Skip to content

QGEA Alignment

How XAF Connected Architecture supports Queensland Government Enterprise Architecture.


What is QGEA?

The Queensland Government Enterprise Architecture (QGEA) is the policy framework that guides digital and ICT investment across Queensland Government. It's managed by the Department of Customer Services, Open Data and Small and Family Business and serves as the primary channel for communicating strategy, policy, and guidance to agencies.

QGEA provides direction and guidance rather than implementation methodology. Key elements include:

Foundation Principles — Enduring values that support digital and ICT investment decision-making. These principles inform policy development and provide guidance where formal policy doesn't exist.

Policies and Standards — Mandatory requirements for agencies. The most significant is IS18 (Information and Cyber Security Policy), which requires departments to implement an Information Security Management System (ISMS) based on ISO 27001 and achieve Essential Eight maturity. Policies use keyword conventions where "must" denotes mandatory obligations and "should" denotes recommendations.

Classification Frameworks — Common vocabularies including the Business Capability Reference Model, Technology Classification Framework, and Queensland Government Information Security Classification Framework (QGISCF). These provide consistent categorisation across agencies.

Guidelines and Better Practice — Non-mandatory guidance to help agencies implement policies effectively.

QGEA operates as a federated architecture — it acknowledges Queensland Government as a single enterprise composed of autonomous agencies. Agencies interpret and apply QGEA within their context.

Applicability varies by entity type. Departments and public service entities must comply with policies like IS18. Statutory bodies "must have regard to" the QGEA under the Financial and Performance Management Standard 2019, meaning they make a documented decision to follow or not follow. Other government entities are encouraged to adopt QGEA as better practice.

For more detail on QGEA, refer to the official QGEA documentation.


How XAF Fits

XAF Connected Architecture is designed to work alongside QGEA, not replace it. QGEA provides the strategic direction — the principles, policies, and classification frameworks that guide Queensland Government ICT investment. XAF provides operational governance mechanisms that can help agencies apply those directions in practice.

Think of it this way: QGEA tells you what's expected. XAF gives you mechanisms for ensuring those expectations are met consistently — with traceability, accountability, and delivery integration.

This page maps how XAF components can support QGEA requirements. The alignment described here requires configuration — XAF doesn't come pre-loaded with QGEA requirements.

Important caveats:

  • XAF is not an official QGEA artefact or endorsed by QGCDG
  • Alignment requires explicit configuration by each agency
  • QGEA requirements evolve — agencies should verify against current publications
  • This mapping represents our understanding, not official guidance

The Relationship

QGEA is a federated architecture — it acknowledges Queensland Government as a single enterprise composed of autonomous agencies. Each agency interprets and applies QGEA within their context.

XAF can fit into this model as an agency-level governance framework. It can provide:

  • Operational mechanisms for applying QGEA principles in practice
  • Decision traceability that demonstrates QGEA alignment
  • Integration with delivery so compliance considerations happen during decisions
  • Templates and tools that can embed QGEA requirements into everyday work

Agencies still own their architecture. XAF can help them do it in a way that's consistent with whole-of-government direction — but this requires intentional configuration and ongoing maintenance as QGEA evolves.


Governance Core Alignment

The XAF Governance Core provides mechanisms that can support QGEA compliance. The alignment described below requires configuration — XAF doesn't automatically encode QGEA requirements out of the box.

Guardrails Framework → QGEA Policies and Standards

QGEA Requirement How XAF Can Support
Foundation principles compliance Guardrails can encode QGEA principles as actionable constraints. This requires explicitly configuring guardrails to reflect relevant principles.
IS18 security requirements Security guardrails can incorporate IS18 mandates. Agencies need to map IS18 requirements to specific guardrails.
Information Standards Information management guardrails can embed recordkeeping and other requirements. Configuration required based on which standards apply.
QGISCF classification framework Classification guardrails can ensure security classification happens consistently. Requires alignment with agency's QGISCF implementation.

