This study aims to evaluate the IT governance and management at the Banjarmasin Regional Library using the COBIT 5 framework, specifically focusing on the EDM03 (Ensure Risk Optimization) and APO12 (Manage Risk) domains. The evaluation is conducted to assess the maturity level in managing IT risks and the alignment between IT and the organization’s strategic objectives. Data collection methods include observations and interviews with IT staff and library management, which are then analyzed using COBIT 5 indicators. The results show that the maturity level in the EDM03 domain is at level 1 (Performed), while APO12 is at level 2 (Managed), with an overall average of 1.41. The gap analysis reveals a significant discrepancy between the current condition and the desired target, with an average gap value of 3.59. These results indicate the need for continuous improvement and the implementation of more structured IT governance and risk management to achieve efficiency, security, and strategic alignment within the library environment.