Requirements - Decision Making & Governance - DM06 - Governance Approach

The overall approach to architecture governance should be appropriate and commensurate with the nature of the solution.

Requirement description

This requirement is concerned with ensuring that architecture governance is proportionate to the characteristics of the solution.

Governance should reflect factors such as complexity, risk, scale, cost, service criticality, regulatory obligations, security considerations, architectural novelty and organisational impact. A small, low-risk change should not require the same governance as a large national platform handling critical health services.

The objective is to apply enough governance to provide confidence and control without creating unnecessary bureaucracy.

In simple terms:
The governance model should match the level of risk, complexity and impact of the solution.

Scoring rubric table – DM06 Proportionate Architecture Governance

Score What it looks like Typical evidence Key gaps / risks
0 No identifiable architecture governance approach exists, or governance is entirely absent regardless of solution risk or complexity. No governance model.
No architecture reviews.
No documented approvals.
No governance records.
Significant service risk. Decisions are not appropriately scrutinised and governance obligations may be missed.
1 Limited governance activities occur but they are informal, inconsistent or unrelated to solution risk and complexity. Ad hoc reviews.
Informal discussions.
Occasional governance engagement.
No documented rationale for governance decisions.
High-risk gaps. Governance may overlook significant risks or apply inappropriate levels of assurance.
2 Some governance arrangements exist and are applied to parts of the solution, but there is limited evidence that governance has been tailored to the solution's characteristics. Partial governance documentation.
Some review records.
Inconsistent use of governance forums.
Limited evidence of risk-based governance decisions.
Significant notable gaps. Governance may be excessive in some areas and insufficient in others.
3 Much of the governance approach is appropriate for the solution. Key governance activities are in place and there is evidence that risk, complexity and impact have influenced governance decisions. Governance framework documentation.
Design Authority reviews.
Documented governance routes.
Evidence of governance proportionality discussions.
Risk and architecture assessments informing reviews.
Notable gaps remain. Some governance activities may be inconsistently applied or lack formal justification.
4 Most governance arrangements are demonstrably aligned to solution risk, complexity and organisational impact. Governance activities are well controlled and consistently applied. Documented governance model.
Risk-based review approach.
Defined escalation criteria.
Regular governance reviews.
Evidence of tailoring governance to solution characteristics.
Minor gaps only. Remaining weaknesses present limited risk and are actively managed.
5 Comprehensive and exemplar governance approach. Governance is demonstrably risk-based, outcome-focused and continuously reviewed to ensure proportionality and effectiveness. Clearly defined governance strategy.
Documented governance tailoring decisions.
Evidence of continuous governance improvement.
Metrics or reviews demonstrating governance effectiveness.
Strong alignment between governance, delivery and risk management activities.
Minimal or no significant gaps. Governance consistently supports effective delivery and decision-making.

What assessors should look for

  1. Proportionality – Is the level of governance appropriate for the solution's risk, complexity, scale and criticality?
  2. Risk-based decision making – Is there evidence that governance activities are influenced by identified risks and architectural concerns?
  3. Consistency – Are governance processes applied consistently across the solution lifecycle?
  4. Tailoring – Has governance been consciously adapted rather than applying a one-size-fits-all approach?
  5. Oversight and control – Do governance arrangements provide sufficient scrutiny, challenge and decision-making authority?
  6. Documentation – Is the governance approach documented and understood by delivery and architecture stakeholders?

What separates a 3 from a 4 or 5

A score of 3 typically means the service is applying governance in a generally sensible way and most key reviews are taking place, but there is limited evidence that governance has been deliberately tailored to risk, complexity or organisational impact.

A score of 4 requires clear evidence that governance decisions are risk-based and proportionate. The rationale for governance activities is documented and consistently applied across the service.

A score of 5 requires governance to be demonstrably optimised for the solution. Evidence should show that governance effectiveness is regularly reviewed, governance processes evolve based on lessons learned, and governance actively improves architecture and delivery outcomes.

Suggested evidence examples (not SAF-mandated artefacts)

  • Architecture governance framework
  • Governance operating model
  • Risk-based governance assessments
  • Design Authority papers and minutes
  • TRG or PDG submissions and outcomes
  • Governance escalation criteria
  • Architecture review schedules
  • Governance decision logs
  • Service risk assessments
  • Architecture assurance reports

Updated: 04 September 2026 (SAF Version 1.1)