UBC — AI Solutions

Audit — Dynamic Documentation Platform

Living documentation that stays in sync with engineering, cloud, AI, and compliance activity. Documents update themselves as the organization changes.

Back to library
SOP
Fresh

SOP-SDLC-02 — Architecture & Design Review

Governs architecture decisions, design reviews, and Architecture Decision Records (ADRs).

Owner: Chief ArchitectApprover: Engineering DirectorVersion: 3.0Updated: 11/17/1969

1. Purpose

Ensure system designs meet functional, quality, security, and cost objectives before implementation.

2. Scope

All new services, significant refactors, and integration changes.

3. Definitions

  • ADR — Architecture Decision Record — a lightweight document capturing a significant design decision.
  • Design Review Board (DRB) — Standing forum that reviews significant designs.

4. Roles & Responsibilities (RACI)

ActivityRACICadence
Author designTech LeadChief ArchitectTeam, Security, SREProduct OwnerPer project
Chair Design ReviewChief ArchitectEngineering DirectorDRB membersTeamWeekly
Publish ADRTech LeadChief ArchitectDRBTeamPer decision

5. Procedure

  1. Author a design document covering context, drivers, options, decision, and consequences.
  2. Perform threat modeling with Security.
  3. Schedule DRB review; distribute materials 48 hours in advance.
  4. Record decisions as ADRs in the architecture repo.
  5. Address action items before entering implementation.

6. Inputs & Outputs

Inputs

  • Requirements baseline
  • NFRs
  • Risk register

Outputs

  • Design document
  • Threat model
  • ADRs
  • DRB minutes

7. Controls & Metrics

MetricTarget
Designs with recorded ADRs100%
Security findings closed pre-implementation≥ 95%

8. Exceptions & Escalation

  • Trivial designs may proceed via async review with a two-approver rule.

9. Records & Retention

RecordRetention
ADRsLife of system + 5 years
DRB minutes7 years
  • SOP-SDLC-03
  • Threat Modeling Guide

11. References

  • CMMI-DEV v2.0 TS
  • ISO 9001 §8.3.4
  • OWASP SAMM

12. Revision History

See the Versions tab for the full change history maintained by the Auto-Doc Engine.


Document code: SOP-SDLC-02 · Aligned to CMMI-DEV v2.0 TS / ISO 9001 §8.3.4. Controlled document — reproduction outside the UBC QMS requires the Quality Manager's approval.

Suggested by AI
No suggestions right now.
Frameworks
CMMI-DEV
ISO 9001
SOC 2
ISO 27001