Requirements - Decision Making & Governance - DM01 - Debt

Where a solution or part of a solution is tactical, short term, or introduces/persists technical and architectural debt, remediation plans should be agreed with relevant stakeholders and governance groups. Architecture debt should be identified with implications, rationale and future mitigation plans (recorded in an Architecture Debt Register), and plans should be realistic and funded.

Requirement description

This requirement is focused on the identification, management and reduction of technical and architectural debt. Where tactical decisions have been made, or where known architectural shortcomings exist, they should be documented, understood, owned and actively managed.

Debt should not simply be acknowledged. There should be a realistic remediation plan, stakeholder agreement, governance visibility and evidence that delivery, funding and timescales have been considered.

In simple terms:
If a team knowingly introduces or carries architecture debt, they should know what it is, why it exists, what risks it creates, who has accepted it, and how and when it will be addressed.

Scoring rubric table – DM01 Architecture Debt Management

Score What it looks like Typical evidence Key gaps / risks
0 No evidence that architecture or technical debt is identified or managed. Tactical decisions are undocumented and unmanaged. No debt register.
No remediation plans.
No governance discussion.
No ownership identified.
Significant service risk. Debt may accumulate unnoticed. Operational, security, resilience or cost impacts are unknown.
1 Limited awareness that debt exists. Some concerns may have been raised informally but no structured process is in place. Meeting notes mentioning debt.
Informal emails.
Ad hoc backlog items.
Unapproved actions.
High-risk gaps. No agreed remediation approach. Risks, costs and impacts are poorly understood.
2 Some debt items have been identified and partially documented. Remediation activity exists but is incomplete or inconsistent. Partial debt register.
Incomplete RAID entries.
Draft remediation plans.
Some assigned owners.
Significant notable gaps. Coverage is incomplete. Funding, governance approval or delivery commitment is unclear.
3 Much of the known debt is documented. Risks, rationale and mitigation actions are generally understood. Stakeholder engagement has occurred. Architecture Debt Register covering most known items.
Documented rationale for tactical decisions.
Named owners.
Remediation plans with indicative timescales.
Evidence of governance discussion.
Notable gaps remain. Some debt items lack funding, delivery commitment, prioritisation or target dates. Governance oversight may be inconsistent.
4 Most debt is actively managed through a maintained process. Remediation plans are realistic, prioritised and supported by stakeholders. Maintained Architecture Debt Register.
Impact assessments.
Prioritised remediation roadmap.
Governance approval records.
Funding route identified.
Evidence of periodic review.
Minor gaps only. A small number of lower-priority items may not yet have confirmed remediation dates.
5 Comprehensive and exemplar debt management. Debt is actively measured, reviewed and reduced through governance and delivery processes. Comprehensive Architecture Debt Register.
Clear categorisation and prioritisation.
Funded remediation plans.
Governance reporting and review cycles.
Architecture KPIs or measures showing debt reduction.
Evidence that debt information informs investment and delivery decisions.
Minimal or no significant gaps. Debt is transparently managed with continuous improvement in place.

What assessors should look for

  1. Identification of debt – Is technical and architecture debt formally recognised and recorded?
  2. Quality of remediation planning – Are actions specific, achievable, prioritised and linked to delivery plans?
  3. Ownership and accountability – Does every significant debt item have an identified owner?
  4. Funding and feasibility – Is there evidence that remediation activities are affordable, planned and realistically deliverable?
  5. Governance and stakeholder agreement – Have relevant stakeholders and governance groups reviewed and accepted the approach?
  6. Risk awareness – Are business, operational, security, resilience and cost implications documented and understood?

What separates a 3 from a 4 or 5

A score of 3 typically means the organisation understands its debt position and has documented most major issues, but remediation remains partially planned, unfunded or inconsistently governed.

A score of 4 requires evidence that debt management is operationalised, with maintained registers, governance oversight, prioritised plans and credible funding or delivery routes.

A score of 5 requires debt management to be embedded within normal governance and investment processes. Debt information is actively used to influence architecture decisions, prioritisation and delivery planning, with evidence of continuous improvement and debt reduction over time.

Suggested evidence examples (not SAF-mandated artefacts)

  • Architecture Debt Register
  • Architecture remediation plan
  • Roadmaps showing debt reduction activities
  • RAID logs containing architecture debt items
  • Governance or Design Authority minutes
  • TRG, PDG or programme governance outputs
  • Architecture Decision Records explaining tactical choices
  • Funding approvals or delivery commitments
  • Product backlog items linked to remediation activities
  • Periodic architecture review records

Updated: 04 September 2026 (SAF Version 1.1)