Why this review exists
Most organisations know their IT environment has problems. Systems go down. Projects overrun. Costs climb. Security incidents occur. Staff complain about tools that don't work.
The instinct — and the approach taken by most large consulting firms — is to start at the bottom. Audit every system. Catalogue every vulnerability. Review every incident ticket. Count every unpatched server. This is expensive, slow, and produces findings the organisation usually already knows. It is the equivalent of responding to a disease outbreak by testing every individual in the population before asking whether the laboratory that released the pathogen was following its own containment procedures.
Empirical AI takes the opposite approach.
We start at the top, because that is where the problems start. Technology failures — cost blowouts, unreliable systems, unresolved security issues, duplicated platforms, ungoverned architecture — are symptoms of governance failures. They are predictable consequences of missing or poorly implemented management frameworks. An organisation that has no functioning architecture governance will, inevitably, end up with five competing event-streaming technologies and systems deployed outside the DMZ. An organisation whose Change Advisory Board operates as an interrogation rather than a peer review will, inevitably, accumulate a backlog of unresolved caveats that degrade system integrity over time.
By assessing governance maturity against established international frameworks, we can identify root causes, predict the operational symptoms those causes produce, and confirm those predictions against a targeted set of evidence — in weeks, not months.
The approach: first principles, not forensics
This is a C-level review. It is designed to answer the question that a Board, CEO, or COO actually needs answered: Is the IT function being governed and managed in a way that will reliably produce good outcomes — or are we operating on luck and momentum?
It is not a technical penetration test, a cybersecurity assessment, a software licensing audit, or a line-by-line review of every operational system. Each of those has its place. But none of them answers the fundamental question, and all of them become significantly less useful without the governance context that tells leadership which findings matter, why they keep recurring, and what structural changes will prevent them.
Why top-down works
IT governance frameworks exist because the relationship between governance inputs and operational outcomes is well established and predictable. Decades of organisational research and international standards development have produced a clear model:
- Missing governance input → Predictable operational failure
- No architecture governance → Uncontrolled technology sprawl, duplicated platforms, integration failures
- No change management discipline → Unresolved caveats, production incidents from poorly reviewed changes
- No service management framework → Unmeasured performance, invisible backlogs, recurring incidents
- No asset management → Uncontrolled costs, licence exposure, unsupported hardware
- No strategy-to-execution cascade → Project portfolio disconnected from business priorities, shadow IT
The review identifies which governance inputs are missing, incomplete, or ineffective. It then predicts the downstream consequences. It then validates those predictions against a small, targeted set of operational evidence — incident reports, service metrics, architecture artefacts — to confirm the causal chain.
Whereas a traditional bottom-up review catalogues symptoms and leaves leadership to infer causes, this approach diagnoses causes and confirms them against symptoms. It is faster, less disruptive, and produces findings that leadership can act on structurally rather than tactically.
Assessment framework
The review is structured around two internationally recognised and enduring frameworks:
COBIT 2019 — Governance and Management Objectives
COBIT provides the governance architecture. Its 40 objectives span the full lifecycle of IT governance and management, organised as a cascade from Board-level direction through planning, building, delivering, and monitoring. COBIT includes a built-in capability maturity model based on ISO/IEC 33000, providing a consistent and defensible rating scale.
The 40 objectives cover:
- Evaluate, Direct and Monitor (EDM): Five objectives addressing Board and executive governance — ensuring IT strategy aligns with business strategy, benefits are delivered, risk is optimised, resources are adequate, and stakeholders are informed.
- Align, Plan and Organise (APO): Fourteen objectives covering IT strategy, architecture, innovation, portfolio management, budgeting, human resources, relationships, service agreements, suppliers, quality, risk, and security management.
- Build, Acquire and Implement (BAI): Eleven objectives covering programme and project management, requirements, solutions development, availability, change management, change acceptance, knowledge management, asset management, and configuration management.
- Deliver, Service and Support (DSS): Six objectives covering operations, service requests, incidents, problems, continuity, and security services.
- Monitor, Evaluate and Assess (MEA): Four objectives covering performance monitoring, internal controls, compliance, and assurance.
ITIL v4 — Service Management Practices
ITIL provides the operational detail underneath the COBIT governance structure. Where COBIT asks 'do you have a change management process?', ITIL defines what a mature change management process looks like in practice — the workflow, the roles, the metrics, the integration with other practices.
The ITIL practices most relevant to this review include service desk, incident management, problem management, change enablement, service level management, availability management, capacity and performance management, IT asset management, service configuration management, release management, and continual improvement.
What we ask you to provide
The assessment follows the Empirical AI evidence model: Policy, Implementation, Evidence. For each governance and management domain, we examine whether the policy exists, whether implementation documentation demonstrates it has been operationalised, and whether evidence confirms it is functioning as intended.
The document set is deliberately bounded. We are not asking for everything. We are asking for the documents that reveal whether governance and management frameworks are in place and functioning.
Governance and strategy
- IT strategy or technology strategic plan
- IT governance framework or charter
- IT risk register or risk management framework
- Board or executive IT reporting (recent examples)
- IT organisational structure and RACI
Planning and architecture
- Enterprise or solution architecture standards
- Technology roadmap
- Project or programme portfolio documentation
- Investment or business case process documentation
Build and change
- Change management policy and CAB terms of reference
- Release management or deployment process
- Recent CAB minutes or change records (sample)
- Development or acquisition standards
Service delivery and operations
- Service management framework or policy
- Service level agreements or OLAs (internal or vendor)
- Service desk and incident management reports (recent)
- Problem management records or known error register
Asset and configuration management
- Hardware asset register
- Software licence register
- Configuration management database or system register
Continuity and resilience
- Business continuity or disaster recovery plan
- Backup policy and recent test results
- Recent incident post-mortems (if available)
Targeted operational evidence
- Recent incident reports (particularly major incidents)
- Service performance metrics or dashboard reports
- Architecture decision records or exception registers
- Any audit or review findings (internal or external) from the past two years
This is typically 20–30 documents. Many organisations will not have all of them — and that is itself a finding.
