Designing IT Governance for SME digital transformation based on COBIT 2019 SME focus area

Mega Ayu Natalia, Rahmat Mulyana, Ridha Hanafi

Abstract


As Industry 4.0 advances, organizations must embrace digital transformation (DT) to remain competitive. However, inadequate IT Governance (ITG) often leads to DT failures. While ambidextrous ITG models, combining traditional and agile approaches, have proven effective for large banks, their applicability to small and medium enterprises (SMEs) remains unexplored. This study aims to recommend prioritized ITG solutions for SMEs and estimate improvements in capability maturity levels to ensure successful DT. Employing Design Science Research (DSR) across five stages—problem identification, requirement specification, design, demonstration, and evaluation—data were collected through semi-structured interviews and document analysis. Using COBIT 2019’s SME focus area, the analysis identified three key Information Technology Governance and Management (ITGM) objectives: EDM03 (Ensured Risk Optimization), APO12 (Managed Risk), and MEA03 (Compliance with External Requirements), with an average capability maturity level of 3.38. Sixteen solutions, based on seven ITGM components, were developed and compiled into a roadmap to elevate the maturity level to 3.84. This research enriches COBIT 2019 literature, proposes a hybrid ITG framework for SMEs, and enhances web-based information systems, fostering operational efficiency, risk mitigation, regulatory compliance, and sustainable competitiveness for SMEs undergoing DT.

Keywords


Digital transformation ; Design science research; IT Governance; COBIT 2019; SME focus area

Full Text:

PDF

References


G. Khaerunnisa, R. Mulyana, and L. Abdurrahman, “Pengujian Pengaruh Tata Kelola TI Terhadap Transformasi Digital dan Kinerja Asuransi A Menggunakan Structural Equation Modeling,” J. Ilm. Penelit. dan Pembelajaran Inform., vol. 8, no. 2, pp. 381–392, Jun. 2023, doi: 10.29100/jipi.v8i2.3469.

C. Gong and V. Ribiere, “Developing a unified definition of digital transformation,” Technovation, vol. 102, Apr. 2021, Art. no. 102217, doi: 10.1016/j.technovation.2020.102217.

G. Vial, “Understanding digital transformation: A review and a research agenda,” J. Strateg. Inf. Syst., vol. 28, no. 2, pp. 118–144, Jun. 2019, doi: 10.1016/j.jsis.2019.01.003.

R. Mulyana, L. Rusu, and E. Perjons, “How Hybrid IT Governance Mechanisms Influence Digital Transformation and Organizational Performance in the Banking and Insurance Industry of Indonesia,” in Proc. 2023 Int. Conf. Inf. Syst. Dev., 2023.

R. Mulyana, L. Rusu, and E. Perjons, “IT Governance Mechanisms Influence on Digital Transformation: A Systematic Literature Review,” in Proc. AMCIS 2021, 2021.

I. Sebastian et al., “How Big Old Companies Navigate Digital Transformation,” MIS Q. Exec., vol. 16, no. 3, pp. 197–213, Sep. 2017.

Republic of Indonesia, “Undang-Undang Republik Indonesia Nomor 20 Tahun 2008 tentang Usaha Mikro, Kecil, dan Menengah,” 2008.

Republic of Indonesia, “Undang-Undang Republik Indonesia Nomor 10 Tahun 1998 tentang Perbankan,” 1998,

Republic of Indonesia, “Undang-Undang Republik Indonesia Nomor 4 Tahun 2023 tentang Pengembangan dan Penguatan Sektor Keuangan,” 2023.

BRIN and BKF, “Ekosistem Lembaga Pembiayaan Mikro,” 2022. [Online]. Available: https://fiskal.kemenkeu.go.id/files/berita-kajian/file/1674547577_laporan_akhir_ekosistem_lembaga_pembiayaan_mikro_27122022.pdf

S. De Haes and W. Van Grembergen, “IT Governance and Its Mechanisms,” 2004. [Online]. Available: https://blog.dinamika.ac.id/erwin/files/2013/02/jpdf041-ITGovernanceandIts.pdf

D. Utomo et al., “Leveraging COBIT 2019 to Implement IT Governance in SME Context: A Case Study of Higher Education in Campus A,” CommIT J., vol. 16, no. 2, pp. 129–141, Jun. 2022, doi: 10.21512/commit.v16i2.8172.

