Video summary
IT governance is presented as a vital framework designed to help higher education institutions balance limited resources with strategic needs, moving beyond simple operational oversight to address value, cost, and risk. The core of this concept involves creating a structured environment where stakeholders can discuss what the organization can afford versus what provides the most benefit, ensuring that IT services align with institutional goals even when IT does not directly report to specific departments. By drawing parallels to financial governance, such as verifying accurate reporting and managing reserves, the video argues that IT governance establishes clear mental models for decision-making at various levels of an institution, from central administration down to individual libraries or cabinets.
In practice, effective IT governance shifts the role of the IT department from being perceived merely as a gatekeeper saying "no" to becoming a strategic partner engaged in negotiation and resource allocation. This is achieved through infrequent but high-impact meetings that focus on major decisions rather than daily operational details, allowing teams to prepare adequately without surprises. A key mechanism involves using scorecards or triage tools to evaluate new projects based on their potential value, cost implications, and associated risks, though human judgment remains essential for final approval. The process encourages distinguishing between mandatory maintenance tasks and strategic initiatives that drive future growth, ensuring that time and budget are directed toward activities that truly support the institution's mission rather than getting bogged down in "gold-plated" or unnecessary features on existing systems.
To function effectively, IT governance must be supported by robust supporting practices such as project portfolio management, financial tracking of actual service costs, and clear service level agreements. These complementary disciplines provide the necessary data for governance bodies to make informed decisions about whether a specific service is worth its cost or if certain support requests fall outside acceptable risk parameters. By defining ground rules through service levels, organizations can prevent staff from making subjective judgments that lead to burnout while ensuring resources are available for innovation and new initiatives. Ultimately, this holistic approach creates a virtuous cycle where better alignment between IT strategy and institutional outcomes leads to increased trust and resource availability, enabling the organization to tackle more ambitious projects in the future.
Read the full video transcript
Hello. My name is John Borwick from the
University of Washington and this
recording is about IT governance. CNI
has had a number of presentations and
workshops on IT governance in the last
few years, but there's not a lot of
resources available that make IT
governance accessible
or really relevant for higher education
and that's the purpose of this video. As
we need IT to do more and more while our
resources in higher education are
further constrained, IT governance is
one approach to help us balance what we
are able to afford with what is most
valuable.
So, the purpose of this recording is to
introduce some IT governance concepts to
help us ensure we have the same mental
models for thinking about what the term
IT governance means.
So, IT governance can create a space for
us to talk about resource constraints.
It can help us talk about what we need
in IT service even if IT doesn't report
to your organization. If you are using
IT services, IT governance
probably should still exist so you can
talk about the level of service you
need.
>> [sighs and gasps]
>> Also, there is a website
heitgovernance.com
where a few other people and I have been
linking to resources such as past CNI
presentations. So, please check that out
if you'd like to kind of sign up to
learn more about IT governance or IT
governance in libraries.
I am the director of IT services and
digital strategies for U Dub Libraries.
I have worked in or for higher ed for my
whole career
and I hold a number of IT management
related certificates such as the CGEIT,
which stands for certified in the
governance of enterprise IT.
My career goal is to make people's lives
easier through improved IT management.
So, as some caveats for this
presentation, I'm going to try to
provide a general overview that includes
my personal experience,
but this recording is not going to be
specific to libraries. Also, I'm not
going to talk about every possible IT
governance concept, and I will be
talking more about what IT governance is
than how to set it up.
So, in this video we'll see kind of what
does the term governance mean,
what is the core of IT governance in my
opinion,
why might you build IT governance,
what might governance look like in
practice,
what are some key types of IT governance
decisions, and what are some other
things that IT could do to make IT
governance more effective.
So, to begin,
what does the term governance mean and
like where have we seen that term?
So, in a for-profit organization, you
might have a CEO that reports to a board
of directors,
or in higher ed, we might have a
president or a chancellor that reports
to a board of regents or board of
trustees.
The purpose of these boards is to steer
the organization. That is a governance
function and the board doesn't get into
the details, but they are trying to make
sure that overall things are going okay.
The term governance is probably most
easy to connect with for financial
governance. If we think about financial
governance, you know, we're asking
questions like are the books in order?
Can we trust the numbers in a report?
And then moving from that kind of more
operational concern to more tactical or
strategic concerns, what financial
reserves might we need? What bond rating
do we need to have? What can the
institution afford?
So in higher ed, I am less familiar with
boards having like an IT specific
subcommittee, but this type of
governance can exist at several levels
in the organization. Within the
libraries, there could be an IT
governance structure. Central IT could
have an IT governance structure.
A cabinet might have an IT governance
structure. But when we use this term
governance, one way to check is to think
about how that term shows up for
financial governance.
There are some IT governance frameworks.
COBIT by ISACA is a framework kind of
built around IT governance nowadays.
There's also an ISO standard 38500.
And um it's very short.
Neither of these frameworks give you
sort of a basic intro in my opinion. So
that's one reason for this video.
