AGA Alignment
How XAF Connected Architecture supports Australian Government Architecture.
What is AGA?
The Australian Government Architecture (AGA) is a collection of digital artefacts and guidance materials maintained by the Digital Transformation Agency (DTA). It supports digital transformation by providing policies, standards, and designs that guide federal agencies in aligning with the government's digital direction.
Unlike traditional enterprise architecture frameworks, the AGA operates as a contributory architecture — the DTA collects best practice guidance from across government and industry, curates it, and makes it available as a shared resource. The AGA is designed for architects, policy specialists, and senior decision-makers, accessible at architecture.digital.gov.au.
Key elements include:
Domain and Capability Model — The AGA organises government digital and ICT capabilities into 11 integrated domains, including Individual Experience, Business Experience, Government Service Delivery, Cyber Security, Data and Information, and Governance. This provides common vocabulary for discussing digital capabilities across agencies.
Policies — High-level direction that articulates requirements for digital investments. AGA policies include areas like information asset management, reuse, and alignment with whole-of-government strategies.
Standards — More detailed requirements that support policies. Standards cover areas like application security, information asset security, and interoperability.
Designs — Practical patterns and reference architectures showing how to implement standards. These are contributed by agencies based on real implementations.
The AGA connects to investment oversight. Alignment to the AGA is tested through the Whole-of-Government Digital and ICT Investment Oversight Framework (IOF) for new investments. The IOF uses AGA guidance as a decision-making construct when assessing digital investment proposals for Budget cycles.
Applicability is broad but not always mandatory. The AGA applies to all agencies when delivering digital outcomes for government. However, mandatory compliance depends on the specific policy or standard — some are endorsed requirements, others are recommended guidance. The PGPA Act entities must apply certain frameworks like the Protective Security Policy Framework (PSPF).
For more detail on AGA, refer to the official AGA website and the DTA's AGA overview.
How XAF Fits
XAF Connected Architecture can work alongside AGA, providing operational governance mechanisms that help agencies apply AGA direction in practice.
The AGA focuses on what government expects from digital investments — the policies, standards, and designs that represent good practice. XAF focuses on how agencies govern architecture decisions internally — the mechanisms that ensure those expectations are consistently applied.
This page maps how XAF components can support AGA alignment. The alignment described here requires configuration — XAF doesn't come pre-loaded with AGA requirements.
Important caveats:
- XAF is not an official AGA artefact or endorsed by the DTA
- Alignment requires explicit configuration by each agency
- AGA is continually evolving — agencies should verify against current publications
- This mapping represents our understanding, not official guidance
- XAF was developed primarily in a Queensland Government context; federal requirements differ
The Relationship
The AGA supports a federated model where agencies maintain autonomy while aligning with whole-of-government direction. The DTA acts as steward, curating guidance and providing oversight through the investment framework.
XAF can fit into this model as an agency-level governance framework. It can provide:
- Internal governance mechanisms for applying AGA policies and standards consistently
- Decision traceability that demonstrates AGA alignment in investment proposals
- Delivery integration so alignment considerations happen during decisions, not after
- Templates and tools that can embed AGA requirements into everyday work
Agencies still own their architecture decisions. XAF can help them make those decisions in a way that's consistent with AGA direction — but this requires intentional configuration and ongoing maintenance as AGA evolves.
Governance Core Alignment
The XAF Governance Core provides mechanisms that can support AGA compliance. The alignment described below requires configuration — XAF doesn't automatically encode AGA requirements.
Guardrails Framework → AGA Policies and Standards
| AGA Requirement | How XAF Can Support |
|---|---|
| AGA policy compliance | Guardrails can encode AGA policies as actionable constraints. This requires explicitly configuring guardrails to reflect relevant policies. |
| PSPF security requirements | Security guardrails can incorporate PSPF requirements. Agencies need to map PSPF policies (particularly information security and cyber security) to specific guardrails. |
| Reuse requirements | Guardrails can encourage checking the AGA for existing capabilities before building new. Configuration required to embed this in decision processes. |
| Standard compliance | Guardrails can reflect AGA standards like information asset security and application security. Requires mapping standards to actionable constraints. |
How it works: The AGA describes guardrails as part of its contributory model — best guidance that agencies follow. XAF's Guardrails Framework provides the mechanism to operationalise those guardrails at agency level, making them part of how decisions happen rather than separate compliance checks.
