ITIL 5 SL : Strategic Risk & Resilience (Domain 2)
ITIL 5 – Strategic Leader : Certified ITIL Strategic Leader - Domain 2 - Strategic Risk, Resilience and Portfolio Management
This study guide provides a comprehensive analysis of Domain 2: Strategic Risk, Resilience and Portfolio Management, which constitutes 16.25% of the ITIL 5 Strategic Leader (SL) qualification. The domain focuses on the intersection of enterprise strategy, governance, and the management of digital products and services (DPSM). It equips professionals to lead organizational change and manage complexity in AI-enabled environments.
1. Foundations of Strategic Risk
Strategic risk management in the ITIL 5 framework represents a shift from operational IT management toward the strategic oversight of digital products and services. In this context, risk is not merely an operational concern but a fundamental aspect of enterprise strategy and governance.
The Strategic Context
Organizations operating in modern digital ecosystems must navigate a Volatile, Uncertain, Complex, and Ambiguous (VUCA) environment. Strategic risk foundations are built upon the ability to align technology investments with business outcomes. The ITIL 5 Strategic Leader designation requires a mastery of two primary modules that address these risks:
- Direct, Plan and Improve (DPI): Focuses on governance, strategic alignment, and risk management at the portfolio level.
- Digital and IT Strategy (DITS): Emphasizes digital strategy authoring, disruption response, and aligning IT strategy to broader business goals.
Governance and the Three Lines of Defense
Board-level governance is critical for establishing the foundations of strategic risk. The “Three Lines of Defense” model is utilized to provide a structured approach to risk and assurance. This model ensures that:
- First Line: Management provides internal control and execution.
- Second Line: Risk management and compliance functions provide oversight.
- Third Line: Internal audit provides independent assurance to the board.
Strategic leaders use these foundations to ensure that every technology investment supports the organization’s vision and purpose while maintaining ethical and regulatory compliance, particularly regarding AI governance and digital ethics.
2. The Strategic Risk Register
The strategic risk register is a core tool utilized at the portfolio level to document, track, and manage risks that could impact the organization’s long-term objectives. Unlike operational risk registers, which may focus on technical failures, the strategic risk register focuses on factors that influence the organization’s competitive positioning and value realization.
Components of the Strategic Risk Register
The register acts as a repository for risks identified through the Strategy Development Lifecycle. Key data points captured in the register include:
| Component | Description |
|---|---|
| Risk Identification | Recognition of threats and opportunities arising from PESTLE factors (Political, Economic, Social, Technological, Legal, Environmental). |
| Strategic Impact | Evaluation of how the risk affects the organization’s purpose, vision, and long-term direction. |
| Mitigation Strategies | Planned actions to reduce the likelihood or impact of negative risks, including “build, buy, or partner” decisions. |
| Ownership | Assignment of responsibility to senior leaders or portfolio managers. |
Integration with Portfolio Management
The strategic risk register is not a static document; it is an active component of portfolio-level decision-making. It informs investment prioritization by highlighting which initiatives carry the highest risk-to-reward ratios. In AI-enabled contexts, the register must also account for risks related to data strategy, transparency, and accountability.
3. Risk Appetite and Tolerance
Strategic leaders must define the organization’s risk appetite—the amount of risk they are willing to accept in pursuit of strategic objectives. Risk tolerance provides the specific, measurable thresholds for those risks.
Defining Thresholds in VUCA Environments
In a VUCA environment, setting risk appetite requires a balance between innovation and stability. Organizations pursuing aggressive digital transformation may have a high appetite for technological risk but a low tolerance for risks involving digital ethics or sustainability (ESG) reporting.
Strategic Considerations
- Alignment with Values: Risk appetite must reflect the organization’s core values and purpose.
- Sustainability and ESG: Long-term strategic success depends on balancing risk with environmental and social governance. Strategic leaders must ensure risk appetite levels do not compromise ESG targets.
- AI Governance: Risk tolerance for AI adoption focuses on responsible, ethical, and compliant use. Leaders must set clear boundaries regarding transparency and accountability in automated decision-making.
By establishing clear appetite and tolerance levels, strategic leaders can delegate decision-making authority while ensuring that execution remains aligned with the enterprise’s strategic direction.
4. Operational Resilience in Digital Ecosystems
Operational resilience is the ability of an organization to withstand, adapt to, and recover from disruptions within its digital ecosystem. As organizations transition toward digital product and service management (DPSM), resilience becomes a strategic differentiator.
Building Resilient Operating Models
Strategic leaders focus on Target Operating Model (TOM) design to ensure resilience. This involves:
- Digital Disruption Response: Developing strategies to respond to market shifts or technological breakthroughs.
- Service Integration and Management (SIAM): Managing complex ecosystems of internal and external service providers at a strategic level.
- Mergers and Acquisitions (M&A) Strategy: Ensuring that new entities can be integrated without compromising the resilience of the existing digital infrastructure.
Resilience and the Four Dimensions
Resilience must be addressed across the four dimensions of product and service management:
- Organizations and People: Cultivating a culture of continuous improvement and complexity thinking.