So in my mind, and this is supported by
frameworks like COBIT, the essence of IT
governance is thinking about value,
cost, and risk. What value are we
getting from IT? How do we control IT
costs? And what are the risks related to
IT and how are those risks being
managed?
I like to think about this as a triangle
of value, cost, and risk.
And the key
items I'll highlight for this triangle
are the value component is owned by the
recipients of IT service. As much as an
IT practitioner might want to say that
this new technology is really valuable,
that's really determined by who's using
the technology.
In contrast, the cost of IT are best
known by the providers. So, the provider
comes to governance understanding the
costs, the recipients of IT come to
governance understanding the value.
And then risk is a two-way conversation
where some risks are owned by IT, some
risks are going to be owned by the
recipients, uh people using IT.
For example, there may be a non-IT
workaround when an IT tool is down
that allows the provider to invest less
in that IT tool.
Uh one challenge is that is that if IT
doesn't have a place to check on what is
acceptable risk, the default expectation
is perfection. So, IT governance creates
a place to talk about what are
reasonable risks.
As we think about IT governance, one
helpful concept is the level of review
can be proportional to the level of risk
and impact. So, a smaller decision
doesn't need to go to a governance
structure, but a big decision, a really
high-risk decision, those are tells that
they may need to go for additional
review.
So, why might you build IT governance?
As an IT director and in a couple of
different organizations, I've built out
IT governance partly because I don't
want to be perceived as the department
of no.
In my experience, IT always has more
demanded of it than we have ability to
kind of deliver. And IT governance
creates a way for the organization to
talk about what we can afford to do
right now.
So, IT governance creates a new kind of
framework for discussions rather than
just a director needing to say yes or no
to things.
IT governance also helps align IT to the
institution.
As IT undergirds more and more strategic
opportunities for the institution, we
want to ensure that the institution and
IT have kind of a way to talk and be
able to align on where we need to go.
IT may also have a lot of assumptions
about how IT services provisioned, and
IT governance is a place to check those
assumptions. Do we still need the
printing services?
For these two projects, which one is
more important to get done first?
Are there times when we might be willing
to spend a little extra money to free IT
up to be able to work on something more
strategic?
I also like to think about IT governance
as a negotiation
where I really like the definition of
negotiation from the book Getting to
Yes, where we are looking for options,
we're looking for potential new value or
opportunities rather than zero-sum
decision-making. And this could be
something like being willing to fund a
fancier disk system because it provides
a higher service level, or agreeing that
we'll be okay with less frequent backups
for a cheaper system.
So, in practice, here are some things
you might observe in an organization
that has IT governance.
I like to think about the meetings that
are being held for IT governance. In my
personal ideal world, these meetings are
infrequent, so that kind of forces them
to be a little bit more strategic rather
than operational.
The meetings are consultative, that is a
two-way discussion, not uh
informational. They are high impact, so
important things are being decided these
meetings. And ideally, these meetings
have no surprises. The people going to
the meetings get agendas ahead of time.
They get some context ahead of time. So,
people have a general sense of what
they're going to be asked to discuss.
That allows people to prepare so that
the meetings can be more effective.
Sometimes in IT governance structures,
you might see scorecards, notably for
new projects. Projects might get a
score, and again, in terms of value, in
terms of cost, in terms of risk. Um they
could say, "How big is this project? How
much is it going to cost now and in the
future? What kind of return are we going
to get? Like, how valuable is this thing
to us?"
These scorecards are useful for triage,
but I would caution against using the
scorecard as the decision. The scorecard
can kind of put requests into quadrants,
but then governance, like humans, need
to talk about like which things actually
need to move forward.
If you're kind of looking at
organizations practicing IT governance,
often they are thinking in terms of IT
resources and how to allocate them. A
lot of IT resources are just people's
time.
So, if you're particularly thinking
about kind of time here with this bar
representing all of our time.
I like to break that up into three
buckets. Existing stuff, kind of keeping
current things going. New stuff, so new
things that we haven't been able to do
before. And then the administrative
stuff. Administrative stuff is things
like maybe vacation, you know, team
meetings, other like training.
Each of these is very important. I don't
mean to minimize any of the three of
these. IT governance can really help in
thinking about really each of these. But
particularly IT governance often focuses
on the new stuff.
If we have a certain amount of time for
new stuff, maybe IT still makes the call
about some of that work. But IT
governance can start to make the call
about more of that new stuff. You know,
where should we be putting our time?
That in turn can create a virtuous cycle
where as IT is able to deliver on those
new things, IT governance starts to see
the value of their time. And that
results in often better alignment to the
institutional outcomes, which frequently
then means there's more IT resources
available.
So IT governance is about making
decisions. What are some key types of
decisions we might see in governance?
Often we'll see decisions about that new
stuff.
Frequently that new stuff is called
projects.
So project decisions could be around
what's getting funded, when is it being
scheduled to start and end. Projects can
have gate reviews. For example, a big
project might be approved to plan, might
be approved for a phase two, might be
then approved to close out at the end.
