Compliance
August 25, 2026

7 IT Governance Frameworks Explained (with Examples)

Nicole Wood
Senior Content Strategist
In this Article

Every technology decision your organization makes carries a cost, risk, and an assumption about who's accountable when it goes wrong. IT governance makes those three things clear and deliberate, so they're decided on purpose.

The pressure to formalize IT governance keeps rising. Much of that pressure is due to artificial intelligence, which introduces a new category of spend, risk of cybersecurity incidents, and emerging regulations. AI aside, organizations face a growing list of overlapping regulations like GDPR, HIPAA, and SOC 2. Not having a governance framework in place can lead to potential board-level consequences should you encounter a cybersecurity incident or become non-compliant.

In the early 1990s, IT governance frameworks began to emerge. Over time, new ones were added to address different needs like managing IT services and audit control, and eventually SaaS. This guide covers the major frameworks, classifies each one accurately, and examines where they fall short in a modern SaaS and AI environment.

What Is an IT Governance Framework?

An IT governance framework is a set of policies, controls, processes, and accountability models that align technology decisions with business objectives. It defines who holds decision rights, how risk gets evaluated, how resources are allocated, and how performance is measured. COBIT, ITIL, TOGAF, ISO/IEC 38500, and the NIST Cybersecurity Framework are the most widely adopted examples.

The word "framework" is key. A framework offers structure rather than strict rules: a shared vocabulary, a defensible decision-making process, and evidence you can show to auditors and boards that technology investments are being actively directed.

A working framework connects five things: 

  1. Policies that state intent 
  2. Controls that enforce it
  3. Processes that operationalize it
  4. Accountability that names owners
  5. Strategic alignment tying all of it to business objectives

Without each of those elements, governance becomes more difficult to follow, especially as it becomes more decentralized.

Why IT Governance Matters

Done well, IT governance manages risk, reduces spend, and keeps you compliant with regulatory and oversight requirements. Done poorly or not at all, technology drains budget long before it becomes a security or compliance liability.

Increasing Waste

IT governance helps keep financial waste in check. According to Zylo's 2026 SaaS Management Index, the average organization spends $55.7M on SaaS annually while using just 54% of its licenses. The unused licenses translate to $19.8M in  waste annually. The waste persists simply because no one owns the decision to stop paying for unused seats.

Security Exposure

Security exposure can increase without proper governance. Even with visibility, the research found 46% of applications carry a Poor or Low Cloud Confidence Index rating, and organizations have secured only 21% of applications behind single sign-on. Together, those figures describe a portfolio where nearly half of all apps entered without a security review and the vast majority sit outside centralized access control, leaving IT unable to see or govern where sensitive data actually lives.

Budget Predictability

Budget predictability is the third pressure. Zylo's survey of IT leaders found 79% encountered price increases at renewal in the past 12 months, 77% hit unexpected costs after a contract was signed, and 61% cut projects because of unplanned SaaS cost increases. When surprise costs are this widespread, SaaS spend becomes harder for Finance to forecast and starts actively displacing planned work. At that point, unmanaged spend becomes a governance problem rather than just a budgeting one.

The 6 Key Pillars of IT Governance

Six pillars help you maintain every functioning governance program, whichever framework you adopt:

  1. Strategic alignment
  2. Risk management
  3. Resource optimization
  4. Performance measurement
  5. Compliance and auditability
  6. Accountability and ownership

Strategic Alignment

Technology investments trace back to stated business objectives. In practice, it's being able to answer "why are we funding this?" for every material line in the budget.

Risk Management

Risk management addresses technology risk before it becomes an incident response. Mature programs keep a risk register with named owners and scored tolerance thresholds, not a list of concerns.

Resource Optimization

Resource optimization covers people, budget, infrastructure, and software entitlements. It answers whether you're paying for capacity you use, and whether you can prove it.

Performance Measurement

You can't govern what you don't measure. Ticket volume tells you how busy the service desk is. Cost per active user and license utilization tell you whether spend produces value.