ISACA, COBIT® 2019 Framework: Introduction and Methodology, 2019. [Online]. Available: https://store.isaca.org/s/store#/store/browse/detail/a2S4w000004Ko9cEAC.

ISACA, COBIT for Small and Medium Enterprises, 2021. [Online]. Available: https://store.isaca.org/s/store#/store/browse/detail/a2S4w000004L2noEAC.

N. Obwegeser et al., “7 Key Principles to Govern Digital Initiatives,” 2020. [Online]. Available: https://mitsmr.com/2UWvNEs.

R. Mulyana, L. Rusu, and E. Perjons, “IT Governance Mechanisms that Influence Digital Transformation: A Delphi Study in Indonesian Banking and Insurance Industry,” in Proc. PACIS 2022, 2022.

R. Mulyana, L. Rusu, and E. Perjons, “Key Ambidextrous IT Governance Mechanisms for Successful Digital Transformation: A Case Study of Bank Rakyat Indonesia (BRI),” Digit. Bus., vol. 4, no. 2, Dec. 2024, Art. no. 100083, doi: 10.1016/j.digbus.2024.100083.

R. Mulyana, L. Rusu, and E. Perjons, “Key Ambidextrous IT Governance Mechanisms Influence on Digital Transformation and Organizational Performance in Indonesian Banking and Insurance,” in Proc. PACIS 2024, 2024.

F. Luthfia, R. Mulyana, and L. Ramadani, “Analisis Pengaruh Tata Kelola TI Terhadap Transformasi Digital dan Kinerja Bank B,” ZONAsi: J. Syst. Inf., vol. 4, no. 2, 2022.

T. Z. Nurafifah, R. Mulyana, and L. Abdurrahman, “Pengujian Model Pengaruh Tata Kelola TI Terhadap Transformasi Digital dan Kinerja Bank A,” J. Inf. Syst. Res. (JOSH), vol. 4, no. 1, pp. 73–82, Oct. 2022, doi: 10.47065/josh.v4i1.2257.

O. T. P. Poetry, “Perancangan Tata Kelola Teknologi Informasi untuk Digital di Industri Perbankan Menggunakan Framework COBIT 2019 dengan Domain, Deliver, Service, and Support: Studi Kasus Bank XYZ,” 2021. [Online]. Available: https://openlibrarypublications.telkomuniversity.ac.id/index.php/engineering/article/view/15776.

D. A. Permana, R. Fauzi, and R. Mulyana, “Perancangan Tata Kelola Teknologi Informasi untuk Transformasi Digital di Industri Perbankan Menggunakan Framework COBIT 2019 Domain Align, Plan, and Organise: Studi Kasus di Bank XYZ,” 2021.

Bq. D. Tarbiyatuzzahrah, R. Mulyana, and A. F. Santoso, “Penggunaan COBIT 2019 GMO dalam Menyusun Pengelolaan Layanan TI Prioritas pada Transformasi Digital BankCo,” J. Teknol. Inf. dan Multimedia (JTIM), vol. 5, no. 3, pp. 218–238, Oct. 2023, doi: 10.35746/jtim.v5i3.400.

N. Riznawati, R. Mulyana, and A. F. Santoso, “Pendayagunaan COBIT 2019 DevOps dalam Merancang Manajemen Pengembangan TI Agile pada Transformasi Digital BankCo,” SEIKO: J. Manag. Bus., vol. 6, no. 2, pp. 2023–223, 2023.

Y. W. Dwi, M. Dewi, R. Mulyana, and A. F. Santoso, “Penggunaan COBIT 2019 I&T Risk Management untuk Pengelolaan Risiko Transformasi Digital BankCo,” 2023.

A. Rahmadana, R. Mulyana, and A. F. Santoso, “Pemanfaatan COBIT 2019 Information Security dalam Merancang Manajemen Keamanan Informasi pada Transformasi BankCo,” 2023.

