Enterprise Architecture Frameworks and Governance
In the Certified in the Governance of Enterprise IT (CGEIT) context, Enterprise Architecture (EA) is a key enabler of effective IT governance. It gives a structured, holistic view of how business processes, information, applications, and technology fit together to achieve strategic objectives. EA b… In the Certified in the Governance of Enterprise IT (CGEIT) context, Enterprise Architecture (EA) is a key enabler of effective IT governance. It gives a structured, holistic view of how business processes, information, applications, and technology fit together to achieve strategic objectives. EA bridges strategy and execution so that IT investments align with enterprise goals, deliver value, and manage risk. Enterprise Architecture Frameworks offer standardized methods, models, and vocabularies for designing and maintaining an architecture. Common frameworks include: 1. TOGAF (The Open Group Architecture Framework): Its Architecture Development Method (ADM) guides organizations through iterative phases, from the architecture vision through business, data, application, and technology architectures to migration planning and change management. 2. Zachman Framework: A classification matrix that organizes architectural artifacts by stakeholder perspective (planner, owner, designer, builder) and by interrogatives (what, how, where, who, when, why). 3. FEAF (Federal Enterprise Architecture Framework): Used mainly in the public sector to standardize architecture across government agencies. 4. COBIT: Not an EA framework itself, but it includes the 'Managed Enterprise Architecture' practice (APO03), which links EA to governance objectives. From a governance perspective, the board and executive management must ensure that EA is sponsored, resourced, and aligned with business strategy. Typical governance mechanisms include an Architecture Review Board, architecture principles and standards, compliance reviews, and exception handling. These mechanisms ensure that projects follow approved architectures, reduce redundancy, enable interoperability, and support agility. EA also supports the core CGEIT objectives. It enables benefits realization by showing how investments contribute to capabilities. It supports risk optimization by identifying technical debt and vulnerabilities. It supports resource optimization by rationalizing application portfolios and infrastructure. Key governance practices include defining the current (baseline) and target architectures, performing gap analysis, developing transition roadmaps, and measuring architecture maturity. Ultimately, EA governance turns strategic intent into coherent, well-managed IT capabilities that create sustainable business value.
Enterprise Architecture Frameworks and Governance (CGEIT: Governance of Enterprise IT)
Introduction
Enterprise Architecture (EA) is one of the most important tools a governing body has for making sure that IT investments, systems and capabilities move the organization toward its strategic goals rather than away from them. In the ISACA CGEIT (Certified in the Governance of Enterprise IT) exam, EA sits within Domain 1: Governance of Enterprise IT. It is examined from a governance perspective, not a technical one. This guide explains why EA matters, what it is, how EA frameworks and EA governance work, and how to answer exam questions on the topic.
1. Why Enterprise Architecture Is Important
EA matters because it links strategy to execution. Without it, organizations tend to build disconnected systems, duplicate capabilities, accumulate technical debt and lose sight of how technology supports the business. Its main benefits are listed below.
Strategic alignment: EA turns business strategy into a structured target state for business processes, information, applications and technology. This directly supports the CGEIT goal of aligning IT with enterprise objectives.
Value delivery: EA helps leaders prioritize the investments that contribute most to the target state. It also helps avoid redundant spending.
Risk optimization: A clear architecture reduces complexity and dependency risk. It exposes single points of failure and supports security and compliance by design.
Resource optimization: EA promotes reuse, standardization and rationalization of applications and infrastructure, which lowers total cost of ownership.
Agility and change readiness: A well-understood current state (baseline) and target state let the enterprise respond faster to mergers, regulation, digital transformation and new technologies.
Informed decision-making: EA gives the board, executives and steering committees a holistic view. Decisions on projects, sourcing and technology then rest on facts rather than silos.
Communication: EA provides a common language and set of views that business and IT stakeholders can both understand.
In governance terms, EA is an enabler. COBIT 2019 lists architecture among its governance and management objectives (APO03 Managed Enterprise Architecture). The COBIT enabler/component model also includes processes, organizational structures, principles and policies, information, and services, infrastructure and applications.
2. What Enterprise Architecture Is
Enterprise Architecture is the discipline of defining, documenting and governing the structure and behavior of an enterprise's business processes, information, applications and technology, along with the relationships between them. It covers both the current state and the target state, plus a roadmap for moving from one to the other.
Core EA domains (layers):
Business Architecture: strategy, capabilities, value streams, organization and processes.
Data/Information Architecture: data entities, ownership, flows, quality and information lifecycle.
Application Architecture: the application portfolio, its interactions and how it maps to business capabilities.
Technology Architecture: infrastructure, platforms, networks, cloud and standards.
Many frameworks also add Security Architecture as a cross-cutting concern.
