Reference Architecture Studio

For governance & assurance owners

Make every consequential AI system knowable, owned, and governable.

Build the operating system behind responsible AI decisions: inventory, risk tiers, accountable gates, controls, evidence, monitoring, and a credible path to change, pause, or retire.

Buyer problem

The risk is larger than the model.

Purpose, affected people, data, retrieval, prompts, tools, vendors, access, monitoring, and human intervention shape the real system. When those parts live in separate documents—or nowhere—approvals become inconsistent, evidence becomes fragile, and change becomes invisible.

Discovery & advisory entry

Governance Baseline or Operating Model Design

Start with the smallest boundary that can retire uncertainty: inventory a priority portfolio, assess maturity and material gaps, classify risk, map applicable obligations, define decision rights and controls, and produce an activation plan.

  • AI-system and use-case inventory
  • Current-state and maturity evidence
  • Risk classification and assessment plan
  • Decision rights, gates, controls, and forums
  • Prioritized roadmap and professional-review questions

Governance decision landscape

Govern the decision, then preserve the evidence.

01

Intake & inventory

Name purpose, boundary, owners, people, data, models, retrieval, tools, vendors, and lifecycle state.

02

Classify & assess

Set a tier and evaluate technical, human, third-party, security, privacy, and applicability risks.

03

Decide & approve

Approve, condition, reject, or pause with named authority, evidence, expiration, and review triggers.

04

Control & evidence

Activate policies, standards, controls, architecture records, evaluations, and acceptance evidence.

05

Monitor & respond

Watch quality, drift, incidents, exceptions, adoption, cost, residual risk, and control performance.

06

Change or retire

Reassess material change, transfer records, revoke access, retain or delete evidence, and close cleanly.

Select / Source

Reuse systems of record before buying a control plane.

Map capabilities across the client’s GRC, ITSM, IAM, catalog, MLOps, observability, records, security, and reporting estate. Add or source a governance platform only when scale, enforcement, evidence, or workflow requirements justify it.

Commercial boundary: Scott supports capability evaluation, platform selection, and sourcing. Resale, pricing rights, partnership, certification, or product implementation experience is never implied without current evidence and authorization.

Capability-first reference architecture

Eight delivery domains, three control planes, and human accountability.

Products are representative options under active evidence review—not a bill of materials.

1. Governed data foundationAuthoritative data · lifecycle · access · lineage · recoveryRepresentative options: Databricks Unity Catalog · Snowflake Horizon Catalog · AWS Lake Formation
2. Data movement & transformationAuthorized movement · reproducible transformation · tests · recovery · ownersRepresentative options: Fivetran Automated Data Movement · dbt platform
3. Streaming & event contractsOwned streams · schemas · compatibility · replay · retention · observabilityRepresentative option: Confluent Platform
4. Metadata, lineage, quality & observabilityMeaning · ownership · provenance · quality evidence · operational healthRepresentative options: Microsoft Purview · Google Knowledge Catalog · OpenMetadata · OpenLineage · GX Core · Monte Carlo Data + AI Observability
5. Model & AI lifecycleVersions · datasets · evaluations · approvals · releases · monitoring · retirementRepresentative options: MLflow Model Registry · IBM watsonx.governance
6. Model access & AI gatewayIdentity · data boundaries · routing policy · quotas · logs · fallbackRepresentative options: Amazon Bedrock · Microsoft Foundry · Vertex AI Model Garden · OpenAI Responses API · LiteLLM Proxy
7. Retrieval & enterprise knowledgeSource permissions · provenance · freshness · retrieval quality · deletion propagationRepresentative options: Pinecone Database · Weaviate Database · pgvector
8. Agent runtime & orchestrationExplicit tools · least privilege · bounded state · approvals · reconstructable actionsRepresentative option: LangGraph
Control plane: privacy, security, access & policyIdentity · secrets · classification · enforcement · encryption · retention · supply chainRepresentative options: BigID Data Discovery and Classification · Privacera Access Management · Open Policy Agent · HashiCorp Vault
Control plane: evaluation, tracing & runtime safetyVersioned tests · privacy-aware traces · thresholds · feedback · incident triggersRepresentative options: LangSmith · Arize Phoenix · MLflow Tracing · NVIDIA NeMo Guardrails · Amazon Bedrock Guardrails · Google Model Armor
Control plane: governance workflow, evidence, cost & usageInventory · risk · approvals · exceptions · incidents · budgets · value evidenceRepresentative options: OneTrust AI Governance · ServiceNow AI Control Tower · FOCUS Specification
Human accountability & operating modelPurpose · risk acceptance · competence · review · intervention · recourse · stop authorityNo product slot. Named people remain accountable.

Representative technologies illustrate credible implementation paths. Inclusion does not indicate partnership, endorsement, certification, implementation experience, or a required product.

Implement via FDE

Operationalize the model in real delivery workflows.

FDE can configure governance and evidence workflows, integrate systems of record, instrument evaluation and monitoring, implement technical controls, automate decision and evidence flows, establish incident and exception procedures, train owners, and complete acceptance and transfer.

Explore Forward Deployed Engineering →
Inventory and workflow activationControl and evidence implementationArchitecture and decision recordsEvaluation, monitoring, and human oversightTraining, cadence, transfer, and support

Standards, regulation & assurance

Map useful references to actual operating evidence.

The model can map to NIST AI RMF and its Generative AI Profile, ISO/IEC 42001 and related AI, data, security, and privacy standards, and current legal requirements including the EU AI Act. Mapping is an implementation aid—not legal advice, certification, conformance, or a fixed applicability conclusion. Qualified review remains required.

Outcomes & deliverables

A governance capability the organization can run.

Known portfolio and accountable ownersRisk tiers and assessment recordsDecision rights, forums, and gatesPolicy, standards, and control librarySystem, data, model, retrieval, and agent cardsEvaluation, monitoring, and incident proceduresEvidence register and executive reportingTraining, cadence, renewal, and closeout
01

Discover

02

Advise

03

Select / Source

04

Implement via FDE

05

Adopt / Optimize / Expand

Start with one portfolio, system, or use case

Bring the governance decision and the evidence you have today.