
Consider a hypothetical situation. The board approves a strategy: grow sales, enter a new market and reduce customer service costs. Three months later, IT presents its work list: a server migration, an accounting system upgrade and thirty requests from the departments that pushed hardest. The strategy is missing, although nobody deliberately ignored it. Everyone did their part; nobody owned the translation from strategy to IT work.
This article explains how to organise that translation. Its reference points are research and established frameworks: COBIT 2019, ISO/IEC 38500 and ITIL 4 principles. Research dates matter: a finding from a decade ago is not a forecast for today's implementation. The ITIL 4 principles cited here remain useful, although PeopleCert now also offers ITIL (Version 5)[8].
The scale of the problem
Gartner's research published in October 2024, for the 2025 CIO Agenda, surveyed 3,186 CIOs and technology executives in 88 countries, supplemented by 1,126 executives outside IT. On average, 48% of digital initiatives meet or exceed their business outcome targets. For the group Gartner calls the “Digital Vanguard”, the figure is 71%[1].
What distinguishes that group? Gartner points to CIOs and business executives sharing responsibility for digital delivery. Those business executives dedicate 35% of their business-area staff to technology work, compared with 21% for other executives, and meet their CIOs four times as often[1]. This is an observed association, not proof that a new meeting schedule alone will raise success to 71%.
Older research shows that the problem is longstanding. McKinsey and the University of Oxford analysed more than 5,400 IT projects. Large projects, with initial budgets above USD 15 million, averaged 45% budget overruns, 7% schedule overruns and 56% less value than expected. The authors found that 17% of IT projects performed so badly that they could threaten the company's existence[2]. Published in 2012, the research concerns large programmes and should not be applied directly to an implementation in an 80-person business. It illustrates the risk of assuming value at the outset and never checking it again.
PMI's 2016 Pulse of the Profession estimated that organisations wasted USD 122 million for each USD 1 billion invested in projects because of poor project performance[3]. These historical figures support monitoring benefits; they are not a current loss estimate for every business.
How many digital initiatives achieve business outcomes?
Difference: 23 percentage points
Scale: 0–100%
Gartner · release dated 22 Oct 2024 · 2025 CIO Agenda · 3,186 CIOs and technology executives, plus 1,126 business executives. Digital Vanguard is part of the surveyed population; this descriptive comparison does not establish causation. Gartner [1]
Why goals do not translate themselves
Business goals and IT tasks use different language. The board says: “Reduce order fulfilment from five days to three.” IT hears: “Do something with the warehouse system.” Someone who understands both sides must identify the real bottleneck — perhaps manual entry of orders from three sales channels — and put it at the top of the work list.
The frameworks describe this missing step in different terms.
COBIT 2019 from ISACA uses a goals cascade: stakeholder needs inform enterprise goals, which inform alignment goals and then governance and management objectives. Its core model contains 40 governance and management objectives linked to processes and organisational goals[4]. Mapping helps identify what matters, but a commitment requires a board decision. The practical output should be a small set of priorities, not an entire relationship matrix. That is a practical interpretation of the model.
ISO/IEC 38500 addresses governance of IT for governing bodies in organisations of all sizes[6]. The 2024 edition replaced the 2015 edition, moving from six principles to eleven, aligned with ISO 37000, and adding stakeholder engagement to its model[7]. The governing body sets direction; operational management works within it.
ITIL 4 starts with “focus on value”: identify stakeholders and the outcomes they need. Its other principles are equally practical: start where you are, progress iteratively with feedback, keep things simple, and optimise before automating[8].
TOGAF from The Open Group and ISO/IEC 27001 add two perspectives. The TOGAF Architecture Development Method moves from an architecture vision to business architecture, followed by information systems and technology architecture[9]. ISO/IEC 27001 relates information security management to organisational context and risk[10]. These are general descriptions, not a complete account of their requirements.
A useful IT priority can therefore be traced back to a goal approved by the board and forward to a measurable result.
- 01Business goalExpected outcome
- 02Process constraintThe bottleneck
- 03Initiative and ownerDecision and accountability
- 04Measurable resultMeasurement and review
Author’s diagram: a board decision must reach the work plan, and its result must return for review.
Six steps from goal to priority
The following is the author's synthesis, not a requirement of any one standard. A small company can use a single page; a large organisation may need additional tools.
- Express the goal as an outcome. Replace “implement CRM” with “increase repeat purchasing from 30% to 40% within 18 months”. Those figures are illustrative.
