Skip to main content

Connecting the framework to TOGAF 10 ADM

Embedding Generative AI into the TOGAF 10 Architecture Development Method (ADM)​

Deploying Generative Artificial Intelligence (GenAI) at an enterprise scale does not require discarding established corporate governance or enterprise architecture (EA) practices. Doing so introduces significant operational, compliance, and financial risk. Instead, high-performing technology leaders integrate GenAI capabilities directly into The Open Group Architecture Framework (TOGAF 10) ADM.

Traditional Enterprise Architecture is designed around deterministic software systems: inputs yield predictable, repeatable outputs. GenAI introduces probabilistic intelligence, where identical inputs can yield varying, non-deterministic outputs based on statistical weights. To manage this paradigm shift safely and profitably, technology executives must adapt the ADM cycle to accommodate non-deterministic execution, dynamic data boundaries, and specialized hardware constraints.

The layout below maps the entry points where probabilistic AI workloads interlock with the standard TOGAF ADM lifecycle.

Phase A: Architecture Vision​

Adapting to Probabilistic Intelligence​

Phase A establishes the strategic boundary, identifies key stakeholders, and validates the high-level business value of the proposed architecture. When adapting Phase A for GenAI, leaders must transition from a pure cost-benefit lens to an AI Opportunity & Feasibility Matrix.

1. Strategic Guardrails & Scoping​

Every GenAI initiative must be classified by its architectural impact and risk exposure. This is achieved using the Enterprise AI Archetype Framework:

  • Archetype 1: Productivity Enhancers (Low Risk). Internal-facing systems with an expert user in the loop (e.g., automated internal documentation search, code assistants).
  • Archetype 2: Operational Transformers (Medium Risk). B2B or customer-assisted systems requiring bounded reasoning (e.g., contract analysis tools, customer service copilots).
  • Archetype 3: Autonomous Agents (High Risk). Unassisted, customer-facing, or transaction-executing systems (e.g., autonomous negotiation agents, real-time medical or financial advising).

2. The AI Architecture Capability Assessment Template​

Before proceeding to baseline architecture definition, the CTO/Enterprise Architecture Board must evaluate readiness across five core pillars. Use this structural assessment scorecard during Phase A tollgate reviews:

PillarArchitectural DimensionEvaluation CriteriaTarget Metric / Artifact
Cognitive ReadinessTask AppropriatenessIs a LLM actually required, or can a deterministic rules engine/heuristic model solve this?Task Complexity Mapping
Data MaturityContext AvailabilityDoes the organization possess high-quality, unstructured proprietary data to differentiate the model?Data Cleanliness Score (> 85%)
Compute & NetworkInfrastructure ElasticityCan the current network handle distributed inference workloads and low-latency API hops?Target Latency SLA (< 2.0s)
Trust & ComplianceAlignment & BiasAre there mechanisms to track data lineage, PII leakage, and non-deterministic drift?AI Risk Register
Talent & OpsLLMOps CapabilityDoes the team possess prompt engineering, retrieval-augmented generation (RAG) tuning, and evaluation skills?Skill Gap Matrix

Phase B: Business Architecture​

Designing the Human-in-the-Loop Lifecycle​

Phase B ensures that business processes match strategic goals. For GenAI, this means redefining workflows to manage non-deterministic outputs through structured exception-handling loops.

1. Process Redesign with Cognitive Triage​

When integrating an LLM or autonomous agent into a business process, the business architecture must classify every process node using a Cognitive Triage Framework:

Cognitive Triage Framework

2. Best Practices for Human-in-the-Loop (HITL) Engineering​

  • Dual-Custody Workflows: For high-value transactions (e.g., credit approvals, medical summaries generated by AI), require a human operator to sign off on the AI-generated artifact before committing it to a system of record.
  • Asynchronous Exception Handling: Design the business architecture to tolerate latency when the AI flags an output as "low-confidence," shunting the payload to a human queue without breaking the synchronous system pipeline.
  • Continuous Feedback Aggregation: Capture user corrections (edits to the AI output) as structured data. These inputs are fed directly into Phase C as reinforcement learning or fine-tuning datasets.

Phase C: Information Systems Architecture​

Data Architecture for Contextual Retrieval​

Phase C encompasses Data and Application Architecture. GenAI turns traditional enterprise data warehouses upside down by prioritizing unstructured data pipelines and vector embeddings over traditional relational schemas.

Phase C Data Pipeline

1. The Vector Storage Asset Strategy​

Relational databases are ill-equipped to handle semantic search. The Target Data Architecture must incorporate specialized vector database patterns:

  • Hybrid Search Topologies: Combine traditional lexical search (BM25) with dense vector search (Cosine/Dot Product similarity) to maintain keyword accuracy alongside conceptual understanding.
  • Partitioning & Tenant Isolation: Isolate embeddings by business unit or security clearance level at the database layer (e.g., using metadata filtering) to prevent unauthorized cross-department data retrieval through prompts.