Compliance and Auditability

HIPAA, GDPR, SOC 2, and PCI DSS all require demonstrable controls, not stated intentions. Auditability means your system of record answers an auditor's question without a three-week scramble.

Accountability and Ownership

Every application, contract, and risk needs a named owner. This pillar fails more than any other, because ownership is easy to assign and hard to sustain as people change roles.

IT Governance vs IT Management

Governance decides what should happen and who's accountable. Management executes it. Combining the two stalls governance programs, because executives get pulled into operational detail while nobody sets direction.

Governance Management
Strategic Operational
Executive and board ownership IT team ownership
Policy-focused Execution-focused
Evaluate, direct, monitor Plan, build, run
Sets decision rights and risk appetite Works within defined decision rights
Asks "are we doing the right things?" Asks "are we doing things right?"

This distinction between IT governance and IT management is also how you classify the frameworks below. Several of the best-known frameworks sit further toward management than their reputation suggests.

The Top IT Governance Frameworks Explained

Not everything on this list is a governance framework, and treating them as interchangeable produces bad architecture decisions. Seven dominate the conversation, and each solves a different problem:

1. COBIT (Control Objectives for Information and Related Technologies)

Developed by ISACA, COBIT is a true governance framework and one of the few that explicitly separates governance from management. COBIT 2019 organizes 40 objectives across five domains, holding the governance domain (Evaluate, Direct and Monitor) distinct from four management domains.

  • Strengths: Comprehensive scope, strong audit alignment, and published crosswalks to the NIST Cybersecurity Framework.
  • Weaknesses: Full implementation is heavy, demanding sustained executive sponsorship. Design factors exist precisely so you can tailor it rather than adopt all 40 objectives.
  • Best for: Large enterprises, regulated industries, and organizations demonstrating governance maturity to a board.

2. ITIL (Information Technology Infrastructure Library)

ITIL is an IT service management framework, not a governance framework, that tells you how to run services well. Now owned by PeopleCert, it has moved past ITIL 4 to ITIL Version 5, which reorganizes around digital product and service management and makes responsible AI practice a core capability.

  • Strengths: The most operationally practical framework here, with mature, widely adopted guidance for running services day to day.
  • Weaknesses: It doesn't establish decision rights, board accountability, or investment governance, so it can't carry a governance program on its own.
  • Best for: Service-heavy IT functions and managed service providers.

3. TOGAF (The Open Group Architecture Framework)

Maintained by The Open Group, TOGAF governs enterprise architecture through the Architecture Development Method, an iterative cycle running from architecture vision through business, information systems, and technology architectures to implementation governance.

  • Strengths: The ADM works as a repeatable process, and TOGAF's governance chapters address compliance review in ways other frameworks skip.
  • Weaknesses: Narrow in scope, saying almost nothing about cost governance or spend accountability.
  • Best for: Complex integration environments and enterprises consolidating or migrating platforms.

4. ISO/IEC 38500

ISO/IEC 38500 is the international standard for corporate governance of IT and the only framework here written for directors rather than practitioners. Its third edition, published in 2024, replaced the 2015 version, elaborated the governance principles, aligned them with ISO 37000, and added stakeholder engagement. Six principles (responsibility, strategy, acquisition, performance, conformance, and human behavior) apply through an evaluate-direct-monitor cycle.

  • Strengths: Short, vendor-neutral, and compatible with COBIT, ITIL, and NIST.
  • Weaknesses: Non-prescriptive and not certifiable, so it sets direction without telling you how to implement controls.
  • Best for: Boards and executive committees carrying explicit accountability for technology outcomes.

5. NIST Cybersecurity Framework (National Institute of Standards and Technology) 

The NIST Cybersecurity Framework is increasingly used in governance contexts, and CSF 2.0 accelerated that shift by adding Govern as a sixth core function alongside Identify, Protect, Detect, Respond, and Recover.

