The rapid development of information technology today requires every company to continually evolve by adopting the latest technologies. On the other hand, the application of information technology requires substantial investment and poses a considerable risk of failure. Company conditions like this require consistency in managing the application of information technology. Therefore, companies need to implement risk management to identify potential risks when implementing information technology. The COBIT 4.1 framework is the framework that best suits the needs of the company because it ensures that information technology has been aligned with business processes, identifies risks, assesses risks, handles risks appropriately, maps maturity levels, and produces recommendations to be able to achieve targets that are in accordance with the company's wishes.