Adapting enterprise architecture for the AI Act and DORA

Adapting-enterprise-architecture-for-the-AI-Act-and-DORA

Digital Content Editor, Eve Goode hears exclusively from Nick Reed, Chief Strategy Officer of Bizzdesign about how enterprise architecture must adapt ahead of the AI Act and DORA.

How are leading organisations adapting their enterprise architecture to meet new regulations like the AI Act and DORA?

Leading organisations are shifting from a reactive, reporting-led view of compliance to a proactive, continuous governance approach.

Enterprise architecture (EA) is central to that shift, moving from static documentation to dynamic models that reflect how critical business processes interact with AI, systems, data and third parties on which they depend.

These live digital models provide real-time insights into complex dependencies, enabling more effective anticipation, management of and recovery from, incidents and disruption.

That shift toward continuous oversight is also changing when compliance work begins.

Organisations are using the extended timeline under the EU AI Act to build governance into transformation efforts from the start, rather than deferring compliance readiness.

This earlier intervention depends on better visibility.

Organisations are using EA to surface interdependencies across the enterprise, including where AI is used, the technology and vendors involved, the data it processes and its compliance and cost status.

EA models enable stakeholders to simulate how disruption impacts interconnected systems and business processes, allowing identification of vendor concentration risk.

These EA models can include mappings to regulatory compliance requirements, enabling a holistic approach to achieving business outcomes taking compliance into account up front, resulting in outcomes which are “compliant by design.”

With that foundation in place, organisations are moving away from treating each regulation and standard as a separate compliance effort, identifying common infrastructure needs across frameworks to avoid duplication.

EA increasingly acts as a coordination layer, connecting and de-duplicating requirements across AI Act, DORA, GDPR and NIS2, and enabling cross-functional alignment between security, risk, legal and business teams and a more streamlined approach to control implementation and compliance reporting and monitoring.

This approach helps maximise compliance return on investment by enabling leaders to take a business perspective on prioritising investment by identifying areas of highest risk and impact, avoiding blanket compliance spending and linking compliance spend directly to business value.

What role does architectural visibility play in identifying compliance risks across IT environments?

Architectural visibility is the key foundation for ensuring a complete enterprise-wide view of risk across IT environments.

At a basic level, it establishes a shared view of how business processes, data, and technology connect to compliance requirements.

Without it, it’s hard to know if risk assessment has covered everything in that IT landscape and where the compliance gaps are.

From that foundation, ownership and accountability becomes explicit.

Roles can be mapped to assets, assets to compliance requirements, and requirements to controls, gaps and risks, creating clarity that can be evidenced and audited.

The same architectural visibility allows organisations to assess scope of applicability with greater clarity.

When the landscape changes, whether through new systems, changes in suppliers or evolving regulations, impact of changes can be modelled and identified proactively, rather than discovering gaps retrospectively.

For example, when a vendor tool is reclassified as high-risk, or a change in the application landscape that requires re-assessment, these models enable organisations to answer critical questions fast: Which processes depend on it? What data does it store or process? Are there alternatives? How quickly can we resolve a compliance gap? What is the scope and impact of making a change?

Crucially, architectural visibility enables a business-led perspective for risk prioritisation based on business impact, enabling team to focus on the most important response activities first.

During incidents, architectural visibility also accelerates response and recovery by identifying affected systems, data, customers and regulatory obligations and all the dependencies between them in real time, enabling response and recovery actions to be optimally sequenced to accelerate recovery time and improve resilience.

How are governance frameworks evolving to improve accountability and traceability under these regulations?

Clearly, the speed with which AI technology is evolving is placing immense pressure on organisations to adapt their governance to keep pace.

There are no well-established playbooks for this, so everyone is essentially having to figure it out as they go.

The need to adopt AI at speed means governance frameworks have to facilitate experimentation at speed, which simultaneously balancing it with ensuring privacy, security, resilience and compliance when deployed into production in business operations.

This means governance frameworks need to bifurcate into “explore” and “exploit” modes.

Innovation and experimentation are governed by “explore mode” where teams can move fast in the knowledge that there is limited risk of causing serious harm, for example, using synthesided data, which mimics the characteristics of real data, but with sensitive data obfuscated or anonymised.

Production deployment and scaling are governed by “exploit mode” where the boundaries for accountability and ownership are clearly defined and compliance requirements and controls are applied and tested.

This is particularly important where AI is concerned, as AI models may process data from many different sources and how it uses that data is not fully deterministic and may not be explainable.

Ensuring separation of accountability for data quality at source, with approved data platforms or products and data processing with AI, with clear ownership for AI applications, provides improved accountability and traceability from a governance perspective.

Agentic AI provides additional new challenges. When AI agents are able to process data and take action in real-time, traditional governance approaches no longer work.

Clear identification of where “human in the loop” governance is required is essential, to ensure human accountability for approvals is enabled.

Where agents need to act autonomously, governance guardrails need to be baked into the agents in the form of “policy as code,” so agents ‘know’ the boundaries within which they must operate.

In all of this, feedback loops are critical, to ensure AI-driven outcomes are evaluated and AI applications are optimised on an ongoing basis to ensure results comply with governance requirements, such as confidence levels in the correctness of results, levels of bias, privacy and security compliance.

Above all, the one certainty at the current time is that things will continue to evolve and change at high speed.

So, flexibility and adaptability in governance frameworks will become an increasingly important characteristic.

There is no point over-engineering governance frameworks now if there is a good chance they will need to be reworked in a few months’ time.

What practical steps are organisations taking to manage AI risk and transparency requirements?

