An Enterprise Architecture-Driven Service Integration Model for Enhancing Fiscal Oversight in Supreme Audit Institutions
Abstract
1. Introduction
1.1. Context and Institutional Motivation
1.2. Related Work and Research Gap
- Strengthen IT service integration within oversight bodies.
- Incorporate baseline maturity assessments and measurable governance improvements.
- Demonstrate how technological integration supports fiscal supervision and public-value creation.
1.3. Aim and Contribution
- A novel, context-aware integration model: We present a model that adopts ITILv4, TOGAF, and COBIT, specifically for the mission, regulatory constraints, and oversight functions of an SAI, which is a contribution absent in current literature.
- An empirically grounded architecture: The model is derived from diagnostic assessments, stakeholder engagement, maturity analysis, and iterative validation within CGR, ensuring relevance and applicability.
- A replicable framework for SAIs: The proposed model provides conceptual and procedural foundations that can be adopted by other oversight institutions seeking to modernize their technological service ecosystems.
2. Background
2.1. TOGAF Framework
2.2. ITIL
- General Management Practices: They reflect capabilities traditionally associated with enterprise-level administration adapted to support IT service management. These practices include areas such as governance, strategy management, continuous improvement, and workforce management. These practices also improve the alignment of IT initiatives with business objectives, foster a culture of accountability, and provide mechanisms to embed long-term value generation across organizational processes. Finally, general management practices contribute to risk mitigation and regulatory compliance, while supporting robust decision-making in dynamic environments [35].
- Service Management Practices: They form the operational core of ITIL, addressing the full life cycle of IT services. Service management practices cover all the stages, from design and transition to delivery and support. These practices emphasize service quality, user experience, and continuous feedback, enabling organizations to provide consistent and reliable value to stakeholders. By promoting standardized approaches to incident handling, service configuration, availability management, and customer engagement, the practices proposed in ITIL contribute to reducing service disruption and improving responsiveness to evolving demands. Moreover, service management practices support the development of adaptive service models, which are critical in fast-paced digital economy present in nowadays societies [36,37].
- Technical Management Practices: They focus on the effective and secure operation of IT infrastructures and platforms supporting organizational services. This set of practices provides guide on deployment, monitoring, and technical support, ensuring resilience and scalability of the technological components that sustain service delivery. By applying these practices, organizations can drive infrastructure management, reduce technical debt, and adopt modern approaches such as automation and infrastructure-as-code [38]. Technical management practices are essential to guarantee service and business continuity, especially in hybrid or cloud-native environments where system reliability is a key aspect [39].
2.3. COBIT
- Meeting stakeholder needs: That means ensuring enterprise IT governance aligns with the priorities and expectations of all stakeholders, to balance benefits, risk, and resource optimization.
- Covering the enterprise end-to-end: It corresponds to the integration of governance responsibilities across the entire organization and its processes, not limited to the IT function, but encompassing all business and technological areas.
- Enabling a holistic approach: That is, structuring governance through a set of interrelated components, including processes, organizational structures, policies, information flows, culture, and skills. This integrated vision, involving all the elements, is key for a true adoption within the enterprise
- Separating governance from management: It means to clearly distinguish governance activities (evaluating, directing, and monitoring) from management activities (planning, building, running, and monitoring operations).
- Governance and Management Objectives: Grouped into five domains: Governance (evaluate, direct, and monitoring) and management (APO—Align, plan and organize; BAI—build, acquire and implement; DSS—deliver, service and support; MEA—monitor, evaluate and assess), which collectively cover strategy, planning, execution, support, and performance monitoring.
- Components of a Governance System: These are enablers such as processes, organizational structures, policies and procedures, information, culture, ethics, behavior, services, infrastructure, and human resources. These components interact among them to ensure effective governance.
- Performance Management: These are mechanisms to assess the capability and maturity of governance and management practices. This assessment contributes to supporting continuous improvement.
- Design Factors: They include organizational characteristics (e.g., strategy, risk profile, compliance requirements) that influence how the governance system should be tailored to organizational needs.
- Goals Cascade: This is a translation mechanism from stakeholder drivers and needs into specific enterprise goals, and subsequently into aligned governance and management objectives.
2.4. Framework Application and Institutional Integration
3. Methodology
3.1. Design Science Research (DSR) Approach
- Problem Space: where diagnosis, data collection and governance assessment allow to analyze needs, constraints, and contextual requirements of CGR.
- Design and Validation Space: where maturity assessments, expert validation, and verification of alignment with institutional priorities allow the construction and evaluation of an integration model using TOGAF, COBIT, and ITILv4 artifacts.
- DP1 (Modularity): Decouple audit data from specific applications to ensure long-term availability.
- DP2 (Traceability): Every IT service action must map to a fiscal oversight requirement.
- DP3 (Transparency): Performance metrics must be accessible to non-technical stakeholders to reduce bureaucratic resistance.