How it works: Guardrails pre-encode requirements so teams don't need to check policies before every decision. But this only works if guardrails are explicitly configured to reflect QGEA requirements relevant to your agency.

Tiered Oversight → QGEA Exception Process

QGEA Requirement How XAF Can Support
Alignment exception process Tiered oversight provides internal governance before formal QGEA exceptions are sought. XAF doesn't replace the QGEA exception process — it prepares for it.
Risk-based decision making Classification criteria can align with QGEA's risk orientation, but agencies define their own criteria.
Accountable officer attestation Escalation paths can route decisions to appropriate authority levels. Agencies configure escalation based on their delegation structure.

How it works: QGEA allows agencies to seek exceptions through documented processes. XAF's tiered oversight provides internal governance that precedes formal QGEA exception requests. The formal QGEA exception process remains separate.

Decision Records → QGEA Traceability

QGEA Requirement How XAF Can Support
Audit and assurance Decision records provide evidence trails. Usefulness depends on what's captured and how consistently.
Investment justification Decisions can link to QGEA principles if templates are configured to prompt for this.
Exception documentation Where QGEA exceptions are sought, decision records can capture rationale. This supplements, doesn't replace, formal exception documentation.

How it works: Decision records create documentation that supports QGEA compliance evidence. The value depends on template design and consistent use.

Architecture Passport → QGEA Asset Management

QGEA Requirement How XAF Can Support
Application classification Passports can track QGEA classification framework positions. Requires configuring passport templates with QGEA-aligned fields.
Business capability alignment Passports can link systems to capabilities using QGEA Business Capability Reference Model vocabulary. Requires adopting that vocabulary.
Security classification QGISCF classification can be a passport attribute. Agencies configure based on their classification approach.
Lifecycle management Passport lifecycle states can align with investment planning. Alignment is agency-configured.

How it works: Passports provide system-level documentation. Using QGEA vocabulary requires explicit configuration of passport templates and consistent data entry.

Technical Debt Register → QGEA Risk Management

QGEA Requirement How XAF Can Support
Risk-based resource allocation Debt can be prioritised using QGEA-aligned risk criteria. Criteria definition is agency responsibility.
Technical sustainability Debt items can track against technology currency and end-of-support. Requires maintaining current information.
Investment planning input Debt visibility can inform business cases. Value depends on data quality and integration with planning processes.

How it works: QGEA emphasises risk-based decision making. The debt register makes technical risk visible. How this connects to QGEA risk frameworks depends on agency configuration.

Delivery Integration → QGEA Implementation

QGEA Requirement How XAF Can Support
Initiative alignment Architecture touchpoints can include QGEA alignment checks. Requires defining what alignment means for your context.
Investment assurance Stage gates can verify QGEA alignment. Gate criteria need explicit definition.
Continuous improvement Retrospectives can capture lessons about QGEA implementation. Requires intentional focus on this.

How it works: Delivery integration ensures architecture governance happens during delivery. QGEA alignment through this mechanism requires configuring checkpoints to include relevant QGEA considerations.

Architecture Registry → QGEA Reporting

QGEA Requirement How XAF Can Support
ICT reporting requirements Registry data can feed reporting. Requires structuring registry to capture required information.
Cross-agency visibility Standard registry structure can support portfolio views. Vocabulary alignment with QGEA frameworks helps.
Shared service alignment Registry can track shared service relationships. Requires maintaining this information.

How it works: The registry provides portfolio visibility. Supporting QGEA reporting requires configuring the registry to capture the right information in compatible formats.


Domain Module Alignment

XAF domain modules provide depth in specific architecture areas. Some align more directly with QGEA frameworks than others.

Business Architecture → QGEA Business Capability Reference Model

QGEA Framework XAF Alignment
Business Capability Reference Model XAF capability models can use QGEA vocabulary. The QGEA reference model provides a starting point that agencies extend for their context.
Business Process Classification Framework Value streams can connect to process classifications. Requires intentional mapping.
Service delivery channels Capability-to-channel mapping can support QGEA channel management. Not automatic.

