Most teams find out the wrong way. Five questions, answered honestly:
- Can you trace every architecture decision to a requirement or risk control? Not just the ones you remember. Every one.
- Does your SOUP registry reflect what is running in production today? Not at submission. Today.
- If a clinical anomaly occurred last night, would you know? Not a crash. Something clinically wrong happening silently.
- Has every vendor been formally qualified, not just reviewed? A contract is not a supplier qualification.
- Does your architecture description match the repository right now? Not at launch. Systems change. Documents often don't.
All five answered yes? You are in good shape. Any pause tells you where to start.
Seen this differently?
Questions, corrections and counterexamples are welcome.