R. Santosa and D. Irawan, “Studi Risiko TI pada Sektor Keuangan,” Jurnal Sistem Informasi Bisnis, vol. 6, no. 2, 2021, hlm. 34–45, doi: 10.31933/jsib.v6i2.210.

P. I. Fusch and L. R. Ness, “Are We There Yet? Data Saturation in Qualitative Research,” Qual. Rep., vol. 20, no. 9, pp. 1408–1416, 2015. [Online]. Available: http://www.nova.edu/ssss/QR/QR20/9/fusch1.pdf.

A. K. Shenton, “Strategies for ensuring trustworthiness in qualitative research projects,” Educ. Inf., vol. 22, no. 2, pp. 63–75, 2004, doi: 10.3233/EFI-2004-22201.

Otoritas Jasa Keuangan, “POJK NOMOR 75/POJK.03/2016 Tentang Standar Penyelenggaraan Teknologi Informasi Bagi Bank Perkreditan Rakyat dan Bank Pembiayaan Rakyat Syariah,” 2016. [Online]. Available: https://ojk.go.id/id/kanal/perbankan/regulasi/peraturan-ojk/Pages/POJK-tentang-Standar-Penyelenggaraan-Teknologi-Informasi-bagi-Bank-Perkreditan-Rakyat-dan-Badan-Pembiayaan-Rakyat-Syariah.aspx

Otoritas Jasa Keuangan, “SEOJK NOMOR 15/SEOJK.03/2017 Tentang Standar Penyelenggaraan Teknologi Informasi Bagi Bank Perkreditan Rakyat dan Bank Pembiayaan Rakyat Syariah,” 2017. [Online]. Available: https://ojk.go.id/id/kanal/perbankan/regulasi/surat-edaran-ojk/Pages/Surat-Edaran-Otoritas-Jasa-Keuangan-Nomor-15-SEOJK.03-2017-.aspx

SFIA Foundation, “SFIA 8: The Framework Reference,” 2021. [Online]. Available: https://www.sfia-online.org

J. Song, A. Martens, and M. Vanhoucke, “Using Earned Value Management and Schedule Risk Analysis with resource constraints for project control,” Eur. J. Oper. Res., vol. 297, no. 2, pp. 451–466, 2022, doi: 10.1016/j.ejor.2021.05.036.

S. Tangprasert, “A Study of Information Technology Risk Management of Government and Business Organizations in Thailand using COSO-ERM based on the COBIT 5 Framework,” J. Appl. Sci. (Thailand), vol. 19, pp. 13–24, Jun. 2020, doi: 10.14416/j.appsci.2020.01.002.

S. Jagannathan and A. Sorini, “A Cybersecurity Risk Analysis Methodology for Medical Devices,” in Proc. 2015 IEEE Symp. Product Compliance Eng. (ISPCE), 2015, pp. 1–6, doi: 10.1109/ISPCE.2015.7138706.




DOI: http://dx.doi.org/10.62870/tjst.v21i1.28291

Refbacks

  • There are currently no refbacks.


Copyright (c) 2025 Teknika: Jurnal Sains dan Teknologi

Creative Commons License
This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.

Creative Commons License

Teknika: Jurnal Sains dan Teknologi is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.

 
 
 
 
 
 
 
 
 
 
 
 
 
 

mega888 android

mega888 ios

mega888 login

mega

pussy888

mega888

mega888

mega888 apk

mega888 ios

mega888 android

mega888 game

mega888 download

mega888 free credit

mega888 free test id

mega888 original

918kiss

pussy888

ntc33

joker123

xe88

ace333

mega888

mega888 download

mega888 ios

mega888 original

mega888 online casino

mega888 games

mega888

mega888

pussy888

918kiss

xe88

joker123

ntc33

mega888

918kiss

pussy888

joker123

xe88

ntc33

mega888

mega888 game

mega888 apk

mega888 apk

mega888

mega888

mega888 malaysia

mega888

mega888

mega888

mega888

mega888

mega888

mega888

pussy888

mega888 game

kiss918

kiss918

BRI303

BRI303

BRI303

BRI303

BRI303

BRI303

BRI303

BRI303

BRI303