- Information and Technology: Implementing data strategies and AI governance to ensure system integrity.
- Partners and Suppliers: Making strategic sourcing decisions that prioritize reliability and ethical compliance.
- Value Streams and Processes: Optimizing value chains to remove single points of failure.
5. Scenario Planning Techniques
Scenario planning is a strategic capability that allows leaders to explore multiple future states and develop flexible strategies. It is particularly relevant during the Strategy Development Lifecycle.
The Role of PESTLE Factors
Strategic leaders use PESTLE analysis to identify external drivers that could create different future scenarios. By analyzing these factors, organizations can prepare for various economic shifts, regulatory changes (such as new AI laws), or environmental impacts.
Planning for Transformation
During periods of transformation, scenario planning helps identify new opportunities and define target operating models. It enables organizations to:
- Synthesize and Reflect: Take strategic insights and translate them into actionable implementation plans.
- Assess Internal Capabilities: Determine if existing resources and capabilities are sufficient to meet the challenges of different scenarios.
- Select Execution Approaches: Decide whether to utilize Agile, DevOps, or traditional project management (PRINCE2) methodologies based on the predicted environment.
By utilizing scenario planning, leaders move away from rigid, long-term plans toward an adaptive strategy that can be continually adjusted as the environment evolves.
6. Portfolio-Level Objectives and Key Results (OKRs)
Objectives and Key Results (OKRs) serve as a mechanism for strategy cascading, ensuring that high-level vision is translated into measurable, actionable outcomes at the portfolio level.
OKR Cascading
The process of OKR cascading involves aligning the organization’s purpose and vision with specific portfolio objectives.
- Objectives: Qualitative, ambitious goals that define what the organization wants to achieve (e.g., “Become the market leader in carbon-aware digital services”).
- Key Results: Quantitative, time-bound metrics that track progress toward the objective (e.g., “Reduce carbon footprint of digital operations by 20% by Q4”).
Alignment and Focus
Portfolio-level OKRs ensure that all digital products and services contribute to the overall enterprise strategy. This framework supports leadership by providing clarity and confidence, allowing teams to understand how their daily work aligns with long-term value realization. In an AI-enabled economy, OKRs are essential for tracking the impact of innovation initiatives and digital transformation.
7. Portfolio-Level Key Performance Indicators (KPIs)
While OKRs focus on ambitious goals and change, Key Performance Indicators (KPIs) are used at the portfolio level to monitor the health and performance of existing value streams and daily operations.
Measurable Success Criteria
Strategic leaders must define success criteria that go beyond simple financial metrics. Effective portfolio KPIs include:
- Value Stream Metrics: Measuring the efficiency and value delivery of core business processes.
- Balanced Scorecard: Utilizing a multi-dimensional approach to measure financial performance, customer experience, internal process efficiency, and learning/growth.
- Strategic Communication: Ensuring that KPI data is reported to boards in a way that supports informed decision-making.
Sustainability and ESG Reporting
Modern KPIs must incorporate sustainability and ESG (Environmental, Social, and Governance) data. This includes reporting on carbon-aware strategies and digital ethics. By tracking these metrics at the portfolio level, organizations can demonstrate transparency and maintain professional credibility with stakeholders.
8. Investment Prioritization and Resource Allocation
Strategy serves as the primary guide for resource allocation and investment decisions. Portfolio management involves making informed choices about where to direct capital and talent to achieve the best strategic outcomes.
The Prioritization Process
Investment prioritization is guided by the ITIL Strategy Management Model, which consists of two lifecycles: strategy development and strategy implementation. Leaders must evaluate initiatives based on:
- Strategic Alignment: Does the project support the vision and purpose?
- Risk Profile: What is the strategic risk associated with the investment, as documented in the risk register?
- Value Realization: What is the expected measurable business value?
Resource Allocation Decisions
Strategic leaders must make critical “build, buy, or partner” decisions. Sourcing decisions are influenced by:
- Internal Capabilities: Can the organization develop the digital capability in-house?
- Strategic Sourcing: Would a partner provide better resilience or faster time-to-market?
- Innovation Strategy: Does the investment support long-term competitive positioning?
Effective resource allocation ensures that the organization’s approach to markets and operations remains sustainable and value-driven.
9. Balancing Change with Daily Operations
One of the most significant challenges for strategic leaders is managing the friction between transformation initiatives and “Business as Usual” (BAU). Sustainable strategy management requires a delicate balance between these two forces.
Managing the Friction
Strategy implementation must not disrupt the core capabilities required for successful day-to-day operations. Leaders achieve this balance through:
- Organizational Change Management (OCM): Supporting individuals and teams through the transition to new operating models.
- Strategy Implementation Lifecycle: Using a structured approach to translate objectives into initiatives without overwhelming the organization.
- Continuous Improvement: Integrating improvement activities into the Unified Lifecycle of digital products and services.
