IT governance and project portfolio management (PPM) are how organisations ensure their IT investments create measurable value while staying within risk appetite, budget, and compliance requirements. In South African university contexts—especially in modules like Unisa MNG0001 (Project Management) and related IT governance / IT service management curricula—candidates are often expected to connect frameworks like COBIT (governance and control) and ITIL (service management best practice) to practical portfolio decisions. This study guide explains key governance concepts, portfolio lifecycle approaches, and how ITIL/COBIT thinking fits together, with exam-style examples and scenarios aligned to common South African coursework patterns.
IT Governance Foundations for IT Project Portfolio Management (Unisa MNG0001 Style)
IT governance is the set of structures and processes that ensures IT supports business objectives, uses resources responsibly, manages risk, and complies with regulations. For exam purposes, think of IT governance as the “decision rights + accountability + control” layer that enables portfolio management. Without governance, portfolio management becomes a collection of unrelated projects competing for funding rather than a coherent investment strategy.
What IT Governance Actually Includes (Not Just “Management”)
A useful way to define IT governance is to split it into four pillars:
-
Strategic direction
Who decides which IT outcomes matter most? How is the target operating model reflected in IT initiatives? -
Risk management and control
How are risks assessed and treated? What controls ensure acceptable risk levels and compliance? -
Resource and performance accountability
Who is responsible for budgets, outcomes, and benefits realisation? -
Transparency and oversight
How do boards, executives, and audit committees monitor progress and ensure controls are effective?
In frameworks terms, COBIT is designed to provide governance and management objectives with measurable practices. ITIL is designed to improve service delivery outcomes. For portfolio management, you need both:
- COBIT gives governance/control scaffolding.
- ITIL gives guidance for delivering and managing services that portfolio investments aim to improve.
Stakeholders and Decision Rights (Who Approves What)
A core exam competency is recognising that governance is about decision rights. Typical stakeholders include:
- Board / executive committee: sets risk appetite and strategic direction.
- IT leadership: turns strategy into plans, policies, architecture, and delivery capacity.
- Business owners: define business outcomes and benefits.
- Project / programme management office (PMO): coordinates governance processes, portfolio reporting, and stage gates.
- Risk and compliance: ensures regulatory alignment and control effectiveness.
- Audit / assurance: checks whether governance and controls work in practice.
A practical portfolio governance model often uses stage gates:
- Idea/benefit validation gate
- Business case approval gate
- Delivery planning gate
- Review/benefits realisation gate
Each gate has decision-makers and required evidence (e.g., risk assessment, budget estimate, assurance plan, architecture compliance).
Linking IT Governance to Portfolio Management
Portfolio management is the coordinated management of projects and programmes to achieve strategic objectives. Governance provides the “how decisions are made,” while portfolio management provides the “what investments we fund and manage.”
Consider this simplified chain:
- Strategy (business goals)
- Portfolio themes (e.g., “customer experience,” “risk reduction,” “operational efficiency”)
- Investment categories (run/maintain, change, growth)
- Projects and programmes (specific initiatives)
- Delivery and assurance (implementation controls)
- Benefits realisation (outcome tracking)
- Feedback loop (learn and adjust portfolio)
In exam answers, you should be able to describe how governance influences portfolio decisions:
- Governance sets investment approval criteria.
- Governance sets risk appetite and requires risk treatment plans.
- Governance defines capacity constraints and prioritisation rules.
- Governance demands performance reporting and corrective actions.
COBIT in Governance Terms (Exam-friendly Overview)
COBIT (commonly taught in governance/controls courses) can be understood as a framework to ensure that enterprise IT processes achieve desired outcomes using governance and management objectives.
When applied to portfolio management, COBIT helps you answer:
- Which processes ensure that the enterprise has clear direction for IT?
- Which processes ensure that IT risk is assessed and managed?
- Which processes ensure that resources are used effectively?
- Which processes ensure that performance is monitored?
In many exam scenarios, candidates are expected to match “portfolio governance” activities to “COBIT governance outcomes,” such as:
- Ensure value delivery and strategic alignment
- Ensure risk optimisation
- Ensure resource optimisation
- Ensure transparency and accountability
ITIL in Service Delivery Terms (Exam-friendly Overview)
ITIL is centered on service management. For portfolio management, ITIL matters because IT investment usually aims to improve or create services: incident resolution, problem management, release management, service request fulfilment, and so on.
