The primary goals for information technology governance are to
(1) assure that the investments in IT generate business value, and
(2) mitigate the risks that are associated with IT.
This can be done by implementing an organizational structure with well-defined roles for the responsibility of information,business processes, applications, infrastructure, etc.
Is IT governance different from IT management and IT controls? The problem with IT governance is that often it is confused with good management practices and IT control frameworks. ISO 38500 has helped clarify IT governance by describing it as the management system used by directors. In other words, IT governance is about the stewardship of IT resources on behalf of the stakeholders who expect a return from their investment. The directors responsible for this stewardship will look to the management to implement the necessary systems and IT controls. Whilst managing risk and ensuring compliance are essential components of good governance, it is more important to be focused on delivering value and measuring performance.
Related: Formal architecture compliance process: a process for ensuring new projects are adopting standard technologies
Source: answers.com