At its most basic definition, IT governance is the process by which decisions are made around IT
investments. How decisions are made, who makes the decisions, who is held accountable, and how
the results of decisions are measured and monitored are all parts of IT governance. Based on this
definition, everyone has some form of IT governance. Unfortunately for many firms, the governance
process is ad hoc and informal. There is no consistency across the enterprise, accountability is weak
— if present at all — and there are no formal mechanisms to measure and monitor the outcomes of
the decisions.