Requirements - Decision Making & Governance
-
DM05 - Governance Process
The solution design and architecture decisions should be managed through a tiered governance process, ultimately leading, if appropriate, to TRG.
Requirement
DM05 : The solution design and architecture decisions should be managed through a tiered governance process, ultimately leading, if appropriate, to TRG.
The decision process:
- Decisions should be made at the lowest possible level, with the appropriate stakeholders involved.
- All decisions should follow local governance processes, such as a programme design authority.
- If the solution requires assessment against Principles, Policies, Patterns and Standards then presentation to PDG or TRG would be appropriate.
- At the appropriate stages of the lifecycle, all large items must go to TRG.
- The relevant Lead Architects and Subject Matter Experts (SMEs) should be engaged and supportive.
Requirement description
This requirement is concerned with ensuring that architecture decisions are governed through an appropriate and proportionate governance structure.
Decisions should be made at the lowest practical level, but with appropriate oversight. Local governance forums should be used where possible, with escalation to wider architecture governance bodies when required by risk, complexity, strategic importance or policy assessment.
The governance process should be transparent, documented and supported by the appropriate architects, SMEs and stakeholders.
In simple terms:
Architecture decisions should follow an agreed governance path, involve the right people and be escalated to the appropriate governance forums when required.
Scoring rubric table – DM05 Architecture Governance Process
| Score | What it looks like | Typical evidence | Key gaps / risks |
|---|---|---|---|
| 0 | No evidence of architecture governance. Decisions are made without review, challenge or formal approval processes. |
No governance records. No Design Authority engagement. No architecture review evidence. No documented approvals. |
Significant service risk. Decisions may conflict with organisational strategy, policy, standards or architecture direction. |
| 1 | Limited governance activity exists but is informal, inconsistent or dependent on individuals. |
Ad hoc reviews. Informal discussions. Occasional architecture challenge sessions. No consistent governance route. |
High-risk gaps. Governance coverage is inconsistent and key decisions may bypass review and scrutiny. |
| 2 | Some governance processes are followed, but coverage is incomplete and application is inconsistent. |
Partial governance records. Evidence of some Design Authority reviews. Limited architecture approval records. Incomplete decision traceability. |
Significant notable gaps. Important decisions may not receive appropriate review or escalation. |
| 3 | Most significant architecture decisions follow recognised governance processes. Appropriate stakeholders are generally involved and governance forums are being used. |
Programme Design Authority reviews. Architecture review records. Meeting minutes. Evidence of SME involvement. Governance actions and approvals. |
Notable gaps remain. Governance routes may not always be consistently applied, documented or completed. |
| 4 | Most architecture decisions are managed through a defined governance process with clear escalation criteria and governance evidence. |
Governance framework documentation. Design Authority approvals. TRG or equivalent submissions where required. SME engagement records. Documented governance decisions and actions. |
Minor gaps only. Governance is generally effective and consistently applied. |
| 5 | Comprehensive and exemplar governance arrangements. Governance is embedded in delivery practices and consistently drives informed architecture outcomes. |
Well-defined governance model. Clear decision authorities. Comprehensive governance audit trail. Evidence of timely escalation. Regular engagement with architects and SMEs. Governance outcomes influencing roadmap and investment decisions. |
Minimal or no significant gaps. Governance processes are mature, proportionate and continuously improved. |
What assessors should look for
- Governance pathway – Is there a clear route through which architecture decisions are reviewed and approved?
- Appropriate escalation – Are decisions escalated to the correct governance forum based on risk, scope, strategic importance or policy assessment requirements?
- Stakeholder participation – Are architects, SMEs and relevant stakeholders involved in decision-making?
- Decision traceability – Can key decisions be traced to governance discussions, approvals and actions?
- Consistency – Is governance applied consistently across significant architecture decisions?
- Evidence of challenge – Is there evidence that governance forums provide scrutiny, review and informed challenge rather than simply ratifying decisions?
What separates a 3 from a 4 or 5
A score of 3 typically indicates that governance processes exist and are being used for most major decisions, but governance may be inconsistent, poorly documented or dependent on individual behaviours.
A score of 4 requires a clearly defined and consistently applied governance model. Evidence should show that decisions are reviewed through appropriate forums, escalation paths are understood and governance outcomes are documented.
A score of 5 requires governance to be embedded within normal delivery activities. Architecture decisions are reliably routed through appropriate governance structures, stakeholders and SMEs are routinely engaged, and governance evidence demonstrates measurable influence over solution outcomes.
Suggested evidence examples (not SAF-mandated artefacts)
- Architecture governance framework documents
- Programme Design Authority papers and minutes
- TRG submission packs and outcomes
- PDG review records
- Architecture review board outputs
- Governance decision logs
- Approval records
- Action and recommendation trackers
- SME review comments and responses
- Governance escalation records
Additional Info
The requirement describes a tiered governance approach and references local governance, PDG, TRG, Lead Architects and SMEs, but it does not prescribe a mandatory governance structure, review frequency, approval workflow or minimum set of artefacts. Assessors should therefore focus on whether architecture decisions are governed through an appropriate and proportionate process rather than expecting a specific governance model.
Updated: 04 September 2026 (SAF Version 1.1)