How the process works
Phase 1 — Detection (Governance Assessment)
Empirical AI assesses each COBIT governance and management objective against the evidence provided, using the framework's built-in capability maturity model. For each objective, the assessment determines whether the process is performed, managed, established, predictable, or optimising — or whether it is incomplete or absent.
The output of this phase is a governance maturity profile: a clear picture of where the organisation sits across all 40 objectives, where the critical gaps are, and — critically — what operational problems those gaps are likely producing.
This is the crystal ball moment. Before we look at a single incident report or service metric, we can tell you what we expect to find based on what is missing from your governance layer. When we then validate those predictions against your operational evidence, the causal chain is established and the remediation path is clear.
Phase 2 — Enhancement (Remediation Planning)
The Enhancement Phase translates governance findings into a prioritised remediation plan. This is not a list of a hundred things to fix. It is a structured programme that addresses root causes in the right order — because fixing governance inputs will resolve multiple downstream symptoms simultaneously.
Remediation recommendations are practical and proportionate. For a mid-sized organisation, they might include establishing a functioning architecture governance forum, implementing a service management framework, introducing a genuine change advisory process, or creating a technology risk register that feeds into enterprise risk reporting. Each recommendation includes expected outcomes and suggested measures of success.
Phase 3 — Continuous Learning (Ongoing Monitoring)
The Continuous Learning Phase establishes the measurement framework that confirms whether remediation is working. Empirical AI defines and monitors key performance indicators aligned to each governance objective, drawn from established IT service management metrics:
- Service availability and reliability: Critical system and website uptime, outage frequency and duration
- Service performance: Incident volumes, mean time to resolve, first-contact resolution, SLA compliance, service desk backlog trends
- Asset management: Register accuracy, licence compliance and utilisation, asset lifecycle compliance, hardware failure rates
- Change and release: Change success rate, emergency change frequency, CAB backlog
- Security posture: Patch compliance, open vulnerability age, cybersecurity incident rate
- Cost effectiveness: IT cost per employee, unused licence cost, project cost variance
- Continuity: Backup success rates, recovery test results, recovery time vs targets
These KPIs are not the assessment itself — they are the ongoing measurement mechanism that tells leadership whether the governance improvements are translating into operational results.
Regulatory context
The assessment is structured around governance and management maturity, not legislative compliance. However, the governance framework naturally encompasses obligations under relevant Commonwealth legislation, and findings will note where governance gaps create regulatory exposure.
The primary legislative obligations relevant to IT governance include:
- Privacy Act 1988 (Cth): Obligations around collection, use, storage, and security of personal information under the Australian Privacy Principles.
- Security of Critical Infrastructure Act 2018 (Cth): Obligations for entities operating critical infrastructure assets, including risk management programmes and reporting requirements.
- Corporations Act 2001 (Cth): Director and officer obligations regarding adequate information systems, records management, and risk oversight.
- Electronic Transactions Act 1999 (Cth): Requirements for the legal validity of electronic records and communications.
Additional legislation may apply depending on the organisation's sector, activities, and regulatory environment. The assessment identifies where governance gaps create exposure to these obligations rather than conducting a separate legislative compliance review for each act.
What you get
- IT Governance Maturity Assessment: A COBIT-based maturity profile across all 40 governance and management objectives, with capability ratings and gap analysis.
- Root Cause and Prediction Report: Mapping of governance gaps to predicted and confirmed operational symptoms, establishing the causal chain from missing governance inputs to the problems the organisation is experiencing.
- Prioritised Remediation Plan: A sequenced programme of governance and management improvements, prioritised by impact, with expected outcomes and success measures.
- KPI Framework: A defined set of ongoing performance indicators aligned to governance objectives, providing the measurement mechanism for continuous improvement.
- Executive Presentation: A Board-ready summary of findings, root causes, and recommended actions.
- Ongoing Monitoring Reports: Periodic assessment of KPI trends and remediation progress through the Continuous Learning phase.
How this differs from a traditional IT review
A traditional bottom-up IT review — the kind typically delivered by large consulting firms — begins with the symptoms. It catalogues every unpatched server, every failed backup, every overdue incident ticket, every expired licence. This work can take months, cost hundreds of thousands of dollars, and produce a report that tells leadership what their own staff could have told them: that things are broken.
It does not tell them why things are broken, or what to fix first, or how to prevent the same problems from recurring.
This review starts where the problems start — at the governance layer — and works down only far enough to confirm the diagnosis. It is faster, less expensive, less disruptive to the organisation, and produces findings that drive structural change rather than tactical remediation.
If your IT environment has systemic problems, the answer is not to catalogue every symptom. It is to identify and fix the governance failures that are producing those symptoms. Fix the system, and the symptoms resolve. Catalogue the symptoms, and they will simply recur.
Scope boundaries
This review assesses IT governance and service management maturity. It does not replace, and should not be confused with, the following specialist assessments, each of which may be warranted depending on the organisation's risk profile and the findings of this review:
- Cybersecurity assessment: Detailed evaluation of security controls, vulnerability management, and threat posture against frameworks such as the ISM, NIST CSF, or Essential Eight.
- Privacy and data protection review: Comprehensive assessment of compliance with the Australian Privacy Principles and related obligations.
- AI governance review: Assessment of artificial intelligence systems, policies, and risk management arrangements (available as a separate Empirical AI capability).
Where this review identifies governance gaps that indicate the need for one of these specialist assessments, it will recommend accordingly.