Government context: The QGEA Business Capability Reference Model (released July 2024) provides common vocabulary. XAF's capability model approach is compatible but agencies need to adopt QGEA vocabulary explicitly. XAF doesn't mandate any specific capability framework.

Technology Architecture → QGEA Technology Classification Framework

QGEA Framework XAF Alignment
Technology Classification Framework Technology radar categories can align with QGEA technology domains. Requires configuration.
Platform and infrastructure standards Technology guardrails can incorporate whole-of-government platform directions where they exist.
Vendor and product guidance Radar positions can reflect QGEA guidance. Agencies maintain their own radar.

Government context: QGEA's Technology Classification Framework provides taxonomy for categorising technologies. XAF's technology radar is a different artefact type — it communicates technology recommendations rather than classifying technologies. The two serve complementary purposes but aren't direct equivalents.

Security Architecture → IS18 and QGISCF

QGEA Requirement XAF Alignment
IS18 Information Security Policy Security guardrails can embed IS18 requirements. XAF doesn't provide an IS18 implementation — agencies still need their own ISMS.
QGISCF classification framework Security domain module references QGISCF. Templates can be configured to align with agency QGISCF implementation.
Essential Eight maturity Security patterns can support Essential Eight strategies. XAF doesn't replace Essential Eight assessment or reporting.
PSPF alignment Where agencies interact with Commonwealth, security architecture can support PSPF. This is additional to QGEA requirements.

Government context: IS18 is mandatory for departments. It requires an Information Security Management System based on ISO 27001. XAF's security architecture module provides governance mechanisms but doesn't constitute an ISMS. Agencies need both — IS18 compliance infrastructure and governance mechanisms to ensure it's applied consistently.

Information Architecture → QGEA Information Principles

QGEA Requirement XAF Alignment
Information classification Classification schemes can align with QGISCF. Requires explicit configuration.
Recordkeeping requirements Information lifecycle management can incorporate Queensland State Archives requirements. XAF references IS40 (now repealed and replaced) — agencies should verify current requirements.
Open data principles Information architecture can support open data considerations. Not a primary focus of XAF.

Government context: QGEA emphasises information management. XAF's information architecture module references QGEA information principles and relevant Information Standards. Agencies should verify current requirements — some standards referenced in XAF documentation (like IS40) have been updated or replaced.

Data Architecture → QGEA Data Standards

QGEA Requirement XAF Alignment
Data standards and naming conventions Data models can reference QGEA data standards. Requires agencies to identify and apply relevant standards.
Data sharing frameworks Data governance can consider whole-of-government data sharing. Not deeply covered in current XAF.
Privacy and security Data classification can align with QGISCF. Configuration required.

Government context: XAF's data architecture module references QGEA data standards and recommends building compliance into baseline standards. The depth of QGEA data guidance varies — agencies may need to reference additional sources for comprehensive data governance.

Innovation Architecture → QGEA AI and Emerging Technology

QGEA Framework XAF Alignment
FAIRA (Future of AI Risk Assessment) AI/ML governance references FAIRA for government AI initiatives. FAIRA is Australian Government, not specific to Queensland.
Australian AI Ethics Principles Ethics assessment templates reference national principles. These are federal, not QGEA-specific.
Emerging technology guidance Innovation guardrails can reflect QGEA positions where they exist. AI/emerging tech guidance in QGEA is evolving.

Government context: AI governance is an emerging area. XAF references Australian Government frameworks (FAIRA, AI Ethics Principles) because they're more developed than Queensland-specific guidance. Agencies should monitor QGEA for Queensland-specific AI direction as it develops.


Implementation Approach

Starting Point

For Queensland Government agencies implementing XAF alongside QGEA:

  1. Map your current QGEA obligations — Which policies are mandatory for your agency type? What reporting requirements apply?

  2. Configure guardrails to reflect QGEA requirements — Start with the guardrails that encode your most critical QGEA obligations (typically IS18 security requirements).