3.2. Overall Design and Stages
- Institutional Diagnosis: Analysis of the technological ecosystem, governance structures, and interoperability challenges in CGR.
- Data Collection and Stakeholder Engagement: Gathering qualitative and quantitative evidence from institutional documents, interviews, and surveys.
- Maturity and Readiness Assessment: Evaluation of the service practices aligned with ITILv4 and COBIT governance capabilities.
- Integration Modeling and Validation: Development of the service integration model and its conceptual validation through expert sessions and alignment with the strategic plans of CGR.
3.3. Timeline of the Model Development
- Phase 1: Institutional Diagnosis and Evaluation (Initiation): This phase began with the launch of the R&D&I project CGR-407-2024. It was driven by the institutional need to modernize fragmented systems (auditing, internal control, and citizen complaints) as outlined in the 2022–2026 strategic cycle.
- Phase 2: Primary Research and Data Collection: Quantitative data collection was centered around an institutional survey conducted among CGR officials. The survey assessment was aligned with the current PETI 2022–2026 strategy to ensure the findings reflected contemporary technological needs and digital transformation goals.
- Phase 3: Maturity Assessment and Readiness Assessment: Following data collection, a baseline maturity assessment was performed using COBIT 2019 and ITILv4. This assessment (detailed in Table 2 and Table 3) established the current state of the IT governance and service capabilities of the institution for the current strategic period.
- Phase 4: Integration Modeling and Validation: The conceptual validation of the service integration model (the DSR artifact) will take place during the “structuring phase”. This phase involves iterative validation sessions with the CGR IT governance board, and it will be finalized for submission during 2026.
3.4. Data Sources and Collection Methods
- Document Analysis: Review of institutional IT policies, strategic plans (PECGR 2022–2026 and PETI 2022–2026), service management procedures, and architecture repositories.
- Semi-structured Interviews: Conducted with directors and process leaders from OSEI and DIARI to identify pain points, dependencies, and service expectations.
- Survey Instrument: The survey instrument (Appendix A) comprises 44 items. While perception-based items use a five-point Likert scale (1 = strongly disagree, 5 = strongly agree), operational capability items (marked in Appendix A) utilize a categorical scale to verify the formalization and existence of IT management practices. Both types of data were integrated into the maturity assessment scores presented in Section 4.2.To ensure a comprehensive evaluation, a mixed-scale approach was employed:
- −
- Strategic and Performance Dimensions (Items 1–5, 7–10, etc.): These items assessed institutional perception and maturity using a five-point Likert scale, ranging from “strongly disagree” (1) to “Strongly Agree” (5).
- −
- Operational and Capability Dimensions (Items 6, 11, 17, 23, 29, 35, 41): These items focused on the existence and formalization of specific ITILv4 and COBIT 2019 practices. They were measured using a categorical scale (e.g., Yes/No/In Progress or frequency-based options) to provide a binary or ordinal baseline for maturity calculations, which were subsequently normalized to the 0.0–5.0 scale presented in the results.
- Quantitative Maturity Assessments: Application of ITILv4 maturity models and Technology Readiness Level (TRL) scales to evaluate operational readiness for integrated service management.
3.5. Sampling Design and Population Stratification
3.6. Conduction of Interviews
- Contextualize the Problem Space: By validating the “isolated” operation of the mission-critical systems like the financial auditing and citizen complaints platforms.
- Inform the Architecture Design: By ensuring the TOGAF ADM application correctly maps the 23 formalized ITILv4 procedures to the actual technical domains of the SAI.
- Linking of findings: By providing qualitative depth to the low maturity scores (below 2.0) found in the quantitative COBIT and ITILv4 assessments.
3.7. Maturity and Readiness Assessment Procedure
- ITILv4 Practice Maturity: Evaluation of organization and people, information and technology, partners and suppliers, and value streams and processes. Each domain was rated on a maturity scale with five levels. Table 4 summarizes the level descriptions.
- COBIT 2019 Process Capability: Complementary evaluation of governance processes using the maturity scale of COBIT (0 to 5), as shown in Table 3.
- Technology Readiness Level (TRL) Analysis: Assessment of prototype readiness, controlled pilots, and operational feasibility for each service domain.
3.8. Analytical Instruments
- Compliance Matrices: For the mapping of CGR processes to COBIT control objectives and ITILv4 practices.
- Dependency Models: For the identification of data flows, shared services, and interoperability points among the core systems of CGR.
- Process Maps: For the modeling of incident, problem, capacity, change, and catalog management workflows.
3.9. Link with Institutional Results
4. Key Findings
4.1. Survey Data Analysis and Descriptive Results
4.2. Analysis of the Current State of Technological Service Delivery in CGR
- Quantitative Assessment: Applying the 44-item construct to the study sample () to generate scores for seven ITILv4 and COBIT 2019 dimensions.