  • Strengths: Free, sector-agnostic, and heavily mapped to other standards, with ISACA guidance for implementing it using COBIT.
  • Weaknesses: Covers security risk only, so it won't govern software spend or investment priorities.
  • Best for: Healthcare providers under HIPAA, critical infrastructure operators, and federal contractors.

6. CMMI (Capability Maturity Model Integration) 

Capability Maturity Model Integration, managed by ISACA through the CMMI Institute, is a process maturity model rather than a governance framework. It scores maturity across five levels, from initial and unpredictable through optimizing, giving you a defensible baseline and comparable appraisal results.

  • Strengths: Produces a defensible baseline and appraisal results that are comparable across organizations.
  • Weaknesses: It measures how consistently you execute processes, not whether those processes govern the right decisions, so it complements a governance framework rather than replacing one.
  • Best for: Process benchmarking, defense contractors, and demonstrating rigor to regulators.

7. FinOps Framework

The FinOps Framework from the FinOps Foundation governs technology spend as an operational discipline, organizing work into three phases (Inform, Optimize, Operate) supported by domains, capabilities, and a maturity model. Its governance relevance grew sharply with the 2026 update, which added Executive Strategy Alignment as a capability, expanded Technology Categories beyond public cloud to include SaaS and licensing, and addressed convergence with IT asset management.

  • Strengths: The only framework here built for variable, consumption-driven cost models.
  • Weaknesses: Focused on spend, so it doesn't address security, architecture, or service management on its own.
  • Best for: Cloud-native organizations and enterprises with material AI or consumption-based spend.

Comparing the Leading IT Governance Frameworks

Framework Primary Focus Governance vs. Management Best For Complexity Compliance Strength Ideal Company Size
COBIT Enterprise governance of IT Governance + management Regulated enterprises, board reporting High Very strong 1,000+ employees
ITIL IT service management Management Service-heavy IT functions Medium Moderate Any size
TOGAF Enterprise architecture Architecture governance Complex integration environments High Moderate 500+ employees
ISO/IEC 38500 Corporate governance of IT Governance only Boards and executive committees Low Strong (non-certifiable) Any size
NIST CSF Cybersecurity risk Risk governance + management Regulated and critical infrastructure Medium Very strong Any size
CMMI Process maturity Neither (maturity model) Process benchmarking, contractors Medium Moderate 250+ employees
FinOps Framework Technology cost governance Governance + management Consumption-based and AI spend Medium Low Any size

Where Traditional IT Governance Frameworks Fall Short in a SaaS and AI World

Every framework shares an assumption that stopped being true a decade ago: that IT controls the technology estate.

According to Zylo's 2026 SaaS Management Index, IT is responsible for just 15% of software spend and 13% of applications. Meanwhile, lines of business and employees are responsible for the remaining 85% of spend and 87% of applications. A governance model routing decisions through central IT governs a shrinking minority of the estate.

Traditional frameworks fall short in four specific ways once software and AI spend leave central IT's control:

SaaS Sprawl and Shadow IT

Legacy frameworks assume centralized procurement with a defined intake process. Today, any employee with a corporate card can add an application in five minutes, and the transaction surfaces weeks later on an expense report, if at all. On average, 45% of applications are purchased through expense channels entirely outside procurement, which is how shadow IT takes hold. 

That unsanctioned buying is what drives the sprawl. Organizations add nearly nine applications every month, or 103 a year, and those steady additions compound into 34% annual portfolio growth. At that rate, shadow IT accounts for close to half the portfolio, well beyond anything a policy can treat as an occasional outlier.

Because that spend never passes through a central intake, the frameworks have no way to see it in the first place. None of them provide a discovery mechanism. They tell you to maintain an accurate asset inventory and leave the question of how entirely open.

Decentralized Software Ownership

Governance frameworks assume someone owns each application and answers for it. That assumption breaks when purchasing authority spreads across dozens of business units: ownership scatters along with the spending, and no framework tells you how to put it back together.