Ensuring Ongoing Relevance
To maintain success, organizations must balance the need for radical change with the need for operational stability. This involves using the ITIL Guiding Principles to adapt strategy to the organization’s current circumstances and goals, ensuring that every technology investment supports both immediate business outcomes and long-term transformation.
10. Managing Uncertainty in VUCA Environments
Managing uncertainty is a core competency for the ITIL 5 Strategic Leader. In environments characterized by volatility and complexity, traditional management styles are often insufficient.
Complexity Thinking and Adaptability
Strategic leaders utilize complexity thinking to navigate AI-driven environments. This involves:
- Informed Decision-Making: Making conscious decisions despite incomplete information.
- Responsible AI Adoption: Using AI governance to manage the risks and uncertainties associated with emerging technologies.
- Digital Ethics: Ensuring that even in uncertain times, the organization’s actions remain ethical and compliant.
Strategic Capabilities
To manage uncertainty effectively, leaders must develop specific capabilities:
- Communication: Maintaining transparency with stakeholders and boards.
- Governance: Providing the structure needed to maintain direction while allowing for flexibility.
- Innovation: Continually identifying new opportunities created by market disruptions.
By combining these capabilities with a focus on long-term value creation, strategic leaders can act with clarity and confidence, ensuring their organizations remain relevant and successful in a rapidly changing digital landscape.
Short-Answer Questions
- What is the percentage weight of Domain 2 in the ITIL 5 Strategic Leader exam?
- Which two ITIL 5 modules are required to obtain the Strategic Leader designation?
- What does the acronym VUCA stand for?
- Define “Strategy” according to the ITIL 5 Strategy course.
- What are the two lifecycles within the ITIL Strategy Management Model?
- What is the purpose of the “Three Lines of Defense” model in strategic governance?
- Identify three PESTLE factors that influence strategy development.
- How do OKRs differ from KPIs at the portfolio level?
- What is the primary focus of the ITIL AI Governance extension module?
- What is the passing score for the ITIL 5 Strategy examination?
Answer Key
- 16.25%: This is the topic-by-topic weightage used by PeopleCert for Domain 2 on the live exam.
- Direct, Plan and Improve (DPI) and Digital and IT Strategy (DITS): These modules provide the foundation for leadership, strategy, and digital transformation.
- Volatile, Uncertain, Complex, Ambiguous: This describes the environment in which modern digital strategy must operate.
- A set of decisions and plans: Specifically, those that enable an organization to fulfill its purpose and progress toward its vision.
- Strategy Development and Strategy Implementation: These two cycles work together to translate vision into actionable initiatives and sustained value.
- To provide a structured approach to risk and assurance: It ensures clear roles for execution, oversight, and independent assurance to the board.
- Political, Economic, and Social (also Technological, Legal, and Environmental): These external factors are analyzed during scenario planning and strategy development.
- OKRs focus on ambitious goals and change, while KPIs monitor health and daily operations: OKRs track progress toward a vision, whereas KPIs measure the performance of existing value streams.
- The responsible, ethical, and compliant adoption of artificial intelligence: It addresses risk management, transparency, accountability, and regulatory considerations.
- 70%: Candidates must correctly answer 28 out of 40 questions on the 90-minute open-book exam.
Open-Ended / Design Questions
- Designing a Strategic Risk Register: Imagine you are a Strategic Leader for a global logistics firm transitioning to AI-powered routing. Design a strategic risk register entry for the potential risk of “Algorithmic Bias in Delivery Prioritization.” Include identification, impact on purpose, and a mitigation strategy involving AI governance.
- Resilience Strategy: Develop a high-level plan for improving the operational resilience of a digital product ecosystem that relies heavily on third-party cloud providers. How would you apply SIAM (Service Integration and Management) at a strategic level to manage this?
- OKR Cascading: Your organization’s vision is to “Become the most carbon-aware financial service provider by 2030.” Design one Portfolio-Level Objective and three supporting Key Results that align with this vision and the principles of ESG reporting.
- Managing BAU vs. Transformation: A major digital transformation initiative is causing significant burnout in the operations team (BAU). As a leader, how would you use Organizational Change Management (OCM) and the ITIL Strategy Implementation Lifecycle to balance these competing demands?
- Scenario Planning for Disruption: Use PESTLE factors to conduct a brief scenario planning exercise for a traditional retail organization facing the “scenario” of a 50% increase in regional data privacy regulations and a simultaneous economic downturn. How would this shift your investment prioritization?
Glossary of Key Terms
- AI Governance: The framework for the responsible, ethical, and compliant adoption of artificial intelligence, focusing on transparency and accountability.
- Business as Usual (BAU): The successful day-to-day operations and core building blocks of an organization.
- Complexity Thinking: A leadership capability used to navigate and make informed decisions in complex, non-linear digital environments.
- Digital and IT Strategy (DITS): An ITIL 5 module focusing on digital strategy authoring, business alignment, and operating model design.
- Digital Product and Service Management (DPSM): The evolved approach from traditional IT management to a focus on managing the full lifecycle of digital products.
- Digital Transformation: The process of using digital technology to fundamentally change how an organization creates value and interacts with its environment.