- Qualitative Triangulation: Refining the “Comment” columns through semi-structured interviews with process leaders from OSEI and DIARI units to identify root causes of low scores.
- Target Definition: Aligning the performance targets (Table 4) with the requirements established in the institutional PETI 2022–2026 and the CGR-407-2024 project milestones.
4.3. Reinterpreting Framework Concepts for Public Governance
- TOGAF ADM Tailoring: Phase B (Business Architecture) was modified to include a “Legal-Technical Traceability” sub-phase. This ensured that every IT service defined in the catalog was mapped not just to a business process, but to a specific article of the Colombian fiscal oversight law.
- COBIT Operationalization: Performance metrics were shifted from corporate return of investment to “oversight capability”. For example, the COBIT metric “percent of IT-enabled business programs” was adopted at CGR as “percentage of digital audit artifacts with automated chain-of-custody verification”.
- ITILv4 Adaptation: The “service request management” practice was specifically integrated with the CGR-407-2024 security protocols, requiring multi-factor authentication and role-based access for any data modification involving fiscal evidence.
5. Service Integration Model
5.1. Model Overview and Design Logic
- In the context of CGR, the engagement component implements semi-structured feedback loops identified in the diagnosis, while design and transition focuses specifically on the migration of legacy audit workflows into the new interoperable state. By focusing on these SAI-specific applications, the model avoids the generalities of standard ITIL implementations as described in Section 2.
- Obtain/Build: Addresses infrastructure provisioning, software implementation, prototyping, and service validation. This phase aligns with TRL readiness criteria and the Build–Test cycles of systems engineering.
- Delivery and Support: Ensures operational performance through incident management, service desk operation, request fulfillment, monitoring, and performance measurement. It corresponds to service value chain activities of ITILv4.
5.2. Architecture and Value Flow Model
- IT Governance: guides decision-making through policies, risk management, continuity planning, and accountabilities defined in COBIT.
- Architecture and Innovation Management: orchestrates the design of organizational, data, application, and technology architectures following TOGAF ADM.
- Information Systems and Automation: manages core platforms, business processes, and interoperability services.
- IT Services and Infrastructure: oversees operational delivery, infrastructure provisioning, and reliability management.
6. Assessment and Validation Framework
6.1. Evaluation Dimensions
- People and Organization: user satisfaction, usability, adoption levels, and organizational alignment.
- Information and Technology: system performance, data quality, security controls, interoperability, and platform reliability.
- Partners and Suppliers: contractual performance, risk management, and alignment with service levels defined in SLAs.
- Value and Process Flows: consistency of service workflows, process standardization, and governance indicators linked to fiscal oversight functions.
6.2. Key Performance Indicators
- Administrative Efficiency: average service response time, mean time to repair (MTTR), SLA compliance rate.
- Technological Interoperability: system integration rate, data synchronization reliability, service availability.
- User Satisfaction and Adoption: perceptions of service quality, system usability, communication effectiveness, and overall satisfaction scores.
- Audit velocity that measures the reduction in time required to compile fiscal evidence through automated service integration.
- Forensic integrity rate that quantifies the percentage of digital artifacts with a cryptographically verified chain of custody.
- Public value impact that correlates IT service availability with the successful recovery of public funds in high-priority sectors. These indicators ensure that the architecture does not simply exist to support IT, but to directly enhance the efficiency of fiscal oversight.
6.3. Analytical Evidence and Validation Results
- Infrastructure Diagnosis: Identified documentation gaps, absence of standardized monitoring mechanisms, and heterogeneous hardware conditions across regional offices.
- User Experience Analysis: Revealed fragmentation of IT services between central and territorial offices, inconsistent communication channels, and limited visibility of service procedures.
- Maturity Assessment: ITILv4 and ISO 20000–1 evaluations rated the IT service management of CGR at Level 2, with Technology Readiness Levels (TRL) between five and six, indicating functional prototypes and controlled pilots ready for integration.
- Improvement Roadmap: Defined measurable targets such as service availability above 98%, MTTR below 24 h, periodic SLA reviews, and progressive standardization of operational workflows.
6.4. Framework Alignment and Institutional Outputs
6.5. Institutional Impact and Readiness
- Establishing a unified architectural vision aligned with the mission of CGR,
- Reducing fragmentation in processes and data flows,
- Improving traceability, transparency, and governance mechanisms,
- Enabling a structured transition toward digital maturity.
7. Discussion
7.1. Limitations
7.2. Theoretical and Scientific Innovation
- Managerial Innovation: The optimized service catalog for the CGR.
- Scientific Innovation: The development of the “audit-service coupling theory”. This theory suggests that in supreme audit institutions, IT service maturity is not an independent variable but is functionally dependent on the level of Architectural Traceability. By formalizing this relationship, this work contributes a new systems-innovation framework that explains how decentralized public-sector IT can achieve centralized fiscal legitimacy without losing operational agility.
