Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Agile meets Architecture meets Regulation

Sponsored · Your Podcast. Everywhere. Effortlessly. Share. Educate. Inspire. Entertain. You do you. We'll handle the rest.
Avatar for Simon Rohrer Simon Rohrer
March 12, 2026
3

Agile meets Architecture meets Regulation

Agile meets Architecture 2026 presentation on achieving continuous delivery in regulated industry

Avatar for Simon Rohrer

Simon Rohrer

March 12, 2026
Tweet

Transcript

  1. STEP 1: BLUE AGILE CHANGE LIFECYCLE AUTUMN 2014 Pipeline Inception

    Construction Transition Analysis Build and design Testing ∙ User stories ∙ Product backlog ∙ Adaptive planning ∙ Architecture spike ∙ TDD/BDD ∙ Continuous integration ∙ Refactoring ∙ Automated testing ∙ Agile testing ∙ Portfolio backlog ∙ Portfolio epics ∙ Epic value statement ∙ Initial scope - epics ∙ Product backlog ∙ Release planning ∙ Agile estimation ∙ Architecture vision ∙ MVP definition ∙ Environment standup ∙ Automated testing ∙ Agile testing ∙ Feature toggles ∙ Continuous deployment A01 A02 A03 A04 A05 A06 ~20 ARTEFACTS
  2. SYSTEMS UNDERLYING GOVERNANCE PROCESS DON’T SUPPORT AGILE WAYS OF WORKING

    SDLC COUPLED TO INVESTMENT PROCESS – INHIBITS MOVE TO DEVOPS VALUE STREAM MAP TO ESTIMATE COST OVERHEAD
  3. PEOPLE CONTINUOUS COLLABORATION LEAN CONTROL PROCESS SUMMER 2015 DELIVERY RISK

    & CONTROL SOFTWARE RELEASES FREQUENT SOFTWARE PRODUCTS + BACKLOGS + DOCUMENTATION LONG-LIVED
  4. WHERE DID MY SECURITY DATA PROTECTION ACCESSIBILITY INFORMATION RISK MANAGEMENT

    QUESTIONNAIRE GO? INFORMATION SECURITY DATA PROTECTION ACCESSIBILITY INFORMATION RISK MANAGEMENT COMPLIANCE
  5. “IT'S POSSIBLE TO FOLLOW ITIL PRINCIPLES AND PRACTICES IN A

    LIGHTWEIGHT WAY THAT ACHIEVES THE GOALS OF EFFECTIVE SERVICE MANAGEMENT WHILE AT THE SAME TIME ENABLING RAPID, RELIABLE DELIVERY” https://continuousdelivery.com/2010/11/continuous-delivery-and-itil-change-management/
  6. PLAYBOOK RULE 1: TO ENSURE CONTINUOUS DELIVERY IS COMPLIANT YOU

    MUST OWN THE FORMALLY DOCUMENTED POLICIES AND PROCEDURES
  7. DELIVERY + POLICY + PROCEDURE + CONTROLS INTERNAL RISK ARTICULATION

    + EXTERNAL REGULATORY COMPLIANCE EVIDENCED COMPLIANCE WITH INTERNAL + EXTERNAL BUSINESS / OPERATIONS / TECH 1ST LINE RISK + COMPLIANCE 2ND LINE INTERNAL AUDIT 3RD LINE THREE LINES OF DEFENCE
  8. INSPIRATION FROM TAPABRATA “TOPO” PAL & JENNIFER BRADY FROM CAPITAL

    ONE https://github.com/devopsenterprise/2018-London/blob/master/MONDAY/Breakout Sessions/Pal, Topo, Better Governance- Banking on Continuous Delivery.pdf
  9. APPLICATION SERVICE #1 APPLICATION SERVICE #2 APPLICATION SERVICE #3 APPLICATION

    SERVICE #4 HIGH FRICTION IN TAKING A NEW APPLICATION SERVICE INTO PRODUCTION
  10. APPLICATION SERVICE #1 APPLICATION SERVICE #2 APPLICATION SERVICE #3 APPLICATION

    SERVICE #4 HIGH FRICTION IN TAKING A NEW APPLICATION SERVICE INTO PRODUCTION
  11. APPLICATION SERVICE #1 APPLICATION SERVICE #2 APPLICATION SERVICE #3 APPLICATION

    SERVICE #4 HIGH FRICTION IN TAKING A NEW APPLICATION SERVICE INTO PRODUCTION
  12. APPLICATION SERVICE #1 APPLICATION SERVICE #2 APPLICATION SERVICE #3 APPLICATION

    SERVICE #4 HIGH FRICTION IN TAKING A NEW APPLICATION SERVICE INTO PRODUCTION
  13. “…WE SPEND MOST OF THE MONEY IN SOFTWARE DEVELOPMENT ON

    MAINTENANCE […] IN THE XP WORLD WE TOOK THIS […] ALL THE WAY AND SAID INSTEAD OF SPENDING 70% ON MAINTENANCE WHAT IF WE SPEND 99% ON MAINTENANCE?” Continued Learning: The Beauty of Maintenance - Kent Beck - DDD Europe 2020, https://www.youtube.com/watch?v=3gib0hKYjB0
  14. APPLICATION SERVICE #1 APPLICATION SERVICE #2 APPLICATION SERVICE #3 APPLICATION

    SERVICE #4 LOW FRICTION IN TAKING A NEW APPLICATION SERVICE INTO PRODUCTION
  15. APPLICATION SERVICE #1 APPLICATION SERVICE #2 APPLICATION SERVICE #3 APPLICATION

