Client Background

The client is a leading, long-established bank in the UAE with a broad retail, corporate and treasury franchise supported by a large and complex technology estate. Internal audit reviews and regulatory technology examinations had surfaced recurring issues in how incidents, problems, changes and control objectives were governed, tracked and closed. Ticket ownership was split between teams, performance was reported from several tools that rarely agreed, and governance forums met irregularly without clear terms of reference. The bank wanted to align its IT service management and IT governance practices with international standards, and engaged Cedar to run a current-state diagnostic as the first module of a wider programme spanning framework design and execution support.

Cedar’s Approach

Cedar applied a structured diagnostic across people, process and technology, benchmarking every observation against ITIL 4 and COBIT 2019 and grading it through Cedar's impact-rating framework, which classifies gaps as high, medium or low according to their effect on service stability, compliance and strategic alignment. The five-week diagnostic combined stakeholder insight with hard evidence drawn from the bank's own records.

Stakeholder Discovery – Cedar held more than 30 interviews with over 14 stakeholders across IT governance, risk and control, service management, technology operations and the service desk, followed by walkthroughs with six heads of technology line functions to validate findings and ownership.

Evidence-Based Review – The team analysed a full year of incident data, sampled root cause analyses, ticket categorisation and prioritisation rules, application scorecards, governance forum minutes, risk and issue logs, and open internal audit and regulatory observations, documenting evidence for each gap rather than relying on opinion.

Gap Consolidation – Findings were captured as 54 observations spanning service management, IT governance and other audit findings, then consolidated into 14 thematic gaps covering governance forums, dashboards and reporting, ticket ownership, communication, quality assurance, tool configuration, knowledge management, risk tracking, control objectives and culture.

Recommendations – For each theme Cedar defined targeted remedies: a governance charter with formal forums, escalation matrix and RACI; a single MIS team and CIO dashboard fed from one source of truth; consolidation of ticket ownership within service management; formal triage protocols; a centralised QA and testing centre of excellence with quality tollgates; an IT service scorecard; an accountable knowledge management function supported by AI-assisted recommendations; a bank-wide RAID log; automated monitoring of control objectives aligned to regulatory guidelines; and role-level KPIs to build a one-team culture.

Strategic Outcome and Way Forward

The diagnostic gave the bank's technology leadership an evidence-backed, prioritised view of where service management and governance fell short of recognised standards, and why recurring audit findings were slow to close. Each gap was linked to a clear recommendation and impact rating, allowing management to sequence remediation by risk rather than by the loudest issue.

The way forward moves into governance and control framework design, including the governance framework, CIO dashboard and a dedicated governance day, followed by action-plan alignment with line function heads and a twelve-week period of Cedar execution support to embed the recommendations.

Relevant Client Cases