  3. Align classification schemes — Ensure your registry and passports use QGEA vocabulary (Technology Classification Framework, Business Capability Reference Model, QGISCF).

  4. Establish decision record templates — Include QGEA alignment as a standard section so decisions explicitly reference relevant policies and principles.

  5. Connect to QGEA reporting — Configure registry exports to support your ICT dashboard and annual reporting requirements.

Maintaining Alignment

QGEA evolves. When policies update:

  1. Review affected guardrails — Update constraints to reflect new requirements
  2. Assess current systems — Use passports to identify systems that need attention
  3. Log debt where needed — If immediate compliance isn't feasible, track it explicitly
  4. Update decision criteria — Ensure new decisions align with updated policies

Exception Handling

When QGEA exceptions are required:

  1. Document through XAF first — Use decision records to capture the rationale, alternatives, and risk acceptance
  2. Escalate through tiered oversight — Ensure appropriate internal authority has approved
  3. Submit formal exception — Use XAF documentation to support the QGEA alignment exception process
  4. Track in passport — Record the exception status against affected systems

The Bottom Line

XAF can support QGEA compliance, but it's not a substitute for understanding QGEA requirements directly.

QGEA provides the direction: principles, policies, classification frameworks, and standards that guide Queensland Government digital and ICT investment. XAF provides governance mechanisms that can help embed those requirements into everyday decision-making.

What XAF offers:

  • Guardrails that can encode QGEA policies as actionable constraints
  • Decision records that can demonstrate alignment and capture exceptions
  • Passports that can apply QGEA classification consistently
  • Registry structures that can support reporting requirements
  • Delivery integration that can ensure alignment happens during decisions

What XAF doesn't do:

  • Replace the need to understand QGEA requirements directly
  • Automatically configure itself to reflect QGEA policies
  • Constitute an ISMS for IS18 compliance
  • Substitute for formal QGEA exception processes
  • Guarantee compliance without appropriate configuration and use

The value of using XAF alongside QGEA depends on how well agencies configure XAF components to reflect their specific QGEA obligations, and how consistently teams use the governance mechanisms provided.

For agencies subject to QGEA, start with QGEA requirements. Then consider how XAF mechanisms can help operationalise those requirements in practice.


Where XAF Differs

XAF is not an official QGEA artefact. It's a separate framework developed by InnovateX Solutions based on practical experience in Queensland Government and other contexts. Being transparent about this matters.

XAF adds operational governance that QGEA doesn't prescribe. QGEA provides direction and policy but generally doesn't specify how agencies should implement internal governance mechanisms. XAF fills this gap with specific components (guardrails, tiered oversight, decision records, etc.) — but these are XAF constructs, not QGEA requirements.

Terminology differs in places. XAF uses terms like "guardrails," "passports," and "tiered oversight" that aren't part of QGEA vocabulary. When implementing both, agencies need to maintain clarity about which framework introduced which concept.

XAF is framework-agnostic by design. While this page focuses on QGEA alignment, XAF works with other frameworks too (TOGAF, COBIT, etc.). Some XAF concepts may align better with approaches from other frameworks than with QGEA specifically.

Not all XAF domain modules have direct QGEA equivalents. For example:

  • XAF's Innovation Architecture module addresses AI/ML governance — QGEA provides some guidance here but it's an evolving area
  • XAF's approach to technical debt management doesn't map directly to a specific QGEA framework
  • Some XAF templates go beyond what QGEA classification frameworks cover

QGEA is authoritative for Queensland Government. Where XAF guidance conflicts with QGEA policy, QGEA takes precedence for agencies subject to it. XAF should be configured to support QGEA requirements, not the other way around.

Verify alignment independently. This page represents our understanding of how XAF supports QGEA, but agencies should verify alignment against current QGEA publications. QGEA evolves, and specific requirements may have changed since this was written.



XAF Connected Architecture | Developed by InnovateX Solutions