
Most companies build project management, architecture governance, and AI governance as three separate functions. Each with its own leader, processes, and language. It looks logical on paper, but in practice it creates blind spots, duplicated effort, and decisions that work against each other. This article describes how the three disciplines connect, and how an integrated approach delivers better projects, stronger architecture, and real control over AI.
A Project Management Office (PMO) ensures that projects are executed in a structured way and deliver the expected result. Enterprise Architecture (EA) ensures that technology choices support the business strategy and fit into the overall system landscape. AI governance ensures that the use of artificial intelligence happens responsibly, legally, and with documented risk management. All three functions exist to protect the company from poor decisions and wasted resources. Yet in many organisations they operate in silos, where PMO reports to a CIO or COO, EA sits in a technology department, and AI governance is placed with legal. The result is that a project can be approved by PMO without EA assessing the architectural consequence, or an AI solution gets implemented without anyone classifying it under the EU AI Act.
A Stage Gate model divides an IT project into phases with clear gates, decision points where the project is assessed before it progresses. Typical phases are idea and screening, preliminary analysis, planning, execution, testing, and launch. At each gate, concrete questions are asked: is the business case still valid? Have risks been identified and managed? Are the necessary resources in place? This model is PMO's governance tool. But it becomes far more powerful when EA and AI governance are integrated directly into the phases. Instead of architecture reviews and compliance checks happening as isolated side processes, they are embedded as mandatory elements at the relevant gates.
In an integrated model, Enterprise Architecture participates actively at a minimum of three gates. At the preliminary analysis, EA assesses whether the proposed solution fits into the existing system landscape, or whether it creates technical debt. At the planning phase, EA defines the architecture principles and guardrails the project must adhere to. And at the testing phase, EA verifies that the delivered solution actually complies with the established principles. This requires an Architecture Board, a cross-functional body with the mandate to approve or reject architecture decisions. Without an Architecture Board, architecture assessments end up as recommendations that project managers can freely ignore when the timeline pressures mount. An Architecture Board with real mandate is the difference between EA as governance and EA as documentation.
The EU AI Act came into broad effect on 2 August 2026 for high-risk systems and transparency requirements. This means that every project involving AI must be risk-classified early in the process. In an integrated Stage Gate model, this classification happens at the preliminary analysis. The questions are concrete: does the project use AI for decisions that affect people? Does it use personal data for training? Is the system covered by Annex III of the EU AI Act? If the answer is yes, a governance track is activated in parallel with the project plan. This track covers documentation of datasets, risk assessment, bias testing, and a plan for human oversight. By integrating this into the project model, the company avoids the classic mistake: building the solution first and attempting to make it compliant afterwards. Retrofitting compliance is always more expensive and often impossible without fundamental changes.
Enterprise Architecture provides the guidelines and guardrails on which AI governance builds. Guidelines describe the preferred approach: which data platforms do we use? What standards for data modelling do we follow? How do we document integrations? Guardrails are the hard boundaries: no AI model may be trained on data that has not been classified. No new integration may be created without EA approval. No third-party AI service may be adopted without a risk assessment. The distinction between guidelines and guardrails is critical. Guidelines can be deviated from with justification. Guardrails cannot. When AI governance operates within EA's guardrails, it becomes part of daily operations rather than a separate compliance project that lives its own life alongside the organisation.
A company wants to implement an AI-based solution for automated customer service. In a siloed organisation, the project would be initiated by the business, approved by PMO based on a business case, and handed to IT for implementation. EA might be consulted along the way, and compliance would be contacted close to launch. In an integrated model, the process looks different. At the idea phase, EA assesses whether the solution fits into the existing system landscape, and AI governance classifies the system under the EU AI Act (in this case, likely limited risk with transparency requirements). At the preliminary analysis, EA defines the data requirements, and the governance team verifies that the planned datasets can be used legally. At planning, PMO establishes the timeline and resources with input from EA on architecture requirements and from governance on documentation requirements. At testing, all three functions verify: PMO that the deliverable is complete, EA that architecture principles have been followed, and governance that documentation is in place for a potential regulatory inquiry. The difference is not more meetings. The difference is that the right questions are asked at the right time, instead of being asked too late.
None of the three disciplines function without reliable data. PMO needs data for status reporting and resource management. EA needs data to map the system landscape. AI governance needs data for risk assessment and lineage. A structured data platform with clear master data, a tiered data structure, and data governance is therefore not a separate initiative. It is the foundation on which PMO, EA, and AI governance all rest. Without unambiguous data sources, PMO cannot report accurately, EA cannot assess dependencies, and AI governance cannot document which data a model was trained on.
The most common mistake is placing AI governance with legal alone. Legal can assess regulatory requirements, but cannot assess which data a system draws on, or which other systems it is connected to. That is architecture knowledge. The best AI governance we have seen sits with Enterprise Architecture, with legal as an advisor. PMO should likewise have a close link to EA, so the project model's gates reflect architecture requirements. Specifically, we recommend that the Architecture Board includes a permanent representative from PMO, and that PMO's gate criteria include EA and governance approvals. This creates an integrated governance chain where no decision is made in isolation.
Start by mapping how the three functions operate today. Where do they sit organisationally? Who reports to whom? Where is there overlap, and where are there gaps? Next, establish a shared project model with Stage Gates that include EA assessment and AI classification as mandatory elements. Third, create or strengthen an Architecture Board with real mandate to say no. Fourth, define clear guardrails for AI that are anchored in EA's existing principles. Fifth, ensure the data platform supports all three functions with unambiguous sources and clear lineage. None of these steps require a large programme. They require someone to sit at the head of the table and decide that these disciplines no longer operate in silos.
Many companies have the competencies internally but lack the capacity or mandate to drive the change. An external advisor adds two things: an outside perspective that sees the blind spots the organisation itself is too close to notice, and an independence that makes it easier to ask the uncomfortable questions. At We Lead Projects, we have built PMO functions, established Architecture Boards, and designed AI governance frameworks for companies ranging from retail to the public sector. Our experience is that the greatest value lies not in the individual functions, but in the integration between them.

Brian P.N. Tofft
Managing Partner, We Lead Projects
Brian has more than 30 years of experience in project management and IT transformations across industries.
Get in touch and find out how we can help with your next project.
Contact us