When applied to portfolio decisions, ITIL influences:
- How service outcomes are defined (service catalogue, SLAs, service levels)
- How operational readiness is ensured (transition planning)
- How change and releases are managed safely
- How service improvements are measured after go-live
An important exam point: portfolio management does not end at “project completion.” It extends to service outcomes and ongoing management. ITIL provides the operational mechanisms to deliver those outcomes.
Exam-Style Example: Governance Failure Leads to Portfolio Instability
Scenario: A financial services company in South Africa approves multiple digital initiatives without a consistent risk and architecture review process. After go-live, customers report intermittent payment failures and service desk volume spikes. The PMO notices that several projects implemented overlapping solutions (e.g., two different identity components), and operational teams were not fully prepared.
Governance symptoms:
- Approvals were granted without consistent architecture and risk evidence.
- Risk appetite was unclear.
- Benefits were measured only at build milestones, not at operational outcomes.
Portfolio management impact:
- Rework and emergency fixes consume delivery capacity.
- Future approvals face credibility issues.
- Compliance risk increases because controls are inconsistent.
In exam answers, you should show that IT governance would have enforced:
- decision rights and required evidence per stage gate
- risk assessments with clear treatment
- architecture compliance checks
- benefits realisation metrics tied to service performance (ITIL)
Project Portfolio Management Processes (How to Build a Portfolio That Delivers Value)
Project portfolio management (PPM) aims to select, prioritise, manage, and evaluate a set of investments (projects/programmes) to achieve strategic objectives. The “portfolio” is not just a list; it is a dynamic system that balances value, cost, risk, and capacity.
Portfolio Lifecycle: From Intake to Benefits Realisation
A common PPM lifecycle includes the following stages:
-
Portfolio intake and demand management
- Collect proposals (“ideas”)
- Capture business cases and high-level requirements
- Ensure proposals are submitted in consistent templates
-
Categorisation and alignment
- Map initiatives to business objectives and portfolio themes
- Classify into run/maintain, change, growth (and sometimes regulatory/mandatory)
-
Scoring, prioritisation, and selection
- Evaluate value potential vs cost and risk
- Use scoring models and ranking mechanisms
- Apply capacity constraints and dependencies
-
Resource allocation and scheduling
- Allocate capacity (people, vendors, budgets)
- Plan sequencing to reduce dependency conflicts
- Use programme increments where appropriate
-
Execution oversight
- Monitor progress using KPIs/KRIs
- Run portfolio reviews (weekly/monthly)
- Control scope, schedule, and budget changes
-
Benefits realisation and post-implementation review
- Verify outcomes against business case targets
- Assess whether operational metrics meet expectations
- Capture lessons learned and update governance rules
-
Portfolio optimisation
- Terminate underperforming initiatives early
- Re-baseline or restructure initiatives if assumptions fail
- Re-prioritise the pipeline based on new information
A key exam insight: stage gates are not only for entry—they can also be used for continuation, re-planning, or termination.
Demand Management and Intake Controls
Demand management is about ensuring that portfolio proposals are complete and comparable. If intake is messy, prioritisation becomes subjective.
A strong intake approach includes:
- Standardised submission form fields (business outcome, sponsor, cost estimate range, timeline, risks, dependencies)
- Minimum evidence requirements (e.g., cost-benefit assumptions, compliance need)
- Ownership assignment (named sponsor and accountable business owner)
Example proposal fields (typical):
- Business objective mapping
- Expected benefits (financial and non-financial)
- Implementation approach (build/buy/partner)
- Expected service impact (availability, performance, risk)
- High-level architecture considerations
- Delivery dependencies (e.g., data readiness, integration)
- Risk rating and mitigation plan
Scoring Models: Value vs Risk vs Cost
Portfolio selection often uses a multi-criteria decision model. A simplified scoring model might be:
- Value (0–5): strategic alignment, expected benefits, customer/employee impact
- Risk (0–5): likelihood and impact of failure, compliance risk, technology risk
- Cost (0–5): total cost of ownership (TCO), implementation effort
- Effort/Time to value (0–5): ability to deliver early outcomes
- Dependencies (0–5): ease of integration and readiness factors
Then you compute a weighted score, such as:
- Value: 40%
- Risk: 25% (often treated as inverse score—higher risk means lower score)
- Cost: 20%
- Time-to-value: 15%
Exam caution: Always explain what your “risk score direction” means. If the model treats higher numbers as “better,” then risk must be inverted (e.g., high risk becomes low risk score).