- Direct, Plan and Improve (DPI): An ITIL 5 module covering governance, risk, and continual improvement at the portfolio level.
- ESG Reporting: The measurement and disclosure of Environmental, Social, and Governance data to demonstrate organizational sustainability.
- Governance: The core building block that establishes the structure for direction, oversight, and strategic alignment within an organization.
- ITIL 5: The evolution of the ITIL framework, introduced in 2026, focusing on DPSM and AI-enabled environments.
- KPI (Key Performance Indicator): A quantitative metric used to monitor the performance and health of existing value streams.
- OKR (Objectives and Key Results): A framework for cascading strategy and measuring progress toward ambitious, qualitative goals.
- PESTLE: A tool used to analyze external factors (Political, Economic, Social, Technological, Legal, Environmental) that influence strategy.
- Portfolio Management: The strategic management of investments, resources, and risks across all digital products and services.
- Risk Appetite: The amount and type of risk an organization is willing to pursue or retain to achieve its strategic objectives.
- SIAM (Service Integration and Management): A practice for managing multiple service providers to ensure a seamless and resilient digital ecosystem.
- Strategy: A set of decisions and plans that enable an organization to fulfill its purpose and progress toward its vision.
- Target Operating Model (TOM): The designed approach for how an organization will function in the future to deliver its strategy.
- Three Lines of Defense: A governance model that provides a structured approach to risk management and independent assurance.
- VUCA: An acronym for Volatile, Uncertain, Complex, and Ambiguous, describing the modern strategic environment.
Leaderboard
No scores saved yet. Be the first!
30 Questions — ITIL 5 – Strategic Leader : Certified ITIL Strategic Leader - Domain 2 - Strategic Risk, Resilience and Portfolio Management
Expand any question to reveal the correct answer and explanation.
-
1 A digital enterprise is defining the specific degree of variance it will accept regarding its strategic objectives for AI implementation. Which ITIL (Version 5) concept is being established?
Distinguish between the broad willingness to accept risk and the specific, measurable deviations permitted.
Risk Tolerance
Tolerance refers to the specific, measurable level of variation allowed around an organization's risk appetite for a particular objective.
-
✗ Risk Appetite
Appetite is the broad amount and type of risk an organization is willing to take, rather than the specific variance measurement.
-
✗ Strategic Risk Register
This is a tool used to record identified risks, not the predefined measurement for allowable variance.
-
✗ Operational Resilience
This describes the ability to withstand and recover from disruption rather than the limit of acceptable variance.
-
-
2 When developing a digital strategy in a highly volatile Industry 5.0 context, which technique helps leaders prepare for multiple, mutually exclusive future states without relying on linear forecasting?
Consider the method used to manage complexity and high uncertainty by envisioning different plausible outcomes.
Scenario Planning
Scenario planning is designed for unpredictable environments where multiple plausible futures are explored to build resilience.
-
✗ Trend Extrapolation
This assumes the future will be a linear continuation of the past, which fails in complex, unpredictable environments.
-
✗ Hoshin Kanri
This is a strategic deployment method focused on alignment and cascading goals, not on exploring multiple future environmental states.
-
✗ Root Cause Analysis
This is a reactive problem-management technique rather than a proactive strategy-development technique for future uncertainty.
-
-
3 An organization is transitioning from ITIL 4 to Version 5. In the context of Portfolio Management, what has replaced the traditional Service Value Chain (SVC) to better reflect end-to-end product thinking?
Look for the new 8-activity model that unifies product and service delivery.
Product and Service Lifecycle Model (PSLM)
The PSLM is the 8-activity iterative model that replaces the 6-activity SVC to encompass a broader digital product and service scope.
-
✗ Service Value System (SVS)
The SVS is the overarching framework that contains the lifecycle, but it is not the direct replacement for the value chain activities.
-
✗ Digital Operating Model (DOM)
The DOM describes how the organization is structured and works, whereas the PSLM specifically replaces the value chain activities.
-
✗ Strategy Management Model
This model specifically addresses strategy development and implementation lifecycles rather than the core value-creation activities.
-
-
4 Which component of the Strategic Leader framework focuses on ensuring technology investments support business strategy and long-term value realization during both Business as Usual (BAU) and transformation?
Focus on the module that defines the decisions and plans enabling an organization to fulfill its long-term purpose.
ITIL Strategy
ITIL Strategy guides resource allocation and capability development to maintain competitive advantage in both stable and changing environments.
-
✗ ITIL Transformation
While it deals with change, this module focuses on the execution of specific improvements rather than the overarching long-term direction.
-
✗ ITIL Foundation
Foundation provides the basic language and concepts but does not explore the advanced application of strategy and investment.
-
✗ ITIL Practice Manager
This designation focuses on managing specific operational practices rather than high-level strategic alignment and investment.
-
-
5 In the Strategic Risk and Resilience domain, what is the primary purpose of establishing a 'Three Lines of Defence' model?
Think about how organizations structure governance to provide independent reporting and risk oversight.