Key EA artefacts:
- Architecture principles, for example 'buy before build', 'data is an asset' and 'reuse before buy'
- Baseline (as-is) and target (to-be) architectures
- Gap analysis
- Architecture roadmap and transition architectures
- Standards and reference models
- Architecture repository
- Architecture contracts and compliance assessments
3. Common Enterprise Architecture Frameworks
A framework provides a structured method, vocabulary, viewpoints and artefacts for developing and maintaining EA. CGEIT does not test the fine detail of each framework. It does expect you to recognize the main ones and what they emphasize.
TOGAF (The Open Group Architecture Framework):
- The most widely used EA framework.
- Its core is the Architecture Development Method (ADM), an iterative cycle. The phases are: Preliminary, A Architecture Vision, B Business Architecture, C Information Systems Architectures (Data and Application), D Technology Architecture, E Opportunities and Solutions, F Migration Planning, G Implementation Governance and H Architecture Change Management.
- Requirements Management sits at the center of the cycle.
- Other key elements are the Enterprise Continuum, the Architecture Repository, the Architecture Content Framework and the Architecture Capability Framework. The Architecture Capability Framework includes the Architecture Board and Architecture Compliance.
Zachman Framework:
- An ontology, or classification schema, presented as a 6x6 matrix.
- The columns are the interrogatives: What (data), How (function), Where (network), Who (people), When (time) and Why (motivation).
- The rows are perspectives: Planner/Executive, Owner/Business Management, Designer/Architect, Builder/Engineer, Implementer/Technician and User/Enterprise.
- It is not a method. It tells you what to describe, not how to develop the architecture.
FEAF (Federal Enterprise Architecture Framework):
- Used by US federal agencies.
- Based on reference models: Performance, Business, Data, Application, Infrastructure and Security.
DoDAF / MODAF / NAF: defense frameworks that emphasize viewpoints such as operational, systems and capability.
Gartner EA approach: pragmatic and business-outcome-driven. It focuses on business value, not comprehensive documentation.
ArchiMate: a modelling language, often used together with TOGAF, for visualizing architectures across layers.
Related governance frameworks:
- COBIT 2019 governs and manages EA through APO03 and links it to EDM01 (Ensured Governance Framework Setting and Maintenance), APO02 (Strategy), APO05 (Portfolio) and BAI processes.
- ITIL supports service design and the operational alignment of the architecture.
4. How EA Governance Works
EA governance is the set of structures, processes, roles and controls that ensure architecture is developed, approved, followed and kept up to date in line with business strategy. It answers four questions: who decides, by what criteria, how compliance is checked, and how exceptions are handled.
Key components of EA governance:
Governing body and executive sponsorship: the board and executive management set direction. EA must be sponsored at senior level to have authority.
Architecture Board or Architecture Review Board (ARB): a cross-functional body that approves architectures, standards, principles and exceptions. It also resolves conflicts and oversees compliance.
IT Strategy Committee and IT Steering Committee: these committees make sure EA decisions align with strategy and investment priorities.
Chief Architect / EA Office: develops and maintains the architecture, the repository and the roadmap.
Architecture principles and policies: high-level rules approved by governance that guide all IT decisions.
Architecture compliance reviews: checkpoints within project and program lifecycles where solutions are assessed against standards.
Dispensation or waiver process: a controlled, documented way to approve exceptions. Waivers are time-bound and risk-assessed, with remediation plans.
Architecture contracts: agreements between the architecture function and the development or implementation teams.
Change management: the architecture is reviewed and updated as strategy, technology or regulation changes (TOGAF Phase H).
Performance measurement: metrics such as the percentage of projects compliant with EA, the reduction in application redundancy, reuse rates, alignment scores and value realized.
Integration with portfolio management: EA informs investment decisions, so proposals are evaluated for architectural fit.
The EA governance lifecycle in practice:
1. Business strategy and drivers are set by the governing body.
2. Architecture principles and the vision are developed and approved.
3. The baseline and target architectures are defined and a gap analysis is performed.
4. A roadmap is prioritized jointly with portfolio management and the IT strategy.
5. Projects are initiated and checked for architecture compliance at defined gates.
6. Exceptions are reviewed by the ARB and risk-accepted where justified.
7. Outcomes are monitored and the architecture is refined continuously.
Critical success factors:
- Visible executive sponsorship
- Business ownership, rather than an IT-only exercise
- A clear link to strategy and value
- Pragmatic, just-enough documentation
- Integration with portfolio, project and change processes
- Skilled architects
- Measurable outcomes
Common failure causes:
- EA seen as an ivory-tower IT documentation exercise
- No enforcement mechanism
- Lack of business involvement
- An outdated repository
- No link to funding decisions
5. EA in the Context of CGEIT Domains
Domain 1, Governance of Enterprise IT: EA is a governance framework component that supports alignment and decision rights.
