Requirements - Solution Design & Methods
-
SD12 - Well Architected Framework
The relevant cloud 'Well Architected Framework' should be followed, and the solutions assessed against it.
Requirement description
This requirement is about ensuring cloud-hosted solutions are designed, reviewed and maintained using the relevant cloud provider's Well-Architected Framework.
The focus is not simply using cloud services. The solution should be assessed against the appropriate framework and demonstrate that architectural decisions have considered areas such as reliability, security, operational excellence, performance, cost optimisation and sustainability where applicable.
The assessment should show that risks have been identified, recommendations have been considered and improvement actions are being managed.
In simple terms:
Design cloud solutions using recognised cloud architecture best practice and periodically assess compliance against the relevant Well-Architected Framework.
Scoring rubric table – Cloud Well-Architected Assessment
| Score | What it looks like | Typical evidence | Key gaps / risks |
|---|---|---|---|
| 0 | No evidence that a Well-Architected Framework has been considered or applied. | No assessment, no architecture review, no documented consideration of cloud architecture principles. | Significant service risk. Cloud architecture quality cannot be demonstrated and major risks may be unidentified. |
| 1 | Limited awareness of Well-Architected principles. Some cloud design decisions have been made but there is little formal assessment evidence. | Informal discussions, isolated architecture artefacts, undocumented assumptions regarding cloud services. | High-risk gaps. Architectural weaknesses may exist across security, resilience, performance or operational management. |
| 2 | Some elements of the relevant Well-Architected Framework have been considered and partially assessed. | Partial assessment records, architecture documentation, evidence that selected framework principles have been reviewed. | Significant notable gaps. Assessment coverage is incomplete and findings may not be tracked or acted upon. |
| 3 | Much of the framework has been assessed and there is acceptable evidence that recommendations have informed the solution design. | Well-Architected review outputs, architecture decisions linked to assessment findings, documented risks, actions and mitigations. | Notable gaps remain. Some framework areas have not been fully assessed, remediation actions may be incomplete, or review activities are not regularly repeated. |
| 4 | Most applicable Well-Architected principles have been assessed with clear evidence that findings are actively managed through architecture and governance processes. | Completed assessments, documented remediation plans with owners, governance review records, regular reassessment activities, architectural evidence demonstrating implementation of recommendations. | Minor gaps only. Remaining weaknesses are understood, documented and managed through agreed action plans. |
| 5 | Comprehensive and exemplar adoption of Well-Architected practices. Assessments are routinely performed, findings drive continuous improvement and architectural decisions are demonstrably aligned to framework principles. | Maintained assessment history, measurable improvement plans, evidence of completed remediation activities, governance oversight, architecture metrics and regular reassessment against framework recommendations. | Minimal or no significant gaps identified. |
What assessors should look for
- Framework selection – Evidence that the solution uses the appropriate cloud provider's Well-Architected Framework.
- Formal assessment – Evidence that a structured assessment has been completed rather than relying solely on architectural judgement.
- Coverage of framework domains – Evidence that relevant areas such as security, reliability, operational excellence, performance and cost considerations have been reviewed.
- Management of findings – Evidence that identified weaknesses have owners, actions and review arrangements.
- Governance – Evidence that assessment outcomes are visible within architecture governance and risk management processes.
- Continuous improvement – Evidence that assessments are repeated periodically and used to improve the solution over time.
What separates a 3 from a 4 or 5
A score of 3 usually indicates that a meaningful Well-Architected assessment has been completed and that findings have influenced parts of the solution design. However, there are still notable gaps in coverage, governance, ownership of actions or remediation progress.
A score of 4 requires evidence that assessment findings are actively managed. Actions have owners, governance reviews occur, remediation activity is tracked and most framework recommendations have been addressed or formally accepted.
A score of 5 requires evidence of a mature and repeatable process. Assessments are routinely performed, findings are used to drive continuous improvement, governance oversight is visible and architectural decisions can be traced back to framework recommendations.
Suggested evidence examples (not SAF-mandated artefacts)
- AWS Well-Architected Review outputs
- Azure Well-Architected Review outputs
- Architecture assessment reports
- Cloud risk registers
- Remediation plans with owners and target dates
- Architecture Decision Records influenced by assessment findings
- Design authority review papers
- Governance dashboards tracking remediation progress
- Evidence of reassessment following major architectural changes
Updated: 04 September 2026 (SAF Version 1.1)