To ensure board-level governance through clear roles in risk and assurance
The Three Lines of Defence model clarifies responsibilities for management, risk oversight, and independent assurance at the strategic level.
-
✗ To provide technical redundancy for critical digital services
Redundancy is a technical resilience tactic, whereas Three Lines of Defence is a governance and risk management model.
-
✗ To automate the response to digital disruption
While automation is part of Version 5, this model is specifically about human and organizational governance and accountability.
-
✗ To map the movement of data across value streams
Mapping data is part of a data strategy, whereas this model focuses on risk-related oversight and independent reporting.
-
-
6 Which metric would be most appropriate at the Portfolio Level to measure the efficiency and health of the digital estate across multiple value streams?
Consider the type of metrics that emphasize the end-to-end flow of value rather than siloed technical performance.
Value Stream Metrics
Value stream metrics provide high-level visibility into flow, lead time, and efficiency across integrated product and service lines.
-
✗ Mean Time to Repair (MTTR)
MTTR is typically an operational or practice-level metric focused on incident management rather than portfolio-level health.
-
✗ Individual Team Velocity
Velocity is a team-level productivity metric that does not capture the strategic value or cross-functional flow at the portfolio level.
-
✗ System Uptime Percentage
Uptime is a technical output metric that Version 5 suggests moving beyond in favor of holistic outcome and experience metrics.
-
-
7 A Chief Digital Officer (CDO) is prioritizing investments based on 'Complexity Thinking.' How does this approach differ from traditional strategic planning?
Think about the framework that helps professionals adapt their responses to different types of environmental order.
It adapts responses based on whether the environment is ordered, complex, or chaotic
Complexity thinking allows leaders to recognize that different environments require different management styles and decision frameworks.
-
✗ It focuses solely on optimizing for maximum efficiency in predictable markets
This describes Industry 4.0 or older styles of management that fail to account for the unpredictability of complex systems.
-
✗ It removes the need for governance to speed up delivery
Complexity thinking actually requires robust governance to manage the risks and uncertainties inherent in complex systems.
-
✗ It relies on historical data to predict exactly when a disruption will occur
Complexity thinking acknowledges that disruptions in complex systems are often unpredictable and cannot be perfectly forecast.
-
-
8 Within ITIL Strategy (Version 5), which activity in the Strategy Development lifecycle involves analyzing internal capabilities and external PESTLE factors to inform direction?
Identify the initial phase of the cognitive loop focused on environmental scanning.
Observe
The observation phase utilizes environmental frameworks to evaluate market signals, disruption indicators, and organizational constraints.
-
✗ Decide
The decision phase involves selecting a course of action based on the information gathered, rather than the initial analysis itself.
-
✗ Orient
The orientation phase translates the observed signals against internal logic and mental models before a decision is made.
-
✗ Plan
The planning phase involves structuring the chosen decision into a roadmap or future-state operating model.
-
-
9 How does ITIL (Version 5) define 'Operational Resilience' in the context of strategic risk management?
Consider the shift from 'prevention of failure' to 'survival and service persistence during failure'.
The ability to withstand and recover from disruption while continuing to provide essential services
Operational resilience focuses on the persistence of critical business services through volatility and failure.
-
✗ The elimination of all risks through redundant automated systems
Resilience accepts that failure will occur; it is about the ability to survive and persist rather than purely avoiding risk.
-
✗ The speed at which an IT team can restart a crashed server
This is a narrow technical recovery metric, whereas operational resilience is an organizational and strategic capability.
-
✗ The implementation of a carbon-neutral data strategy
While related to sustainability, carbon neutrality is not the primary definition of operational resilience.
-
-
10 When cascading strategy to the portfolio level, why does ITIL (Version 5) recommend using Objectives and Key Results (OKRs) over traditional static KPIs?
Focus on the need for flexibility and outcome-based tracking in Industry 5.0.
They emphasize outcomes and measurable progress in uncertain, fast-paced environments
OKRs provide the flexibility needed for digital transformation by focusing on what needs to be achieved rather than just performance metrics.
-
✗ They are easier to automate than performance indicators
Ease of automation is not the primary driver; the driver is alignment and outcome focus in complex environments.
-
✗ They replace the need for a strategic risk register
OKRs and risk registers are complementary; one tracks progress while the other tracks potential threats to that progress.
-
✗ They ensure all teams follow the exact same rigid processes
OKRs are designed to support autonomy and alignment, moving away from rigid, process-centric command-and-control structures.
-
-
11 In investment prioritization, which factor is highlighted in ITIL (Version 5) as a core tenet of Industry 5.0 that must be balanced alongside financial profit?
Think about the broader responsibilities organizations now have toward the 'planet' and 'people'.
Sustainability and ESG Impact
Industry 5.0 emphasizes a triple bottom line where organizations must balance profit with social and environmental responsibility.
-
✗ Maximum Technical Complexity
Complexity should be managed and understood, but maximizing it is never an organizational priority or investment goal.
-
✗ Total Elimination of Human Intervention
Industry 5.0 promotes human-centricity and technology-human collaboration, not the complete removal of humans.