- Identify what limits the result. It may be a process, data, skills or a system. Business and IT assess this together.
- Collect candidate initiatives. Each must identify the goal it supports. Requests without that link go through a separate channel for maintenance, compliance or minor changes.
- Use shared evaluation criteria. Start with contribution to the goal, risk including inaction, total cost and the organisation's capacity to deliver change. Check for an owner and a measurable outcome. This is a working set of criteria for a joint decision.
- Set capacity limits. A team cannot do everything at once. Ten simultaneous “priorities” usually mean no priority. Once capacity is full, a new item enters only when another leaves.
- Appoint a business owner and review quarterly. Shared accountability is consistent with Gartner's observation[1]. Quarterly reviews are a practical suggestion; higher-risk projects may need more frequent scrutiny.
What changes with company size
Scope matters. Eurostat surveys enterprises with at least ten employees and self-employed people. PARP reports that microenterprises accounted for 97.2% of Poland's active non-financial enterprises in 2024; small, medium and large firms accounted for 2.0%, 0.6% and 0.2%, respectively. There were 2.37 million active enterprises[11]. The following figures therefore exclude most Polish businesses.
Cloud and AI: company size matters
Small companies (10–49)
Medium companies (50–249)
Large companies (250+)
Scale: 0–100%
Eurostat · EU, 2025 · selected sectors · enterprises with at least ten people employed. Values rounded to one decimal place. Cloud and AI can be used by the same enterprise; percentages must not be added. Eurostat [12], [13]
| Company size (EU, 2025) | Paid cloud use | AI use |
|---|---|---|
| Small (10–49 people) | 49.3% | 17.0% |
| Medium (50–249) | 66.8% | 30.4% |
| Large (250+) | 84.7% | 55.0% |
Source: Eurostat[12][13]. Figures cover 2025, selected sectors and enterprises with at least ten people employed. Poland's AI adoption rate was 8.4%, the second lowest in the EU[13].
Among firms that considered AI but did not adopt it, the most commonly reported reasons were lack of relevant expertise (70.9%), unclear legal consequences (52.5%) and concerns about data protection (48.8%)[13]. Respondents could select more than one reason. These are knowledge, legal and risk barriers. My interpretation is that someone must define the intended outcome and conditions of use before choosing a tool; the data do not establish why expertise is missing.
Small companies, up to 49 people. A full framework may be excessive. A quarterly meeting between the owner or CEO and the person responsible for IT, often an external provider, can establish three annual goals and three to five supporting initiatives on one page. Ask whether the implementation can be operated without additional hires. Improving what is already in place can deliver more than another purchase, consistent with “start where you are”[8].
Medium companies, 50–249 people. Competing departmental requests become a real issue. Use a simple initiative register, shared criteria and regular steering meetings involving finance, operations, sales and IT. IT should present options and costs, not merely execute orders.
Large organisations, 250 or more people. An initiative portfolio, a project or transformation office and multiple layers of goals become useful. The COBIT goals cascade, ISO/IEC 38500 governance and enterprise architecture can support this. The risk is bureaucracy without ownership. McKinsey highlights strategy and stakeholder management, teams with aligned incentives and short delivery cycles in large projects[2].
When regulation sets a priority
Some priorities originate outside a growth strategy. Poland's amendment to the National Cybersecurity System Act, implementing NIS2, entered into force on 3 April 2026. The Ministry of Digital Affairs states that entities meeting the criteria at commencement and not registered automatically had until 3 October 2026 to apply for entry in the KSC register. Entities meeting the criteria at commencement have until 3 April 2027 to implement the new obligations. The first mandatory audit for the specified essential entities is due by 3 April 2028[14]. This reflects the position on 6 October 2026; the obligations do not apply to every company.
IT planning must include compliance in the same initiative register. A legal deadline limits freedom of choice: the board must provide resources and agree the sequence of work. The first step is to establish whether the rules apply to the organisation.
Questions for the next board meeting
- Which three business goals matter most this year, and how will we measure achievement?
- Which IT initiative supports which goal? Can we explain the connection for every item?
- Who in the business owns each initiative's outcome, beyond responsibility for delivery?
- How much IT capacity goes to maintenance and how much to change? Is that allocation deliberate?
- What will leave the plan when a new priority enters?
Start with one page
Gartner's findings support shared accountability between business and IT. Frameworks provide language and structure, but the board must decide which goals matter and who owns them. One page recording this year's three goals is a workable starting point.
← All posts