Capacity Constraints: The Hidden Driver of Prioritisation
Two portfolios can have identical scoring but different feasibility based on capacity. Capacity might include:
- specialist skills (e.g., cloud security engineers)
- vendor availability
- business subject-matter expert time
- infrastructure constraints (data platforms, integration bandwidth)
In South African exam cases, a common theme is limited skills and budget. A portfolio model must therefore include:
- resource calendars and availability windows
- critical path constraints for key dependencies
- rules for “must-have” projects (regulatory, safety, mandatory)
Dependencies and Portfolio Sequencing
Portfolio management must handle dependencies to avoid wasted effort. Examples of dependencies:
- Data migration requires a stable data model before application releases
- Identity integrations require agreed authentication and authorisation rules
- Legacy system changes must precede new channel enablement
A portfolio sequencing approach may use:
- release trains
- programme increments
- dependency mapping matrices
- cross-project integration milestones
Selection Methods: Ranking vs Budget Allocation vs Balanced Portfolio
Common selection approaches include:
-
Ranking
- Sort projects by score and fund until the budget runs out.
- Risk: creates imbalance (e.g., too many large projects at once).
-
Budget allocation
- Allocate budget per portfolio theme (e.g., 30% customer, 40% risk, 30% efficiency).
- Then select within themes.
-
Balanced portfolio
- Set targets for balance across:
- risk levels (avoid only high-risk “bets”)
- time horizons (short-term fixes + long-term platforms)
- investment types (run/maintain vs change vs growth)
- Set targets for balance across:
A well-structured exam answer usually argues for balanced portfolio thinking: it reduces the chance that the portfolio fails due to concentration of risk.
ITIL Integration: Service Outcomes as Portfolio Delivery Criteria
ITIL contributes by ensuring that portfolio decisions account for service impact. Two important integration points:
-
Change and release readiness
Projects introducing changes must consider ITIL practices such as release planning, approvals, and change risk assessments. -
Service metrics and operating model alignment
Benefits realisation should include operational KPIs/SLAs:- incident volume and mean time to restore (MTTR)
- service availability
- change success rate
- customer satisfaction (where applicable)
A portfolio that selects projects based solely on financial targets may still fail if it ignores operational feasibility. ITIL closes that gap.
COBIT Integration: Control Requirements for Portfolio Assurance
COBIT supports portfolio oversight by requiring assurance across governance and management objectives. In portfolio terms, that often means:
- ensuring decision-making processes are repeatable and auditable
- ensuring risk assessments are documented
- ensuring performance and governance reporting are defined
- ensuring resource optimisation practices exist
In an exam scenario, you can describe “portfolio assurance evidence” such as:
- business case approval record
- risk register and risk treatment plan
- architecture review sign-off
- compliance impact assessment
- benefits tracking plan and measurement method
- release/transition plan that aligns with ITIL
Governance of Portfolio Execution: Stage Gates, KPIs, and ITIL/COBIT Controls
Once projects enter the portfolio, governance must ensure they remain aligned and under control. Execution governance covers monitoring, decision escalation, and control of change—especially where new information appears.
Stage-Gate Governance: Entry, Continuation, and Termination
Stage gates function as quality and control checkpoints. A typical structure:
-
Gate 0: Idea validation
- Identify the business problem/opportunity
- Confirm sponsor and expected benefits category
- Perform preliminary risk screening
-
Gate 1: Business case
- Validate benefits assumptions (including measurement method)
- Provide cost estimate range and resource plan
- Assess compliance/architecture fit
- Provide high-level risk analysis and mitigation options
-
Gate 2: Planning approval
- Confirm delivery approach and governance model for the initiative
- Define milestones, quality plan, and assurance approach
- Create a benefits realisation plan and operating model change plan
-
Gate 3: Delivery review
- Confirm progress versus plan
- Review risks, issues, and change requests
- Validate scope stability and dependency readiness
-
Gate 4: Go-live and benefits readiness
- Ensure transition plans are in place (ITIL)
- Confirm training, documentation, and support readiness
- Verify that KPIs used for benefits are measurable post go-live
-
Gate 5: Post-implementation review
- Validate benefits against targets and assumptions
- Capture lessons learned and update portfolio rules
Exam strength: State why each gate matters. For example, Gate 2 prevents “planning without control,” while Gate 4 reduces operational failure risks.