The result is a predictable gap between policy and practice: the policy exists, and nobody making purchasing decisions has read it. 

For example, marketing signs a two-year contract without a security review, and Finance discovers the renewal three days before it auto-renews. 

Zylo's data shows the average organization handles 211 renewals annually, close to one per business day, while only 38% of surveyed IT leaders treat renewals as a meaningful cost reduction opportunity. Each unowned renewal is a decision no one is accountable for, made by default rather than design.

AI Consumption Governance

No legacy framework addresses token-based pricing, usage-based AI billing, or autonomous agents incurring cost without a human initiating each transaction. They were written for software you license by the seat, where cost is fixed the moment you sign, so they have no concept of spend that climbs with every query.

That blind spot is expensive. Average spending on AI-native applications grew 108% in 2025, and nearly 400% for large enterprises (>10k employees), a majority of it consumption-based. Because that spend scales with usage instead of headcount, it climbs without anyone signing a new contract, which is exactly the trigger point traditional governance relies on to catch it.

Consumption models break the control assumptions frameworks rest on. A seat license has a known ceiling. Token consumption doesn't. Zylo's survey found 78% of IT leaders hit unexpected charges tied to consumption or AI features in the past year, and no volume of policy documentation prevents that. AI consumption cost management exists as a discipline for exactly this reason.

The Visibility and Execution Gap

The visibility and execution gap underlies every other shortfall in this section. Frameworks define policy, but they don't discover applications, monitor usage, detect anomalous spend, or enforce controls across a sprawling estate. Each one names a control it can't actually carry out.

  • COBIT tells you to maintain a configuration management database, but gives you no way to find the applications or keep it current. The inventory is only as good as the manual effort behind it.
  • ISO/IEC 38500 directs the board to monitor performance against strategy, but never says where the spend and usage data comes from. Directors monitor whatever happens to reach them.
  • ITIL governs the services already in the catalog, but stays silent on the ones employees adopt outside it.
  • TOGAF reviews the architecture teams submit, but software bought on a corporate card never reaches the review board.

At the scale of 305 applications changing by nine a month, policy on paper loses to automated enforcement every time.

Closing the gap requires a system of record that continuously discovers software and AI spend from financial data, SSO logs, and expense feeds, then connects it to ownership, usage, contracts, and renewals. That's the layer frameworks assume exists and never specify.

How IT Governance Frameworks Are Adapting to AI

The frameworks aren't standing still, though regulation is outrunning framework revision cycles. Four developments matter most: the NIST AI Risk Management Framework, the EU AI Act, AI consumption and spend governance, and the rise of shadow AI.

The NIST AI Risk Management Framework

The NIST AI Risk Management Framework is the closest thing to a consensus AI governance structure in the United States. The NIST AI Risk Management Framework is the closest thing to a consensus AI governance structure in the United States, and it has evolved quickly:

  • January 2023: AI RMF 1.0 released, organizing AI risk into four functions: Govern, Map, Measure, and Manage.
  • July 2024: NIST adds a Generative AI Profile.
  • April 2026: NIST releases a concept note for a profile covering trustworthy AI in critical infrastructure.
  • Ongoing: AI RMF 1.0 is currently being revised.

It layers cleanly onto traditional frameworks. Organizations running COBIT typically treat AI RMF as the AI-specific risk taxonomy feeding their existing risk register.

The EU AI Act

The EU AI Act is the first comprehensive AI regulation from a major regulator and applies to any organization placing AI systems on the EU market. It classifies systems by risk tier, with penalties for prohibited uses reaching €35M or 7% of global annual turnover.

Its compliance timeline has shifted repeatedly:

  • August 2025: General-purpose AI model obligations take effect.
  • 2 August 2026: Transparency obligations apply.
  • 2 December 2027: Under the Digital Omnibus proposed in November 2025, the latest applicability date for Annex III high-risk systems, tied to the availability of support tools.
  • 2 August 2028: Latest applicability date for high-risk systems under EU harmonized legislation.

