Skip to content

2. Stakeholders & Concerns

Recommended ISO 42010 TOGAF

ISO/IEC/IEEE 42010 requires that an architecture description identify stakeholders and their concerns. This section ensures the SAD addresses the needs of all relevant parties and documents the compliance and regulatory context.

Minimum

Identify all stakeholders with an interest in the solution’s architecture:

StakeholderRole / GroupKey ConcernsRelevant Views
Business OwnerBusinessBusiness value, cost, timelineExecutive Summary, Cost
Solution ArchitectArchitectureDesign integrity, standards complianceAll views
Security ArchitectSecurityThreat model, access control, data protectionSecurity View
Infrastructure EngineerOperationsDeployment, scaling, networkingPhysical View
Data ArchitectData ManagementData storage, classification, privacyData View
Development LeadDevelopmentComponent design, integration patternsLogical View, Integration & Data Flow View
Operations / SREOperationsObservability, incident response, reliabilityQuality Attributes
Compliance OfficerComplianceRegulatory adherence, audit evidenceGovernance
[additional stakeholders][role][concerns][views]

Guidance

Consider stakeholders from:

  • Business - sponsors, product owners, end users
  • Technology - architects, engineers, developers, DBAs
  • Operations - SRE, support teams, NOC
  • Security & Compliance - CISO office, risk, audit
  • External - vendors, customers, regulators, partners
Recommended

Map stakeholder concerns to the views and sections that address them:

ConcernStakeholder(s)Addressed In
Solution meets business requirementsBusiness Owner1. Executive Summary, 3.6 Scenarios
Solution is secure and compliantSecurity Architect, Compliance3.5 Security View, 6. Governance
Solution is reliable and recoverableOperations, Business4.2 Reliability & Resilience
Solution is cost-effectiveBusiness Owner, Finance4.4 Cost Optimisation
Solution can be operated and monitoredOperations / SRE4.1 Operational Excellence
Data is properly managed and protectedData Architect, Compliance3.4 Data View
Solution can scale to meet demandInfrastructure Engineer4.2 Reliability, 3.3 Physical View
[additional concerns][stakeholders][sections]

Guidance

The concerns matrix ensures every stakeholder’s key concerns are traceable to specific sections of the SAD. This helps reviewers verify that the architecture addresses all stakeholder needs and helps authors understand which sections matter most to which audience.

Recommended

Document the regulatory and compliance landscape that applies to this solution:

Regulation / StandardApplicabilityImpact on Design
[e.g., UK GDPR, PCI-DSS, US SOX, UK FCA][how it applies][design implications]

Does the solution support any regulated activities?

  • Yes - [describe which regulated activities and entities]
  • No

List any internal or external standards that the design must conform to:

StandardVersionApplicability
[e.g., internal security standard][version][which sections]

Guidance

Identifying the compliance landscape early shapes the entire design. Common regulations to consider:

  • Data protection — UK GDPR, EU GDPR, UK Data Protection Act, US CCPA
  • Financial services — PCI-DSS, US SOX, UK FCA rules, EU PSD2
  • Healthcare — NHS DSPT (UK), US HIPAA, HL7/FHIR standards
  • Security — ISO 27001, NIST CSF (US), Cyber Essentials (UK), SOC 2
  • Internal — organisational security policies, cloud platform standards, data classification policies