Requirements - Documentation - D01 - Document Storage

All architecture documentation should be maintained (with supporting processes and change control) within the appropriate NHS England knowledge store(s) e.g. Aalto, SharePoint, Confluence.

Requirement description

This requirement is concerned with ensuring that architecture documentation is stored, maintained and governed within approved NHS England knowledge repositories.

Documentation should not be held solely on personal drives, local devices, email folders or unmanaged locations. Architecture artefacts should be version controlled, accessible to appropriate stakeholders and maintained through a defined change management process.

The objective is to ensure architecture knowledge remains available, current, auditable and usable throughout the service lifecycle.

In simple terms:
Architecture documentation should be stored in approved repositories, kept up to date and managed through controlled processes.

Scoring rubric table – D01 Architecture Documentation Management

Score What it looks like Typical evidence Key gaps / risks
0 No evidence that architecture documentation is maintained or stored within approved knowledge repositories. Missing architecture documentation.
Files held locally or in personal storage.
No version control.
No evidence of maintenance activity.
Significant service risk. Knowledge may be lost, inaccessible or inconsistent.
1 Limited architecture documentation exists and storage arrangements are informal or inconsistent. Scattered documents.
Local copies.
Uncontrolled repositories.
Limited evidence of ownership or maintenance.
High-risk gaps. Documentation may quickly become outdated and difficult to locate.
2 Some architecture documentation is stored within approved repositories, but coverage, governance or maintenance is inconsistent. Partial use of SharePoint, Aalto or Confluence.
Some version history.
Incomplete architecture document sets.
Limited evidence of review activity.
Significant notable gaps. Important documentation may be missing, duplicated or out of date.
3 Much of the architecture documentation is maintained within approved repositories and is subject to basic governance and change control. Architecture artefacts stored within approved platforms.
Document ownership identified.
Version control in place.
Evidence of periodic updates.
Document review history.
Notable gaps remain. Some artefacts may be out of date, incomplete or subject to inconsistent change control.
4 Most architecture documentation is maintained through defined processes and controlled within approved repositories. Comprehensive document repository.
Defined document ownership.
Document review cycle.
Change control records.
Version management.
Evidence that delivery teams actively use the repository.
Minor gaps only. Any documentation deficiencies are low risk and actively managed.
5 Comprehensive and exemplar documentation management. Architecture knowledge is treated as a managed asset and is actively maintained throughout the service lifecycle. Complete architecture repository.
Clear ownership and governance.
Automated or well-controlled review processes.
Strong change management practices.
Traceability between documentation and delivery activities.
Evidence of continuous improvement and active consumption of architecture knowledge.
Minimal or no significant gaps. Documentation is accurate, accessible, governed and routinely used to support decision-making.

What assessors should look for

  1. Approved storage location – Are architecture artefacts stored in approved NHS England repositories such as Aalto, SharePoint or Confluence?
  2. Maintenance – Is there evidence that documentation is reviewed and updated when architecture changes occur?
  3. Change control – Are document updates subject to version management or change control processes?
  4. Ownership – Are document owners identified and accountable for maintenance?
  5. Accessibility – Can relevant stakeholders locate and access documentation when required?
  6. Completeness – Does the repository contain the architecture artefacts required to understand and govern the solution?

What separates a 3 from a 4 or 5

A score of 3 generally indicates that most architecture documents exist and are stored in approved repositories, but maintenance activities, ownership, coverage or change control are inconsistent.

A score of 4 requires evidence that architecture documentation is actively governed, reviewed and maintained through defined processes. Ownership, change control and repository management should be clearly demonstrated.

A score of 5 requires documentation management to be embedded within delivery and governance processes. Architecture artefacts are actively maintained, trusted by stakeholders and routinely used to support architecture decisions, assurance and service evolution.

Suggested evidence examples (not SAF-mandated artefacts)

  • Architecture repositories in Aalto, SharePoint or Confluence
  • Document ownership records
  • Version history and change logs
  • Document review schedules
  • Architecture governance procedures
  • Solution Design Overview documents
  • Architecture roadmaps and models
  • Document approval workflows
  • Repository access and usage records
  • Architecture quality review outputs

Updated: 04 September 2026 (SAF Version 1.1)