The governance implication is direct: AI inventory is now a compliance requirement. You can't classify systems you haven't discovered.

AI Consumption and Spend Governance

AI spend is based on usage. Existing IT governance frameworks address seat-based software and don’t transfer to consumption-based apps or elements of a contract. Consumption of AI tokens can vary day to day and lack built in caps or alerts. In a single busy month, you can quickly blow past your budget—no signature required.

To govern AI spend, IT and Finance leaders need visibility at the workload level: understanding what’s being used, how much, and by whom, as well as cost consumption trends and anomalies.  

Visibility alone won’t solve uncontrolled AI spend, but it does enable IT and Finance to attribute costs proportionally across business units. Without these two pieces in place, it will be difficult to keep teams accountable to what they’re spending and measure AI’s impact on your business outcomes.

AI spend management as the overarching business practice is just beginning. Over time, it will mature to where organizations have a holistic view of their AI spend and can easily: 

  • Allocate costs to business units
  • Forecast with greater accuracy
  • Measure the impact of AI investments

At Zylo, we’ve already built the foundation for successful AI cost management and continue to innovate into this new era of financial spend management.

Shadow AI

Shadow AI, like shadow IT, results when teams or individual employees purchase AI tools outside of approved channels. The two main differences: AI tools bill by consumption rather than a fixed seat price, and they carry a larger data exposure surface. Shadow AI is becoming more common, with eight of the 50 most expensed applications being AI-native—according to Zylo’s 2026 SaaS Management Index.

The stakes are higher with shadow AI than they are with a conventional unsanctioned SaaS app. An unsanctioned project management tool creates redundant spend. An unsanctioned AI tool receiving proprietary data creates a disclosure event: sensitive company information leaves your control the moment an employee pastes it into a model you don't govern, potentially used to train it or exposed to others.

Frameworks written before generative AI have no vocabulary for this, which is why AI governance can't be appended to them. It needs discovery, classification, and enforcement built for tools employees adopt in minutes. 

How to Choose the Right IT Governance Framework

To select the right IT governance framework, start with the problem. Most organizations that struggle with governance picked a framework before articulating what they needed it to fix. Weigh these factors:

  • Organization size. COBIT's full scope suits enterprises with dedicated governance staff. Smaller organizations get further starting with ISO/IEC 38500 principles and NIST CSF controls.
  • Regulatory requirements. HIPAA, PCI DSS, and financial services regulation push toward NIST CSF and COBIT for their audit alignment.
  • Cloud and SaaS maturity. If most of your estate is SaaS, cost and vendor governance matter more than infrastructure architecture, favoring FinOps over TOGAF.
  • Cybersecurity posture. Acute security exposure argues for anchoring on NIST CSF 2.0 and layering governance on top.
  • Architecture complexity. Heavy integration or active migration justifies TOGAF's overhead. Simple environments don't.
  • Budget and resources. One framework adopted well beats three adopted badly.
  • SaaS estate size. Past a few hundred applications growing at double-digit rates, portfolio governance outgrows spreadsheets.
  • AI adoption. Where AI spend is material or growing fast, NIST AI RMF and cost governance capability move from optional to required.

IT Governance Framework Examples by Use Case

Organizations typically run multiple frameworks in tandem. The practical question is, “Which combination fits your risk profile and regulatory exposure?”

Use Case Recommended Frameworks
Healthcare provider under HIPAA NIST CSF (security controls) + COBIT (board governance) + ISO 27001 (certification)
Cloud-native scale-up TOGAF (architecture) + FinOps Framework (cost governance) + NIST AI RMF (AI risk)
Regulated financial enterprise COBIT + ISO/IEC 38500 (board accountability) + FAIR (risk quantification)
IT-service-heavy organization ITIL (service management) + COBIT (governance overlay)
Enterprise with heavy AI adoption NIST AI RMF + FinOps Framework + EU AI Act compliance mapping

Every pairing above follows the same logic: pick an operational anchor that addresses your sharpest risk, then add a governance layer giving that anchor direction and accountability. A healthcare provider needs demonstrable security controls, so NIST CSF anchors while COBIT shows regulators those controls are directed rather than incidental.

