ITSM-Strategie · 14. April 2026 · 12 Min. Lesezeit · DE / EN

Governance: Immer versprochen.
Selten geliefert.
Und es gibt keine perfekte Lösung.

Über OOTB-Fantasien, KI-Heilsversprechen, CMDB-Religion und die einfache, unbequeme Wahrheit, dass keine Technologie das jemals einfach machen wird — nur weniger schwer.

Frank Eck
Frank Eck
Founder & Managing Director, Flow-IT
LinkedIn
Zurück zum Blog Governance
Titelbild folgt

Ersparen Sie sich das Konferenzticket. Ich habe genug Sessions besucht, genug White Papers gelesen und genug Vendor-Briefings durchgehalten, um die letzten drei Jahrzehnte der Unternehmens-IT in einem einzigen Satz zusammenzufassen: Wir erfinden dasselbe kaputte Versprechen immer wieder neu — nur mit besserem Marketing.

Die aktuelle Dreifaltigkeit: Out-of-the-Box-Konfiguration, Künstliche Intelligenz und CMDB. Davor war es ERP, BPR und der Service Desk. Davor etwas anderes, und davor wieder etwas anderes. Die Besetzung rotiert. Das Skript nicht.

Und mitten in jedem dieser Zyklen sitzt das Wort Governance — feierlich, autoritativ und fast vollständig dekorativ.

Eines vorab: Es gibt keine perfekte Lösung. Nicht für Governance. Nicht für OOTB. Nicht für KI im IT-Betrieb. Nicht für Stammdaten. Nicht für irgendetwas davon. Je früher wir aufhören, nach einer zu suchen, desto früher können wir etwas tatsächlich Nützliches tun.

Let me save you the conference ticket. I have attended enough sessions, read enough white papers, and sat through enough vendor briefings to summarise the last three decades of enterprise IT in a single sentence: we keep reinventing the same broken promise with better marketing.

The current trinity is Out-of-the-Box configuration, Artificial Intelligence, and CMDB. Before that it was ERP, BPR, and the service desk. Before that it was something else, and before that something else again. The cast rotates. The script does not.

And somewhere in the middle of every single one of these cycles sits the word governance — solemn, authoritative, and almost completely decorative.

Let me be clear about something before we go further: there is no perfect solution. Not for governance. Not for OOTB. Not for AI in IT operations. Not for master data. Not for any of it. The sooner we stop looking for one, the sooner we can do something actually useful.

Die Governance-Liturgie

Ich habe in dreißig Jahren, über Branchen, Geographien und Reifegrade hinweg — von „wir tracken noch alles in Excel" bis „wir haben eine dedizierte Platform-Engineering-Abteilung" — noch kein Unternehmen erlebt, das keine Governance wollte. Alle wollen Governance. Governance ist das organisatorische Äquivalent des Wunsches, sich gesünder zu ernähren: universell befürwortet, selektiv praktiziert.

Das Muster ist immer dasselbe. Ein Projekt startet. Jemand zeichnet eine RACI. Ein Lenkungsausschuss wird gebildet. Namenskonventionen werden dokumentiert. Genehmigungsworkflows werden entworfen. Rollendefinitionen werden erstellt.

„Governance scheitert nicht in der Designphase. Es scheitert in der Wartungsphase — und Wartung hat, anders als der Launch-Tag, keinen Champagner." — F. Eck

Dann geht das Projekt live. Der Lenkungsausschuss trifft sich zweimal, dann beginnen Absagen. Die Namenskonventionen werden von dem Team ignoriert, das nicht im Raum war, als sie geschrieben wurden. Der Genehmigungsworkflow wird umgangen, weil jemand einen Deadline hat. Die Rollendefinitionen liegen in einem SharePoint-Ordner, den seit dem initialen Rollout-Review niemand mehr geöffnet hat.

Gibt es ein perfektes Governance-Modell, das all das verhindert? Nein. Jedes Modell ist ein Kompromiss zwischen dem theoretisch Richtigen und dem, was eine Organisation realistisch aufrechterhalten kann. Das ehrliche Ziel ist keine perfekte Governance — es ist Governance, die den Kontakt mit dem Montagmorgen überlebt.

I have yet to work with a company, in thirty years, across industries, geographies, and maturity levels — ranging from "we still track things in Excel" to "we have a dedicated platform engineering department" — that did not want governance. Everyone wants governance. Governance is the organisational equivalent of wanting to eat healthier: universally endorsed, selectively practised.

The pattern is always the same. A project kicks off. Someone draws a RACI. A steering committee is formed. Naming conventions are documented. Approval workflows are designed. Role definitions are created.

