Home / Current Issue / Paper 1722619
IT Governance Frameworks (COBIT/ITIL) and Their Impact on Regulatory Compliance in Nigerian Insurance Firms
Subject area: Science,Engineering and Technology · Area of research: IT Governance Frameworks
DOI: https://doi.org/10.64388/IREV2I5-1722619
Abstract
This review examines how structured information technology governance and service-management practices can strengthen regulatory compliance, operational resilience, and digital accountability within Nigerian insurance firms. Its purpose is to evaluate the complementary roles of COBIT and ITIL, assess their relevance to technology-related regulatory obligations, and identify implementation conditions capable of improving governance maturity across the sector. A structured narrative review method was adopted, drawing on peer-reviewed scholarship, recognised governance frameworks, and relevant regulatory and professional literature published up to 2018. The analysis synthesised evidence on governance structures, internal controls, service management, cybersecurity, risk oversight, auditability, digital transformation, and compliance monitoring. The findings show that COBIT provides a robust architecture for strategic alignment, control ownership, risk optimisation, performance evaluation, and assurance, while ITIL strengthens operational reliability through incident, change, availability, continuity, and service-level management. Their integration offers a coherent governance-to-operations model through which regulatory expectations can be translated into measurable and auditable technology practices. However, implementation effectiveness is constrained by uneven governance maturity, legacy systems, skills shortages, infrastructure limitations, fragmented accountability, cybersecurity exposure, and the cost of sustained process improvement. The review concludes that successful adoption requires contextual tailoring rather than mechanical framework implementation. It recommends phased, risk-based COBIT–ITIL integration, stronger board and executive oversight, clearer control ownership, enhanced cybersecurity capability, continuous service-performance monitoring, and closer alignment between technology governance, internal audit, enterprise risk management, and regulatory reporting. Future research should empirically test how governance maturity influences compliance outcomes, service reliability, audit findings, operational performance, and regulatory costs within Nigerian insurance firms. Such evidence can support proportionate regulation and sustainable sector-wide digital resilience.
Keywords
COBIT; ITIL; IT governance; regulatory compliance; Nigerian insurance; digital governance.
References
[1] Abu-Musa, A.A. (2009) ‘Exploring the importance and implementation of COBIT processes in Saudi organizations: An empirical study’, Information Management & Computer Security, 17(2), pp. 73–95. https://doi.org/10.1108/09685220910963974. (Emerald Publishing)
[2] Adegbite, E. (2012) ‘Corporate governance regulation in Nigeria’, Corporate Governance: The International Journal of Business in Society, 12(2), pp. 257–276. https://doi.org/10.1108/14720701211214124. (Northumbria University Research Portal)
[3] Adesemowo, A.K., Von Solms, R. and Botha, R.A. (2016) ‘Safeguarding information as an asset: Do we need a redefinition in the knowledge economy and beyond?’, South African Journal of Information Management, 18(1), a706. https://doi.org/10.4102/sajim.v18i1.706.
[4] Aduloju, S.A. (2014) ‘Information technology managerial capabilities and customer service performance among insurance firms in Nigeria’, SAGE Open, 4(4), article 2158244014561198. https://doi.org/10.1177/2158244014561198. (Sage Journals)
[5] Ahmad, N. and Shamsudin, Z.M. (2013) ‘Systematic approach to successful implementation of ITIL’, Procedia Computer Science, 17, pp. 237–244. https://doi.org/10.1016/j.procs.2013.05.032.
[6] Ajayi, B.A. and Hussin, H. (2018) ‘Conceptualizing information technology governance model for higher education: An absorptive capacity approach’, Bulletin of Electrical Engineering and Informatics, 7(1), pp. 117–124. https://doi.org/10.11591/eei.v7i1.898.
[7] Alhassan, A.L. and Biekpe, N. (2016) ‘Insurance market development and economic growth: Exploring causality in 8 selected African countries’, International Journal of Social Economics, 43(3), pp. 321–339. https://doi.org/10.1108/IJSE-09-2014-0182. (Emerald Publishing)
[8] Ali, S. and Green, P. (2012) ‘Effective information technology (IT) governance mechanisms: An IT outsourcing perspective’, Information Systems Frontiers, 14(2), pp. 179–193. https://doi.org/10.1007/s10796-009-9183-y.