Tiered Oversight → Investment Oversight Framework Integration
| AGA Requirement | How XAF Can Support |
|---|---|
| IOF alignment for new investments | Tiered oversight can identify which initiatives need IOF engagement based on risk and investment size. XAF doesn't replace IOF — it helps agencies prepare for it. |
| Risk-based governance | Classification criteria can align with how the DTA assesses investment risk. Agencies define their own criteria based on IOF expectations. |
| Reuse assessment | Higher oversight tiers can require demonstration that AGA was consulted for existing capabilities before proposing new investment. |
How it works: The IOF tests AGA alignment for new investments. XAF's tiered oversight provides internal governance that happens before formal IOF engagement — ensuring proposals are well-prepared when they reach DTA assessment.
Decision Records → AGA Traceability
| AGA Requirement | How XAF Can Support |
|---|---|
| Investment justification | Decision records can demonstrate how proposals align with AGA policies and standards. Useful for IOF submissions. |
| Reuse consideration | Decision records can capture what AGA guidance was reviewed and whether existing capabilities were considered before building new. |
| Design rationale | Where AGA designs were adopted or adapted, decision records can capture why and how. |
How it works: The DTA assesses investment proposals against AGA. Decision records create documentation that supports this assessment — showing not just what was decided, but how AGA guidance informed the decision.
Architecture Passport → AGA Capability Alignment
| AGA Requirement | How XAF Can Support |
|---|---|
| Capability classification | Passports can track which AGA domain and capabilities each system supports. Requires configuring passport templates with AGA vocabulary. |
| Security classification | PSPF security classification can be a passport attribute. Agencies configure based on their classification approach. |
| Reuse visibility | Passports can identify systems that might be candidates for whole-of-government reuse or that already leverage shared capabilities. |
How it works: The AGA Domain and Capability Model provides common vocabulary. Passports can apply that vocabulary to create portfolio visibility — but this requires adopting AGA terminology in passport templates.
Technical Debt Register → AGA Risk Visibility
| AGA Requirement | How XAF Can Support |
|---|---|
| Security debt | Debt items can track gaps against PSPF requirements, ISM controls, or Essential Eight maturity. |
| Technical currency | Debt can track systems that don't meet current AGA standards or use deprecated patterns. |
| Investment planning | Debt visibility can inform business cases by showing where remediation is needed. |
How it works: The AGA emphasises reducing duplication, managing risk, and improving consistency. The debt register makes these issues visible — showing where current state doesn't meet AGA expectations.
Delivery Integration → IOF Alignment in Practice
| AGA Requirement | How XAF Can Support |
|---|---|
| Early IOF engagement | Delivery touchpoints can prompt IOF consideration at appropriate stages. Not automatic — requires configuring checkpoints. |
| Continuous alignment | Stage gates can verify AGA alignment throughout delivery, not just at proposal stage. |
| Reuse in delivery | Delivery processes can include checks for AGA capabilities and designs before building. |
How it works: The IOF operates across the investment lifecycle — from strategy through to operation. Delivery integration can embed AGA considerations at each stage, but requires explicit configuration of what gets checked when.
Architecture Registry → AGA Reporting Support
| AGA Requirement | How XAF Can Support |
|---|---|
| Capability visibility | Registry can track capabilities using AGA domain vocabulary, supporting whole-of-government visibility. |
| Reuse identification | Registry can identify capabilities that might support other agencies or leverage shared services. |
| Investment landscape | Registry data can inform the government's view of digital asset landscape. |
How it works: The DTA uses AGA to understand the government's digital landscape. Registry data structured around AGA vocabulary can contribute to this understanding — but requires consistent use of AGA terminology.
Domain Module Alignment
XAF domain modules provide depth in specific architecture areas. Some align more directly with AGA domains than others.
