About Expertise Frameworks Experience Case Studies Services Skills Contact →

Three lenses,
one integrated practice.

Together they answer the three questions every transformation must: why we are changing, what we are building, and how it aligns with national and international standards.

The methods I anchor on.

// Framework 01
TOGAF
The Open Group Architecture Framework

A disciplined, iterative method for designing the enterprise. I apply the Architecture Development Method (ADM) end-to-end — vision through governance — keeping every artifact traceable to business value.

  • ADM phases A through H
  • Architecture Repository & Continuum
  • Capability-based planning
  • Architecture Governance Board
  • Reference models & building blocks
// Framework 02
NORA
National Overall Reference Architecture · KSA

Saudi Arabia's reference architecture for digital government. I align engagements with NORA to ensure compliance with national digital governance, interoperability, and citizen-experience standards across Vision 2030 initiatives.

  • Business · Data · Application · Tech layers
  • Saudi digital governance alignment
  • Vision 2030 traceability
  • Interoperability standards
  • Citizen-centric service design
// Framework 03
ArchiMate
Open Group Modeling Standard

The visual language that makes architecture decisions reviewable. I model business processes, application landscapes, data flows, and technology stacks as a single, navigable map — bridging strategy and implementation.

  • Strategy, Business, Application, Tech, Physical
  • Motivation & Implementation extensions
  • Cross-layer relationships & viewpoints
  • Sparx EA & Visual Paradigm modeling
  • Living architecture documentation

What separates an enterprise architect.

Anyone can draw a target state. The discipline is governing the journey — managing risk, setting guardrails, and proving compliance the whole way.

Architecture Governance

I stand up and run Architecture Review Boards (ARB) — a cadence where every significant decision is reviewed against principles, standards, and the target architecture before it ships.

  • Architecture principles & decision records (ADRs)
  • Compliance reviews at each ADM gate
  • Vendor & SOW technical review against standards
  • Exception & waiver process with sunset dates
Risk & Controls

Risk is tracked, owned, and burned down — not discovered at go-live. I maintain a living risk register and design guardrails into the platform so the safe path is the easy path.

  • Risk register with owners, likelihood & impact
  • Privacy-by-design & least-privilege guardrails
  • Zero Trust segmentation & identity controls
  • HIPAA / GDPR alignment, audit logging, encryption
Compliance & standards in play
TOGAF ADM Governance NORA · KSA Digital Governance HIMSS Stage 6 HIPAA GDPR Zero Trust AAA Model Encryption-at-Rest Audit Logging

Building a governance function from scratch?

I help establish ARBs, principles, and risk processes that make transformation auditable and repeatable.

Get in Touch → in · LinkedIn