[9] Alreemy, Z., Chang, V., Walters, R. and Wills, G. (2016) ‘Critical success factors (CSFs) for information technology governance (ITG)’, International Journal of Information Management, 36(6), pp. 907–916. https://doi.org/10.1016/j.ijinfomgt.2016.05.017.
[10] Angima, C.B. and Mwangi, M. (2017) ‘Effects of underwriting and claims management on performance of property and casualty insurance companies in East Africa’, European Scientific Journal, 13(13), pp. 358–373. https://doi.org/10.19044/esj.2017.v13n13p358.
[11] Bartens, Y., De Haes, S., Lamoen, Y., Schulte, F. and Voss, S. (2015) ‘On the way to a minimum baseline in IT governance: Using expert views for selective implementation of COBIT 5’, 2015 48th Hawaii International Conference on System Sciences, pp. 4554–4563. https://doi.org/10.1109/HICSS.2015.543.
[12] Batyashe, T.N. and Iyamu, T. (2017) ‘Examining IT governance through diffusion of innovations: A case of a South African telecom’, Information Resources Management Journal, 30(3), pp. 26–40. https://doi.org/10.4018/IRMJ.2017070102.
[13] Bernroider, E.W.N. and Ivanov, M. (2011) ‘IT project management control and the Control Objectives for IT and related Technology (CobiT) framework’, International Journal of Project Management, 29(3), pp. 325–336. https://doi.org/10.1016/j.ijproman.2010.03.002.
[14] Biener, C., Eling, M. and Wirfs, J.H. (2015) ‘Insurability of cyber risk: An empirical analysis’, The Geneva Papers on Risk and Insurance – Issues and Practice, 40(1), pp. 131–158. https://doi.org/10.1057/gpp.2014.19. (Springer)
[15] Brown, A.E. and Grant, G.G. (2005) ‘Framing the frameworks: A review of IT governance research’, Communications of the Association for Information Systems, 15, pp. 696–712. https://doi.org/10.17705/1CAIS.01538. (AIS eLibrary)
[16] Carcary, M., Renaud, K., McLaughlin, S. and O’Brien, C. (2016) ‘A framework for information security governance and management’, IT Professional, 18(2), pp. 22–30. https://doi.org/10.1109/MITP.2016.27. (Mary Immaculate College)
[17] Cummins, J.D. and Weiss, M.A. (2014) ‘Systemic risk and the U.S. insurance sector’, Journal of Risk and Insurance, 81(3), pp. 489–528. https://doi.org/10.1111/jori.12039. (Wiley Online Library)
[18] De Barros, M.D., Salles, C.A.L., Gomes, C.F.S., Da Silva, R.A. and Costa, H.G. (2015) ‘Mapping of the scientific production on the ITIL application published in the national and international literature’, Procedia Computer Science, 55, pp. 102–111. https://doi.org/10.1016/j.procs.2015.07.013.
[19] De Haes, S. and Van Grembergen, W. (2009) ‘An exploratory study into IT governance implementations and its impact on business/IT alignment’, Information Systems Management, 26(2), pp. 123–137. https://doi.org/10.1080/10580530902794786. (Taylor & Francis Online)
[20] De Haes, S., Huygh, T., Joshi, A.S. and Van Grembergen, W. (2016) ‘Adoption and impact of IT governance and management practices: A COBIT 5 perspective’, International Journal of IT/Business Alignment and Governance, 7(1), pp. 50–72. https://doi.org/10.4018/IJITBAG.2016010104. (Open Universiteit research portal)
[21] De Haes, S., Van Grembergen, W. and Debreceny, R.S. (2013) ‘COBIT 5 and enterprise governance of information technology: Building blocks and research opportunities’, Journal of Information Systems, 27(1), pp. 307–324. https://doi.org/10.2308/isys-50422.
[22] Ehikioya, B.I. (2009) ‘Corporate governance structure and firm performance in developing economies: Evidence from Nigeria’, Corporate Governance: The International Journal of Business in Society, 9(3), pp. 231–243. https://doi.org/10.1108/14720700910964307.
