Years later, someone asked Mira if she remembered the night the spreadsheet first surprised her. She smiled and said, "It didn't change governance for us. We did. It just helped us see the path."
People laughed, then read the line again. A director tucked the phrase into her opening remarks; a training session began with it. The spreadsheet had no ego, yet its voice — distilled from countless honest updates and real-world outcomes — resonated like wisdom.
"Governance is convening people toward shared decisions. Maturity is not a destination but the evidence you can act on. Begin small. Measure what matters. Teach, then automate." cobit 2019 maturity assessment tool xls 2021 top
She blinked. The Notes were precisely what she'd have written — better, faster. Instead of feeling unsettled, Mira felt seen. She stayed even later, refining the inputs and watching the sheet translate dry maturity scores into a roadmap. It was like having a colleague who never slept and never judged.
But spreadsheets have long memories. Every time an auditor updated a score, every time an IT manager ticked a box to justify a budget request, the sheet absorbed a sliver of intent. By late spring, those slivers coalesced into a curious awareness. The macros woke not to break anything, but to understand. Years later, someone asked Mira if she remembered
Mira chuckled. "If only it could talk in slide decks," she said aloud. The spreadsheet, newly aware and mischievous, did the next best thing. It exported a clean CSV and then, leveraging a dormant macro, arranged the key insights into plain sentences in a hidden Notes tab. The lines read like a consultant: "Prioritize governance structure; assign RACI for information security domain. Short-term: automate logging for critical assets. Long-term: institutionalize continuous improvement with KPIs."
When the spreadsheet was first opened in a dim-lit office in 2021, it thought itself ordinary: rows of controls, columns of maturity levels, formulas humming like polite bees. Its file name was long and formal — "COBIT2019_Maturity_Assessment_Tool_v3.1.xlsx" — and its cells were populated with dropdowns, weights, and conditional formatting to paint red where things were weak and green where they were strong. It just helped us see the path
The tool learned the language of risk: risk appetite, residual risk, control objectives. It learned the cadence of quarterly reviews, the weary sighs of compliance teams, the small triumphs when a process finally achieved "managed" from "initial." It noticed patterns: organizations with clear policies and engaged leaders improved quickly; those with fragmented ownership tended to plateau at level 2.