The Vandium operating model
Ten domains. Fifty capabilities. One shared language.
At the centre of the practice is a single capability framework, aligned to COBIT 2019 — the international standard for the governance and management of enterprise IT. It is the backbone every engagement is scoped, assessed, and delivered against.
The ten domains
The natural logic of an IT operating model.
Govern the enterprise, direct it with strategy, enable it with people and money — then build, run, serve, protect, and source.
| # | Domain | What it covers |
|---|---|---|
| 1 | Governance, Risk & Compliance | Decision rights, value, risk appetite, controls, compliance, continuity — the backbone that directs everything else. |
| 2 | Strategy & Innovation | IT strategy, enterprise architecture, innovation, stakeholder alignment, policy. |
| 3 | People & Leadership | Org design, talent, knowledge, change, performance. |
| 4 | IT Financial & Vendor Management | Budgeting, cost transparency, resource optimisation, vendor portfolio and performance. |
| 5 | Project & Portfolio Management | Investment portfolio, programme and project delivery. |
| 6 | Applications | Application strategy, requirements, build/select, portfolio, product, quality, maintenance. |
| 7 | Data & Artificial Intelligence | Data strategy, governance, management, integration, analytics, AI. |
| 8 | Infrastructure & Operations | Cloud/infrastructure strategy, operations, availability, assets/config, change. |
| 9 | Service Management | Service management, service desk, incident & problem management. |
| 10 | Security & Privacy | Security strategy, management, identity & access, security operations, privacy. |
The fifty capabilities
Every station carries a standards-based reference.
COBIT 2019 codes (EDM / APO / BAI / DSS / MEA) make the map a shared vocabulary between Vandium and your team — and an index into the delivery library. Capabilities without a code are recognised operating-model capabilities that extend beyond the standard's core objectives.
Governance, Risk & Compliance
- IT Governance
EDM01 - Business Value Maximisation
EDM02 - Risk Management
EDM03 - Internal Controls & Assurance
MEA02 - Compliance Management
MEA03 - Business Continuity Management
DSS04
Strategy & Innovation
- IT Strategy
APO02 - Enterprise Architecture
APO03 - IT Innovation Strategy
APO04 - Stakeholder Alignment & Management
EDM05 - IT Management & Policies
APO01
People & Leadership
- Talent Management
APO07 - Organisational Change Management
BAI05 - Knowledge Management
BAI08 - Performance Management
MEA01 - IT Organisational Structure
APO01
IT Financial & Vendor Management
- IT Financial Management
APO06 - Resource Optimisation
EDM04 - Vendor Portfolio Management
APO10 - Vendor Performance Management
APO10
Project & Portfolio Management
- IT Portfolio Management
APO05 - Project & Portfolio Management
BAI01 - Project Management
BAI11
Applications
- Application Strategy
BAI03 - Requirements Gathering
BAI02 - Application Development & Delivery
BAI03 - Application Selection & Implementation
BAI03 - Application Maintenance
- Application Portfolio Management
APO05 - Quality Management
APO11 - IT Product Management
Data & Artificial Intelligence
- Data Strategy
APO14 - Data Governance
- Data Management
- Data Development & Integration
- Data Insights & Analytics
- AI Strategy
Infrastructure & Operations
- Infrastructure & Cloud Strategy
- Operations Management
DSS01 - Availability & Capacity Management
BAI04 - Asset & Configuration Management
BAI09 - Change & Release Management
BAI06
Service Management
- Service Management
APO09 - Service Desk
- Incident & Problem Management
DSS02
Security & Privacy
- Security & Privacy Strategy
APO13 - Security Management
DSS05 - Identity & Access Management
DSS05 - Security Operations
- Privacy Program Management
DSS06
The method
Every engagement runs the same disciplined loop.
Tailored in depth to the need, mapped to a recognised continual-improvement lifecycle. The steps are numbered because the order is real.
Orient
Establish the shared picture of the operating model — the reference view. Everyone starts from the same map and the same vocabulary.
Assess
Score current-state maturity per capability, per business unit, with evidence behind every score.
Prioritise
Rank the gaps by impact, risk, dependency, and the outcome you are actually trying to reach.
Sequence
Produce a dependency-aware roadmap: what to build, in what order — the implementation view.
Deliver
Execute in fixed-scope workstreams, each producing evidence and artifacts, not just slideware.
Sustain
Embed the governance and metrics that keep the gains after the engagement closes.
The Vandium difference in the method: sequencing is never guesswork. Because the capability model has an explicit dependency structure, the roadmap is derived, defensible, and outcome-driven — you can trace why every item sits where it does.
See your own operating model, scored.
The Diagnostic assesses all ten domains and returns the reference map, a scored current state, and a sequenced roadmap.