7.3. Transferability and Boundary Conditions
- Regulatory Alignment: Mapping local audit laws to the ’Audit-Service Coupling’ requirements.
- Stakeholder Mapping: Identifying “process owners” to ensure purposive sampling for KPI validation.
- Infrastructure Readiness: Assessing connectivity led by APIs versus legacy manual data entry.
- Strategic Rebalancing: Customizing the fiscal-impact KPIs to match national anti-corruption priorities.
7.4. The Model as an Applied Systems Innovation
- System-level Emergence: The “strategic pivot” in KPIs (Section 6.2) represents an emergent property of the system. While individual frameworks like ITIL or COBIT focus on component-level efficiency, the integrated architecture produces a new capability—institutional forensic readiness—which does not exist in any of the parts individually but emerges from their structural coupling.
- Feedback and Adaptation: The model incorporates a double-loop feedback mechanism. The operational feedback (SLA compliance) ensures system stability, while the strategic feedback (public value impact) allows the architecture to adapt itself to shifts in legislative requirements or new corruption patterns, ensuring the innovation remains resilient over time.
- Dynamics of Innovation: Unlike traditional “top-down” IT governance, this innovation follows a non-linear path. The transition from a 0.95 maturity score in problem management to a high-velocity audit capability demonstrates how architectural integration acts as a catalyst for systemic change, overcoming institutional inertia through the automation of transparency.
8. Conclusions and Future Work
Author Contributions
Funding
Data Availability Statement
Conflicts of Interest
Appendix A. Survey Instrument and Respondent Profile
Appendix A.1. General Information
- Gender
- Department or Office
- Position (Administrative/Technical/Auditor/Other)
- Years of Service (≤2, 2–5, 6–10, >10)
- Organizational Level (Central/Territorial)
Appendix A.2. Analytical Dimensions and Items
- Block 1. Service Availability and Accessibility
- Q1. Are IT services available when you need them?
- Q2. Rate the ease of access to IT services.
- Q3. Have you experienced frequent service interruptions?
- Q4. Does the IT area resolve incidents promptly?
- Q5. Are services available outside working hours when needed?
- *Q6. What types of interruptions are most frequent (power outages, system failures, connectivity issues)?
- Block 2. Quality of Technical Support
- 7.
- Q7. Is the technical support staff competent and effective?
- 8.
- Q8. Do you receive definitive solutions to reported issues?
- 9.
- Q9. Do you feel that the technical support team is committed to helping you?
- 10.
- Q10. Does the support team clearly explain the solutions provided?
- 11.
- *Q11. What aspects of technical support would you like to see improved?
- Block 3. Technological Infrastructure
- 12.
- Q12. Do computing devices meet your work needs?
- 13.
- Q13. Is the Internet connection stable and sufficient for your tasks?
- 14.
- Q14. Are the systems you use modern and efficient?
- 15.
- Q15. Are technological tools updated regularly?
- 16.
- Q16. Do you consider that the infrastructure is sufficient to meet current demand?
- 17.
- *Q17. What limitations in technological infrastructure affect your productivity?
- Block 4. Information Security and Data Protection
- 18.
- Q18. Do you feel safe using the institution’s systems?
- 19.
- Q19. Do you believe your data are adequately protected?
- 20.
- Q20. Does the IT area inform you about secure data management practices?
- 21.
- Q21. Have you received training in information security?
- 22.
- Q22. Are you concerned about system vulnerability to cyberattacks?
- 23.
- *Q23. What tools or technologies could improve compliance with security measures?
- Block 5. Communication and User Service
- 24.
- Q24. Do you receive timely notifications about service changes?
- 25.
- Q25. Is IT communication clear and understandable?
- 26.
- Q26. Do you feel your opinions are considered by the IT area?
- 27.
- Q27. Are you informed about the status of your requests or tickets?
- 28.
- Q28. Does the IT area regularly request user feedback?
- 29.
- *Q29. Which aspects of technological services are strongest, and which need improvement?
- Block 6. Innovation and Continuous Improvement
- 30.
- Q30. Does the IT area regularly implement innovative solutions?
- 31.
- Q31. Do you feel that technology is aligned with the institution’s needs?
- 32.
- Q32. Have technological updates improved your productivity?
- 33.
- Q33. Does the IT area propose new tools that are useful for your work?
- 34.
- Q34. Do you perceive a continuous effort by the IT area to improve?
- 35.
- *Q35. What technological projects would you like to see implemented in the coming years?
- Block 7. Overall Satisfaction
- 36.
- Q36. Are you satisfied with the overall IT service?
- 37.
- Q37. Does the IT area meet your expectations?
- 38.
- Q38. Do you consider that the IT area understands your needs?
- 39.
- Q39. Would you recommend the IT services to others?
- 40.
- Q40. Would you like to see significant changes in IT services?
- 41.
- *Q41. Which aspects of IT services should be improved to facilitate your daily work?
- 42.
