How to Build IT Governance for Cloud Computing Adoption

The sales manager subscribed to an online CRM service last week using his own credit card. The accounting department started using a foreign web service for file sharing. The IT manager found out two weeks later. For mid-sized companies in Turkey, this scenario is becoming increasingly familiar as broadband connections spread and web-based software services grow cheaper, making it easy for departments to bypass central IT and find their own solutions. The problem is that nobody is calculating the risks that come with this speed.

Cloud computing, meaning the practice of purchasing server capacity and software as internet-based services rather than hosting them in your own data center, offers real flexibility to businesses. A department can be up and running in a few days instead of waiting weeks for an installation project to complete. But this flexibility creates a new challenge for IT governance: who is buying what, where is company data being stored, and who is responsible for monitoring security standards? Governance, simply put, means placing the answers to these questions inside a formal institutional framework. Before cloud services became widespread, this framework was relatively straightforward; the central IT unit made all purchasing and installation decisions. That model alone is no longer sufficient.

So how do you build a governance framework? The first step is defining which services require central approval and which can be adopted at the department level. Routing every web-based tool through IT approval slows things down unnecessarily. However, any service that processes company data, stores customer information, or touches accounting processes must be subject to central oversight. Building an ‘approved services list’ that makes this distinction clearly both reduces the burden on the IT unit and shows departments exactly which tools they can use freely. The list needs to be a living document, updated as new services are evaluated.

The second critical step is data classification. Without defining which data can leave the company’s own infrastructure and which must stay inside, building secure governance is not possible. Sensitive information such as customer payment details, contract specifics, or employee personnel records carries both legal and operational risk when hosted on servers abroad. By contrast, project timelines, marketing materials, or sales reports can move to cloud environments with far fewer restrictions. Making this classification is not a technical decision for the IT manager alone; it means sitting down with legal, finance, and senior management to establish a company-wide policy. In many Turkish companies, that meeting has not yet taken place.

The practical way to balance central control with departmental speed is to make approval processes faster, not to eliminate them entirely. When a department wants to use a new web-based service, they should be able to approach the IT unit and receive a response within a reasonable timeframe. If that process takes weeks, departments will act without waiting for approval. A simple evaluation form and a commitment to respond within two business days solves this problem in most companies. Involving department managers in the process also tends to be far more effective than simply placing them under supervision; a department head who understands the risks of a service becomes an ally who enforces IT policy on their own initiative.

The most frequently overlooked dimension of governance is service contracts and exit planning. Signing agreements without asking how data will be retrieved, what happens if the service is discontinued, and how the provider guarantees data security creates serious problems down the line. This is an area that small and mid-sized businesses frequently ignore; large enterprises involve their legal departments in such contracts, while SMBs typically skip this step entirely. Building this review into the governance framework significantly reduces the risk of data loss or service disruption later on.

Before your company begins adopting cloud services, asking yourself the following questions is the first step toward building a solid governance framework: Which departments are using which web-based tools, and are those tools approved? Which portions of company data can be hosted externally, and which must remain inside? How many days does your IT unit take to respond to new service requests? Who reviews data security and exit terms before a contract is signed? Companies that can answer these questions clearly are positioned to genuinely benefit from the flexibility cloud services offer; those that cannot are accumulating risk while believing they are gaining speed.

This article was originally written in Turkish by Gökhan MERCANOĞLU on June 22, 2009 and has been automatically translated into English and other languages using machine translation.


digital service model creates lasting value only when user behavior, executive ownership, and data quality are handled together. Technology does not create transformation by itself; it only makes the need for transformation more visible. Success is less about the system working and more about the organization learning to work with it.


Gökhan Mercanoğlu
Bulut, SaaS ve Platform Ekonomisi