Skip to content
Open access

Structural Digital Twin-Driven Conformance Assessment of LegalTech Governance Ontology: Reproducible Proof of Concept

Jul 2026 · Information · Vol 17, pp. 725 · 0 citations · 25 references

TL;DR

Overall, the findings suggest that MALTG provides a formally grounded and reproducible approach for automating multi-framework LegalTech governance conformance assessment while maintaining semantic and structural traceability between normative models and operational architectures.

Abstract

The increasing convergence of enterprise architecture and IT governance frameworks, such as TOGAF 9.2, COBIT 5, and NIST CSF 1.1, with LegalTech regulations including GDPR 2016/679, eIDAS 910/2014, and NIS2 2022/2555, has created a growing need for rigorous and automated governance-validation mechanisms. However, to date, no formal approach exists to assess semantic conformance between a normative ontological model and its operational implementation in microservice-based systems, leaving critical governance gaps difficult to detect in legally sensitive environments. This paper proposes MALTG (Multidimensional Architecture for LegalTech Governance), a configurable and reusable formal framework that combines OWL 2 ontology engineering, a JSON-LD-based SDT (Structural Digital Twin), semantic conformance mapping, a hierarchical coverage function, and a conformance gap metric to support automated governance assessment and prioritised remediation. The framework accepts any organisational architecture as input, enabling application to arbitrary LegalTech case studies by replacing the reference SDT. The proposed framework models nine governance dimensions through an ontology of 59 classes and 15 properties and validates them against a semi-real, public-source SDT composed of 39 microservice components and 54 directed connections. The reference SDT was populated through an ontology-driven data-collectionprocess: a scraping campaign guided by the MALTG ontology (data/MALTG_Ontology.owl) harvested public information from the official portal of Ecuador’s Council of the Judiciary (Consejo de la Judicatura, CJ)—probing its technological-maturity level and digital-governance compliance—which was condensed into a single JSON-LD artefact, enforcing domain rigour and traceability on the search for LegalTech governance evidence. Experimental results demonstrated an overall ontological score of 82.6 and an SDT score of 73.7, with a mean conformance gap of 8.9. Five dimensions achieved full conformance, while the LegalTech dimension presented the largest gap. Graph-theoretic validation further confirmed monotonic improvement throughout the remediation sequence. Overall, the findings suggest that MALTG provides a formally grounded and reproducible approach for automating multi-framework LegalTech governance conformance assessment while maintaining semantic and structural traceability between normative models and operational architectures. As a proof of concept, this validation relies on a configurable, ontology-driven public-source (semi-real) SDT; external validity in real production LegalTech organisations remains untested and is left for future work.

Read PDF

Similar papers

Preprint Aug 2026

Operationalizing Regulations into Code: A Model to Enhance Governance and Compliance in LLM Selection for Software Engineering

Integrating Large Language Models (LLMs) into the Software Development Life Cycle (SDLC) can improve developer productivity, but it also introduces security, privacy, and compliance risks during model selection. Regulations and frameworks such as the EU AI Act, the NIST AI Risk Management Framework (RMF), the General Data Protection Regulation (GDPR), the Lei Geral de Prote\c{c}\~ao de Dados (LGPD), and ISO/IEC 42001 establish obligations that are often difficult to translate into operational criteria for technical decision-making. This paper proposes a model to support governance and compliance in LLM selection for software engineering projects. The model is developed through Design Science Research (DSR) and is structured in three layers: (i) regulatory requirements, (ii) organizational governance capabilities, instantiated by a multi-criteria decision matrix with knock-out and weighted scoring criteria, and (iii) productivity and sustainability outcomes, operationalized by the LLM governance assessment protocol (PAG-LLM). A regulatory feedback loop connects operational results back to the normative layer, enabling iterative refinement of the model. A pilot evaluation with 20 adversarial scenarios based on Common Weakness Enumeration (CWE) and the OWASP Top 10 suggests distinct risk profiles between commercial cloud-based LLMs and local open-source LLMs. The results provide preliminary evidence that regulatory disqualification logic, particularly K.O. criteria, can prevent the selection of technically competitive models that nonetheless pose unacceptable compliance risks, demonstrating the feasibility of governance-oriented LLM selection in software engineering projects.

J. Quintino, Hermano Moura, Filipe Calegario · 0 citations
Review Open access Sep 2026

CLOUD DATA GOVERNANCE AND REGULATORY COMPLIANCE FOR ERP–FINTECH ECOSYSTEMS IN SAUDI ARABIA: ALIGNING SAMA, ZATCA, VAT AND IFRS REQUIREMENTS UNDER VISION 2030

Saudi Arabia’s ERP and fintech landscape is becoming a shared transaction environment in which accounting entries, payment instructions, customer data, tax invoices and regulatory evidence move across cloud platforms in near real time. This review examines how cloud data governance can reconcile that speed with Saudi Central Bank oversight, Zakat, Tax and Customs Authority requirements, value added tax controls and evolving financial reporting obligations. A structured integrative review of scholarly research and official instruments published from 2020 to 2025 was undertaken. Evidence was coded across governance, data architecture, cybersecurity, tax determination, financial reporting, third-party risk and assurance. The synthesis shows that compliance cannot be achieved through separate checklists owned by finance, tax, information technology and risk functions. It requires a unified control architecture in which regulatory obligations are translated into canonical data definitions, automated validation rules, accountable workflows and durable evidence. The proposed framework combines a governed data layer, a machine-readable policy layer, preventive and detective controls, and an assurance layer that preserves lineage from source transaction to filing or disclosure. It also distinguishes stable master-data controls from rapidly changing regulatory rules, allowing ERP and fintech services to evolve without weakening auditability. The review identifies four implementation priorities: assigning decision rights for shared data; engineering tax and reporting requirements into transaction design; governing cloud and API dependencies as extensions of the regulated enterprise; and operating continuous compliance through metrics, testing and controlled change. The resulting model supports Vision 2030 by treating trusted financial data as infrastructure for digital growth rather than as a reporting by-product.