Domain 2, IT Resources: EA supports resource optimization, sourcing decisions and capability planning.
Domain 3, Benefits Realization: EA supports portfolio prioritization and value delivery.
Domain 4, Risk Optimization: EA reduces complexity and dependency risk and embeds security and compliance.
Expect questions that cut across domains.
6. Exam Tips: Answering Questions on Enterprise Architecture Frameworks and Governance
Think like a governance professional, not an architect. CGEIT asks what the board, senior management or governance leader should do. Prefer answers about alignment, decision rights, oversight, value and risk over technical design details.
Strategic alignment is usually the primary purpose. When asked for the PRIMARY benefit or objective of EA, the best answer is typically aligning IT with business strategy or objectives. Cost reduction, standardization and documentation are secondary benefits.
Business drives architecture. An answer saying EA should start from business strategy, capabilities and requirements beats one starting from technology. Distractors often describe a technology-first approach.
Executive sponsorship and business ownership are critical success factors. If asked what is MOST important for successful EA adoption, look for senior management support or sponsorship and business involvement.
Know the role of the Architecture Review Board. It approves standards, reviews compliance and grants exceptions. When a project wants to deviate from standards, the correct path is usually a formal exception or waiver process via the ARB, with the risk documented. It is neither silent approval nor outright rejection.
Compliance should be built into lifecycle gates. The best way to enforce EA is to integrate architecture reviews into portfolio, program and project governance, for example at business case approval and design gates. It is not achieved through after-the-fact audits alone.
Link EA to portfolio management. Investment proposals should be evaluated for architectural fit. Questions about preventing redundant or misaligned investments often point to EA and portfolio integration.
Recognize the frameworks quickly:
- ADM, phases, Architecture Board, Enterprise Continuum: TOGAF.
- Matrix, interrogatives (What/How/Where/Who/When/Why), perspectives, classification schema: Zachman.
- Reference models for government agencies: FEAF.
- APO03 Managed Enterprise Architecture: COBIT.
Gap analysis comes before the roadmap. The sequence is baseline (current state), then target state, then gap analysis, then roadmap and transition architectures. Choose answers that respect this order.
Watch for 'FIRST' questions. If an organization is starting EA, the first step is generally to understand business strategy and obtain sponsorship, or to establish principles and a governance structure. Selecting tools or documenting all current systems in detail usually comes later.
EA is continuous, not a one-time project. Prefer answers that include ongoing maintenance, change management and periodic review of the architecture against changing strategy.
Measure EA by business outcomes. The best EA metrics relate to value and alignment, for example the percentage of investments aligned with the target architecture, reduced complexity or time-to-market. The number of diagrams or documents produced is a weak metric.
Balance standardization with agility. If asked how to handle innovation or emerging technology such as cloud or AI, look for answers that update principles and standards through governance while allowing controlled exceptions. Avoid answers that block innovation or ignore standards.
Use the 'best of the right' approach. Several options may be technically correct. Choose the one that is most strategic, most preventive, most holistic and closest to governance accountability.
Beware of distractors:
- 'IT department defines architecture independently'
- 'Purchase an EA tool'
- 'Document everything in detail'
- 'Audit after implementation'
- 'Allow each business unit to set its own standards'
These are rarely the best governance answers.
7. Sample Question Walkthrough
Question: A large enterprise finds that business units are acquiring overlapping applications, which increases cost and integration complexity. What should the IT governance leader recommend FIRST?
A. Centralize all IT purchasing in the IT department
B. Establish an enterprise architecture with governance integrated into the investment approval process
C. Conduct an audit of all applications
D. Implement a new integration platform
Answer: B. It addresses the root cause, which is the lack of an architectural direction and enforcement linked to investment decisions. It is also strategic and preventive. A is a control but ignores alignment and business ownership. C is detective. D is a technical fix that treats the symptom.
8. Quick Revision Summary
- EA translates business strategy into a coherent target state across the business, data, application and technology layers.
- Its primary value is strategic alignment, supported by value delivery, risk reduction and resource optimization.
- TOGAF is a method (ADM). Zachman is a classification schema. COBIT governs EA through APO03.
- EA governance relies on sponsorship, an Architecture Board, principles, compliance reviews, waivers, architecture contracts, metrics and integration with portfolio management.
- In the exam, choose answers that are business-driven, strategic, preventive, sponsored by senior management and embedded in decision processes.
Unlock Premium Access
Certified in the Governance of Enterprise IT
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2995 Superior-grade Certified in the Governance of Enterprise IT practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CGEIT: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!