-
✗ Strict Adherence to ITIL v3 Processes
ITIL Version 5 is an evolution that moves beyond rigid v3 processes toward flexible management practices and value streams.
-
-
12 A board-level Strategic Risk Register in Version 5 must explicitly address risks associated with 'Agentic AI.' What is a primary strategic risk identified for such automated systems?
Focus on the governance challenge of maintaining responsibility when systems act autonomously.
The automation of accountability and loss of human oversight
A core risk in AI governance is the 'automation of accountability,' where humans are removed from the loop of responsibility.
-
✗ The lack of sufficient server cooling for AI chips
This is an operational or infrastructure risk, not a board-level strategic risk regarding governance and accountability.
-
✗ The high cost of AI software licenses
Financial cost is a project risk, but the governance risk of accountability has deeper strategic and ethical implications.
-
✗ The inability to use AI for linear trend forecasting
AI is actually quite good at pattern recognition; the risk lies in its governance, ethics, and human collaboration.
-
-
13 How does 'Portfolio-level KPI' management change under ITIL (Version 5) compared to earlier versions?
Consider the new definition of value that includes how stakeholders 'feel' about the service.
It shifts from measuring technical outputs to measuring outcomes and stakeholder experience
ITIL 5 prioritizes how value is experienced by users and stakeholders over simple performance metrics like uptime.
-
✗ It focuses solely on the internal efficiency of IT silos
Version 5 explicitly attempts to break down silos and measure end-to-end value through cross-functional collaboration.
-
✗ It eliminates the need for financial metrics in the portfolio
Financial metrics remain critical; they are just balanced with experience, outcomes, and sustainability.
-
✗ It moves all KPI measurement to a single centralized IT manager
Management shifts toward integrated value streams and shared accountability across the whole organization.
-
-
14 Which of the following is a key outcome of the 'Strategy Implementation' lifecycle in the ITIL Strategy Management Model?
Think about the phase where 'plans' are turned into 'results'.
Translating strategic intent into actionable initiatives and measurable value
Implementation is about bridging the gap between a written document and actual organizational change through action.
-
✗ Scanning the external environment for PESTLE factors
Scanning is an activity within the Strategy Development lifecycle, not the Implementation lifecycle.
-
✗ Defining the organization's high-level vision and values
Defining vision and values is a core activity of strategy development and direction setting.
-
✗ Performing root cause analysis on failed incidents
This is an operational incident management activity that is too narrow for the scope of the implementation lifecycle.
-
-
15 In the context of Resilience and Safety Culture, what is the strategic importance of 'Psychological Safety'?
Consider how the absence of fear impacts a team's ability to innovate and report risks.
It enables continuous improvement by allowing teams to learn from mistakes without fear
Without psychological safety, teams hide failures, which prevents the organization from identifying and correcting risks.
-
✗ It ensures that no system ever experiences a failure
Psychological safety doesn't stop failure; it allows the organization to handle failure better and learn from it.
-
✗ It is a legal requirement for ESG reporting
While social factors are part of ESG, psychological safety is primarily an internal cultural and resilience-building strategy.
-
✗ It eliminates the need for governance and board-level risk registers
Psychological safety is a component of healthy culture that supports governance, not a replacement for it.
-
-
16 When designing a Target Operating Model (TOM), which strategic consideration helps prevent the creation of new organizational silos?
Look for the approach that emphasizes the end-to-end journey of a product or service.
Organizing around integrated value streams rather than technical functions
Value stream thinking unifies multidisciplinary teams toward a common goal, breaking down traditional departmental barriers.
-
✗ Ensuring every department has its own separate budget and leadership
Separate budgets and leadership for each department are the primary causes of siloed behavior.
-
✗ Focusing purely on the 'Operate' and 'Support' activities of the lifecycle
Focusing on only part of the lifecycle leads to functional silos; the model requires end-to-end thinking.
-
✗ Implementing a strict command-and-control hierarchy
Command-and-control structures often reinforce silos and slow down value creation in complex environments.
-
-
17 Which of the following would likely be found in a Strategic Risk Register rather than an Operational Risk Register?
Think about threats that impact the very purpose and vision of the organization.
The long-term threat of digital disruption to the core business model
Strategic risks focus on high-level, long-term threats to the organization's existence and competitive positioning.
-
✗ A temporary power outage in a regional data center
This is an operational risk that impacts day-to-day delivery but does not necessarily threaten the enterprise strategy.
-
✗ A bug in a specific software feature scheduled for release next week
This is a tactical or project-level risk focused on a single output rather than the strategic direction.
-
✗ The expiration of a standard SSL certificate for a non-critical internal app
This is a routine operational maintenance task/risk and is not a board-level strategic concern.
-
-
18 According to ITIL Strategy (Version 5), how should leaders handle 'Value Co-creation' in an environment with complex supplier ecosystems?
Identify the model used to coordinate diverse providers in a unified way.
Apply Service Integration and Management (SIAM) at a strategic level
SIAM allows for the strategic management and coordination of multiple suppliers to deliver a single integrated experience.