    SERVICE #4 LOW FRICTION IN TAKING A NEW APPLICATION SERVICE INTO PRODUCTION APPLICATION SERVICE #5
  16. “CONTINUOUS DELIVERY ENABLES A LOW-CEREMONY CHANGE MANAGEMENT PROCESS BY ENSURING

    THAT THE FIRST (AND RISKIEST) RELEASE IS DONE LONG BEFORE USERS ARE GIVEN ACCESS TO THE SYSTEM.” https://continuousdelivery.com/2010/11/continuous-delivery-and-itil-change-management/
  17. “PLATFORMS ARE REIFIED ARCHITECTURE, PERHAPS THEY CAN BE REIFIED GOVERNANCE

    ALSO” Gregor Hohpe, https://www.linkedin.com/feed/update/urn:li:activity:7436324542555488256
  18. “IN A PROPERLY EXECUTED PLATFORM STRATEGY, MAJOR ARCHITECTURE AND SECURITY

    CHECKS HAVE HAPPENED, THAT 50-ITEM CHECKLIST DIMINISHES BY 90%.” Charles Betz, Businesses elevate IT architecture to fi ght back tech sprawl (2024)
  19. “ARCHITECTURE: THE SET OF DESIGN DECISIONS THAT KEEPS ITS IMPLEMENTORS

    AND MAINTAINERS FROM EXERCISING NEEDLESS CREATIVITY”
  20. PLATFORMS FTW NUDGE VS MANDATE PULL VS PUSH PRODUCTION RELEASE

    PIPELINE TASK SECURED NETWORK HARDENED HOSTING SERVICE IDENTITY & ACCESS MANAGEMENT COMPLIANCE CLOUD-NATIVE COMPUTE LOG-BASED MESSAGING OBSERVABILITY PLATFORM DBAAS NON-MANDATORY -ILITIES
  21. AUTOMATED COMPLIANCE PRODUCTION RELEASE PIPELINE TASK SOFTWARE COMPOSITION ANALYSIS TEST

    COVERAGE FOUR-EYES CHECK STATIC APPLICATION SECURITY TESTING
  22. “…ENSURE THE INDEPENDENCE OF THE FUNCTIONS THAT APPROVE CHANGES AND

    THE FUNCTIONS RESPONSIBLE FOR REQUESTING AND IMPLEMENTING THOSE CHANGES”
  23. AUTOMATED COMPLIANCE PRODUCTION RELEASE PIPELINE TASK SOFTWARE COMPOSITION ANALYSIS TEST

    COVERAGE FOUR-EYES CHECK STATIC APPLICATION SECURITY TESTING INDEPENDENT FUNCTION APPROVING CHANGE
  24. “…PRESCRIBE THAT THE FINANCIAL ENTITY KEEPS RECORDS OF ALL OF

    THE FOLLOWING… …THE LINKS AND INTERDEPENDENCIES AMONG ICT ASSETS AND THE BUSINESS FUNCTIONS USING EACH ICT ASSET”
  25. LIFECYCLE 1: APPLICATION SERVICE / TECHNOLOGY COMPONENT REQUEST • What?

    • Why? • Fit? hours PRE- PROD • MVP • Wallking skeleton • Tracer bullet hours/weeks LIVE ACCEPT weeks • Feature flags • Friends & family MAINTAIN • Change request • Deployment decades RETIRE • Incidents • Problem fixes hours/weeks
  26. LIFECYCLE 3: INITIATIVE / PROJECT / BET / <INSERT YOUR

    NAME HERE> INVESTMENT MANAGEMENT Simon Wardley, Simple Tips for Managing Any Project, https://medium.com/ mappingpractice/simple-tips-for-managing-any-project-b9fc674b93b1 INTIATE • Requirements • High level design ??? PLAN • Detailed design • Development ??? EXECUTE ??? • Test plan • Test execution CLOSE • Incidents • Problem fixes ??? ?
  27. LIFECYCLE 4: BUSINESS FUNCTION / CAPABILITY / SERVICE DRAFT •

    What? • Why? hours OPERATE decades • Continuous change • Continuous compliance RETIRE • Incidents • Problem fixes hours/weeks
  28. TRANSIENT / CYCLIC LONG-LIVED BUSINESS TECHNOLOGY PROJECT / INITIATIVE /

    INVESTMENT PRIORITISATION LIFECYCLE BUSINESS FUNCTION / CAPABILITY / SERVICE LIFECYCLE TECHNOLOGY COMPONENT / APPLICATION SERVICE LIFECYCLE SOFTWARE CHANGE LIFECYCLE A 4-LIFECYCLE SYSTEMS DEVELOPMENT (& OPS) MODEL CONTINUOUS COMPLIANCE
  29. TRUST & ACCOUNTABILITY “DOING BUSINESS IS ALL ABOUT BALANCING RISK.

    THE OLDEST INSIGHT, HIDING BEHIND ALL THE SHINY NEW TOOLS.” https://www.linkedin.com/posts/patrickdebois_trust-accountability- ai-coding-swarms-activity-7420266824400838656-EFpr/
  30. RECAP: 1. SENIOR BUY-IN NOT BOTTOM-UP 2. DECOUPLE THE LIFECYCLES

    3. CONTINUOUS COMPLIANCE = AUTOMATED COMPLIANCE + CONTINUOUS COLLABORATION 4. OWN THE POLICIES + PROCEDURES + CONTROLS 5. EVERYTHING IS MAINTENANCE
  31. FIN