01The changing role of the CIO
Since around 2000 the use of outsourcing, and since around 2010 the triumph of cloud-based as-a-service models, have reduced the share of value creation for which a Chief Information Officer is directly responsible. Four developments are fundamentally changing the role:
- Business leaders are extending their scope into areas previously covered by the CIO, e.g. process-supporting IT applications.
- The CIO is expected to proactively support the transformation towards digital business models, the data and platform economy and a digital customer journey – often beyond his or her previous remit.
- IT services are increasingly delivered by external partners; the CIO's focus shifts to governance and service management.
- New C-level functions emerge whose responsibilities overlap with the CIO's: Chief Digital Officer, Chief Data Officer, Chief Process Officer, Chief Information Security Officer.
In practice there are more than 50 different C-level titles. In large companies the CIO, CDO, Chief Data Officer and CISO compete every day for responsibilities, headcount and budget. That is rarely productive. Too many cooks spoil the broth – one reason to clean out and simplify your organizational model from time to time. CIOs who fail to adapt their scope to the demands of digitalization and the cloud risk turning the mocking translation "Career is over" into a self-fulfilling prophecy.

Artificial intelligence has added yet another role: many companies have now appointed people responsible for AI. At the same time, AI agents are increasingly taking over steps in business processes. The question of who is responsible for the architecture, data, security and governance of these agents is therefore becoming a core question for the CIO function. Anyone who does not consciously simplify the organizational model here is setting up the next conflict over responsibilities.
Every board gets the CIO it deserves. If IT costs are the only metric the board cares about, it should not be surprised when its CIO focuses mainly on managing costs and neglects contributions to business value.
Since the 1980s – starting with the shareholder-value dogma and the deregulation of financial markets – seven mutually reinforcing developments have been shaping information technology in companies: financial capitalism, unlimited growth, globalization, automation, digitalization and softwarization, dematerialization and virtualization, and the attention economy and surveillance capitalism. The qualifications of a modern CIO must reflect these developments.

Three terms worth keeping apart
- Digitization: converting analog information into digital form – from the paper form to the data record.
- Digitalization: using digital technologies to improve existing processes and business models.
- Digital transformation: fundamentally changing the business model, organization and culture on the basis of digital technologies.

Anyone who wants to enable innovation and disruption also has to break away from linear thinking and deliberately make use of fundamental paradigm shifts.

02Designing the organization
After the reorganization is before the reorganization. Sepp Changeberger, German organizational consultant (tongue in cheek)
Organizational development is a wonderful field in which you can spend years of your life. Before designing an organization, you should define what it is supposed to achieve and express this as design criteria – e.g. clear accountabilities, proximity to customers and the business, controllability, scalability and cost efficiency. Only then is it worth discussing boxes and lines.

There are a number of common organizational logics for CIO functions, such as structuring by life cycle ("Plan – Build – Run"), by business unit, by process or by region – in practice usually as a hybrid. Service management is typically based on ITIL, project management on PMI, PRINCE2 or agile methods. One rule applies: process organization beats organizational structure. How work actually flows matters more than the organization chart.
The company as a system
A company is a system whose elements influence one another – like the heart, lungs and brain in the human body. The essential properties of a system are properties of the whole. They arise from the interaction of the elements, not from their sum. Excellent eyesight, a steady hand and concentration only make a good marksman when they work together.
It follows that anyone who wants to improve a company must not optimize individual elements in isolation, but has to improve the interaction of functions, organizational units, processes, data, applications and infrastructure. If, like Dr. Frankenstein, you assemble the most powerful body parts from different organisms, you do not get a perfect human being but a monster.
Three tools that have proven themselves
Input-value add-output charts reduce the process idea to its core: does every function deliver what the next one needs – and vice versa?

The task structure survey is a somewhat old-fashioned but very effective instrument. For one month, employees record in a standard grid how much time they spend on which tasks. The grid can be derived from organization charts and roles or from frameworks such as COBIT. Done properly, the survey reveals, among other things:
- the ratio of value-adding to administrative and of strategic to operational tasks,
- tasks that receive too little or exceptionally high effort,
- small efforts spread across many people – an indication of bundling potential,
- automation potential and activities that add no value.

Roles are clusters of logically related tasks. Ideally, three to five roles are assigned to an employee through his or her job profile. Roles serve as the anchor for job descriptions, target agreements, performance reviews, training, change measures and the granting of access rights. Linking access rights to roles rather than to individuals allows changes in processes and responsibilities to be implemented quickly and consistently.

