the binders couldn’t answer
An organization I worked with had a polished AI policy library: principles, standards, the lot. When a regulator asked them to demonstrate a single enforced control, they couldn’t. The policies spoke loudly; the controls stayed silent. The lesson the risk discipline keeps teaching: if it isn’t documented and operating, it never happened.
A glimpse ahead
Step back, and the last 30 years look less like a string of technologies and more like a single, accelerating trend: each wave moves something we used to control a little further out of our hands. Client/server distributed our computing. ERP consolidated the data backbone. The internet and cloud externalized our infrastructure, then platform-as-a-service externalized the platform itself. Cryptocurrency externalized trust into the protocol. AI is now externalizing judgment. Quantum will externalize the very mathematics our security depends on, and space-based compute and connectivity will externalize where our infrastructure physically, and jurisdictionally, lives. After that? The frontier will move again. It always does.
But notice the precondition hiding in that sequence: each wave assumes you could already govern the one before it. If you cannot govern I&T today, you will not govern AI, quantum, or whatever comes next, because every emerging technology inherits the governance you already have, or the governance debt you already carry. Governing I&T first is not a step toward governing emerging technology. It is the whole game.
Notice what never moves: accountability. The capability keeps migrating outward; the responsibility stays exactly where it began. That is why borrowed model, owned risk is really the latest verse of a much older song: borrowed infrastructure, borrowed platform, borrowed trust, borrowed judgment owned risk every time. The same governance question echoes through every wave: how do we govern what we don’t fully control?
Borrowed model, owned risk
When you build on a third-party or foundation model, you transfer the operation, never the accountability. Governing the decision matters more than governing the tool. This is exactly the capability COBIT was created to build.
This is also where digital trust stops being a slogan and becomes a governance objective. Trust is no longer an outcome you earn by being compliant; it is multi-dimensional and has to be designed in – not just “is it secure?” but “is it fair, transparent, and worthy of belief?” That is why ISACA built the Digital Trust Ecosystem Framework (DTEF), which operates alongside COBIT rather than competing with it. As an ISACA Now analysis puts it, the DTEF acts as “middleware between multiple frameworks from a digital trust lens,” while COBIT was built to integrate with other standards, so trust becomes something you govern for, with owners and evidence, rather than something you hope for.
Trust as the new control
In an environment where technology evolves faster than regulation, trust becomes the control. Deploy the best tooling you like. If interested parties don’t trust your intent, your frameworks are just paper.
ISACA research found that most organizations don’t know how quickly they could halt a compromised AI system. That blind spot will follow us to quantum, and to orbit, unless governance leads instead of chases.
Mark’s Top Ten for Closing the Gap
- Retire governance debt on purpose. Schedule it like patching. Left alone, it compounds until something fails under pressure. Example: for every new policy or committee you add, retire one that no longer earns its keep.
- Filter your frameworks; do not collect them. You do not need every model on the shelf, only the parts of each that move the enterprise toward its goals. That is the job COBIT does. Example: adopt the three practices from a security standard that fit your risk, and leave the other 200 pages unopened.
- Extend, do not bolt on. New technology is a new room, not a new house. Fold it into the governance system you already run. Example: absorb AI risk into your existing enterprise risk process rather than launching a separate AI risk program.
- Own the decision, not just the tool. Borrowed model, owned risk. You can outsource the operation, never the accountability. Example: sign off on a vendor’s foundation model only once your own controls sit around how it is used.
- Build for “show us,” not “tell us.” Assume the next request is for evidence, because it is. Example: every model and control ships with a log an interested party can inspect on request, not a memo that says it works.
- Lead from the top. Governance delegated to a working group is governance in name only. Direction and accountability start in the boardroom. Example: a board-level technology committee reviews AI and cyber risk each quarter, not an IT-only huddle.
- Revisit decision rights on a cadence. Who decides should change as fast as the technology does. Example: refresh cloud and AI decision rights every year rather than inheriting a policy frozen in 2015.
- Measure resilience, not just recovery. Restoring a system is not the same as keeping the enterprise’s promises. Example: judge continuity by whether interested parties were still served, not by how fast a server came back.
- Govern I&T first. Every emerging technology inherits the governance you already have, or the debt you already carry. Example: fix your I&T decision rights before, not after, you let an autonomous agent act on the enterprise’s behalf.
- Engineer trust. You cannot audit trust in after the fact any more than you can inspect quality into a finished product. Design it in. Example: publish your data-use and model-transparency practices before an interested party thinks to ask.
Thirty years in, COBIT’s lesson is the same as it ever was: governance, not technology, determines whether the enterprise is strengthened or destabilized. The terrain will keep changing and the discipline of governing it well is what closes the gap. Thirty years have proven that COBIT is the only framework in the world with this capability, the one built to govern all the others and turn them into enterprise value. And I would bet it stays that way, through every layer of complexity still ahead, including the changes we do not yet expect.