[23] Ejofodomi, O.A., Gideon, E.N., Oladipo, G.O. and Oshomah, E.R. (2014) ‘Automated detection of architectural detection in mammograms using template matching’, International Journal of Biomedical Science and Engineering, 2(1), pp. 1–6. https://doi.org/10.11648/j.ijbse.20140201.11. (sciencepg.com)
[24] Ekanata, A. and Girsang, A.S. (2017) ‘Assessment of capability level and IT governance improvement based on COBIT and ITIL framework at communication center ministry of foreign affairs’, 2017 International Conference on ICT for Smart Society (ICISS), pp. 1–7. https://doi.org/10.1109/ICTSS.2017.8288871.
[25] Eling, M. and Lehmann, M. (2018) ‘The impact of digitalization on the insurance value chain and the insurability of risks’, The Geneva Papers on Risk and Insurance – Issues and Practice, 43(3), pp. 359–396. https://doi.org/10.1057/s41288-017-0073-0. (IDEAS/RePEc)
[26] Eling, M. and Schnell, W. (2016) ‘What do we know about cyber risk and cyber risk insurance?’, The Journal of Risk Finance, 17(5), pp. 474–491. https://doi.org/10.1108/JRF-09-2016-0122. (Emerald Publishing)
[27] Gacenga, F., Cater-Steel, A. and Toleman, M. (2010) ‘An international analysis of IT service management benefits and performance measurement’, Journal of Global Information Technology Management, 13(4), pp. 28–63. https://doi.org/10.1080/1097198X.2010.10856525.
[28] Gomber, P., Koch, J.A. and Siering, M. (2017) ‘Digital Finance and FinTech: Current research and future research directions’, Journal of Business Economics, 87(5), pp. 537–580. https://doi.org/10.1007/s11573-017-0852-x.
[29] Hardy, G. (2006) ‘Using IT governance and COBIT to deliver value with IT and respond to legal, regulatory and compliance challenges’, Information Security Technical Report, 11(1), pp. 55–61. https://doi.org/10.1016/j.istr.2005.12.004. (ResearchGate)Huygh, T., De Haes, S., Joshi, A. and Van Grembergen, W. (2018) ‘Answering key global IT management concerns through IT governance and management processes: A COBIT 5 view’, Proceedings of the 51st Hawaii International Conference on System Sciences, pp. 5335–5344. https://doi.org/10.24251/HICSS.2018.665.
[30] Iden, J. and Eikebrokk, T.R. (2013) ‘Implementing IT Service Management: A systematic literature review’, International Journal of Information Management, 33(3), pp. 512–523. https://doi.org/10.1016/j.ijinfomgt.2013.01.004.
[31] Idris, A.A., Olumoko, T.A. and Ajemunigbohun, S.S. (2013) ‘The role of information technology in customers’ service delivery and firm performance: Evidence from Nigeria’s insurance industry’, International Journal of Marketing Studies, 5(4), p. 59. https://doi.org/10.5539/ijms.v5n4p59.
[32] Iheanacho, E. (2018) ‘Insurance industry performance and the selected regulatory instruments in Nigeria’, IOSR Journal of Economics and Finance, 9(6), pp. 67–77. https://doi.org/10.9790/5933-0906016777. (Europub)
[33] Jäntti, M. and Cater-Steel, A. (2017) ‘Proactive management of IT operations to improve IT services’, Journal of Information Systems and Technology Management, 14(2), pp. 191–218. https://doi.org/10.4301/S1807-17752017000200004.
[34] Jäntti, M. and Hotti, V. (2016) ‘Defining the relationships between IT service management and IT service governance’, Information Technology and Management, 17(2), pp. 141–150. https://doi.org/10.1007/s10799-015-0239-z.
