IT Governance & Strategy
Every organization makes technology decisions constantly: which platforms to standardize on, which projects to fund, which risks to accept, which teams may choose their own tools. IT strategy is the set of deliberate choices about where technology will create advantage. IT governance is the system that decides who makes which decisions, with what information, and how results are checked.
Weak governance shows up as duplicated tools, stalled projects, surprise risks, and architecture that drifts in every direction. Heavy governance shows up as review boards that slow everything down without improving decisions. The goal is lightweight, clear decision-making that scales.
TL;DR
- Strategy is a set of choices, including what you will not do.
- Governance defines decision rights — who decides, who is consulted, and when decisions escalate.
- Manage investments as a portfolio balanced across run, grow, and transform.
- Make guardrails explicit so teams can move fast inside them without asking permission.
- Record decisions and their rationale so they can be revisited when assumptions change.
- Review outcomes, not just delivery milestones.
Quick Example
A decision-rights table answers "who gets to decide?" before the argument starts.
Core Concepts
Strategy: From Outcomes to Choices
A useful technology strategy connects a few business outcomes (enter new markets, cut cost to serve, improve customer retention) to technology capabilities and investments, then states trade-offs explicitly: "We will standardize on one cloud provider to reduce operational load, accepting some lock-in." A strategy that lists every possible initiative isn't a strategy.
Governance: Decision Rights and Guardrails
Governance works best as guardrails plus escalation: published standards (approved platforms, security baselines, data classification rules) that let teams decide independently, and a clear path for exceptions. Architecture decisions that are expensive to reverse deserve a lightweight review and an architecture decision record.
Portfolio and Investment Management
Reviewing the portfolio quarterly lets you stop, reshape, or accelerate work based on evidence. See Application Portfolio Management.
Frameworks
- COBIT — a governance framework defining objectives for evaluating, directing, and monitoring enterprise IT.
- ITIL — service management practices; governance-adjacent but focused on operations. See IT Operations.
- TOGAF — enterprise architecture method and vocabulary.
- ISO/IEC 38500 — principles for corporate governance of IT at board level.
Use frameworks as checklists and vocabulary; adopting them wholesale usually creates paperwork without better decisions.
Measuring Value
Combine delivery measures (DORA metrics), service health, security posture, cost, adoption, and business outcomes. A project delivered on time that nobody uses is a governance failure, not a success.
Best Practices
Publish Standards as a Paved Road
Make the approved path the easiest path: templates, preapproved platforms, and self-service. Governance by default beats governance by review.
Keep Review Boards Small and Time-Boxed
A review should take days, not months, and focus on hard-to-reverse decisions. Everything else follows published guardrails.
Revisit Decisions When Assumptions Change
Record the assumptions behind major decisions. When an assumption changes — a vendor's pricing, a regulation, team size — trigger a review.
Tie Funding to Outcomes
Fund persistent product teams with measurable outcomes rather than one-off projects that disband at launch.
Include Risk Explicitly
Every major decision should name the risks accepted and the owner who accepted them. See Compliance & Privacy.
Common Mistakes
Governance as a Gate Everyone Queues For
Centralized approval for every tool or change creates bottlenecks and drives shadow IT.
Strategy Documents Nobody Uses
A 60-page strategy that doesn't change any funding or standards decision is theater.
Measuring Activity Instead of Value
Counting projects delivered or tickets closed says little about whether technology improved the business.
No Exception Process
When standards have no legitimate exception path, teams quietly ignore them.
FAQ
What is IT governance?
The system of decision rights, processes, and accountability that ensures technology investments and operations support organizational goals and manage risk appropriately.
What is the difference between IT governance and IT management?
Governance decides direction, priorities, and who has authority; management executes within that direction — planning, building, running, and monitoring technology services.
Do small companies need IT governance?
Yes, but lightweight: a short list of standards, clear decision owners, a tool approval path, and a quarterly look at spend and risk. It grows with the organization.
What is COBIT used for?
COBIT provides a structured set of governance and management objectives for enterprise IT, commonly used to design control frameworks and support audits.
Related Topics
- Application Portfolio Management — Managing the investment portfolio
- Technology Procurement & Vendor Management — Governance at the point of purchase
- Architecture Decision Records — Recording significant decisions
- DORA & Delivery Metrics — Measuring delivery performance
- Compliance & Privacy — Regulatory obligations governance must satisfy