-
✗ Ensure that the internal IT team maintains total control over every supplier activity
In complex ecosystems, 'total control' is often impossible; the focus shifts to integration and shared value creation.
-
✗ Use the lowest-cost provider regardless of their strategic alignment
Strategic Leader training emphasizes alignment and value over simple cost-cutting in sourcing decisions.
-
✗ Eliminate all external suppliers to simplify the value chain
Modern digital strategy often relies on external partners; the skill lies in managing that complexity, not avoiding it.
-
-
19 When prioritizing investments, how does ITIL (Version 5) suggest balancing 'Innovation' with 'Resilience'?
Look for the role of governance as an 'enabler' of both speed and safety.
By using AI governance to introduce accountability without slowing innovation
Effective governance allows for rapid innovation by providing the necessary guardrails to maintain trust and stability.
-
✗ By pausing all innovation until the organization reaches 100% resilience
Pausing innovation is a strategic risk in itself (the risk of irrelevance) and 100% resilience is unrealistic.
-
✗ By prioritizing cost savings over both innovation and resilience
Version 5 moves beyond efficiency-only models to focus on the human-centric and resilient creation of value.
-
✗ By allowing innovation teams to operate without any governance or risk oversight
Innovation without oversight creates significant strategic risks regarding digital ethics, security, and stability.
-
-
20 What is the primary role of 'Environmental Scanning' within the Strategy Development lifecycle?
Think about the tools used to understand the world outside the organization's walls.
To identify disruption indicators and market demand through frameworks like PESTLE
Scanning provides the external context needed to make informed decisions about direction and investment.
-
✗ To physically monitor the energy usage of on-premises data centers
While energy monitoring is part of a sustainability strategy, 'Environmental Scanning' is a broader strategic analysis term.
-
✗ To ensure all employees have a safe physical workspace
This is an HR or facility management concern, not the strategic intent of scanning the business environment.
-
✗ To prevent internal teams from communicating with external stakeholders
Strategic success requires *more* external communication and stakeholder engagement, not less.
-
-
21 A Strategic Leader is using 'Wardley Mapping' to inform investment prioritization. What is a key insight gained from this technique?
Consider how technologies evolve and how that evolution affects 'build versus buy' decisions.
The evolution of components from genesis to commodity and their impact on strategy
Wardley mapping helps leaders decide whether to build, buy, or partner based on the maturity of a technology or practice.
-
✗ The exact number of server CPU cores needed for a new application
Wardley mapping is a strategic tool, whereas capacity planning is a tactical/operational technical activity.
-
✗ The psychological profile of the executive leadership team
Wardley mapping focuses on the business landscape and value chains, not on individual personality assessments.
-
✗ The strict adherence to a waterfall project management schedule
Wardley mapping often encourages more agile and context-aware delivery models by highlighting areas of uncertainty.
-
-
22 Which Portfolio-level OKR would best align with the 'Human-centric' tenet of ITIL (Version 5)?
Look for the outcome that measures the impact on people rather than just systems or costs.
Increase employee and user satisfaction scores by $15\%$ through experience-led design
Human-centricity prioritizes the experience and well-being of the people who interact with the technology.
-
✗ Reduce the total number of human staff needed to operate the service desk
Simply reducing staff is a cost-cutting output; it may actually decrease human-centricity if the user experience suffers.
-
✗ Achieve $99.999\%$ uptime for all non-human automated internal systems
Uptime is a technical metric; while useful, it does not directly capture the human-centric focus of Version 5.
-
✗ Automate $100\%$ of all strategic decision-making processes by year-end
Version 5 warns against automating accountability and human judgment, which are essential for human-centricity.
-
-
23 In strategic risk management, what does 'Scenario Planning' involve that 'Linear Forecasting' does not?
Think about how leaders prepare for the 'unpredictable' in a world of high disruption.
The exploration of multiple plausible futures that do not depend on past data
Scenario planning is essential for complexity and disruption where the past is no longer a reliable guide to the future.
-
✗ The use of advanced mathematical formulas to predict a single, certain outcome
Predicting a single outcome is characteristic of forecasting, which is often inaccurate in complex environments.
-
✗ The strict focus on short-term technical performance metrics
Scenario planning is a long-term strategic tool, not a short-term operational monitoring activity.
-
✗ The reliance on a single 'best-case' scenario for all strategic decisions
Scenario planning specifically avoids the 'single best-case' trap by exploring diverse and challenging alternatives.
-
-
24 How does the 'Sustainability' focus in Version 5 impact investment prioritization at the portfolio level?
Consider the 'Triple Bottom Line' of People, Planet, and Profit.
It requires evaluation of the environmental impact and long-term viability of every initiative
Sustainability is a core tenet of Industry 5.0, forcing organizations to look beyond immediate profit.
-
✗ It mandates that organizations only invest in low-cost, disposable technologies
Disposable technologies are often the opposite of sustainable; the focus is on long-term value and responsibility.