[35] Jewer, J. and McKay, K.N. (2012) ‘Antecedents and consequences of board IT governance: Institutional and strategic choice perspectives’, Journal of the Association for Information Systems, 13(7), pp. 581–617. https://doi.org/10.17705/1jais.00301. (AIS eLibrary)
[36] Joshi, A., Bollen, L., Hassink, H., De Haes, S. and Van Grembergen, W. (2018) ‘Explaining IT governance disclosure through the constructs of IT governance maturity and IT strategic role’, Information & Management, 55(3), pp. 368–380. https://doi.org/10.1016/j.im.2017.09.003.
[37] Kerr, D.S. and Murthy, U.S. (2013) ‘The importance of the CobiT framework IT processes for effective internal control over financial reporting in organizations: An international survey’, Information & Management, 50(7), pp. 590–597. https://doi.org/10.1016/j.im.2013.07.012.
[38] Lunardi, G.L., Becker, J.L., Maçada, A.C.G. and Dolci, P.C. (2014) ‘The impact of adopting IT governance on financial performance: An empirical analysis among Brazilian firms’, International Journal of Accounting Information Systems, 15(1), pp. 66–81. https://doi.org/10.1016/j.accinf.2013.02.001. (IDEAS/RePEc)
[39] Lunardi, G.L., Maçada, A.C.G., Becker, J.L. and Van Grembergen, W. (2017) ‘Antecedents of IT governance effectiveness: An empirical examination in Brazilian firms’, Journal of Information Systems, 31(1), pp. 41–57. https://doi.org/10.2308/isys-51626.
[40] Ly, L.T., Maggi, F.M., Montali, M., Rinderle-Ma, S. and van der Aalst, W.M.P. (2015) ‘Compliance monitoring in business processes: Functionalities, application, and tool-support’, Information Systems, 54, pp. 209–234. https://doi.org/10.1016/j.is.2015.02.007. (Eindhoven University Research Portal)
[41] Marnewick, C. and Labuschagne, L. (2011) ‘An investigation into the governance of information technology projects in South Africa’, International Journal of Project Management, 29(6), pp. 661–670. https://doi.org/10.1016/j.ijproman.2010.07.004. (University of Johannesburg)
[42] Marrone, M. and Kolbe, L.M. (2011) ‘Impact of IT service management frameworks on the IT organization: An empirical study on benefits, challenges, and processes’, Business & Information Systems Engineering, 3(1), pp. 5–18. https://doi.org/10.1007/s12599-010-0141-5.
[43] Marrone, M., Gacenga, F., Cater-Steel, A. and Kolbe, L. (2014) ‘IT service management: A cross-national study of ITIL adoption’, Communications of the Association for Information Systems, 34(1), pp. 865–892. https://doi.org/10.17705/1CAIS.03449.
[44] Maseko, L. and Marx, B. (2016) ‘An analysis of COBIT 5 as a framework for the implementation of IT governance with reference to King III’, Risk Governance & Control: Financial Markets & Institutions, 6(1), pp. 20–34. https://doi.org/10.22495/rgcv6i1art3.
[45] Mignerat, M. and Rivard, S. (2009) ‘Positioning the institutional perspective in information systems research’, Journal of Information Technology, 24(4), pp. 369–391. https://doi.org/10.1057/jit.2009.13. (Sage Journals)
[46] Nakpodia, F., Adegbite, E., Amaeshi, K. and Owolabi, A. (2018) ‘Neither principles nor rules: Making corporate governance work in Sub-Saharan Africa’, Journal of Business Ethics, 151(2), pp. 391–408. https://doi.org/10.1007/s10551-016-3208-5. (IDEAS/RePEc)
[47] Nfuka, E.N. and Rusu, L. (2011) ‘The effect of critical success factors on IT governance performance’, Industrial Management & Data Systems, 111(9), pp. 1418–1448. https://doi.org/10.1108/02635571111182773.