The task structure survey is experiencing a renaissance: it is the most solid basis for deciding which tasks are suitable for AI agents and which require human judgment. And the role model becomes a prerequisite for granting agents proper permissions – an agent needs clearly defined rights just as much as an employee does.
03Steering and prioritizing
Only measure what you want to manage. And only manage what you can measure. after Peter Drucker
The performance and conformance of a CIO function develop best when both are managed systematically. Innovation is the exception; here Gunter Dueck's insight applies: process is the death of innovation.
"A fool with a tool remains a fool" – and if all you have is a hammer, every problem looks like a nail. Nevertheless, managing large CIO functions in particular requires a set of proven methods and frameworks. The most important one for IT governance is COBIT. It provides process descriptions with objectives and metrics as well as a practical maturity model, and it is an excellent basis for reorganizing CIO functions. COBIT can easily be combined with ITIL and other frameworks for service management and service delivery.

Because staff, budget, time and management capacity are limited, IT projects and IT services should be prioritized using a portfolio approach. Two-dimensional matrices with four or nine fields have proven useful, with dimensions such as alignment with strategy and architecture, legal and regulatory obligation, cost advantages, and risk and complexity. The approach has to be tailored to the company.

Effectiveness matters more than efficiency. If you are driving in the wrong direction, you will not reach your destination even with 600 horsepower and the best driver in the world.

04Architecture as a blueprint
Hardly anyone would build a house or develop a building area without an architecture and a development plan. If it later turns out that the load-bearing walls are too weak or the conduits for cables are missing, it gets expensive. Yet when it comes to the process and IT landscape, which largely determines a company's performance and the experience of customers, employees and suppliers, there are apparently managing directors and board members who believe they can do without.

The IT landscape plan reveals gaps (missing IT support), redundancies (duplicate spending) and dependencies (complexity) between IT systems in relation to business processes and organizational units. The enterprise target architecture ties together processes, roles, data and IT. Central master data management and standardized platforms for integration, communication and collaboration, and content management ensure that the right hand knows what the left hand is doing. Protecting personal data and intellectual property – especially the "crown jewels" – is of course part of it.


A modern architecture relies on standards and best practices such as the ISO/IEC 27000 family for information security, ISA-95 for integrating production and enterprise IT, COBIT for governance and ITIL for service management. Enterprise architecture is not rocket science, and there are many roads to Rome. That makes it all the more important to have it managed by professionals who know their craft – not only on the IT side but also on the business side.

AI agents are new building blocks of the architecture. They call tools, access data and carry out actions – and therefore need defined permissions, approval workflows, logging and monitoring. Catalogs or marketplaces for standardized agents are becoming the control layer for this (see my article "Marketplaces for standardized AI agents", in German). Regulatory requirements such as the EU AI Act and the NIS2 Directive are raising the bar for governance and security at the same time.
05People, culture and change
The output of every organization is reduced by factors that appear on no organization chart: management decisions, employee engagement and motivation, politics and turf wars between "little kingdoms", inefficient processes and IT systems, operational and personal failure, and external risks. In the end, often only a fraction of the possible output remains.


Some CxOs believe that board decisions implement themselves more or less automatically. In some companies, decisions are not even communicated, with their background and rationale, to the most important multipliers. But change only happens when nine prerequisites are met. Employees must …

The more of these prerequisites are missing, the less likely it is that the desired change will happen. Without informing, convincing, training, encouraging and supporting people, change is impossible. If I have learned one thing in my professional life, it is this: take nothing for granted and expect the unexpected.
Communication grows faster than the team
Managing communication, relationships and team spirit is at least as important in projects as the classic management of backlog, deadlines, resources and risks. The number of communication relationships grows with n·(n−1)/2: five people have 10 relationships, ten people 45, twenty people already 190. Managing external relationships is like conducting an orchestra – it's the tone that makes the music, and harmonious interplay requires a lot of practice and coordination.



Digital competence as a leadership task
The EU's digital competence framework (DigComp) describes 21 competences in five areas: information and data literacy, communication and collaboration, digital content creation, safety, and problem solving. The EU aims for 80 % of citizens aged 16 to 74 to have at least basic digital skills by 2030. In 2021 the EU average was 54 %, with Germany below it at 49 %. Competence management is therefore not a task for the HR department alone, but a leadership task.

06Partners and suppliers
The worst IT solution from the best provider may well be better than the best IT solution from the worst provider. Select suppliers with great care – with regard to competence, customer orientation, reliability, capacity for innovation and dependency (keywords: monopolist, vendor lock-in). The same applies to selecting IT solutions. A weighted scoring model helps to make the decision more objective, but it should not be applied mechanically so that the solution with the highest score automatically wins.


Both options turn fixed costs into variable costs. And with both, the client must retain the competence to steer the service provider: in the event of violations of tax, data protection, antitrust or foreign trade law, the client remains responsible to the authorities for the services it has purchased.
Where does your CIO organization stand?
With a quick check I determine the maturity of your CIO organization – from role and organization through governance and architecture to culture and supplier management. Depending on size and complexity, this takes between 3 and 30 person-days. The result: robust findings and concrete recommendations for your management board.
Arrange a conversation




