Flevy Management Insights Q&A
What impact does the rise of blockchain technology have on COBIT's framework and guidelines?


This article provides a detailed response to: What impact does the rise of blockchain technology have on COBIT's framework and guidelines? For a comprehensive understanding of COBIT, we also include relevant case studies for further reading and links to COBIT best practice resources.

TLDR Blockchain technology necessitates updates to COBIT's framework, introducing new governance structures, risk management strategies, and control objectives to address decentralized architectures and ensure IT Governance and Management align with emerging risks and opportunities.

Reading time: 5 minutes

Before we begin, let's review some important management concepts, as they related to this question.

What does Governance Frameworks mean?
What does Risk Management mean?
What does Strategic Alignment mean?
What does Performance Measurement mean?


Blockchain technology, with its decentralized and transparent nature, is revolutionizing various sectors by enabling secure, traceable transactions and records without the need for intermediaries. This innovation is not only transforming industries like finance, supply chain, and healthcare but is also influencing frameworks and guidelines that govern IT governance and management, such as COBIT (Control Objectives for Information and Related Technologies). COBIT, developed by ISACA (Information Systems Audit and Control Association), is a comprehensive framework that helps organizations manage and govern their information and technology. The rise of blockchain technology presents both opportunities and challenges for COBIT's framework and guidelines, necessitating adjustments to accommodate new risks, controls, and governance structures.

Impact on Governance and Management Objectives

The introduction of blockchain into an organization's IT landscape significantly impacts COBIT's governance and management objectives. Blockchain's inherent characteristics such as decentralization, immutability, and transparency align well with COBIT's principles of managing IT risks and ensuring effective governance. However, these same characteristics also introduce new complexities. For instance, the decentralized nature of blockchain challenges traditional centralized governance models, requiring updates to COBIT guidelines to address governance over decentralized architectures. This includes the need for new risk management strategies, as the distributed ledger technology brings unique risks such as smart contract vulnerabilities and consensus mechanism failures.

Moreover, the management practices within COBIT, such as APO (Align, Plan and Organise) and DSS (Deliver, Service and Support), must evolve to incorporate blockchain's capabilities. This involves redefining IT processes and controls to ensure they are effective in a blockchain environment. For example, the process of managing data integrity might leverage blockchain's immutability to enhance controls. However, it also requires new competencies and understanding from IT personnel to manage and operate blockchain technologies effectively.

Real-world examples of blockchain's impact on governance and management objectives include financial institutions adopting distributed ledger technology for cross-border payments. This adoption necessitates revising risk management frameworks to address the specific risks associated with blockchain, such as those related to cryptocurrency volatility and regulatory compliance. Similarly, supply chain management using blockchain to ensure product authenticity requires updates to data governance and quality management practices within the COBIT framework.

Are you familiar with Flevy? We are you shortcut to immediate value.
Flevy provides business best practices—the same as those produced by top-tier consulting firms and used by Fortune 100 companies. Our best practice business frameworks, financial models, and templates are of the same caliber as those produced by top-tier management consulting firms, like McKinsey, BCG, Bain, Deloitte, and Accenture. Most were developed by seasoned executives and consultants with 20+ years of experience.

Trusted by over 10,000+ Client Organizations
Since 2012, we have provided best practices to over 10,000 businesses and organizations of all sizes, from startups and small businesses to the Fortune 100, in over 130 countries.
AT&T GE Cisco Intel IBM Coke Dell Toyota HP Nike Samsung Microsoft Astrazeneca JP Morgan KPMG Walgreens Walmart 3M Kaiser Oracle SAP Google E&Y Volvo Bosch Merck Fedex Shell Amgen Eli Lilly Roche AIG Abbott Amazon PwC T-Mobile Broadcom Bayer Pearson Titleist ConEd Pfizer NTT Data Schwab

Adjustments to COBIT's Control Objectives and Practices

Blockchain technology necessitates adjustments to COBIT's control objectives and practices, particularly in areas related to security, privacy, and data integrity. The decentralized and encrypted nature of blockchain offers new mechanisms for securing transactions and information. However, it also introduces challenges such as the need for key management practices to secure cryptographic keys and the difficulty of amending data once it is committed to the blockchain. Therefore, COBIT's control practices related to information security management need to be updated to include guidelines on cryptographic key management, consensus algorithms, and smart contract security.

Additionally, blockchain impacts COBIT's practices around data privacy and compliance. Given the immutable record of transactions blockchain provides, ensuring compliance with data protection regulations such as GDPR becomes complex. COBIT guidelines must therefore evolve to provide a framework for managing these complexities, including the right to be forgotten in a blockchain context. This might involve innovative approaches to data storage on blockchains, such as only storing hashes of personal data, thereby aligning with COBIT's control objectives while ensuring regulatory compliance.

From a practical standpoint, organizations implementing blockchain for traceability in supply chains must adapt their COBIT-aligned IT governance frameworks to manage the integrity and confidentiality of the data within the blockchain. This includes establishing controls around the onboarding of network participants and the validation of transactions, which are critical for maintaining the trustworthiness of the blockchain network.

Strategic Alignment and Performance Measurement

The rise of blockchain technology also impacts COBIT's focus areas of Strategic Alignment and Performance Measurement. Blockchain offers opportunities for organizations to innovate and gain competitive advantages, such as increased efficiency, reduced costs, and enhanced transparency. To capitalize on these opportunities, COBIT's guidance on aligning IT with business strategy needs to incorporate considerations for blockchain. This includes assessing the strategic value of blockchain initiatives and ensuring that they are aligned with the organization's overall goals and objectives.