Rania Mansour · 0 citations
Open access Aug 2026

OpenGRCRMF: A Vendor-Neutral Framework for Teaching and Modeling RMF Automation, Continuous Authorization, and Zero Trust Governance

Abstract—Federal and regulated organizations continue to rely on document-centric Authorization to Operate (ATO) processes even as the NIST Risk Management Framework (RMF), continuous monitoring guidance, Zero Trust Architecture (ZTA), and continuous authorization initiatives require more continuous, evidence-driven risk management [1]-[3], [13], [15]. Manual System Security Plan (SSP) updates, spreadsheet-based Plan of Action and Milestones (POA&M) tracking, and disconnected assessment evidence create governance latency: the delay between operational security events and authorization-ready governance response. This paper presents OpenGRCRMF, a proposed open, vendor-neutral reference framework that models RMF lifecycle activities as workflow states, treats authorization artifacts as structured governance objects, and maps DevSecOps and Zero Trust telemetry into authorization-relevant evidence. Using Design Science Research, the study develops the OpenGRCRMF architecture, formalizes its data and risk model, and evaluates expected governance effects through a synthetic simulation of 1,500 findings across 180 assets and 320 controls [9]. OpenGRCRMF is evaluated as a reference framework rather than a production platform using a self-contained simulation specification and sensitivity analysis. In the simulation, the OpenGRCRMF-enabled workflow reduced modeled governance processing time by 36.8 percent, increased modeled evidence completeness by 41.5 percent, and increased modeled control-to-evidence traceability by 52.7 percent compared with a document-centric baseline. These results are modeled outcomes under stated assumptions, not production deployment proof. The paper contributes a governance object model, governance latency construct, reproducibility-oriented simulation design, threat-to-validity analysis, and education-oriented framework for teaching how operational telemetry becomes authorization evidence.

Anand Janjal · 0 citations
Open access Jun 2025

ESG-as-Code: A Deterministic Rule-Based Framework for Automated ESG Compliance Validation

Environmental, Social, and Governance (ESG) compliance has shifted from voluntary best practice to enforceable legal obligation across major global jurisdictions. Frameworks such as the European Union's Corporate Sustainability Reporting Directive (CSRD), the Sustainable Finance Disclosure Regulation (SFDR), the United Kingdom's Sustainability Disclosure Requirements (SDR), and disclosure rules from the U.S. Securities and Exchange Commission (SEC), adopted in 2024 and now under proposed rescission, impose structured reporting duties on a growing range of organizations. Yet dominant compliance methods remain manual, fragmented, and difficult to verify. Static documentation, subjective interpretation, and scoring systems that cannot be traced back to specific legal provisions continue to define current practice. This paper introduces ESG-as-Code, a deterministic rule-based framework designed to address these limitations by converting ESG regulatory obligations into structured rule logic formally specified for machine implementation. Drawing on established principles from Policy-as-Code, Infrastructure-as-Code, and computational law, the framework provides a structured methodology for encoding jurisdictional ESG rules as conditional logic that can be evaluated systematically against organizational data and disclosures.   Central to the framework is a deliberate separation between probabilistic systems used for document interpretation and deterministic engines used for compliance decision-making. This separation preserves full auditability, allowing every compliance outcome to be traced directly to a specific regulatory provision rather than a statistical inference. Determinism in this sense guarantees reproducibility and rule-level traceability, properties that probabilistic scoring systems cannot offer by design. It does not by itself guarantee that a given outcome is legally correct; that additionally depends on the accuracy of the underlying rule encoding, the currency of the regulatory source, and the governance processes surrounding the rule library. The paper argues that reproducibility and traceability are necessary but not sufficient conditions for regulatory defensibility and proposes deterministic rule-based architecture as the foundation on which the remaining conditions can be built.

Isaiah Oluwasegun Owolabi · 0 citations
Open access Aug 2026

An Integrated University Digital Transformation Model Combining IT Governance, Interoperability, Cloud Security Assessment and Data Analytics: The UTMACH Case in Ecuador

The case indicates that university digital transformation is strengthened when technological implementation is integrated with formal governance, systematic assessment, evidence-based planning, and institutional accountability.

Jennifer Célleri-Pacheco, Fernanda Tusa Jumbo, Oswaldo Chuquirima Camacho et al. · 0 citations
Review Open access Jul 2026

From Text to Executable Semantics: A Modular Ontology and SHACL Controls for University Intellectual Property Non-Disclosure Agreements in Colombia

This article proposes an ontology to formalize non-disclosure agreements (NDAs) at the University of Caldas, Colombia, understood as a specific case within the broader management of IP agreements.

Oscar Mauricio Bedoya-Herrera, Jeferson Arango-López, J. Hochstetter-Diez · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.