Organisations are starting by building foundational visibility of AI systems and associated risk.

This includes creating and maintaining a living inventory of AI systems and use cases, mapped to business capabilities, processes, applications, technologies and relevant compliance requirements, ensuring no system operates outside the scope of governance frameworks.

They’re also clarifying roles under the EU AI Act by understanding whether they’re acting as a provider, deployer, importer or distributor, because those roles can shift based on how AI systems are modified or used.

Part of that initial work includes tackling shadow AI early by bringing ad hoc implementations into governance workflows before they become shadow AI risks or trigger unintended regulatory obligations.

With that baseline in place, organisations can embed governance more directly into operational workflows.

That includes standardising AI risk assessment and human oversight procedures through structured workflows that ensure consistent decision-making across teams and use cases.

It also involves linking risks and controls to business and IT context, and integrating AI risk management with existing security, risk and resilience functions rather than treating it as a standalone domain.

Additionally, organisations are prioritising governance based on AI risk categories, applying stricter controls to higher-risk or higher-impact systems while enabling lighter-touch oversight for lower-risk use cases.

A further step is ensuring traceability, accountability and third-party oversight.

Organisations are establishing data lineage and quality controls to trace data flows from source systems to AI models, documenting provenance, transformations and quality checks across the pipeline.

They’re also bringing third-party AI providers into governance scope through due diligence, contractual requirements, and ongoing monitoring, which is particularly important in regulated environments where supplier dependencies can introduce direct risk exposure.

Establishing clear boundaries and ownership of data sources and targets also helps define the scope of accountability clearly, enabling separation of roles such as data provision and data processing.

How can organisations strengthen operational resilience to meet DORA requirements?

Organisations can strengthen operational resilience under DORA by building a clearer understanding of the dependencies of critical services on business processes, applications, data flows, locations and third parties, and the interdependencies across all these dimensions.

This involves mapping critical services to the underlying systems, data and third‑party providers that support them, ensuring full visibility of ICT dependencies before disruptions occur.

By doing so, organisations can identify where failures such as cyberattacks, system outages or third-party disruptions may arise and understand the potential impact on critical services.

Strengthen third-party risk management is equally critical.

The primary issue is understanding which third parties are dependencies for critical business services, alongside the other dependencies involved, so mitigation and recovery can be planned appropriately.

That also means assessing vendor concentration risk, establishing oversight mechanisms and defining clear exit or fallback strategies for critical providers.

Once dependencies are understood, organisations also need proactive monitoring and regular resilience testing.

Continuous monitoring of service health helps detect degradation early, enabling anticipation of failures before they escalate into full outages or trigger reportable incidents.

Making resilience testing routine through scenario-based exercises, penetration testing and threat-led testing helps validate preparedness and identify gaps in response capabilities.

Participating in information-sharing arrangements also improves collective defence against systemic threats and keeps organisations informed about emerging risks affecting the financial sector.

Another important step is to treat resilience as a day-to-day, business-as-usual activity rather than a one-off or periodic compliance project.

In practice, that means building resilience activity into standard operating processes and procedures across roles and responsibilities, so it becomes part of how the organisation operates, rather than applied as one-off or ad hoc “fire drills”.

Equally important is establishing real-time incident detection, classification and reporting that aligns with DORA requirements, enabling organisations to meet regulatory timelines without scrambling for information.

This approach ensures resilience isn’t retrospective documentation. It’s live, traceable and embedded into how the organisation operates day-to-day.

What capabilities should organisations prioritise now to stay compliant while enabling innovation?

To stay compliant while enabling innovation, organisations should prioritise a few core capabilities.

The first is enterprise-wide visibility across AI systems, data, processes and dependencies, supported by appropriate tooling that helps organisations understand where risk, obligations and ownership sit.

This also requires assigning ownership to the initiative and ensuring executive sponsorship because these issues need to be treated as organisation-wide priorities rather than isolated technical initiatives.

Resilience and AI assurance are now board-level concerns, so they should be treated as such from an implementation perspective.

Organisations also need coordinated governance.

That means integrating governance and risk management across frameworks such as the AI Act, DORA, GDPR and NIS2, and any other relevant standards, treating compliance as a coordinated effort across all frameworks simultaneously rather than separate compliance tracks.

Data lineage and quality controls are a critical part of this, supporting the transparency, explainability and auditability that underpin both compliance and trustworthy AI at scale.

Equally important is cross-functional coordination between IT, risk, legal and business teams, ensuring governance decisions are informed by both technical reality and business context.

Organisations also need to create safe experimentation environments that allow teams to test AI solutions within controlled boundaries, enabling innovation without exposing the organisation to unmanaged risk.

To make this operational, organisations need standardised, compliant platforms, architectures and governance processes so individual projects don’t have to solve governance independently.

This reduces friction, accelerates time to value and creates the foundation for treating governance as strategic infrastructure rather than overhead.

With that infrastructure in place, organisations should align portfolio and investment decisions to prioritise compliant, high-value AI use cases, ensuring resources flow to opportunities that deliver measurable business outcomes.

This further calls for investing in skills and awareness to ensure teams understand how to innovate responsibly, embedding governance literacy across the organisation rather than concentrating it in a compliance function.

Over time, regulatory pressure can be used to build long-term adaptability.

Those that treat governance as a value-adding strategic capability, not a reactive overhead, gain the ability to move faster, scale confidently and turn compliance readiness into a competitive differentiator.

Share this content

Latest Issue

Connect with us

Free digital subscription

Receive the latest breaking news straight to your inbox