This study proposes the CTRI (COBIT Transition and Risk Integration) framework, a novel methodological integration for IT governance evaluation in SMEs. Unlike prior COBIT 4.1 studies that only report maturity gaps, the CTRI framework addresses three critical gaps: (1) lack of actionable recommendations, (2) absence of risk and feasibility considerations, and (3) no systematic bridge from COBIT 4.1 to COBIT 2019. The CTRI framework consists of three integrated layers. Layer 1 quantifies maturity gaps across six COBIT 4.1 domains (PO2, AI2, AI6, DS5, DS11, ME1). Layer 2 introduces the Risk–Feasibility Priority Matrix (RFPM) which calculates a Priority Action Score (PAS) = Risk Impact × Implementation Feasibility, where risk impact is high (3), medium (2), or low (1), and feasibility is easy (3), moderate (2), or difficult (1). Recommendations with PAS ≥ 6 are top priority. Layer 3 provides explicit transition mapping from each COBIT 4.1 recommendation to COBIT 2019 governance objectives and design factors. Applied to a sales application at PT Ciequ (Indonesian SME), data were collected via observation, interviews with three key informants, and documentation review. Findings reveal an average maturity level of 2.45, with largest gaps in AI2 (1.23) and DS5 (0.89). The RFPM prioritizes AI2 (PAS=9), DS5 (PAS=6), and AI6 (PAS=6) as top actions. A three-phase transition roadmap (Stabilize → Standardize → Monitor) to COBIT 2019 is provided, with APO13 (security) and APO05 (portfolio) as priority objectives. This study contributes a reusable, risk-aware, transition-forward methodology that bridges legacy and modern IT governance frameworks for resource-constrained SMEs.
Copyrights © 2026