Business Architecture → AGA Experience and Service Delivery Domains
| AGA Domain | XAF Alignment |
|---|---|
| Individual Experience / Business Experience | XAF capability models can align with AGA's experience domains. Requires mapping agency capabilities to AGA vocabulary. |
| Government Service Delivery | Value streams can connect to AGA service delivery capabilities. Not automatic — requires intentional mapping. |
Federal context: The AGA Domain and Capability Model provides vocabulary for federal service delivery. XAF's business architecture module can adopt this vocabulary, but the AGA model is specifically designed for federal government service patterns which may differ from state/local contexts.
Technology Architecture → AGA Technology Capabilities
| AGA Domain | XAF Alignment |
|---|---|
| Technology capabilities | Technology radar can reference AGA guidance on technology choices. Requires awareness of what AGA says about specific technologies. |
| Hosting and cloud | Technology guardrails can incorporate Hosting Certification Framework requirements. |
| Interoperability | Technology standards can align with AGA interoperability expectations. |
Federal context: The AGA includes guidance on technology choices, cloud hosting, and interoperability. XAF's technology radar is a different artefact type — it communicates agency-specific technology positions. Alignment requires reviewing AGA guidance when setting radar positions.
Security Architecture → PSPF and ISM
| AGA Requirement | XAF Alignment |
|---|---|
| Protective Security Policy Framework | Security guardrails can embed PSPF requirements. PSPF is mandatory for PGPA Act entities. |
| Information Security Manual (ISM) | Security patterns can align with ISM cyber security principles. |
| Essential Eight | Security controls can map to Essential Eight mitigation strategies. |
| IRAP certification | Security architecture can support IRAP assessment requirements for systems handling PROTECTED information. |
Federal context: PSPF is the primary security framework for federal government, with 16 policies across six security domains. This differs from Queensland's IS18. XAF's security architecture module references both, but agencies need to configure for their applicable framework. ISM provides cyber security principles; Essential Eight provides specific mitigations.
Information Architecture → AGA Data and Information Domain
| AGA Domain | XAF Alignment |
|---|---|
| Data and Information capabilities | Information architecture can align with AGA information asset management expectations. |
| Information asset security | Classification and handling can align with PSPF information security requirements. |
| Records management | Information lifecycle can incorporate National Archives requirements (different from Queensland State Archives). |
Federal context: Federal information management requirements differ from state. The AGA information asset management policy sets expectations for creation, management, retention, and disposal. XAF references QGEA information standards which may not directly apply to federal agencies — configuration needed for federal context.
Data Architecture → AGA Data Capabilities
| AGA Domain | XAF Alignment |
|---|---|
| Data management | Data governance can consider AGA data management guidance. |
| Data sharing | Data architecture can support whole-of-government data sharing expectations. |
| Open data | Data classification can support open data release where appropriate. |
Federal context: The AGA emphasises data as a government asset with expectations around sharing and transparency. XAF's data architecture module can support this, but federal data requirements (including privacy legislation and data sharing agreements) differ from state contexts.
Innovation Architecture → AGA AI and Emerging Technology
| AGA Domain | XAF Alignment |
|---|---|
| AI governance | AI/ML governance can align with federal AI frameworks. The AGA references NSW's AI Assessment Framework as a design. |
| Emerging technology | Innovation guardrails can reflect AGA positions on emerging technologies where they exist. |
Federal context: AI governance at federal level is evolving. The AGA includes references to AI frameworks including NSW's approach. XAF references FAIRA and Australian AI Ethics Principles which apply federally. Agencies should monitor AGA for updated AI guidance.
Key Differences from QGEA
For agencies familiar with Queensland's QGEA, the AGA operates differently:
| Aspect | QGEA | AGA |
|---|---|---|
| Model | Comprehensive policy framework | Contributory guidance collection |
| Enforcement | Mandatory policies with exception process | Varies by artefact; tested through IOF for investments |
| Security framework | IS18 (based on ISO 27001) | PSPF (16 policies, six domains) |
| Investment oversight | Internal agency processes | Whole-of-Government IOF through DTA |
| Classification frameworks | QGISCF, Business Capability Reference Model, Technology Classification Framework | Domain and Capability Model (11 domains), PSPF classification |
| Maturity | Long-established (dating to 1990s GIA) | Refreshed 2021-2022, continually evolving |
XAF was developed primarily in Queensland Government context. While the governance mechanisms are transferable, federal agencies need to:
- Replace IS18 references with PSPF requirements
- Adopt AGA Domain and Capability Model vocabulary instead of QGEA frameworks
- Consider IOF integration for investment proposals
- Review AGA standards (not QGEA Information Standards) for specific requirements
Implementation Approach
Starting Point
For federal agencies implementing XAF alongside AGA:
- Understand your AGA obligations — Which policies are mandatory? What IOF engagement is required for your investment portfolio?