-
✗ It removes the need to track financial ROI for digital projects
Financial health is part of long-term viability; sustainability adds to the criteria but does not remove financial oversight.
-
✗ It ensures that no AI technology is ever used in the organization
AI can actually support sustainability; the focus is on *responsible* and *governed* use, not avoidance.
-
-
25 Which role is primarily responsible for aligning digital investments with enterprise goals and establishing the organizational direction?
Look for the advanced designation targeted at decision-makers and senior leaders.
ITIL Strategic Leader (SL)
The SL designation is specifically designed for executives and directors who connect service management to broader organizational goals.
-
✗ Incident Manager
Incident management is a tactical, practice-focused role that does not oversee enterprise-wide investment and strategy.
-
✗ Service Desk Analyst
Analysts deal with operational user support rather than strategic direction and portfolio management.
-
✗ Agile Scrum Master
A Scrum Master focuses on team delivery and methodology rather than the strategic alignment of the entire organization's portfolio.
-
-
26 In the context of the Strategy Management Model, what occurs during the 'Orient' phase of the cognitive loop?
Think about the phase where raw data is interpreted through the lens of the organization's unique context.
Signals from the environment are translated against internal logic and capabilities
Orientation is the critical filter that helps a leader make sense of data before moving to a decision.
-
✗ The organization releases its first marketing campaign for a new product
Marketing release is an execution/output activity, not a strategic cognitive phase.
-
✗ The board monitors the results of a completed transformation project
Monitoring results happens during the 'evaluate' or 'reflect' phases, after the loop has progressed.
-
✗ Teams are given their daily tasks and assigned to specific value streams
Assigning daily tasks is an operational management activity, not a strategic orientation phase.
-
-
27 Which of the following describes a 'Carbon-Aware' strategy in digital portfolio management?
Consider how sustainability is integrated into operational and strategic decision-making regarding energy.
Aligning technology portfolios and processing with periods of high renewable energy availability
Carbon-aware strategy involves making conscious decisions to reduce environmental impact by timing or placing workloads.
-
✗ Purchasing enough carbon offsets to ignore the actual energy usage of the data centers
Simply buying offsets is not a 'strategy' for resilience and sustainability; it does not address the underlying consumption.
-
✗ Replacing all human employees with AI to reduce the carbon footprint of an office
This ignores the 'human-centric' tenet of Version 5 and oversimplifies the energy impact of large-scale AI usage.
-
✗ Only investing in the fastest, most power-intensive hardware available
This would typically be the opposite of a carbon-aware strategy as it prioritizes raw performance over energy efficiency.
-
-
28 When managing a 'Strategic Risk Register' for a digital merger or acquisition (M&A), what is a key Version 5 focus?
Think about the high-level governance needed to integrate two complex digital organizations.
Managing digital disruption, partnership strategy, and operational resilience across entities
DITS explicitly covers digital M&A and partnership strategy, focusing on integrated resilience rather than just technical migration.
-
✗ Counting the total number of mouse pads owned by the acquired company
This is a trivial inventory task that has no board-level strategic value.
-
✗ Ensuring the new employees follow a strict hierarchical command-and-control structure
Modern digital strategy emphasizes servant leadership and collaboration over rigid command-and-control.
-
✗ Immediately shutting down all IT systems from the acquired company to save money
This creates massive operational risk and ignores the potential value and experience of the existing systems.
-
-
29 Why is 'Continual Strategic Improvement' measured at the portfolio level using Value Stream metrics rather than just Practice metrics?
Consider the dangers of 'local optimization' in a complex system.
To ensure that improvements optimize the end-to-end flow of value to the customer
Optimizing a single practice (like incident management) can lead to 'local optimization' that doesn't actually help the customer if other bottlenecks exist.
-
✗ Because Practice metrics are too complicated for senior executives to understand
Executives can understand them, but Practice metrics don't provide the necessary 'big picture' of strategic success.
-
✗ Because the ITIL Version 5 framework has removed all 34 management practices
The 34 practices still exist; they are just reframed as enablers rather than the primary focus of strategic measurement.
-
✗ To hide failures within specific departments by averaging them across the portfolio
Strategic improvement is about transparency and learning, not hiding department-level failures.
-
-
30 A board is evaluating its 'Risk Appetite' for using public cloud versus on-premises infrastructure. Which factor reflects a 'Resilience' priority over simple 'Efficiency'?
Identify the strategy that prioritizes the ability to withstand a major external provider failure.
Investing in multi-cloud diversity to prevent a single point of provider failure
Multi-cloud is often more expensive and less efficient, but it significantly increases resilience by preventing vendor lock-in and systemic outages.
-
✗ Choosing the single cheapest cloud provider available to reduce the annual IT budget
This is an efficiency-driven priority that ignores the resilience risk of a single point of failure.
-
✗ Removing all backup systems to free up server space for more data
Removing backups is a catastrophic failure of both resilience and strategic risk management.
-
✗ Strictly limiting cloud usage to only non-critical development environments
While conservative, this doesn't necessarily build resilience; it simply avoids the modern digital landscape.
-