KPIs and KRIs for Portfolio Health
Portfolio governance uses performance indicators (KPIs) and risk indicators (KRIs). A robust portfolio dashboard usually includes:
Performance KPIs (examples):
- % milestones achieved on time (by project and by portfolio)
- burn-up / burn-down alignment (schedule trend)
- defect density or release quality metrics (where relevant)
- benefits realisation progress (benefit achieved vs planned)
- service outcome KPIs after major releases (availability, MTTR)
Risk KRIs (examples):
- top 10 risks count and trend (increasing/decreasing)
- risk exposure score over time
- audit findings count related to initiative controls
- change failure rate (if tracked)
- vendor SLA breaches count
The critical exam point is linking KPIs and KRIs:
- If risk indicators worsen, portfolio governance should trigger mitigation actions.
- If performance KPIs lag, governance should check whether risks and assumptions changed.
Benefits Realisation: Measuring Value, Not Just Outputs
A common student mistake in exam answers is confusing “delivery outputs” with “business outcomes.” Outputs include:
- system built
- integrations completed
- user training delivered
Outcomes/benefits include:
- reduced processing time
- improved conversion rate
- reduced fraud losses
- improved availability and reduced operational cost
A benefits realisation plan should define:
- benefit owner (accountable business role)
- baseline measurement method
- target value and target date (or target interval)
- data sources and reporting frequency
- assumptions and dependencies
- change control triggers if assumptions fail
Counter-Argument: “Too Much Governance Slows Delivery”
A frequent exam question is whether governance always helps. A balanced answer includes the counter-argument: governance can slow delivery if it becomes bureaucratic.
Counter-argument points:
- excessive approvals
- unclear decision rights
- stage gates that require too much documentation without adding insight
- audit/compliance controls that are not risk-based
Rebuttal with governance maturity:
- governance should be risk-based: low-risk projects use lighter evidence requirements.
- stage gates should be evidence-driven not document-driven.
- decision rights should be clear (fast escalation).
- use templates and automation for consistent reporting.
This is where COBIT thinking matters: COBIT encourages governance and management goals with practices that can be tailored to risk and context. ITIL contributes by ensuring operational change controls are appropriate for service risk, rather than blanket slowing.
Portfolio Reviews and Escalation Paths
Governance requires regular review meetings at multiple levels:
-
Project-level governance (weekly/biweekly):
- delivery status, risks, issues, change requests
-
Programme-level governance (if programmes exist):
- coordination across projects, shared dependencies, integration readiness
-
Portfolio governance board (monthly/quarterly):
- strategic alignment checks
- reprioritisation decisions
- funding and termination decisions
- cross-portfolio risk aggregation
Escalation paths must be defined:
- what thresholds trigger escalation (e.g., schedule slip > X weeks, risk score increased beyond threshold, cost overrun beyond budget tolerance)
- who approves changes (sponsor vs steering committee vs board)
ITIL and Operational Readiness as a Portfolio Gate
A portfolio decision to release a technology change has operational risk. ITIL practices relevant to this transition phase include:
-
Change enablement / change management
- ensure change risk assessed
- ensure approvals align with change type and risk
-
Release management
- plan, build, test, deploy, and coordinate releases
-
Service validation and testing
- confirm service functionality meets required outcomes
-
Knowledge management
- ensure support teams can handle incidents and user questions
In an exam scenario, if a project “delivers on schedule” but service desk volumes rise dramatically and incidents spike, governance should question whether the portfolio gate at go-live considered ITIL operational readiness sufficiently.
COBIT Process Assurance: Evidence and Auditability
In governance exams, you should often mention “audit evidence.” COBIT supports the idea that governance is not just a set of intentions but needs evidence:
- approval records
- risk assessments and mitigation actions
- performance reporting logs
- control testing evidence
- assurance reports and remediation closure
A strong exam answer would say: portfolio governance must be demonstrable—meaning it can be audited and reviewed. That reduces governance risk and improves accountability.
Case-Based Portfolio Governance: Applying ITIL/COBIT in South African Contexts (Unisa, CUT, CUT-style Practical Scenarios)
This section provides integrated, case-based exam scenarios that apply governance and portfolio management concepts with ITIL and COBIT alignment. These scenarios are written in a style consistent with how many South African university modules (e.g., Unisa project management and IT governance modules, as well as applied IT management topics at universities like CUT) often test knowledge: identification of governance gaps, selection/priority justification, and recommended controls.