So IT governance often sees these
project decisions.
If you have a lot of mandatory projects,
it is sometimes a little off-putting to
see those same mandatory projects like
keep network running um on the list with
your really important strategic new
thing that's not technically mandatory.
So, if there are a lot of mandatory
projects, sometimes governance will call
those out into two lists. And the
mandatory work, you can kind of ask,
"What's the least we could do to
complete this?" Because mandatory
projects often end up having gold
plating where people kind of add more
and more to them. Like as long as we're
in here, let's go ahead and do this
other stuff. So, IT governance includes
the practice of reviewing where
resources [clears throat] are going to
kind of ask, like, "What's
the least that should happen without
really approval? And uh what can we then
create space for as far as kind of more
strategic new work?"
Another type of IT governance decision
can be around benefits realization.
Frankly, this is uncommon. It's very
powerful, but it requires organizations
to admit that sometimes the outcomes
don't match what was planned.
But a benefits realization check is when
we say, "Did we get the value we thought
we would get?"
If we justified the project um based on,
you know, a certain outcome, did we see
that outcome at the end? So, this is a
very powerful type of IT governance
decision
uh that makes sure the loop gets closed
for decision making.
There can also be a lot of very powerful
decisions in IT governance made around
existing stuff. Are services still
needed? What's an acceptable level of
service? What's an appropriate level of
spending
for an ex- for an example, you might
have a discussion about a service that
everyone had assumed was 24/7 and needs
kind of constant work to keep up and
running. But maybe that's too high a
level of service for the cost. Maybe
it's okay for that service to be down
outside of business hours as long as we
start working on it again when we're
back at work. That has a significant
effect on IT costs. So, there can be
really useful decisions around existing
stuff that can free up IT to then start
working on new things.
And then again, we can think about where
IT strategy is going and where the
institution's strategy is going and how
to kind of line those up. This could be
anything from seeing an IT strategic
plan uh or IT annual report to having a
discussion in IT governance around a
university strategic plan or the library
strategic plan
to try to kind of create opportunities
and space for discussion around how IT
can be supporting those outcomes.
So, IT governance can help an
institution better balance value, cost,
and risk.
IT governance can become more effective
if you have other IT management
practices in place.
So, for one, if you're thinking about
setting up IT governance or any other IT
management practice
I strongly would encourage you to
consider the plan-do-check-act cycle,
sometimes called the Deming cycle or
PDCA cycle, where we just want to find
one little problem that we can solve or
address through these frameworks.
Then, as we solve that problem, we may
be able to identify the next problem or
challenge. And through a series of
iterations, we can build an effective
process that solves your current
challenges.
For IT governance or for any other IT
management practice,
they should be solving problems that you
have, not creating a new problem for
you.
So, if you have IT governance, there are
other IT management practices that can
really provide sort of care and feeding,
if you will, for IT governance. One is
project and portfolio management. So,
this is understanding what projects you
have, what projects are coming, uh what
their scope is, what their costs are,
who's going to work on them. The better
you are at these practices, the more
specific questions that can be asked of
IT governance.
Another IT management practice is IT
financial management.
This practice can help you understand
the actual costs of your current
services, and then to you can have
discussions in IT governance about if
those services are worth the cost or how
to review the costs of those services.
Service level management is an important
IT service management practice, and
service level management can mean
different things to different people,
but at its core, it's helping you
understand what success looks like for
your current services. Notably, what do
we not do? If we get requests for people
who need help with their home wireless
network, cuz they're a remote employee,
is that something that we help with, or
is that something that we say, "No,
unfortunately, we can't help with."
Service levels
help sort of IT governance and IT
management ensure the people working in
IT have a great understanding of the
ground rules and they're not making
their own personal judgment calls and
then feeling badly if they're not able
to help someone. They're instead kind of
following the service level. Often
service levels will say, you know, and
it's fine to help people, but defining
service levels can help IT governance
then make uh more effective decisions
about where people should be spending
their time.
So, to review
the goal for this presentation was to
provide a hopefully more accessible
introduction to IT governance.
So, we talked about where the term
governance might be used, notably in
financial governance,
and how to kind of connect the ideas and
concepts from financial governance to IT
governance.
We talked about the essence of IT
governance being to balance value, cost,
and risk.
We talked about reasons to build IT
governance. For example, IT not wanting
to be the department of no or wanting to
have a way to check assumptions on IT
service or align where IT is going with
where the libraries or the overall
institution is going.
We talked about what IT governance might
look like in practice, for example,
through infrequent, consultative,
high-value meetings.
We talked about key types of decisions
like authorizing new projects or
reviewing current service levels.
We talked about other IT management
practices that can make IT governance
more effective, such as project and
portfolio management or service level
management.
So, I hope this is a useful introduction
to IT governance. If this is a topic
you're interested in, please check out
heitgovernance.com
linked to past CNI meetings and
recordings and will update for other CNI
meetings and events. But also please
look for me and others talking about IT
governance in the CNI space in the
future.
Thanks again.