- Q42. Do you believe that IT services contribute positively to your unit’s performance?
- 43.
- Q43. Do you feel that technological tools make your tasks more efficient?
- 44.
- Q44. In general terms, how would you rate your experience with the institution’s technological services?
Appendix A.3. Sociodemographic Summary
| Variable | Category | Percentage (%) |
|---|---|---|
| Gender | Male (55%), Female (45%) | 100 |
| Functional Role | Auditing (46%), Administrative (33%), Technical (21%) | 100 |
| Organizational Level | Central (58%), Territorial (42%) | 100 |
| Years of Service | <2 (12%), 2–5 (25%), 6–10 (38%), >10 (25%) | 100 |
Appendix A.4. Reliability
References
- Cook, M.E.; Pardo, T.A. Digital Transformation and Public Value: A Primer for Government Leaders; Center for Technology in Government, University at Albany: Albany, NY, USA, 2021; Volume 7. [Google Scholar]
- Mountasser, T.; Abdellatif, M. Digital Transformation in Public Administration. Int. J. Prof. Bus. Rev. 2023, 8, 1–27. [Google Scholar] [CrossRef]
- Dawes, S.S. The evolution and continuing challenges of e-governance. Public Adm. Rev. 2008, 68, S86–S102. [Google Scholar] [CrossRef]
- Restrepo-Carmona, J.A.; Zuluaga, J.C.; Flórez, D.A.; Gómez, M.S.; Londoño, L.; Gómez, G.; Villamil, R.M.; Morales, O.; Hurtado, Á.M.; Escobar, C.A.; et al. The Design of a Strategic Platform for the Smart Supervision of Public Expenditure for Colombia in the Context of Society 5.0. Urban Sci. 2024, 8, 117. [Google Scholar] [CrossRef]
- Małkowska, A.; Urbaniec, M.; Kosała, M. The impact of digital transformation on European countries: Insights from a comparative analysis. Equilibrium 2021, 16, 325–355. [Google Scholar] [CrossRef]
- Al-Ashmoery, Y.; Haider, H.; Haider, A.; Nasser, N.; Al-Sarem, M. Impact of IT service management and ITIL framework on the businesses. In Proceedings of the 2021 International Conference of Modern Trends in Information and Communication Technology Industry (MTICTI), Sana’a, Yemen, 4–6 December 2021; pp. 1–5. [Google Scholar]
- The Open Group. The Open Group Architecture Framework, Version 9.2; The Open Group: San Francisco, CA, USA, 2018.
- Gavrikova, E.; Volkova, I.; Burda, Y. Strategic aspects of asset management: An overview of current research. Sustainability 2020, 12, 5955. [Google Scholar] [CrossRef]
- ISO/IEC 20000-1:2018; Information Technology—Service Management—Part 1: Service Management System Requirements. International Organization for Standardization: Geneva, Switzerland, 2018. Available online: https://www.iso.org/standard/70636.html (accessed on 25 December 2025).
- CGR. Plan Estratégico; Contraloría General de la República: Bogotá, Colombia, 2022. [Google Scholar]
- CGR. Plan Estratégico de Tecnologías de la Información; Contraloría General de la República: Bogotá, Colombia, 2024. [Google Scholar]
- Bannister, F.; Connolly, R. ICT, public values and transformative government: A framework and programme for research. Gov. Inf. Q. 2014, 31, 119–128. [Google Scholar] [CrossRef]
- Luna-Reyes, L.F. Opportunities and challenges for digital governance in a world of digital participation. Inf. Polity 2017, 22, 197–205. [Google Scholar] [CrossRef]
- Dobrolyubova, E. Measuring outcomes of digital transformation in public administration: Literature review and possible steps forward. Netw. Institutes Sch. Public Adm. Cent. East. Eur. NISPAcee J. Public Adm. Policy 2021, 14, 61–86. [Google Scholar] [CrossRef]
- Xiao, J.; Zhang, H.; Han, L. How digital transformation improve government performance: The mediating role of partnering agility. IEEE Access 2023, 11, 59274–59285. [Google Scholar] [CrossRef]
- Morgeson, F.V., III; Mithas, S. Does E-government measure up to E-Business? Comparing end user perceptions of US federal government and E-business web sites. Public Adm. Rev. 2009, 69, 740–752. [Google Scholar] [CrossRef]
- Chung, C.S.; Kim, S.B. A comparative study of digital government policies, focusing on E-government acts in Korea and the United States. Electronics 2019, 8, 1362. [Google Scholar] [CrossRef]
- Pittaway, J.J.; Montazemi, A.R. Know-how to lead digital transformation: The case of local governments. Gov. Inf. Q. 2020, 37, 101474. [Google Scholar] [CrossRef]
- Sanina, A.; Balashov, A.; Rubtcova, M. The socio-economic efficiency of digital government transformation. Int. J. Public Adm. 2023, 46, 85–96. [Google Scholar] [CrossRef]
- Umbach, G.; Tkalec, I. Evaluating e-governance through e-government: Practices and challenges of assessing the digitalisation of public governmental services. Eval. Program Plan. 2022, 93, 102118. [Google Scholar] [CrossRef]
- Crăciun, A.F.; Țăran, A.M.; Noja, G.G.; Pirtea, M.G.; Răcătăian, R.I. Advanced modelling of the interplay between public governance and digital transformation: New empirical evidence from structural equation modelling and Gaussian and mixed-Markov graphical models. Mathematics 2023, 11, 1168. [Google Scholar] [CrossRef]