Case 1: Digital Citizen Services Programme (Portfolio Selection and ITIL Readiness)
Context: A provincial government department (we’ll call it “Province Alpha”) needs to improve citizen service delivery. The department proposes four initiatives for the upcoming portfolio year:
- Initiative A: Online application portal redesign (growth/customer experience)
- Initiative B: Identity verification integration improvements (risk/compliance)
- Initiative C: Legacy case management system stabilisation (run/maintain)
- Initiative D: Analytics dashboard for workflow performance (efficiency/control)
Governance question (exam style): Which initiatives should be prioritised, and what governance evidence is required before selection?
Step-by-step portfolio approach
-
Categorise initiatives
- A and D: change/growth themes
- B: compliance/risk theme
- C: run/maintain and operational stability
-
Score value, risk, cost, time-to-value
- A: medium risk (integration with existing systems), high value
- B: high risk (identity and compliance), but potentially mandatory
- C: lower risk, moderate value (stabilisation benefit)
- D: medium risk, moderate-to-high value (decision support)
-
Check capacity constraints
- Province Alpha has limited integration specialists available for only one major identity integration effort at a time.
-
Stage gate evidence requirements
- Gate 1 business case evidence: benefits measurement method (e.g., portal completion rates for A; compliance incident reduction metrics for B; incident and backlog metrics for C; cycle time reduction and reporting accuracy for D)
- Architecture review: ensure portal redesign does not duplicate identity components.
- ITIL operational readiness evidence: for D, ensure support and monitoring are included; for A and B, ensure release/transition plans include knowledge updates and change approvals.
Recommended portfolio choice (illustrative rationale)
A balanced portfolio would typically:
- Fund B early if it is compliance-critical and required to reduce risk exposure.
- Fund C to stabilise operations because service instability will undermine citizen experience improvements.
- Sequence A after integration assumptions are stable.
- Include D in parallel where data readiness is available and service impact is limited.
ITIL and COBIT alignment
- ITIL: ensures release and change management protects service continuity and ensures support teams can handle new workflows.
- COBIT: ensures that portfolio selection and approvals include audit evidence of governance (risk assessment, compliance alignment, and accountability).
Exam-ready conclusion: Prioritisation is not only about “highest scores.” It must include compliance/risk urgency, operational readiness, and capacity constraints—with evidence required at each gate.
Case 2: Retail Banking IT Portfolio and Risk Appetite (Risk Optimisation)
Context: A retail bank (“Bank Beta”) has a portfolio with:
- 6 projects improving customer digital onboarding
- 2 projects aimed at reducing fraud
- 1 infrastructure platform upgrade
Bank Beta’s risk appetite allows limited operational change risk without enhanced controls. Yet governance decisions have been inconsistent: some projects were approved quickly, while others were delayed for documentation.
Governance problem (exam style): Identify governance failures and propose corrective actions using COBIT/ITIL concepts.
Diagnosing failures
-
Inconsistent decision rights
- Some approvals were delegated informally without consistent evidence.
-
Weak risk optimisation
- Risks related to identity, fraud rules, and customer authentication were not consistently tied to risk appetite thresholds.
-
Benefits measurement confusion
- Teams reported “go-live achieved” rather than fraud reduction and onboarding completion improvements.
-
Operational readiness gaps
- Change management did not always account for service risk and support readiness, causing incident spikes after releases.
Corrective actions
-
Define risk-based stage gate requirements
- High-risk identity/fraud changes require stronger evidence:
- compliance impact analysis
- control mapping
- test strategy evidence
- change approval and rollback plan (ITIL-style thinking)
- High-risk identity/fraud changes require stronger evidence:
-
Implement portfolio risk aggregation
- Combine risk exposure across related initiatives to prevent “risk concentration.”
- Establish KRI thresholds (e.g., risk score trend worsening triggers steering committee review).
-
Benefits realisation plan standardisation
- Fraud reduction benefits: define baseline (current fraud rate) and target outcome.
- Onboarding improvements: define baseline completion rate and time-to-onboard targets.
- Link metrics to accountable business owners.
-
Strengthen auditability (COBIT evidence mindset)
- Maintain approval records, risk register history, and control test closure evidence.
Counter-argument handling:
If Bank Beta complains that more governance slows delivery, the response is that governance should be risk-based and evidence-driven, not purely document-heavy. This typically reduces rework and emergency fixes, which overall improves time-to-value.
