Maturity assessment domain

Governance in ITSM maturity: who decides, under which rules, and how you prove it

Governance is what keeps a service management practice accountable when people change, budgets tighten and audits arrive. This domain checks whether decision rights, policies, risk controls and evidence are in place, and whether they actually operate.

Why it matters

Governance turns good practice into something that survives turnover

ISO/IEC 20000-1:2018 expects an organization to establish, implement, maintain and continually improve a service management system. Its requirements run from context and leadership through planning, support and operation to performance evaluation and improvement. Policies, responsibilities and reviews are part of the requirement, and governance is what makes them real.

AI is exposing governance gaps quickly. ISACA’s 2026 poll of more than 3,400 digital trust professionals found that 38% of organizations have a formal, comprehensive AI policy, up from 28% in 2025, while 30% have a limited policy and 25% have none. Over half (56%) do not know how long it would take to halt an AI system during a security incident, and 39% do not know whether they have a documented process for shutting down or overriding AI systems.

The same pattern shows up in ordinary ITSM governance: change controls that are heavy for everything or bypassed under pressure, supplier targets that never connect to business outcomes, and reports that show activity instead of impact. Governance maturity is the difference between having policies and having controls that operate and leave evidence.

AI policy coverage in organizations, 2026

Formal, comprehensive AI policy38%Limited AI policy30%No AI policy25%
Source: ISACA, 2026 AI Pulse Poll (more than 3,400 digital trust professionals). Remaining respondents gave other answers.
38%of organizations have a formal, comprehensive AI policy, up from 28% in 2025.ISACA, 2026 AI Pulse Poll, 3,400+ professionals
56%do not know how long it would take to halt an AI system during a security incident.ISACA, 2026
39%do not know whether a documented process exists to shut down or override AI systems.ISACA, 2026
What we assess

Eight things we look at in the governance domain

We test whether each control exists, whether someone owns it, and whether there is evidence that it operated, because those are the three questions an auditor asks.

  • Policies and standardsWritten, approved and current policies for service management, security, change and AI use.
  • Roles and decision rightsWho can approve what, who can override, and how escalation works when owners disagree.
  • Compliance and audit readinessRecords that show controls operated, retrievable without a scramble before an audit or renewal.
  • Risk managementHow service and change risks are identified, rated, owned and reviewed.
  • Change and release controlsA risk-based model that applies lighter control to low-risk change and stronger control where impact is high.
  • Performance reporting to the businessWhether reports describe business impact and feed decisions in a regular governance forum.
  • Supplier and contract governanceService levels, reviews and exit provisions for providers, tied to outcomes rather than volumes.
  • Continual improvement oversightWhether leadership reviews findings, funds improvements and checks that they were delivered.
What good looks like

Three points on the scale for governance

Every domain is scored on the same five levels. These are the anchor points we use most often when we talk with clients about where they are and where they should aim.

Level 1 · Ad Hoc

Decisions are made case by case. Policies are missing or unwritten, and audit readiness depends on individual effort.

Level 3 · Defined

Policies are documented, decision rights and a RACI are set, change is risk-based, and management reviews happen on a schedule with an audit trail.

Level 5 · Optimized

Governance spans service management, security and AI, with continuous control monitoring, board-level reporting and measured improvement outcomes.

Where organizations get stuck

Three patterns we see again and again

Field observation

Policies on paper, controls nowhere

Policies exist but no control, owner or evidence backs them. Audit readiness depends on a scramble by the same few people each time.

Field observation

Change control that is all or nothing

Every change gets the same heavy approval, so people bypass it under pressure. Or there is no risk-based model and everything is waved through.

Field observation

Reports that show activity, not impact

Supplier service levels and monthly reports describe volumes and response times, never the effect on the business, so governance forums have nothing to decide.

These are practitioner observations from assessment and implementation work, not survey findings. They are why governance is scored as its own domain and not assumed from the existence of a policy folder.

How it fits together

One domain of six, scored on the same 0 to 5 scale

Governance is scored from questions on policy, decision rights, risk, compliance evidence, change control, supplier oversight and reporting. It is the domain that tells you whether the other five will hold when people and priorities change. See how the numbers are produced on our scoring methodology page, or read the other domain guides.

Find out whether your governance would stand up to scrutiny.

No sales call required to get your first read, just the assessment.

Start free trial assessment

Sources. ISACA, AI Use Accelerates While Governance and ROI Lag (2026). ISO, ISO/IEC 20000-1:2018 (2018). Survey figures are reported as published by each source.