Governance
Principles, decision rights, controls, accountability, evidence, and editorial integrity.
Framework
EAINE brings governance, knowledge, engineering, architecture, delivery, controls, reuse, and adoption together so teams can see and improve the whole system.
Clear authority and a shared language
Turn strategy into controlled, practical work
Manage delivery, platforms, and controls
Reuse what works and keep improving
Eight components
Organisations can adopt EAINE in stages. The connected design keeps governance, architecture, delivery, and operations aligned.
Principles, decision rights, controls, accountability, evidence, and editorial integrity.
A shared body of knowledge, concepts, domains, taxonomy, and language.
Capabilities connecting strategy, delivery, platform, governance, and learning.
Nine governed stages from discovery through operations and continuous improvement.
Control points for knowledge, models, agents, tools, identity, evidence, and observability.
Minimum expectations for AI SDLC, governance, evaluation, security, prompts, agents, and operations.
Repeatable approaches, tradeoffs, failure modes, and anti-patterns.
Practical implementation paths, review questions, templates, and 90-day guidance.
EAINE does not add governance after engineering. It makes accountability, evidence, and learning part of how engineering is performed.
One operating record
The components provide reusable guidance. The five traces keep one consequential outcome reconstructable from intent through production learning.
What outcome matters, for whom, and within which constraints?
Who may decide, approve, act, stop, and answer?
Which exact configuration produced the outcome?
What justified release, and what remains unknown?
What did production change for the next decision?
Applicability before control depth
Software does not become AI-native simply because AI helped build it. EAINE records AI use and risk separately, so teams apply the right controls.
E0–E4 records whether AI assists, produces, or executes engineering work.
R0–R4 records whether delivered AI informs, recommends, or executes material actions.
Seven profiles add controls for engineering use, internal or embedded AI, high impact, agents, custom models, and third parties.
Consequence and exposure set a base tier; mandatory floors prevent critical factors from being averaged away.
System connections
Business outcomes and risk appetite become use-case decisions, requirements, architecture, and measurable release criteria.
Policies become engineering controls with owners, artefacts, gates, and operational signals.
Shared capabilities support approved delivery paths without removing team or human accountability.
Real behaviour, incidents, cost, and feedback update tests, systems, standards, patterns, and investment.
Lockstep alignment map
If this map changes, it should be mirrored in the book chapters, RA control table, and the relevant website entry pages.
Book anchor: Part I + Chapter 13, Architecture as a Control System
Website anchor: /framework
Control proof: DOM-002, DOM-007, DOM-010, and lifecycle stage linkage in controls JSON.
Book anchor: Chapter 14, 15, 18
Website anchor: /ai-sdlc
Control proof: CMP-002, CMP-005, CMP-006, CMP-007, CMP-008, IF-004 to IF-007.
Book anchor: Chapters 9, 20
Website anchor: /evidence
Control proof: CMP-006, CMP-010, CMP-011, IF-005, DEC-014, DEC-018.
Book anchor: Chapter 19, Knowledge and Context Architecture
Website anchor: /library
Control proof: DOM-004, CMP-007, IF-004, REC-004, REC-005.
Book anchor: Chapters 16, 17, 22
Website anchor: /adoption
Control proof: DOM-009, DOM-010, CMP-012, CMP-013, CMP-015, REC-015, REC-016.
Role alignment
Everyone works from the same system while focusing on the decisions they own.
| Role | Primary question | EAINE starting point |
|---|---|---|
| CTO / CIO | How do we scale AI value without creating invisible enterprise risk? | Executive brief, maturity profile, 90-day adoption path |
| Engineering Leader | How do teams deliver faster while preserving quality and accountability? | AI SDLC, minimum standards, team evidence model |
| Enterprise Architect | Which shared capabilities and control points should the platform provide? | Reference architecture, traceability matrix, engineering model |
| Security / Risk Leader | Where are AI risks controlled and how can the organisation prove it? | Applicability and risk standards, security standard, evidence traceability |
| AI Engineer | What does good engineering look like beyond a working demonstration? | Lifecycle stages, evaluation, prompt/context, agent, and observability standards |
| Practitioner / Reviewer | How can I apply, challenge, and strengthen the discipline? | Worked examples, templates, patterns, review guide |