Case 3: University IT Services Portfolio (Service Management as the Portfolio Outcome)
Context: A university IT department (“Uni Gamma”) manages:
- student portal support
- learning management integration
- identity and access management (IAM)
- infrastructure monitoring and incident response
Uni Gamma receives multiple improvement proposals:
- Proposal 1: new portal features
- Proposal 2: improve incident management and service desk knowledge base
- Proposal 3: identity system refactor
Exam question: explain how ITIL should influence portfolio selection and execution.
Why ITIL affects “selection,” not only “execution”
Some proposals look like enhancements (portal features) but can increase service complexity and incident rates. ITIL provides a structured view of service outcomes and operational impacts.
Portfolio governance should therefore:
- evaluate how each proposal affects service KPIs (availability, MTTR, change success rate)
- require transition readiness for service changes
- ensure knowledge management updates to reduce incident recurrence
Execution oversight using ITIL practices
- For Proposal 1: require change risk assessment, release management plan, and user training.
- For Proposal 2: treat it as an operational improvement with measurable service desk KPIs (e.g., reduced repeat incidents).
- For Proposal 3: require strong validation testing and rollback capability, plus coordination with change management approvals.
COBIT governance overlay
COBIT supports governance by requiring:
- accountability for performance and risk outcomes
- transparent reporting and traceable approval decisions
- alignment with enterprise IT goals
Exam conclusion: ITIL ensures portfolio investments translate into stable and measurable service outcomes, while COBIT ensures governance and controls remain auditable and accountable.
Exam-Focused Framework Mapping: COBIT Governance Goals and ITIL Practices in Portfolio Decisions
To score highly in governance/portfolio questions, it’s not enough to define terms—you must map them to actions and decisions. This section provides a structured mapping that helps you write clear exam answers.
Mapping COBIT Governance Themes to Portfolio Activities
COBIT can be used as a lens for portfolio governance. Key governance themes you can refer to in exam writing include:
- Strategic alignment
- portfolio initiatives must map to business objectives
- Value delivery
- ensure benefits realisation planning and measurement exists
- Risk management
- portfolio decisions consider risk appetite and risk aggregation
- Resource management
- capacity and resource optimisation are explicit constraints
- Performance measurement and monitoring
- portfolio dashboards track outcomes, not only outputs
- Transparency and accountability
- maintain evidence and decision records
In portfolio management, you can phrase each governance activity like this:
- Intake selection → strategic alignment + value delivery
- Stage gate approval → accountability + evidence
- Portfolio reviews → performance monitoring + risk management
- Reprioritisation/termination → value delivery + risk optimisation
- Benefits realisation → value measurement + governance oversight
Mapping ITIL Service Management Concepts to Portfolio Execution
ITIL is most relevant once initiatives affect services. Portfolio governance should ensure that:
- service level expectations are defined and agreed
- change and release processes exist to manage service risk
- incident/problem processes support operational improvements
- knowledge management reduces recurring incidents
- service validation/testing ensures readiness
A practical mapping:
-
Proposal A (new feature)
ITIL: change/release/knowledge updates; service validation; monitoring after go-live. -
Proposal B (stabilisation)
ITIL: problem management to reduce repeat incidents; service continuity thinking. -
Proposal C (operational capability)
ITIL: incident management process improvements; KPI tracking.
Integrating COBIT and ITIL in a Single Portfolio Argument
A strong exam answer often uses a “two-layer model”:
-
COBIT layer (governance/control)
- ensures proper decision-making, accountability, risk evidence, and auditability.
-
ITIL layer (service delivery)
- ensures that the initiative is delivered and transitioned in a way that supports service performance.
If an exam question asks: “How do ITIL and COBIT support project portfolio management?” a high-scoring response should mention:
- COBIT improves portfolio selection and governance control by enforcing decision rights and evidence.
- ITIL ensures that the selected projects deliver the required service outcomes and that operations are prepared.
Example Exam Question and Model Answer Outline (Unisa Exam Style)
Potential exam prompt:
“Explain how IT governance and project portfolio management can be improved using COBIT and ITIL. Include stage gates, risk management, and benefits realisation.”
Model outline (what to include):
- Define IT governance and PPM and their relationship.
- Explain stage gates (Gate 1 business case, Gate 2 planning, Gate 4 go-live readiness, Gate 5 post review).