Furthermore, the performance measurement aspects of COBIT must adapt to include metrics and KPIs relevant to blockchain implementations. This could involve measuring the efficiency gains from blockchain-enabled processes, the reduction in transaction costs, or improvements in data veracity. However, it also requires careful consideration of the performance trade-offs associated with blockchain, such as the potential for increased energy consumption due to consensus mechanisms like Proof of Work.

An example of strategic alignment and performance measurement in action is the adoption of blockchain in the banking sector for remittance services. Banks integrating blockchain technology to facilitate faster and cheaper international transfers must align these initiatives with their broader digital transformation strategies. They must also develop new KPIs to measure the success of blockchain projects, such as transaction speed, cost savings, and customer satisfaction levels, ensuring these metrics contribute to the overall strategic objectives of the organization.

Blockchain technology's impact on COBIT's framework and guidelines underscores the need for continuous evolution in IT governance and management practices. As blockchain continues to mature and find new applications across industries, COBIT will need to adapt to provide relevant and effective guidance for organizations navigating this transformative technology.

Best Practices in COBIT

Here are best practices relevant to COBIT from the Flevy Marketplace. View all our COBIT materials here.

Did you know?
The average daily rate of a McKinsey consultant is $6,625 (not including expenses). The average price of a Flevy document is $65.

Explore all of our best practices in: COBIT

COBIT Case Studies

For a practical understanding of COBIT, take a look at these case studies.

IT Governance Redesign for E-commerce Platform in Competitive Market

Scenario: The organization in question operates within the highly competitive e-commerce space and has recently expanded its market reach, which has led to a significant increase in transaction volume and data processing demands.

Read Full Case Study

Enterprise Governance, Risk and Compliance Optimization using COBIT for a Global Financial Institution

Scenario: A global financial firm with an expansive portfolio, across several geographies, is experiencing challenges streamlining its corporate governance, risk, and compliance due to a large degree of manual processing and multiple disparate software solutions.

Read Full Case Study

COBIT Deployment for Luxury Brand in European Market

Scenario: The organization, a renowned European luxury brand, is grappling with governance issues in its IT processes, which are not aligned with business goals.

Read Full Case Study

COBIT Integration for Global Defense Contractor

Scenario: The organization is a leading defense contractor facing challenges in aligning its IT governance with strategic objectives, in accordance with COBIT frameworks.

Read Full Case Study

COBIT Deployment in Global Life Sciences Firm

Scenario: The organization is a global player in the life sciences industry, facing challenges in aligning IT governance with business objectives.

Read Full Case Study

IT Governance Enhancement in Aerospace Sector

Scenario: The organization is a leading aerospace components manufacturer facing challenges in aligning IT initiatives with business goals, leading to cost overruns and delayed project delivery.

Read Full Case Study

Explore all Flevy Management Case Studies

Related Questions

Here are our additional questions you may be interested in.

How does COBIT address the challenges of cloud computing and data sovereignty?
COBIT offers a comprehensive framework for managing IT governance and data sovereignty challenges in cloud computing, ensuring legal compliance, security, and strategic alignment with business objectives. [Read full explanation]
How does COBIT support sustainability and environmental responsibility in IT operations?
Leverage COBIT for Strategic Alignment in IT with sustainability goals, enhancing Performance Management, Risk Management, and Innovation for environmental responsibility. [Read full explanation]
What are the common pitfalls in implementing COBIT, and how can they be avoided?
To successfully implement COBIT, organizations must align IT governance with Business Objectives, effectively manage Organizational Culture and Change, and secure necessary Expertise and Resources, avoiding common pitfalls for enhanced governance and Operational Excellence. [Read full explanation]
How does COBIT's framework assist in managing IT-related risks in financial institutions?
COBIT framework supports financial institutions in managing IT-related risks by aligning IT strategy with business objectives, optimizing IT investment performance, and ensuring regulatory compliance, thus maintaining operational excellence. [Read full explanation]
What are the best practices for implementing RACI charts in COBIT governance frameworks?
Implementing RACI charts in COBIT frameworks involves strategic planning, stakeholder engagement, clear communication, and continuous improvement to align IT processes with business objectives, ensuring accountability and operational efficiency. [Read full explanation]
How is COBIT evolving to address the challenges of AI and machine learning in IT governance?
COBIT 2019 evolves to address AI and ML in IT governance by introducing flexibility, focusing on Data Governance, AI Ethics, Risk Management, and enhancing Performance Management, ensuring organizations can navigate the complexities and opportunities of AI and ML. [Read full explanation]

Source: Executive Q&A: COBIT Questions, Flevy Management Insights, 2024


Flevy is the world's largest knowledge base of best practices.


Leverage the Experience of Experts.

Find documents of the same caliber as those used by top-tier consulting firms, like McKinsey, BCG, Bain, Deloitte, Accenture.

Download Immediately and Use.

Our PowerPoint presentations, Excel workbooks, and Word documents are completely customizable, including rebrandable.

Save Time, Effort, and Money.

Save yourself and your employees countless hours. Use that time to work on more value-added and fulfilling activities.




Read Customer Testimonials



ls/testimonial_dharris.jpg); background-size:100%;'> 

"FlevyPro provides business frameworks from many of the global giants in management consulting that allow you to provide best in class solutions for your clients."

– David Harris, Managing Director at Futures Strategy



Download our FREE Strategy & Transformation Framework Templates

Download our free compilation of 50+ Strategy & Transformation slides and templates. Frameworks include McKinsey 7-S Strategy Model, Balanced Scorecard, Disruptive Innovation, BCG Experience Curve, and many more.