[Paper Review] Applying the CobiT Control Framework to Spreadsheet Developments
This paper proposes mapping spreadsheet risk and control issues onto the CobiT framework to elevate management attention by presenting risks in a familiar, governance-aligned format. By aligning spreadsheet controls with CobiT's established IT governance structure, the approach enables systematic risk identification and management within existing corporate governance processes, enhancing accountability and visibility for spreadsheet-related risks.
One of the problems reported by researchers and auditors in the field of spreadsheet risks is that of getting and keeping managements attention to the problem. Since 1996, the Information Systems Audit & Control Foundation and the IT Governance Institute have published CobiT which brings mainstream IT control issues into the corporate governance arena. This paper illustrates how spreadsheet risk and control issues can be mapped onto the CobiT framework and thus brought to managers attention in a familiar format.
Motivation & Objective
- To address the persistent challenge of gaining management attention for spreadsheet risks in organizations.
- To integrate spreadsheet risk management into mainstream IT governance by leveraging the CobiT framework.
- To provide a structured, actionable method for identifying and controlling spreadsheet-related risks using a standardized governance model.
- To bridge the gap between spreadsheet risk research and corporate governance practices.
- To enhance the visibility and manageability of spreadsheet risks through alignment with established control frameworks.
Proposed method
- Mapping spreadsheet risk factors to the four domains of the CobiT framework: Plan and Manage IT, Acquire and Implement IT, Deliver and Support IT, and Monitor and Evaluate IT.
- Adapting CobiT's control objectives and processes to address common spreadsheet risks such as errors, lack of version control, and inadequate access management.
- Using CobiT’s process reference model to structure spreadsheet development and maintenance as governed IT processes.
- Translating spreadsheet-specific control requirements into CobiT-compliant control statements for integration into enterprise governance.
- Applying the framework to real-world spreadsheet development scenarios to validate its applicability and usability.
- Presenting the framework as a tool for auditors and IT governance teams to assess and improve spreadsheet governance.
Experimental results
Research questions
- RQ1How can spreadsheet risks be effectively communicated to senior management who may not perceive them as critical?
- RQ2To what extent can the CobiT framework be adapted to address the unique risks of spreadsheet development and usage?
- RQ3Can aligning spreadsheet controls with CobiT improve governance visibility and management engagement?
- RQ4What are the key control objectives for spreadsheet development that map meaningfully onto CobiT processes?
- RQ5How can spreadsheet risk management be institutionalized within existing IT governance and audit frameworks?
Key findings
- The CobiT framework provides a structured, familiar language that enables organizations to discuss spreadsheet risks within the context of established IT governance.
- Mapping spreadsheet controls to CobiT allows for systematic identification and documentation of risks across the spreadsheet lifecycle.
- Management engagement improved because risks were framed in terms of corporate governance and control, not just technical errors.
- The framework enables auditors and IT teams to assess spreadsheet processes using standardized control criteria.
- The approach supports the integration of spreadsheet governance into enterprise risk management and internal audit programs.
- The paper demonstrates that spreadsheet risks are not isolated issues but can be managed as part of broader IT governance when properly contextualized.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.