Common IT Governance Challenges (and How to Avoid Them)

Spotting the gaps in your governance program is only half the work; closing them is what prevents failure. Six challenges account for most of those failures: 

  • Weak executive buy-in
  • Overly complex controls
  • Unclear ownership
  • Governance without automation
  • Shadow IT and SaaS sprawl
  • Shadow AI and multi-cloud governance

Weak Executive Buy-In

When governance lacks a senior sponsor, its rules carry no authority and business units treat them as optional. Tie governance metrics to outcomes executives already own: budget variance, audit findings, and incident frequency. A sponsor who can enforce decisions across business unit boundaries is the difference between policy and paperwork. 

Overly Complex Controls

Controls that create more friction than the risk they address get bypassed, pushing spend into the shadows the controls were meant to govern. Calibrate control intensity to risk and spend thresholds, and give employees a sanctioned fast path for low-risk software. A 14-step approval workflow for a $200 subscription almost guarantees the purchase moves to an expense report. 

Unclear Ownership

An application without a named owner has no one to review its usage, question its renewal, or cancel it when it goes unused. Assign ownership at the application level, surface it in the system of record, and review it quarterly. Applications without named owners often do not get canceled or questioned at renewal. 

Governance Without Automation

Policies enforced by hand can't keep pace with a portfolio that changes weekly, so controls drift out of date faster than anyone can review them. Automate discovery, monitoring, and alerting so exceptions surface as they happen rather than during the next audit cycle. Quarterly manual reviews describe an environment that has already changed. 

Shadow IT and SaaS Sprawl

When employees buy software faster than IT can track it, the portfolio fills with unvetted, redundant, and unsecured applications. Blocking employee purchasing usually costs more in productivity than it saves. A freedom-within-a-framework approach sets clear parameters, provides an approved catalog, and uses continuous financial discovery to catch whatever enters anyway. 

Shadow AI and Multi-Cloud Governance

AI tools and multiple cloud providers scatter spend and data across environments no single team can see, multiplying both cost and exposure risk. Shadow AI and multi-cloud sprawl share one fix: a single system of record consolidating spend, usage, and ownership regardless of where a purchase originated or which provider billed it.

6 IT Governance Best Practices

The most effective governance programs share a set of operating habits. These six best practices separate governance that scales from governance that stalls:    

  1. Automate compliance monitoring. Continuous monitoring catches drift; periodic review documents it after the fact.
  2. Use policy-as-code where possible. Codified policy is enforceable and version-controlled.
  3. Establish KPIs that measure outcomes: license utilization, cost per active user, renewal cycle time, and share of spend with a named owner. Utilization at 54% and SSO coverage at 21% are the benchmarks to measure against.
  4. Continuously assess risk. Move from annual assessment to a model tied to the events that change your posture, including new application adoption.
  5. Create cross-functional governance teams. Bodies made up of IT alone govern only what IT can see.
  6. Extend governance to SaaS and AI spend. This is where most programs have the furthest to travel.

The Future of IT Governance

IT governance is shifting from a periodic, IT-owned checkpoint toward a continuous discipline that spans AI, cost, identity, and data across the whole organization. Six trends are shaping where it goes next: 

  • AI governance is the dominant emerging theme. Boards that reviewed cybersecurity quarterly now field questions on model risk and AI vendor concentration.
  • Multi-cloud governance continues to fragment visibility, since each provider reports differently and normalization falls to the customer.
  • Zero trust has moved into governance vocabulary, because identity is now the practical enforcement point across a decentralized estate.
  • Continuous compliance is replacing point-in-time audit. Regulators increasingly expect evidence that controls operated throughout the period, not just on the audit date.
  • FinOps governance is becoming a first-class discipline, and the 2026 Framework update's recognition of ITAM convergence formalizes what practitioners have done for two years.
  • ESG and data governance overlap keeps expanding, as sustainability reporting and data residency pull technology decisions into disclosure obligations.