- Describe how COBIT supports auditability, accountability, risk and performance monitoring.
- Describe how ITIL supports operational readiness and measurable service outcomes.
- Explain benefits realisation: baseline, targets, measurement, benefits owner.
- Provide a short example scenario (e.g., identity integration or portal redesign).
- Conclude with how risk-based governance reduces rework and improves time-to-value.
This structure mirrors typical South African university marking approaches: definitions + process description + framework mapping + example + conclusion.
Common Exam Pitfalls, Terminology to Remember, and How to Answer Portfolio Governance Questions
To perform well in exams, you need both knowledge and exam technique. This section highlights common pitfalls and gives ready-to-use answer patterns.
Pitfalls That Lower Marks
-
Confusing project management with portfolio management
- Project management executes; portfolio management selects and balances investments.
-
Focusing on outputs only
- Build and go-live are outputs. Benefits are outcomes.
-
Skipping governance evidence
- Examiners often expect mention of decision rights, documentation, risk registers, and assurance.
-
Ignoring capacity and dependencies
- A theoretically best portfolio may not be feasible due to resource constraints.
-
Treating ITIL as “only operations”
- ITIL influences selection and readiness because portfolio outcomes are service outcomes.
-
Using framework buzzwords without linking to actions
- Say what you do differently because of COBIT/ITIL.
Terminology Checklist (Fast Recall)
Use these terms consistently in answers:
- Portfolio intake / demand management
- Business case
- Stage gate
- Strategic alignment
- Value delivery
- Risk appetite
- Risk register
- Capacity constraints
- Dependencies
- Benefits realisation
- KPI / KRI
- Operational readiness
- Change and release management
- Audit evidence / accountability
Answer Patterns That Commonly Earn Marks
Pattern A: “Define → Process → Framework → Example → Conclusion”
- Define the term (governance, PPM, ITIL, COBIT)
- Describe the process steps (intake, scoring, stage gates, monitoring)
- Link to frameworks (COBIT governance/control, ITIL service delivery)
- Provide one coherent example
- Conclude by summarising how governance and PPM together create value under risk
Pattern B: “Compare and Contrast”
When asked to compare:
- COBIT: governance/control and assurance
- ITIL: service management practices for delivery and improvement
Then explain complementarity:
- COBIT ensures decisions and controls are sound
- ITIL ensures operational service outcomes are achieved
Pattern C: “Risk-based governance argument”
When asked whether governance slows delivery:
- acknowledge risk of bureaucracy
- rebut with evidence-driven, risk-based gates
- show that it reduces rework and operational failures
A Mini “Flash Scenario” for Exam Use
If your exam asks for an example, you can adapt these scenario frames:
-
Scenario frame 1 (identity integration):
High compliance risk, requires stronger stage gate evidence and ITIL transition readiness. -
Scenario frame 2 (portal redesign):
Customer-facing value, but requires release management, service validation, and monitoring. -
Scenario frame 3 (operational improvement):
Improves incident and problem outcomes; benefits realisation measured via MTTR and repeat incident rate.
Just ensure you keep one consistent scenario narrative across your answer.
Conclusion: Building IT Governance That Enables Portfolio Value (ITIL + COBIT in Practice)
IT governance and project portfolio management are inseparable for organisations that want IT investment to translate into measurable outcomes. Governance ensures decision quality, risk appetite alignment, accountability, and audit evidence. Portfolio management converts governance intent into a structured process for selecting, prioritising, sequencing, and monitoring initiatives—while remaining aware of capacity and dependencies.
COBIT provides the governance/control perspective: it supports transparent decision rights, risk optimisation, and performance monitoring. ITIL provides the service delivery perspective: it ensures that portfolio investments are transitioned into operations in a controlled way, so benefits are realised as service outcomes—not merely as technical outputs. When combined effectively, COBIT and ITIL help organisations deliver a balanced portfolio that can adapt to new information, reduce operational risk, and demonstrate value to stakeholders across the enterprise.
In South African university exam contexts—especially in project management and IT governance-related modules such as Unisa MNG0001 and adjacent applied IT management assessments—high marks typically require more than definitions. They require process understanding (intake, stage gates, review, benefits realisation), evidence mindset (risk register, approvals, accountability), and framework mapping (COBIT for governance/control; ITIL for service outcomes and operational readiness). This study guide is structured to support exactly that kind of exam performance: clear, consistent, and grounded in practical decision-making.
