Architecture Compliance Checks
Automating conformance to standards so review effort goes to the genuinely novel.
5 to work through
-
intermediate
A policy-as-code gate has run in warn mode for 18 months across 400 repositories. The dashboard shows 2,300 open violations. Leadership asks you to switch it to blocking next month. What happens if you do, and what is the sequence that actually works?
2 min answer -
intermediate
Which architecture requirements can be checked automatically, and which cannot?
2 min answer -
advanced
Every infrastructure pull request passes the policy-as-code check. A quarterly scan finds 40 object storage buckets without the required encryption setting and 12 with public access. Nothing has been merged that would create them. Where is the gap?
3 min answer -
advanced
How can architectural standards be enforced automatically, and which standards genuinely cannot be?
2 min answer -
advanced
How do you check that implemented systems match agreed architectural decisions, without a review board?
1 min answer
5 terms in this topic
Architecture Compliance Check
Automated verification that a running system still conforms to the architectural decisions and standards it was approved against.
practiceConformance Automation
Encoding architectural standards as automated checks, so review effort is spent on novel design decisions rather than on verifying known rules.
practicePolicy as Code
Expressing controls as executable rules evaluated automatically against real system state, so that compliance is demonstrated continuously over the w…
conceptRuntime Compliance Drift
The growing gap between what infrastructure code declares and what the running estate actually looks like, which a pipeline-based policy check cannot…
conceptWarn-Mode Debt
The accumulated violations of a policy that has only ever warned, which makes switching it to blocking politically impossible and hides how many of i…
Neighbouring topics
Assurance, Audit & Model Risk
General material on assurance, architectural governance and risk oversight.
Control Design vs Operation
A control that is well designed and never runs fails exactly like one that is absent.
Audit Evidence
Producing durable, tamper-evident proof as a by-product rather than as a project.
Certification Impact on Architecture
What SOC 2 and ISO 27001 actually require of a design, and what they do not.
Continuous Controls Monitoring
Testing controls continuously instead of sampling them once a year.
Segregation of Duties
Splitting authority so no single actor can both make and approve a change.
Change Advisory vs Automated Gates
Replacing a weekly board with evidence a machine produces on every change.
Risk Appetite
The stated tolerance that tells you which risks you are allowed to accept.
Risk Assessment Methods
Qualitative matrices, FAIR and scenario analysis, and the illusion of a precise score.
Security Design Review
Reviewing an architecture for security while changing it is still cheap.
Exception & Waiver Management
Time-boxed, owned deviations with a remediation date, rather than permanent silence.
Design Authority
How an ARB should decide, what it should not review, and how it avoids becoming a queue.
Three Lines Model
Ownership, oversight and independent assurance, and where architecture sits in it.
Model Risk Management
Inventory, validation, monitoring and challenge for models that make consequential decisions.
AI Risk Tiering
Classifying a use case by potential harm, and the obligations each tier triggers.
Model Documentation
Model cards, intended use, limitations, and the record a regulator will ask for.
Model Evaluation & Red-Teaming
Adversarial testing of a probabilistic system with no fixed expected output.
Bias & Fairness Controls
Measuring disparate outcomes, choosing a fairness definition, and living with the trade-off.
Human-in-the-Loop Design
Meaningful review rather than a rubber stamp, and designing against automation bias.