- Kaufmann, D.; Kraay, A. The worldwide governance indicators. Hague J. Rule Law 2024, 3, 220–246. [Google Scholar] [CrossRef]
- Yang, C.; Gu, M.; Albitar, K. Government in the digital age: Exploring the impact of digital transformation on governmental efficiency. Technol. Forecast. Soc. Change 2024, 208, 123722. [Google Scholar] [CrossRef]
- Shibambu, A.; Ngoepe, M. Enhancing service delivery through digital transformation in the public sector in South Africa. Glob. Knowl. Mem. Commun. 2023, 74, 63–76. [Google Scholar] [CrossRef]
- Singh, P.; Lynch, F.; Helfert, M. Enterprise architecture for the transformation of public services based on citizen’s feedback. Digit. Policy Regul. Gov. 2024, 26, 38–54. [Google Scholar] [CrossRef]
- Waara, Å. Examining Digital Government Maturity Models: Evaluating the Inclusion of Citizens. Adm. Sci. 2025, 15, 73. [Google Scholar] [CrossRef]
- Tangi, L.; Janssen, M.; Benedetti, M.; Noci, G. Barriers and drivers of digital transformation in public organizations: Results from a survey in the Netherlands. In International Conference on Electronic Government; Springer: Berlin/Heidelberg, Germany, 2020; pp. 42–56. [Google Scholar]
- Zoo, H.; Lee, H.; Yoon, J. Assessing the e-government maturity for public sector innovation in developing countries: Case of national informatization assessment tool (NIAT). In IFIP Advances in Information and Communication Technology; Springer: New York, NY, USA, 2017; pp. 778–789. [Google Scholar] [CrossRef]
- Benito, B.; Guillamón, M.D.; Ríos, A.M. Transforming European Governance: Proposals Towards Transparency, Sustainability and Efficiency for the New European Commission (2024–2029). Financ. Account. Manag. 2025. [Google Scholar] [CrossRef]
- Restrepo-Carmona, J.A.; Zuluaga, J.C.; Velásquez, M.; Zuluaga, C.; Villamil, R.M.; Morales, O.; Hurtado, Á.M.; Escobar, C.A.; Sierra-Pérez, J.; Vásquez, R.E. Smart Supervision of Public Expenditure: A Review on Data Capture, Storage, Processing, and Interoperability with a Case Study from Colombia. Information 2024, 15, 616. [Google Scholar] [CrossRef]
- Schmitz, A.; Wimmer, M.A. Framework for interoperable service architecture development. Gov. Inf. Q. 2023, 40, 101869. [Google Scholar] [CrossRef]
- Concha, G.; Astudillo, H.; Porrua, M.; Pimenta, C. E-Government procurement observatory, maturity model and early measurements. Gov. Inf. Q. 2012, 29, S43–S50. [Google Scholar] [CrossRef]
- Gottschalk, P. Maturity levels for interoperability in digital government. Gov. Inf. Q. 2009, 26, 75–81. [Google Scholar] [CrossRef]
- Santosa, I.; Mulyana, R. The it services management architecture design for large and medium-sized companies based on itil 4 and togaf framework. JOIV Int. J. Inform. Vis. 2023, 7, 30–36. [Google Scholar] [CrossRef]
- Gërvalla, M.; Preniqi, N.; Kopacek, P. IT Infrastructure Library (ITIL) framework approach to IT Governance. IFAC-PapersOnLine 2018, 51, 181–185. [Google Scholar] [CrossRef]
- Baradari, I.; Shoar, M.; Nezafati, N. Defining the relationship between IT Service management and knowledge management: Towards improved performance. Knowl. Manag. Res. Pract. 2023, 21, 384–396. [Google Scholar] [CrossRef]
- Permatasari, A.R.; Sulistyo, S.; Santosa, P.I. Optimizing IT Services Quality: Implementing ITIL for Enhanced IT Service Management. In Proceedings of the 2024 11th International Conference on Information Technology, Computer, and Electrical Engineering (ICITACEE), Semarang, Indonesia, 29–30 August 2024; pp. 296–301. [Google Scholar]
- Yonia, D.L.; Anggraini, R.N.E.; Sarno, R.; Haryono, A.T.; Septiyanto, A.F.; Mulyanto, S. E-learning evaluation using information technology infrastructure library 4 with iso/iec 25010 indicators. In Proceedings of the 2024 IEEE International Conference on Artificial Intelligence and Mechatronics Systems (AIMS), Bandung, Indonesia, 21–23 February 2024; pp. 1–6. [Google Scholar]
- Sarwar, M.I.; Abbas, Q.; Alyas, T.; Alzahrani, A.; Alghamdi, T.; Alsaawy, Y. Digital transformation of public sector governance with IT service management–A pilot study. IEEE Access 2023, 11, 6490–6512. [Google Scholar] [CrossRef]
- Isaca. Cobit 5; Information Systems Audit and Control Association: Schaumburg, IL, USA, 2012. [Google Scholar]
- Rusman, A.; Nadlifatin, R.; Subriadi, A.P. Analysis Factors Affect Information System Audit Using COBIT and ITIL Framework. J. Dan Penelit. Tek. Inform. 2022. [Google Scholar] [CrossRef]
- ISO/IEC 27001:2022; Information Security, Cybersecurity and Privacy Protection—Information Security Management Systems—Requirements. International Organization for Standardization: Geneva, Switzerland, 2022. Available online: https://www.iso.org/standard/27001 (accessed on 25 December 2025).