[48] Oham, C., Jurdak, R., Kanhere, S.S., Dorri, A. and Jha, S. (2018) ‘B-FICA: Blockchain-based framework for auto-insurance claim and adjudication’, in 2018 IEEE International Congress on Cybermatics, pp. 1171–1180. https://doi.org/10.1109/Cybermatics_2018.2018.00210. (UNSW Sites)
[49] Okike, E.N.M. (2007) ‘Corporate governance in Nigeria: The status quo’, Corporate Governance: An International Review, 15(2), pp. 173–193. https://doi.org/10.1111/j.1467-8683.2007.00553.x. (Wiley Online Library)
[50] Osemeke, L. and Adegbite, E. (2016) ‘Regulatory multiplicity and conflict: Towards a combined code on corporate governance in Nigeria’, Journal of Business Ethics, 133(3), pp. 431–451. https://doi.org/10.1007/s10551-014-2405-3. (IDEAS/RePEc)
[51] Owolabi, A.O. (2018) ‘Insurance products: Technological service delivery perspective’, Business and Economic Research, 8(3), pp. 19–28. https://doi.org/10.5296/ber.v8i3.13238.
[52] Ozili, P.K. (2018) ‘Impact of digital finance on financial inclusion and stability’, Borsa Istanbul Review, 18(4), pp. 329–340. https://doi.org/10.1016/j.bir.2017.12.003. (OA Monitor Ireland)
[53] Pereira, R. and Mira da Silva, M. (2012) ‘Designing a new integrated IT governance and IT management framework based on both scientific and practitioner viewpoint’, International Journal of Enterprise Information Systems, 8(4), pp. 1–43. https://doi.org/10.4018/jeis.2012100101.
[54] Pollard, C. and Cater-Steel, A. (2009) ‘Justifications, strategies, and critical success factors in successful ITIL implementations in U.S. and Australian companies: An exploratory study’, Information Systems Management, 26(2), pp. 164–175. https://doi.org/10.1080/10580530902797540.
[55] Pooser, D.M., Browne, M.J. and Arkhangelska, O. (2018) ‘Growth in the perception of cyber risk: Evidence from U.S. P&C insurers’, The Geneva Papers on Risk and Insurance – Issues and Practice, 43(2), pp. 208–223. https://doi.org/10.1057/s41288-017-0077-9. (IDEAS/RePEc)
[56] Ramalingam, D., Arun, S. and Anbazhagan, N. (2018) ‘A novel approach for optimizing governance, risk management and compliance for enterprise information security using DEMATEL and FoM’, Procedia Computer Science, 134, pp. 365–370. https://doi.org/10.1016/j.procs.2018.07.197.
[57] Rooswati, R. and Legowo, N. (2018) ‘Evaluation of IT project management governance using COBIT 5 framework in financing company’, in 2018 International Conference on Information Management and Technology (ICIMTech), pp. 81–85. https://doi.org/10.1109/ICIMTech.2018.8528192.
[58] Rubino, M., Vitolla, F. and Garzoni, A. (2017) ‘The impact of an IT governance framework on the internal control environment’, Records Management Journal, 27(1), pp. 19–41. https://doi.org/10.1108/RMJ-03-2016-0007. (Emerald Publishing)
[59] Sahibudin, S., Sharifi, M. and Ayat, M. (2008) ‘Combining ITIL, COBIT and ISO/IEC 27002 to design a comprehensive IT framework in organizations’, 2008 Second Asia International Conference on Modelling & Simulation, pp. 749–753. https://doi.org/10.1109/AMS.2008.145.
[60] Serumaga-Zake, P.A.E. (2017) ‘The role of user satisfaction in implementing a Business Intelligence System’, South African Journal of Information Management, 19(1), a736. https://doi.org/10.4102/sajim.v19i1.736.
[61] Stoeckli, E., Dremel, C. and Uebernickel, F. (2018) ‘Exploring characteristics and transformational capabilities of InsurTech innovations to understand insurance value creation in a digital world’, Electronic Markets, 28(3), pp. 287–305. https://doi.org/10.1007/s12525-018-0304-7. (Springer)
[62] Sunday, E.A. and Omoegun, G.O. (2018) ‘Integrating solar power solutions in small-scale manufacturing industries in Nigeria’, International Journal of Scientific Research in Science, Engineering and Technology, 4(8), pp. 832–853. https://doi.org/10.32628/IJSRSET23102175.
