Vandium Consulting Group Book a diagnostic

The Vandium operating model

Ten domains. Fifty capabilities. One shared language.

At the centre of the practice is a single capability framework, aligned to COBIT 2019 — the international standard for the governance and management of enterprise IT. It is the backbone every engagement is scoped, assessed, and delivered against.

The ten domains

The natural logic of an IT operating model.

Govern the enterprise, direct it with strategy, enable it with people and money — then build, run, serve, protect, and source.

The ten domains of the Vandium operating model
#DomainWhat it covers
1Governance, Risk & ComplianceDecision rights, value, risk appetite, controls, compliance, continuity — the backbone that directs everything else.
2Strategy & InnovationIT strategy, enterprise architecture, innovation, stakeholder alignment, policy.
3People & LeadershipOrg design, talent, knowledge, change, performance.
4IT Financial & Vendor ManagementBudgeting, cost transparency, resource optimisation, vendor portfolio and performance.
5Project & Portfolio ManagementInvestment portfolio, programme and project delivery.
6ApplicationsApplication strategy, requirements, build/select, portfolio, product, quality, maintenance.
7Data & Artificial IntelligenceData strategy, governance, management, integration, analytics, AI.
8Infrastructure & OperationsCloud/infrastructure strategy, operations, availability, assets/config, change.
9Service ManagementService management, service desk, incident & problem management.
10Security & PrivacySecurity strategy, management, identity & access, security operations, privacy.

The fifty capabilities

Every station carries a standards-based reference.

COBIT 2019 codes (EDM / APO / BAI / DSS / MEA) make the map a shared vocabulary between Vandium and your team — and an index into the delivery library. Capabilities without a code are recognised operating-model capabilities that extend beyond the standard's core objectives.

Governance, Risk & Compliance

  • IT GovernanceEDM01
  • Business Value MaximisationEDM02
  • Risk ManagementEDM03
  • Internal Controls & AssuranceMEA02
  • Compliance ManagementMEA03
  • Business Continuity ManagementDSS04

Strategy & Innovation

  • IT StrategyAPO02
  • Enterprise ArchitectureAPO03
  • IT Innovation StrategyAPO04
  • Stakeholder Alignment & ManagementEDM05
  • IT Management & PoliciesAPO01

People & Leadership

  • Talent ManagementAPO07
  • Organisational Change ManagementBAI05
  • Knowledge ManagementBAI08
  • Performance ManagementMEA01
  • IT Organisational StructureAPO01

IT Financial & Vendor Management

  • IT Financial ManagementAPO06
  • Resource OptimisationEDM04
  • Vendor Portfolio ManagementAPO10
  • Vendor Performance ManagementAPO10

Project & Portfolio Management

  • IT Portfolio ManagementAPO05
  • Project & Portfolio ManagementBAI01
  • Project ManagementBAI11

Applications

  • Application StrategyBAI03
  • Requirements GatheringBAI02
  • Application Development & DeliveryBAI03
  • Application Selection & ImplementationBAI03
  • Application Maintenance
  • Application Portfolio ManagementAPO05
  • Quality ManagementAPO11
  • IT Product Management

Data & Artificial Intelligence

  • Data StrategyAPO14
  • Data Governance
  • Data Management
  • Data Development & Integration
  • Data Insights & Analytics
  • AI Strategy

Infrastructure & Operations

  • Infrastructure & Cloud Strategy
  • Operations ManagementDSS01
  • Availability & Capacity ManagementBAI04
  • Asset & Configuration ManagementBAI09
  • Change & Release ManagementBAI06

Service Management

  • Service ManagementAPO09
  • Service Desk
  • Incident & Problem ManagementDSS02

Security & Privacy

  • Security & Privacy StrategyAPO13
  • Security ManagementDSS05
  • Identity & Access ManagementDSS05
  • Security Operations
  • Privacy Program ManagementDSS06

The method

Every engagement runs the same disciplined loop.

Tailored in depth to the need, mapped to a recognised continual-improvement lifecycle. The steps are numbered because the order is real.

  1. Orient

    Establish the shared picture of the operating model — the reference view. Everyone starts from the same map and the same vocabulary.

  2. Assess

    Score current-state maturity per capability, per business unit, with evidence behind every score.

  3. Prioritise

    Rank the gaps by impact, risk, dependency, and the outcome you are actually trying to reach.

  4. Sequence

    Produce a dependency-aware roadmap: what to build, in what order — the implementation view.

  5. Deliver

    Execute in fixed-scope workstreams, each producing evidence and artifacts, not just slideware.

  6. Sustain

    Embed the governance and metrics that keep the gains after the engagement closes.

The Vandium difference in the method: sequencing is never guesswork. Because the capability model has an explicit dependency structure, the roadmap is derived, defensible, and outcome-driven — you can trace why every item sits where it does.

See your own operating model, scored.

The Diagnostic assesses all ten domains and returns the reference map, a scored current state, and a sequenced roadmap.