- ISO/IEC 38500:2024; Information Technology—Governance of IT for the Organization. International Organization for Standardization: Geneva, Switzerland, 2024. Available online: https://www.iso.org/standard/81684.html (accessed on 25 December 2025).
- Antariksa, M.D.S.; Angin, M.P.; Widodo, A.P. COBIT 2019 Framework in IT Governance: A Systematic Literature Review of Implementation Challenges and Benefits Across Various Industry Sectors. J. Renew. Energy, Electr. Comput. Eng. 2025, 5, 99–105. [Google Scholar] [CrossRef]
- Carter, L.; Yoon, V.; Liu, D. Analyzing e-government design science artifacts: A systematic literature review. Int. J. Inf. Manag. 2022, 62, 102430. [Google Scholar] [CrossRef]
- ISO/IEC 22301:2019; Security and Resilience—Business Continuity Management Systems—Requirements. International Organization for Standardization: Geneva, Switzerland, 2019. Available online: https://www.iso.org/standard/75106.html (accessed on 25 December 2025).








| DSR Component | Implementation in This Study (Local) | Theoretical Abstraction (General) |
|---|---|---|
| Artifact | CGR Service Integration Model. | SAI Governance Meta-Model. |
| Justificatory Knowledge | Institutional Theory. | Audit-Service Coupling Theory. |
| DP1 | Use of GLPI for ticket tracking | Automated Forensic Traceability. |
| DP2 | TOGAF ADM implementation | Modular Architecture for Oversight. |
| DP3 | KPI Dashboard and Pilot Feedback | Adaptive Governance Feedback Loop. |
| Dimension | Key Indicators (Main Results) | Descriptive Statistics (Means/Majority Responses) | Interpretation Summary |
|---|---|---|---|
| Availability and Access | 93.6% report services generally or always available; 81.8% consider access easy or very easy; 71.6% experience interruptions < 2 h; 73.9% report resolution < 10 h. | Mean = 4.3; SD = 0.6; Mode = 5 (High). | High service availability and accessibility; connectivity issues remain the main source of incidents. |
| Technical Support Quality | 94.1% rate staff as competent; 90.7% find incidents resolved definitively; 96.6% perceive strong commitment. | Mean = 4.5; SD = 0.4; Mode = 5. | Users highlight competence and responsiveness; communication and feedback consistency need improvement. |
| Technological Infrastructure | 80.9% state their equipment meets needs; 75% find the connection stable; 65% consider the infrastructure sufficient. | Mean = 3.9; SD = 0.8. | General adequacy of infrastructure, but equipment obsolescence and connectivity deficiencies persist, especially in territorial offices. |
| Security and Data Protection | 52% always and 46.3% generally feel secure; 92.6% consider their data protected; 70% show concern about cyberattacks. | Mean = 4.2; SD = 0.5. | Positive perception of cybersecurity; users request more training and stronger preventive tools (firewalls, antivirus, awareness). |
| Communication and User Attention | 47% generally receive notifications; 53.7% perceive communication as clear; 49% feel their opinions are considered. | Mean = 3.8; SD = 0.7. | Effective communication overall, but inconsistent; users demand clearer, more inclusive, and timely messages. |
| Innovation and Continuous Improvement | 52.8% perceive regular innovation; 73% affirm updates improve productivity; 43% recognize new tool proposals. | Mean = 3.9; SD = 0.6. | Moderate innovation perception; users highlight the need for unified systems, interoperability, and use of AI tools. |
| Overall Satisfaction | 82.4% satisfied or highly satisfied; 77% feel expectations are generally or always met; 81.3% would recommend IT services. | Mean = 4.1; SD = 0.5. | High overall satisfaction, with expectations for modernization, improved communication, and better connectivity. |
| Family | Current | Comment (Excerpt) |
|---|---|---|
| EDM (Evaluate, Direct, Monitor) | 2.60 | Governance intents are defined; reporting is partially standardized. |
| APO (Align, Plan, Organize) | 2.21 | Strategy/architecture are defined; portfolio and SLA management incipient. |
| BAI (Build, Acquire, Implement) | 1.82 | Project controls and change enablement heterogeneous across units. |
