Please read this scenario prior to answering the question.
You are employed as an Enterprise Architect within an Enterprise Architecture (EA) team at an environmental agency. The agency has multiple divisions, and is responsible for overseeing environmental protection, regulation, and conservation efforts.
The agency has a well-established EA practice and follows the TOGAF standard as its method for architecture development. Along with the EA program, the agency also uses various management frameworks, including business planning, project/portfolio management, and operations management. The EA program is sponsored by the Chief Information Officer (CIO), who has actively promoted architecting with agility within the EA department as the preferred approach for projects.
The agency is preparing itself for a world where Artificial Intelligence (AI) is widely adopted. As a result, the agency is looking to determine the impact and role that AI will play moving forward.
The CIO has approved a Request for Architecture Work to look at how AI can be used for services across the agency. She has noted that digital platforms will be a priority for investment in order to scale the planned AI applications. Using AI to automate tasks and make things run smoother is seen as a big advantage. Process automation, and improved efficiency from manual, repetitive activities has been identified as the key benefits of applying generative AI to their agency’s business. This will include back-office automation, for example, for help center agents who receive hundreds of email inquiries. This should also improve services for their customers by making them more efficient and personalized, tailored to each individual’s needs.
Many of the agency leaders are worried about relying too much on AI. Some leaders think their employees will need to learn new skills. Some employees are worried they might lose their jobs to AI. Other leaders worry about security and cyber resilience in the digital platforms needed for AI to be successful.
Refer to the scenario.
The EA team leader has asked how to address the concerns, and how to manage the risks of a new architecture for the project.
Based on the TOGAF standard, which of the following is the best answer?
A. You recommend creating an Organization Map to display the links between different parts of the agency. This will help the EA team to find and involve all areas of the agency impacted by this strategic change. Multiple business models should then be created that can be applied to AI related projects. A meeting will be held with the stakeholders to teach them how to interpret the models and see how their concerns are being addressed. Risk will be managed as part of the Security Architecture development.
B. You recommend that the key stakeholders be formally identified. This should include those who will be most helpful for the change to be successful. A Communication Plan should be made to address their needs. This plan should include a report that summarizes the key features of the architecture based on stakeholder requirements and addressing concerns. You meet with each key stakeholder to make sure their concerns are being addressed. You make sure that the architecture being developed clearly addresses risk management.
C. You recommend conducting an analysis that separates the different types of stakeholders into groups. They can be put into categories including corporate functions, end-user organization, project organization, systems, and external. Models should be developed for each stakeholder category to ensure that all the necessary information and details are considered. A meeting should be held with the stakeholders to verify that their concerns have been addressed. Risk management will be considered during the Implementation Governance phase.
D. You recommend an assessment of the power, influence, and interest of key individuals affected by the project. This includes documenting the positions, concerns, issues, and cultural factors of each interest group. This information will shape how the architecture is presented and explained. The concerns and relevant views can be defined for each group and recorded in the Architecture Vision document. The requirements for addressing risk should be recorded in the Architecture Requirements Specification and checked through regular assessments and feedback.
Explanation:
Option D is the best answer because it most closely follows the TOGAF guidance for Phase A C Architecture Vision, where stakeholder management and risk identification are fundamental activities. The scenario emphasizes multiple stakeholder concerns, including AI adoption, workforce impact, security, cyber resilience, and organizational change. TOGAF recommends performing stakeholder analysis by assessing each stakeholder’s power, influence, interest, concerns, issues, and cultural considerations. This information is then used to determine appropriate viewpoints, communications, and architecture views.
TOGAF also requires that stakeholder concerns be reflected in the Architecture Vision, which provides a shared understanding of the proposed architecture and demonstrates how stakeholder concerns will be addressed. At the same time, architecture-related risks and the requirements needed to mitigate them should be captured in the Architecture Requirements Specification, where they can be traced and managed throughout the ADM lifecycle. Continuous review and feedback ensure that risks remain visible and that requirements continue to reflect stakeholder needs as the architecture evolves.
Option A incorrectly limits risk management to Security Architecture.
Option B includes stakeholder identification and communication but omits TOGAF's emphasis on stakeholder analysis, viewpoints, and formal recording of risks and requirements.
Option C incorrectly postpones risk management until Implementation Governance. Therefore, Option D is the answer most closely aligned with the TOGAF Standard.