IT Governance Frameworks Give You Structure, Execution Requires Visibility

IT governance frameworks assume an accurate inventory, a known owner for every asset, and enforcement happening somewhere outside their own scope. In an estate of 305 applications growing 34% a year, where IT controls just a fraction of the software portfolio, that assumption is where governance programs break.

Structure isn't the hard part anymore. Seeing your environment is. Executing governance across a sprawling SaaS and AI estate takes the visibility and automation frameworks don't provide, and closes that gap starts with knowing what you have.

For SaaS governance and visibility, Zylo for IT and SAM discovers and inventories the full software estate. 

For AI consumption governance, Zylo's AI cost management connects AI spend to usage and ownership. 

For cost governance across the portfolio, Zylo for FinOps brings software spend under the same discipline as cloud.

Frequently Asked Questions About IT Governance Frameworks

The main IT governance frameworks are COBIT, ISO/IEC 38500, ITIL, TOGAF, the NIST Cybersecurity Framework, CMMI, and the FinOps Framework. Only COBIT and ISO/IEC 38500 govern IT broadly; the rest focus on a single domain like service management, architecture, security, or spend.

COBIT governs, and ITIL manages. COBIT defines which technology decisions get made, who holds authority, and how risk is evaluated. ITIL defines how IT services are designed, delivered, and improved day-to-day. Many organizations run COBIT as the governance layer with ITIL operating beneath it.

ITIL is a management framework. Its strategy and transformation modules touch governance topics, and ITIL Version 5 added responsible AI practice, but it doesn't establish board accountability or investment governance.

COBIT is the most widely used framework built specifically for IT governance, particularly in regulated industries with formal audit requirements. ITIL has broader adoption overall but governs service management. NIST CSF leads for security-focused governance because it's free and sector-agnostic.

Traditional frameworks address AI only partially, which is why AI-specific frameworks emerged alongside them. The NIST AI Risk Management Framework supplies an AI risk taxonomy, the EU AI Act imposes binding obligations by risk tier, and the FinOps Framework's 2026 update covers consumption-based AI spend.

IT governance is strategic and executive-owned, setting direction, decision rights, and risk appetite. IT management is operational and IT-team-owned, executing within those parameters. ISO/IEC 38500 draws the line most explicitly through its evaluate-direct-monitor cycle.

Check Out These Related Resources

Blog
August 25, 2026

7 IT Governance Frameworks Explained (with Examples)

Read More
Read More
Blog
July 14, 2026

Zylo MCP Server: SaaS Intelligence, Everywhere You Work

Read More
Read More
Blog
July 7, 2026

AI Cost Management Is a Software Management Problem First

Read More
Read More
Podcast
August 27, 2025

Inside Hyatt's Plan for Continuous Software Audit Control

Read More
Read More
Podcast
July 17, 2025

From Chaos to Control: Applying FinOps Thinking to SaaS

Read More
Read More
Podcast
May 21, 2024

From Spreadsheets to Success: A Guide to High-Velocity SaaS Procurement with Brittney Linville

Read More
Read More
Webinar
July 28, 2026

ON DEMAND: Accelerating Measurable Business Outcomes with Zylo’s MCP

Read More
Read More
Reports
June 23, 2026

2026 Gartner® Magic Quadrant™ for SaaS Management Platforms

Read More
Read More
Reports
January 4, 2024

The IT Leader’s Guide to Software License Management

Read More
Read More
Reports
April 20, 2022

Evolving Your SaaS Governance Framework for the Digital Workplace

Read More
Read More
Sort by Date