"Governance does not fail at the design stage. It fails at the maintenance stage — and maintenance, unlike launch day, has no champagne." — F. Eck

Then the project goes live. The steering committee meets twice, then starts cancelling. The naming conventions are ignored by the team that wasn't in the room when they were written. The approval workflow is bypassed because someone has a deadline. The role definitions sit in a SharePoint folder that no one has opened since the initial rollout review.

Is there a perfect governance model that prevents all of this? No. There is not. Every model is a compromise between what is theoretically correct and what an organisation can realistically sustain. The honest goal is not perfect governance — it is governance that survives contact with Monday morning.

Die OOTB-Illusion

Out-of-the-Box-Konfiguration ist ein wunderschönes Konzept. Die Plattform so nutzen, wie sie designed wurde. Customization-Schulden vermeiden. Auf dem Upgrade-Pfad bleiben. Schnellere Time-to-Value erzielen. Das sind echte Vorteile, und ich habe jahrelang dafür plädiert.

Aber „OOTB" ist zu einem rhetorischen Mittel geworden — einer Möglichkeit, das härtere Gespräch über die Prozessdisziplin zu vermeiden, die OOTB tatsächlich erfordert. Sie können ServiceNow am Tag eins OOTB deployen. Was Sie nicht können: es OOTB betreiben ohne operative Disziplin am Tag dreihundert.

Die Plattform wartet sich nicht selbst. Die Daten kuratieren sich nicht selbst. Die Nutzer schulen sich nicht selbst um, wenn sich ein Prozess ändert.

ℹ️

Die entscheidende FrageNicht: „Haben wir es beim Go-live korrekt konfiguriert?" Sondern immer: „Wer ist am vierhundertsten Tag dafür verantwortlich — und hat diese Person die Zeit, Autorität und das Mandat, tatsächlich etwas zu tun?" Es gibt keine Konfiguration, die diese Frage zum Verschwinden bringt.

Out-of-the-Box configuration is a beautiful concept. Use the platform as it was designed. Avoid customisation debt. Stay on the upgrade path. Achieve faster time-to-value. These are all real benefits, and I have spent years advocating for them.

But "OOTB" has become a rhetorical device — a way to avoid the harder conversation about the process discipline that out-of-the-box actually requires. You can deploy ServiceNow OOTB on day one. What you cannot do is run it OOTB without operational discipline on day three hundred.

The platform does not maintain itself. The data does not curate itself. The users do not retrain themselves when a process changes.

ℹ️

The real questionNot: "Did we configure it correctly at go-live?" Always: "Who is responsible for it on the four hundredth day, and do they have the time, authority, and mandate to actually do anything?" There is no configuration that makes this question go away.

Über die KI

Ich werde nicht argumentieren, dass KI nutzlos ist. Das ist sie nicht. Ich verwende sie täglich. Sie macht mich schneller bei Dingen, die ich bereits beherrsche, und überrascht mich gelegentlich.

Aber das KI-Gespräch im Enterprise-IT hat derzeit eine messianische Qualität, die ich erschöpfend finde. Das implizite Versprechen — manchmal das explizite — ist, dass KI das Governance-Problem lösen wird. Dass sie die Daten beobachtet, Anomalien kennzeichnet, Lücken füllt, Regeln durchsetzt.

„KI erbt die Qualität der Umgebung, in der sie operiert. Garbage in, garbage out. Sie können sich nicht durch ein Disziplindefizit automatisieren."

KI ist ein Werkzeug. Ein wirklich nützliches in den richtigen Händen, mit den richtigen Daten, im richtigen Kontext. Es ist keine Lösung für die organisatorischen Probleme, die schlechte Daten und kaputte Prozesse überhaupt erst erzeugen. Diese Unterscheidung ist enorm wichtig — und die Industrie tut derzeit ihr Bestes, sie zu verschleiern.

I am not going to argue that AI is useless. It is not. I use it every day. It makes me faster at things I already know how to do, and occasionally it surprises me.

But the AI conversation in enterprise IT right now has a messianic quality that I find exhausting. The implicit promise — sometimes the explicit promise — is that AI will resolve the governance problem. That it will watch the data, flag the anomalies, fill the gaps, enforce the rules.

"AI inherits the quality of the environment it operates in. Garbage in, garbage out. You cannot automate your way out of a discipline deficit."

AI is a tool. A genuinely useful one in the right hands, with the right data, in the right context. It is not a solution to the organisational problems that create bad data and broken processes in the first place. That distinction matters enormously — and the industry is currently doing its best to obscure it.