| DSS (Deliver, Service, Support) | 1.83 | Incident/problem continuity not fully institutionalized. |
| MEA (Monitor, Evaluate, Assess) | 1.75 | KPIs defined in templates; routine monitoring yet to be consolidated. |
| Practice | Score | Comment |
|---|---|---|
| Strategy Management | 3.50 | Strategic alignment and planning artifacts exist. |
| Risk Management | 3.18 | Risk registers and treatment plans are partially implemented. |
| Information Security Management | 3.00 | Policies in place; operationalization uneven across offices. |
| Service Desk | 2.86 | Escalation pathways are defined; heterogeneous response times. |
| Incident Management | 2.67 | Logging standardized; root cause and continuity procedures pending. |
| Service Design | 1.71 | Design templates are not consistently applied across services. |
| Service Level Management | 1.73 | SLA negotiation and review mechanisms in the early stages. |
| problem management | 1.60 | Root-cause analysis and knowledge capture are not systematic. |
| ID | Indicator Name | Unit | Target (Meta) |
|---|---|---|---|
| IND-ES-1 | Overall IT service availability | Percentage (%) | 0.90 |
| IND-OP-4 | Incident response time compliance (SLA) | Percentage (%) | 0.90 |
| IND-OP-8 | Mean Time to Repair (critical services) | Hours | <4 h |
| IND-PR-5 | Project on-time delivery rate | Percentage (%) | 0.90 |
| IND-OP-6 | Scheduled maintenance adherence | Percentage (%) | 0.90 |
| IND-OP-7 | Security incident closure within timeframe | Percentage (%) | 0.90 |
| Framework | Key Implementation Activities | Institutional Deliverables |
|---|---|---|
| TOGAF | Application of ADM to design enterprise, data, and technology architectures; mapping fiscal oversight processes and interoperability requirements among SIGECI, SIRECI, SIGEDOC, APA, and SIREF. | Enterprise Architecture Model; Interoperability diagrams; Infrastructure and Demand Reports. |
| ITILv4 | Formalization of 23 management procedures and creation of the Service Catalog and SLAs; configuration of monitoring and escalation workflows. | Institutional Service Catalog (67 services); Standardized ITSM documentation; Operational dashboards. |
| COBIT 2019 | Definition of governance objectives, roles, and performance indicators integrated with PETI 2022–2026. | Governance RACI structure; KPI dashboard (availability, MTTR, satisfaction, SLA compliance, Audit Velocity, Forensic Integrity); Continuous Improvement Plan. |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2025 by the authors. Published by MDPI on behalf of the International Institute of Knowledge Innovation and Invention. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Villamil, R.M.; Restrepo-Carmona, J.A.; Escobar, A.; Aponte-Moreno, A.; Herrera, J.A.; Gutiérrez-Betancur, S.A.; Fletscher, L. An Enterprise Architecture-Driven Service Integration Model for Enhancing Fiscal Oversight in Supreme Audit Institutions. Appl. Syst. Innov. 2026, 9, 16. https://doi.org/10.3390/asi9010016
Villamil RM, Restrepo-Carmona JA, Escobar A, Aponte-Moreno A, Herrera JA, Gutiérrez-Betancur SA, Fletscher L. An Enterprise Architecture-Driven Service Integration Model for Enhancing Fiscal Oversight in Supreme Audit Institutions. Applied System Innovation. 2026; 9(1):16. https://doi.org/10.3390/asi9010016
Chicago/Turabian StyleVillamil, Rosse Mary, Jaime A. Restrepo-Carmona, Alejandro Escobar, Alexánder Aponte-Moreno, Juliana Arévalo Herrera, Sergio Armando Gutiérrez-Betancur, and Luis Fletscher. 2026. "An Enterprise Architecture-Driven Service Integration Model for Enhancing Fiscal Oversight in Supreme Audit Institutions" Applied System Innovation 9, no. 1: 16. https://doi.org/10.3390/asi9010016
APA StyleVillamil, R. M., Restrepo-Carmona, J. A., Escobar, A., Aponte-Moreno, A., Herrera, J. A., Gutiérrez-Betancur, S. A., & Fletscher, L. (2026). An Enterprise Architecture-Driven Service Integration Model for Enhancing Fiscal Oversight in Supreme Audit Institutions. Applied System Innovation, 9(1), 16. https://doi.org/10.3390/asi9010016