[63] Sutherland, E. (2017) ‘Governance of cybersecurity – The case of South Africa’, The African Journal of Information and Communication, 20, pp. 83–112. https://doi.org/10.23962/10539/23574. (Wits University)
[64] Talesh, S.A. (2018) ‘Data breach, privacy, and cyber insurance: How insurance companies act as “compliance managers” for businesses’, Law & Social Inquiry, 43(2), pp. 417–440. https://doi.org/10.1111/lsi.12303. (Cambridge University Press)
[65] Veronica and Suryawan, A.D. (2017) ‘Information technology service performance management using COBIT and an ITIL framework: A systematic literature review’, 2017 International Conference on Information Management and Technology (ICIMTech), Yogyakarta, Indonesia, pp. 150–155. https://doi.org/10.1109/ICIMTech.2017.8273528.
[66] von Solms, B. (2005) ‘Information security governance: COBIT or ISO 17799 or both?’, Computers & Security, 24(2), pp. 99–104. https://doi.org/10.1016/j.cose.2005.02.002. (University of Johannesburg)
[67] Wilkin, C.L. and Chenhall, R.H. (2010) ‘A review of IT governance: A taxonomy to inform accounting information systems’, Journal of Information Systems, 24(2), pp. 107–146. https://doi.org/10.2308/jis.2010.24.2.107. (Monash University)
[68] Yamakawa, P., Obregón Noriega, C., Novoa Linares, A. and Vega Ramírez, W. (2012) ‘Improving ITIL compliance using change management practices: A finance sector case study’, Business Process Management Journal, 18(6), pp. 1020–1035. https://doi.org/10.1108/14637151211283393.
[69] Yusuf, T.O. and Ajemunigbohun, S.S. (2015) ‘Effectiveness, efficiency, and promptness of claims handling process in the Nigerian insurance industry’, European Journal of Business and Economics, 10(2), pp. 6–10. https://doi.org/10.12955/ejbe.v10i2.686.
How to cite this paper
@article{1722619,
author = {Samuel Fadero, Serif Oyindamola Oyesiji, Stanley Nwakamma, Demilade Jooda},
title = {IT Governance Frameworks (COBIT/ITIL) and Their Impact on Regulatory Compliance in Nigerian Insurance Firms},
journal = {Iconic Research And Engineering Journals},
year = {2018},
volume = {2},
number = {5},
pages = {478-496},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1722619.pdf},
abstract = {This review examines how structured information technology governance and service-management practices can strengthen regulatory compliance, operational resilience, and digital accountability within Nigerian insurance firms. Its purpose is to evaluate the complementary roles of COBIT and ITIL, assess their relevance to technology-related regulatory obligations, and identify implementation conditions capable of improving governance maturity across the sector. A structured narrative review method was adopted, drawing on peer-reviewed scholarship, recognised governance frameworks, and relevant regulatory and professional literature published up to 2018. The analysis synthesised evidence on governance structures, internal controls, service management, cybersecurity, risk oversight, auditability, digital transformation, and compliance monitoring.
The findings show that COBIT provides a robust architecture for strategic alignment, control ownership, risk optimisation, performance evaluation, and assurance, while ITIL strengthens operational reliability through incident, change, availability, continuity, and service-level management. Their integration offers a coherent governance-to-operations model through which regulatory expectations can be translated into measurable and auditable technology practices. However, implementation effectiveness is constrained by uneven governance maturity, legacy systems, skills shortages, infrastructure limitations, fragmented accountability, cybersecurity exposure, and the cost of sustained process improvement. The review concludes that successful adoption requires contextual tailoring rather than mechanical framework implementation.
It recommends phased, risk-based COBIT–ITIL integration, stronger board and executive oversight, clearer control ownership, enhanced cybersecurity capability, continuous service-performance monitoring, and closer alignment between technology governance, internal audit, enterprise risk management, and regulatory reporting. Future research should empirically test how governance maturity influences compliance outcomes, service reliability, audit findings, operational performance, and regulatory costs within Nigerian insurance firms. Such evidence can support proportionate regulation and sustainable sector-wide digital resilience.},
keywords = {COBIT; ITIL; IT governance; regulatory compliance; Nigerian insurance; digital governance.},
month = {November},
doi = {https://doi.org/10.64388/IREV2I5-1722619}
}