- Map PSPF requirements to guardrails — Start with security guardrails that reflect PSPF policies relevant to your entity (particularly information security and cyber security).
- Adopt AGA vocabulary — Configure registry and passports to use AGA Domain and Capability Model terminology for consistency with whole-of-government reporting.
- Connect to IOF — Understand where in your delivery process IOF engagement occurs and configure XAF touchpoints accordingly.
- Establish decision record templates — Include AGA alignment as a standard section, capturing which policies and standards were considered.
Maintaining Alignment
The AGA is continually evolving. When guidance updates:
- Review affected guardrails — Update constraints to reflect new requirements
- Assess current systems — Use passports to identify systems that need attention
- Log debt where needed — If immediate compliance isn't feasible, track it explicitly
- Update decision criteria — Ensure new decisions align with updated guidance
IOF Preparation
When preparing investment proposals for IOF assessment:
- Document AGA alignment — Use decision records to show which AGA guidance informed the proposal
- Demonstrate reuse consideration — Show that existing AGA capabilities and designs were reviewed
- Address standards — Ensure proposal meets relevant AGA standards
- Prepare for contestability — Decision records and passports provide evidence for DTA assessment
The Bottom Line
XAF can support AGA alignment, but it's not a substitute for understanding AGA requirements directly.
The AGA provides the guidance: policies, standards, and designs that represent government expectations for digital investments. XAF provides governance mechanisms that can help embed those expectations into everyday decision-making.
What XAF offers:
- Guardrails that can encode AGA policies as actionable constraints
- Decision records that can demonstrate alignment for IOF assessment
- Passports that can apply AGA capability vocabulary consistently
- Registry structures that can support whole-of-government visibility
- Delivery integration that can ensure alignment happens during decisions
What XAF doesn't do:
- Replace the need to understand AGA requirements directly
- Automatically configure itself to reflect AGA policies
- Constitute PSPF compliance or IRAP certification
- Substitute for IOF engagement
- Guarantee compliance without appropriate configuration and use
The value of using XAF alongside AGA depends on how well agencies configure XAF components to reflect federal requirements, and how consistently teams use the governance mechanisms provided.
For federal agencies, start with AGA and PSPF requirements. Then consider how XAF mechanisms can help operationalise those requirements in practice.
Where XAF Differs
XAF is not an official AGA artefact. It's a separate framework developed by InnovateX Solutions based on practical experience, primarily in Queensland Government context. Being transparent about this matters.
XAF adds operational governance that AGA doesn't prescribe. The AGA provides policies, standards, and designs but generally doesn't specify how agencies should implement internal governance mechanisms. XAF fills this gap — but these are XAF constructs, not AGA requirements.
XAF was developed for state government context. While governance mechanisms are transferable, XAF documentation references QGEA frameworks, IS18, and Queensland-specific requirements. Federal agencies need to adapt references for their context.
Terminology differs. XAF uses terms like "guardrails," "passports," and "tiered oversight" that aren't part of AGA vocabulary. When implementing both, agencies need to maintain clarity about which framework introduced which concept.
Not all XAF domain modules map directly to AGA domains. The AGA Domain and Capability Model organises capabilities differently than XAF's domain modules. Mapping requires interpretation.
AGA is authoritative for federal government. Where XAF guidance conflicts with AGA policy, AGA takes precedence for agencies subject to it. XAF should be configured to support AGA requirements, not the other way around.
Verify alignment independently. This page represents our understanding of how XAF can support AGA, but agencies should verify against current AGA publications. The AGA is continually evolving.
Related Resources
- Australian Government Architecture (AGA)
- DTA - Australian Government Architecture Overview
- AGA Domain and Capability Model
- Protective Security Policy Framework (PSPF)
- Information Security Manual (ISM)
- Essential Eight Maturity Model
XAF Connected Architecture | Developed by InnovateX Solutions