Stammdaten und das Problem des lebenden Organismus

Ein Unternehmen ist keine Datenbank. Es ist ein lebender Organismus. Es wächst, was Schmerz verursacht: neue Abteilungen, neue Systeme, neue Beziehungen, die niemand gemappt hat. Es schrumpft, was eine andere Art von Schmerz verursacht: Fusionen, Redundanzen, decommissionierte Systeme, die irgendwie noch drei Jahre nach der Abschaltung im Asset-Register auftauchen.

Stammdaten-Governance operiert unter der Annahme, dass es eine stabile, kanonische Wahrheit über die Organisation gibt, die erfasst, gepflegt und referenziert werden kann. Es gibt sie nicht. Es gibt eine Wahrheit, die letztes Quartal ungefähr korrekt war, jetzt teilweise korrekt ist und vor dem nächsten Planungszyklus wieder überarbeitet werden muss.

💡

Das ist kein Versagen — das ist Biologie. Keine Stammdatenstrategie ändert diese fundamentale Realität. Der Organismus bewegt sich weiter. Die Daten hinken hinterher. Die Lücke zwischen ihnen ist kein zu lösendes Problem; es ist ein zu managender Zustand.

A company is not a database. It is a living organism. It grows, which causes pain: new departments, new systems, new relationships that nobody mapped. It shrinks, which causes a different kind of pain: mergers, redundancies, sunset systems that still somehow appear in the asset register three years after decommissioning.

Master data governance operates on the assumption that there is a stable, canonical truth about the organisation that can be captured, maintained, and referred to. There is not. There is a truth that was approximately correct last quarter, is partially correct now, and will need revision again before the next planning cycle.

💡

That is not a failure — that is biology. No master data strategy changes this fundamental reality. The organism keeps moving. The data keeps lagging. The gap between them is not a problem to be solved; it is a condition to be managed.

Was dreißig Jahre wirklich gelehrt haben

Jede Technologie, jeder Prozess, jede Organisationsstruktur erfordert harte Arbeit, um zu funktionieren. Das ist kein ServiceNow-Phänomen. Kein SAP-Phänomen. Kein Cloud-Phänomen. Es ist die fundamentale, nicht verhandelbare Realität des Betriebs komplexer Systeme in komplexen Organisationen.

Der ehrliche Rat lautet nicht: „Finde eine bessere Plattform." Nicht: „Implementiere KI." Nicht: „Gehe OOTB." Er lautet: Entscheide, was du tatsächlich bereit bist zu warten, besetz es ordentlich, gib jemandem echte Verantwortung dafür, und sei ehrlich mit dir selbst, wenn die Lücke zwischen deinem Governance-Design und deiner Governance-Realität sich zu weiten beginnt.

„Siebenmal fallen. Achtmal aufstehen. Dann die CMDB aktualisieren, die Genehmigungsgruppe neu zuweisen und dokumentieren, was sich geändert hat — denn niemand sonst wird es tun, und kein Tool wird es für dich erledigen." — F. Eck

Was helfen könnte — schrittweise, unvollkommen, nachhaltig — ist eine Organisation, die aufhört zu warten, bis die Technologie Governance einfach macht, akzeptiert, dass keine solche Technologie kommt, und beginnt, die unspektakuläre Arbeit des tatsächlichen Governierens zu erledigen.

Any technology, any process, any organisational structure requires hard work to keep running. This is not a ServiceNow phenomenon. Not an SAP phenomenon. Not a cloud-era phenomenon. It is the fundamental, non-negotiable reality of operating complex systems in complex organisations.

The honest advice is not "find a better platform." Not "implement AI." Not "go OOTB." It is: decide what you are actually willing to maintain, staff it properly, give someone real accountability for it, and be honest with yourself when the gap between your governance design and your governance reality starts to widen.

"Fall down seven times. Stand up eight. Then update your CMDB, reassign the approval group, and document what changed — because nobody else will, and no tool will do it for you." — F. Eck

What might help — gradually, imperfectly, sustainably — is an organisation that stops waiting for the technology to make governance easy, accepts that no such technology is coming, and starts doing the unglamorous work of actually governing.

Governance ITSM-Strategie OOTB KI / AI CMDB Stammdaten ServiceNow
Frank Eck
Frank Eck

Frank Eck ist Gründer und Geschäftsführer der Flow-IT GmbH, einer unabhängigen ServiceNow-Beratung mit Sitz in Deutschland und einem Competence Centre in der Slowakei.

Hinweis: Dieser Artikel wurde mit Hilfe eines KI-Avatars erstellt.

Artikel teilen: LinkedIn

Governance in der Praxis umsetzen?

Wir helfen Organisationen dabei, Governance-Strukturen aufzubauen, die den Alltag überleben — herstellerunabhängig, pragmatisch, nachhaltig.