Metadata-First Enterprise Architecture (MFEA): From Passive Description to Active Control to Automated Enforcement — The Governance Substrate for Trustworthy Enterprise AI
Fuente:
Zenodo
Salvato in:
| Autore principale: | |
|---|---|
| Natura: | Recurso digital |
| Lingua: | inglese |
| Pubblicazione: |
Zenodo
2026
|
| Soggetti: | |
| Accesso online: | |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
| _version_ | 1866902308601724928 |
|---|---|
| author | Rao, Venkat |
| author_facet | Rao, Venkat |
| contents | <p>Enterprise AI systems routinely retrieve from expired, superseded, unauthorized, or jurisdictionally restricted information sources — not because models lack capability, but because enterprise corpora carry no machine-readable governance signal at inference time.</p> <p>This paper introduces Metadata-First Enterprise Architecture (MFEA), a storage-agnostic governance registry that operationalizes the third stage of metadata governance evolution: automated enforcement. MFEA attaches a four-tier metadata envelope (T1 Structural, T2 Semantic, T3 Operational, and T4 Governance) and a continuously computed MFEA Score to every enterprise information asset, making governance state machine-readable and query-able at inference time without requiring storage migration or platform modification.</p> <p>Seven original contributions are advanced: (1) the four-tier metadata architecture isolating human governance burden to Tier 4—under 5 minutes per asset; (2) the I-O-C-L-P governance envelope as the complete specification of the enterprise governance act; (3) the MFEA Score as a binary governance gate, not a retrieval ranking signal; (4) the Triple-Layer Retrieval Architecture (TLRA) enforcing governance before relevance before precision; (5) the Non-Fungible Data Record for tamper-evident governance history; (6) the Continuous Information Audit as a permanently operating governance intelligence system; and (7) a public protocol governance model and submission pathway.</p> <p>Integration matrices are provided for TOGAF, Zachman, CMMI, ISO/IEC 42001, ISO/IEC 27001, NIST AI RMF 2.0, COSO ERM, OWASP LLM Top 10, EU AI Act, GDPR, and India DPDPA. Falsifiable predictions and a three-level empirical hypothesis architecture are specified.</p> <p>The paper advances the thesis that MFEA constitutes the missing semantic governance layer of enterprise digital infrastructure, the Aadhaar of data, enabling trustworthy AI at the enterprise and, as a public protocol, at the civilizational scale.</p> <p> </p> <p><strong>Venkat Rao</strong></p> <p><strong>Contact: venkat@twopointsingularity.com / venramak@gmail.com</strong></p> <p><strong>LinkedIn: https://www.linkedin.com/in/venkatrrao/</strong></p> |
| format | Recurso digital |
| id | zenodo_https___doi_org_10_5281_zenodo_19029898 |
| institution | Zenodo |
| language | eng |
| publishDate | 2026 |
| publisher | Zenodo |
| record_format | zenodo |
| spellingShingle | Metadata-First Enterprise Architecture (MFEA): From Passive Description to Active Control to Automated Enforcement — The Governance Substrate for Trustworthy Enterprise AI Rao, Venkat Enterprise AI Governence Metadata Architecture, Retrieval-Augmented Generation RAG governance TOGAF Zachman Framework CMMI ISO 42001 ISO 27001 NIST AI RMF COSO ERM OWASP LLM EU AI Act GDPR India DPDPA Data Provenance AI alignment Digital Public Infrastructure Information Lifecycle Management Governance-Aware Retrieval Corpus Governance MFEA Score Continuous Information Audit Non-Fungible Data Record Triple-Layer Retrieval Architecture Enterprise Architecture Data Governance AI safety <p>Enterprise AI systems routinely retrieve from expired, superseded, unauthorized, or jurisdictionally restricted information sources — not because models lack capability, but because enterprise corpora carry no machine-readable governance signal at inference time.</p> <p>This paper introduces Metadata-First Enterprise Architecture (MFEA), a storage-agnostic governance registry that operationalizes the third stage of metadata governance evolution: automated enforcement. MFEA attaches a four-tier metadata envelope (T1 Structural, T2 Semantic, T3 Operational, and T4 Governance) and a continuously computed MFEA Score to every enterprise information asset, making governance state machine-readable and query-able at inference time without requiring storage migration or platform modification.</p> <p>Seven original contributions are advanced: (1) the four-tier metadata architecture isolating human governance burden to Tier 4—under 5 minutes per asset; (2) the I-O-C-L-P governance envelope as the complete specification of the enterprise governance act; (3) the MFEA Score as a binary governance gate, not a retrieval ranking signal; (4) the Triple-Layer Retrieval Architecture (TLRA) enforcing governance before relevance before precision; (5) the Non-Fungible Data Record for tamper-evident governance history; (6) the Continuous Information Audit as a permanently operating governance intelligence system; and (7) a public protocol governance model and submission pathway.</p> <p>Integration matrices are provided for TOGAF, Zachman, CMMI, ISO/IEC 42001, ISO/IEC 27001, NIST AI RMF 2.0, COSO ERM, OWASP LLM Top 10, EU AI Act, GDPR, and India DPDPA. Falsifiable predictions and a three-level empirical hypothesis architecture are specified.</p> <p>The paper advances the thesis that MFEA constitutes the missing semantic governance layer of enterprise digital infrastructure, the Aadhaar of data, enabling trustworthy AI at the enterprise and, as a public protocol, at the civilizational scale.</p> <p> </p> <p><strong>Venkat Rao</strong></p> <p><strong>Contact: venkat@twopointsingularity.com / venramak@gmail.com</strong></p> <p><strong>LinkedIn: https://www.linkedin.com/in/venkatrrao/</strong></p> |
| title | Metadata-First Enterprise Architecture (MFEA): From Passive Description to Active Control to Automated Enforcement — The Governance Substrate for Trustworthy Enterprise AI |
| topic | Enterprise AI Governence Metadata Architecture, Retrieval-Augmented Generation RAG governance TOGAF Zachman Framework CMMI ISO 42001 ISO 27001 NIST AI RMF COSO ERM OWASP LLM EU AI Act GDPR India DPDPA Data Provenance AI alignment Digital Public Infrastructure Information Lifecycle Management Governance-Aware Retrieval Corpus Governance MFEA Score Continuous Information Audit Non-Fungible Data Record Triple-Layer Retrieval Architecture Enterprise Architecture Data Governance AI safety |
| url | https://doi.org/10.5281/zenodo.19029898 |