Metadata-First Enterprise Architecture (MFEA): From Passive Description to Active Control to Automated Enforcement — The Governance Substrate for Trustworthy Enterprise AI

Fuente: Zenodo
Salvato in:
Dettagli Bibliografici
Autore principale: Rao, Venkat
Natura: Recurso digital
Lingua:inglese
Pubblicazione: Zenodo 2026
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866902308601724928
author Rao, Venkat
author_facet Rao, Venkat
contents <p>Enterprise AI systems routinely retrieve from expired, superseded, unauthorized, or jurisdictionally restricted information sources — not because models lack capability, but because enterprise corpora carry no machine-readable governance signal at inference time.</p> <p>This paper introduces Metadata-First Enterprise Architecture (MFEA), a storage-agnostic governance registry that operationalizes the third stage of metadata governance evolution: automated enforcement. MFEA attaches a four-tier metadata envelope (T1 Structural, T2 Semantic, T3 Operational, and T4 Governance) and a continuously computed MFEA Score to every enterprise information asset, making governance state machine-readable and query-able at inference time without requiring storage migration or platform modification.</p> <p>Seven original contributions are advanced: (1) the four-tier metadata architecture isolating human governance burden to Tier 4—under 5 minutes per asset; (2) the I-O-C-L-P governance envelope as the complete specification of the enterprise governance act; (3) the MFEA Score as a binary governance gate, not a retrieval ranking signal; (4) the Triple-Layer Retrieval Architecture (TLRA) enforcing governance before relevance before precision; (5) the Non-Fungible Data Record for tamper-evident governance history; (6) the Continuous Information Audit as a permanently operating governance intelligence system; and (7) a public protocol governance model and submission pathway.</p> <p>Integration matrices are provided for TOGAF, Zachman, CMMI, ISO/IEC 42001, ISO/IEC 27001, NIST AI RMF 2.0, COSO ERM, OWASP LLM Top 10, EU AI Act, GDPR, and India DPDPA. Falsifiable predictions and a three-level empirical hypothesis architecture are specified.</p> <p>The paper advances the thesis that MFEA constitutes the missing semantic governance layer of enterprise digital infrastructure, the Aadhaar of data, enabling trustworthy AI at the enterprise and, as a public protocol, at the civilizational scale.</p> <p> </p> <p><strong>Venkat Rao</strong></p> <p><strong>Contact: venkat@twopointsingularity.com / venramak@gmail.com</strong></p> <p><strong>LinkedIn: https://www.linkedin.com/in/venkatrrao/</strong></p>
format Recurso digital
id zenodo_https___doi_org_10_5281_zenodo_19029898
institution Zenodo
language eng
publishDate 2026
publisher Zenodo
record_format zenodo
spellingShingle Metadata-First Enterprise Architecture (MFEA): From Passive Description to Active Control to Automated Enforcement — The Governance Substrate for Trustworthy Enterprise AI
Rao, Venkat
Enterprise AI Governence
Metadata Architecture,
Retrieval-Augmented Generation
RAG governance
TOGAF
Zachman Framework
CMMI
ISO 42001
ISO 27001
NIST AI RMF
COSO ERM
OWASP LLM
EU AI Act
GDPR
India DPDPA
Data Provenance
AI alignment
Digital Public Infrastructure
Information Lifecycle Management
Governance-Aware Retrieval
Corpus Governance
MFEA Score
Continuous Information Audit
Non-Fungible Data Record
Triple-Layer Retrieval Architecture
Enterprise Architecture
Data Governance
AI safety
<p>Enterprise AI systems routinely retrieve from expired, superseded, unauthorized, or jurisdictionally restricted information sources — not because models lack capability, but because enterprise corpora carry no machine-readable governance signal at inference time.</p> <p>This paper introduces Metadata-First Enterprise Architecture (MFEA), a storage-agnostic governance registry that operationalizes the third stage of metadata governance evolution: automated enforcement. MFEA attaches a four-tier metadata envelope (T1 Structural, T2 Semantic, T3 Operational, and T4 Governance) and a continuously computed MFEA Score to every enterprise information asset, making governance state machine-readable and query-able at inference time without requiring storage migration or platform modification.</p> <p>Seven original contributions are advanced: (1) the four-tier metadata architecture isolating human governance burden to Tier 4—under 5 minutes per asset; (2) the I-O-C-L-P governance envelope as the complete specification of the enterprise governance act; (3) the MFEA Score as a binary governance gate, not a retrieval ranking signal; (4) the Triple-Layer Retrieval Architecture (TLRA) enforcing governance before relevance before precision; (5) the Non-Fungible Data Record for tamper-evident governance history; (6) the Continuous Information Audit as a permanently operating governance intelligence system; and (7) a public protocol governance model and submission pathway.</p> <p>Integration matrices are provided for TOGAF, Zachman, CMMI, ISO/IEC 42001, ISO/IEC 27001, NIST AI RMF 2.0, COSO ERM, OWASP LLM Top 10, EU AI Act, GDPR, and India DPDPA. Falsifiable predictions and a three-level empirical hypothesis architecture are specified.</p> <p>The paper advances the thesis that MFEA constitutes the missing semantic governance layer of enterprise digital infrastructure, the Aadhaar of data, enabling trustworthy AI at the enterprise and, as a public protocol, at the civilizational scale.</p> <p> </p> <p><strong>Venkat Rao</strong></p> <p><strong>Contact: venkat@twopointsingularity.com / venramak@gmail.com</strong></p> <p><strong>LinkedIn: https://www.linkedin.com/in/venkatrrao/</strong></p>
title Metadata-First Enterprise Architecture (MFEA): From Passive Description to Active Control to Automated Enforcement — The Governance Substrate for Trustworthy Enterprise AI
topic Enterprise AI Governence
Metadata Architecture,
Retrieval-Augmented Generation
RAG governance
TOGAF
Zachman Framework
CMMI
ISO 42001
ISO 27001
NIST AI RMF
COSO ERM
OWASP LLM
EU AI Act
GDPR
India DPDPA
Data Provenance
AI alignment
Digital Public Infrastructure
Information Lifecycle Management
Governance-Aware Retrieval
Corpus Governance
MFEA Score
Continuous Information Audit
Non-Fungible Data Record
Triple-Layer Retrieval Architecture
Enterprise Architecture
Data Governance
AI safety
url https://doi.org/10.5281/zenodo.19029898