Governance in ITSM maturity: who decides, under which rules, and how you prove it
Governance is what keeps a service management practice accountable when people change, budgets tighten and audits arrive. This domain checks whether decision rights, policies, risk controls and evidence are in place, and whether they actually operate.
Governance turns good practice into something that survives turnover
ISO/IEC 20000-1:2018 expects an organization to establish, implement, maintain and continually improve a service management system. Its requirements run from context and leadership through planning, support and operation to performance evaluation and improvement. Policies, responsibilities and reviews are part of the requirement, and governance is what makes them real.
AI is exposing governance gaps quickly. ISACA’s 2026 poll of more than 3,400 digital trust professionals found that 38% of organizations have a formal, comprehensive AI policy, up from 28% in 2025, while 30% have a limited policy and 25% have none. Over half (56%) do not know how long it would take to halt an AI system during a security incident, and 39% do not know whether they have a documented process for shutting down or overriding AI systems.
The same pattern shows up in ordinary ITSM governance: change controls that are heavy for everything or bypassed under pressure, supplier targets that never connect to business outcomes, and reports that show activity instead of impact. Governance maturity is the difference between having policies and having controls that operate and leave evidence.
AI policy coverage in organizations, 2026
Eight things we look at in the governance domain
We test whether each control exists, whether someone owns it, and whether there is evidence that it operated, because those are the three questions an auditor asks.
- Policies and standardsWritten, approved and current policies for service management, security, change and AI use.
- Roles and decision rightsWho can approve what, who can override, and how escalation works when owners disagree.
- Compliance and audit readinessRecords that show controls operated, retrievable without a scramble before an audit or renewal.
- Risk managementHow service and change risks are identified, rated, owned and reviewed.
- Change and release controlsA risk-based model that applies lighter control to low-risk change and stronger control where impact is high.
- Performance reporting to the businessWhether reports describe business impact and feed decisions in a regular governance forum.
- Supplier and contract governanceService levels, reviews and exit provisions for providers, tied to outcomes rather than volumes.
- Continual improvement oversightWhether leadership reviews findings, funds improvements and checks that they were delivered.
Three points on the scale for governance
Every domain is scored on the same five levels. These are the anchor points we use most often when we talk with clients about where they are and where they should aim.
Decisions are made case by case. Policies are missing or unwritten, and audit readiness depends on individual effort.
Policies are documented, decision rights and a RACI are set, change is risk-based, and management reviews happen on a schedule with an audit trail.
Governance spans service management, security and AI, with continuous control monitoring, board-level reporting and measured improvement outcomes.
Three patterns we see again and again
Policies on paper, controls nowhere
Policies exist but no control, owner or evidence backs them. Audit readiness depends on a scramble by the same few people each time.
Change control that is all or nothing
Every change gets the same heavy approval, so people bypass it under pressure. Or there is no risk-based model and everything is waved through.
Reports that show activity, not impact
Supplier service levels and monthly reports describe volumes and response times, never the effect on the business, so governance forums have nothing to decide.
These are practitioner observations from assessment and implementation work, not survey findings. They are why governance is scored as its own domain and not assumed from the existence of a policy folder.
One domain of six, scored on the same 0 to 5 scale
Governance is scored from questions on policy, decision rights, risk, compliance evidence, change control, supplier oversight and reporting. It is the domain that tells you whether the other five will hold when people and priorities change. See how the numbers are produced on our scoring methodology page, or read the other domain guides.
Find out whether your governance would stand up to scrutiny.
No sales call required to get your first read, just the assessment.
Start free trial assessmentSources. ISACA, AI Use Accelerates While Governance and ROI Lag (2026). ISO, ISO/IEC 20000-1:2018 (2018). Survey figures are reported as published by each source.