2. Chunking and Embedding Specifications​

Data architects must define standard enterprise data preparation frameworks:

  • Dynamic Chunking: Avoid fixed-size text chunking. Implement semantic chunking that respects structural boundaries like paragraphs, Markdown headers, or token budget limits.
  • Embedding Model Standardization: Mandate that all applications utilizing a specific vector namespace share identical embedding models and dimensions (e.g., 1536-dimensional text-embedding vectors) to guarantee semantic alignment.

Phase D: Technology Architecture​

Physical Infrastructure, Gateways, and Isolation​

Phase D translates logical application blueprints into physical hardware configurations, hosting strategies, and networking topologies.

1. Model Infrastructure Options: A Comparative Trade-off Matrix​

Enterprise technology leaders must align their infrastructure deployment with security and performance SLAs. Use this architectural reference table during the technology selection process:

Architectural StyleLatencyCapex / Opex ProfileSecurity & PrivacyEngineering Overhead
Public API Gateway (e.g., OpenAI, Anthropic cloud)Lowest time-to-market; high concurrencyZero Capex; predictable volume-based OpexShared responsibility; requires strict data processing agreementsMinimal; simple REST integration
Private Cloud Deployment (VPC Hosted Virtual Appliances)Medium; bound by cloud instance scaling limitsLow Capex; high, continuous run-rate OpexHigh; data remains within company-managed boundariesModerate; requires infrastructure orchestration
On-Premises Bare Metal (Dedicated GPU Clusters)Highest predictability; lowest localized latencyExtreme Capex; low localized operational run-rateMaximum; physical and logical control over weights and dataHigh; requires specialized infrastructure teams

2. The AI API Gateway Pattern​

Never let individual software applications call model endpoints directly. Introduce a dedicated Enterprise AI Gateway Layer to act as a reverse proxy. This gateway enforces critical capabilities:

  • Rate Limiting & Token Throttling: Prevent cost overruns from malfunctioning applications or malicious prompt injections by restricting token consumption per API key.
  • Model Fallback and Circuit Breaking: If a primary model provider goes down or encounters an API error, automatically route the payload to a secondary fallback model to maintain uptime.
  • PII & Compliance Scrubbing: Intercept incoming prompts in real-time to detect and redact Tax IDs, credit card numbers, or proprietary source code before transmission outside company firewalls.

3. Network Isolation Zones​

Isolate model fine-tuning and inference infrastructure from the general corporate network. Deploy Zero Trust Network Access (ZTNA) and dedicated VPC endpoints, ensuring that training clusters cannot communicate directly with the public internet without passing through stateful packet inspection firewalls.

Phase E: Opportunities and Solutions​

Transitioning from POC to Production Scale​

Phase E evaluates implementation vehicles, identifies major projects, and determines the migration strategy to deliver the Target Architecture. This phase prevents the "POC Trap," where projects stall at the prototype stage.

1. The Build vs. Buy Strategy Framework​

Before allocating capital, utilize this strategic rubric to evaluate every proposed GenAI solution:

The Build vs. Buy Strategy Framework

2. Production Rollout & Transition Architecture​

Transitioning fragile proofs of concept into scalable production platforms requires structured Transition Architectures (as defined by TOGAF) to derisk deployment:

  • State 1: Shadow Inference. Deploy the new GenAI application in parallel with existing legacy workflows. Feed real-world data into the model and log its outputs, but do not present them to end users. Run automated validation checks to quantify drift and hallucination rates.
  • State 2: Canary Releases. Route a minor portion of transactional volume (e.g., 5% of traffic) to the model. Pair this with real-time logging tools to capture exception codes and guardrail violations immediately.
  • State 3: Full Production with Blue-Green Upgrades. Achieve full deployment. Implement a blue-green upgrade structure for underlying model parameters. Since models change performance when retrained or adjusted, maintain the old model architecture active ("Blue") while testing user sentiment and system response against the new model configuration ("Green").

Architecture Governance Blueprint​

Enterprise Tollgates for Architecture Review Boards (ARB)​

To maintain architectural compliance across the ADM cycle, the Enterprise Architecture Review Board must mandate three concrete artifacts before approving any GenAI platform for production deployment:

  1. The Context Injection Audit: Documentation demonstrating that the data feeding the model is clean, permissioned, and appropriately bounded by role-based access control (RBAC).
  2. The Cost and Token Model Sandbox: A financial projection tool mapping anticipated system scale against token usage profiles, showing clear break-even parameters.
  3. The Vulnerability Mitigation Plan: Explicit validation that the system resists common vulnerabilities like Prompt Injection, Insecure Output Handling, and Denial of Service (DoS) via long-context saturation.

By systematically embedding these steps directly into Phases A through E of your TOGAF 10 framework, your enterprise ensures that its adoption of Generative AI is structured, resilient, and ready to scale.