On the afternoon of September 21, at the headquarters of the State Audit Office of Vietnam (SAV), Deputy State Auditor General Bui Quoc Dung chaired a working session with the Information Technology Department (IT Department) and the consulting unit to review and finalize the draft Digital Architecture Framework of the SAV for the 2026–2031 period before submitting it to the competent authorities for consideration and approval.
The working session was held after the SAV completed the collection of comments from its units nationwide on the draft Digital Architecture Framework dossier, comprising the BC03 Explanatory Report and the BC04 Digital Architecture Framework Report.
Finalizing the Digital Architecture Framework Based on Feedback from SAV Units
According to a report by the IT Department, the draft was circulated for comments to all 29/29 units under the SAV. A total of 22 units provided 157 comments, focusing on institutional arrangements, data, technical infrastructure, and the actual working conditions of auditors.

Deputy State Auditor General Bui Quoc Dung discusses the draft Digital Architecture Framework with the IT Department and the consulting unit.
To date, the drafting team has completed the processing of all comments. Of these, 38 major issues were directly incorporated and revised, while the remaining comments were partially incorporated or addressed and clarified in the draft.
Key areas of focus include clearly defining the SAV’s independent legal status under the Constitution; clarifying the read-only connection mechanism to ensure that it does not interfere with the original systems of audited entities; and updating the organizational structure to be applied consistently across all 29 units following the SAV’s organizational restructuring in August 2026.
The draft Digital Architecture Framework is developed based on a four-layer architecture model, aligned with the National Digital Architecture Framework under Decision No. 1425/QD-TTg of the Prime Minister. The Framework is also further specified through five reference models covering business operations, data, applications, technology, and information security.
Based on the assessment of the current state, the draft identifies 26 capability gaps, including data being dispersed across multiple software systems, data sharing being carried out through separate individual connections, and a lack of centralized analytical tools. On this basis, the draft identifies 13 priority tasks and seven groups of key performance indicators (KPIs) to be achieved by 2031.
Tightening Investment Discipline and Developing Practical KPIs
At the working session, Deputy State Auditor General Bui Quoc Dung acknowledged the efforts of the IT Department and the consulting unit in receiving and processing a large volume of feedback. However, he requested further review to ensure that, once issued, the Digital Architecture Framework can be applied consistently across the SAV and remains aligned with the practical requirements of audit activities.

Deputy State Auditor General Bui Quoc Dung discusses the contents of the draft Digital Architecture Framework.
The Deputy State Auditor General emphasized that it is first necessary to ensure that units have a proper understanding of the Digital Architecture Framework. The Framework establishes the common framework, principles, interoperability models, and indicators to guide the SAV’s technology activities during the 2026–2031 period; it is not a document describing the detailed technical features of individual software systems or projects.
Specific technical requirements will be determined during the development of solution designs and implementation of individual projects. Clearly distinguishing these contents will help ensure a consistent understanding among units and facilitate implementation.
Another requirement emphasized by the Deputy State Auditor General is the need to ensure consistency in IT investment. Accordingly, IT projects during the 2026–2031 period must be reviewed and assessed for their conformity with the Digital Architecture Framework before approval and capital allocation.
Investment must be linked to the identified capability gaps, while limiting the situation in which individual units make separate investments, resulting in system duplication and data fragmentation. The Deputy State Auditor General also requested the consistent use of the term “estimated cost level” instead of “preliminary estimate” when a project has not yet been specifically formulated.
Regarding the KPI framework through 2031, the Deputy State Auditor General requested further review of baseline data, calculation methods, and feasibility.
According to the analysis presented at the working session, some indicators in the draft do not yet have sufficient baseline data but have already established targets for subsequent years. For example, for the shared data indicator group, the total number of categories requiring implementation has not yet been fully determined, while the draft sets targets of 80% completion by 2028 and 100% by 2031.
For information security, the indicator concerning the number of systems with approved security-level dossiers also needs to be updated to reflect actual conditions. At present, the SAV has approved Level 4 security classification for only one interconnected data system. Other indicators, such as a network incident response time of less than one hour, also need clearly defined measurement methods and an assessment of feasibility.
The Deputy State Auditor General requested that the KPI framework be based on accurate baseline data and clear calculation methods, with sufficient capacity for monitoring and evaluation throughout implementation, thereby avoiding targets that are not appropriate to actual conditions.
Gradual Application of AI with Audit Effectiveness as the Focus
Regarding the direction for the application of artificial intelligence (AI), the Deputy State Auditor General requested that the draft Digital Architecture Framework adopt a cautious approach. Audit activities are closely associated with evidence, legal regulations, and auditors’ responsibilities. Therefore, the application of AI and big data analytics should be implemented gradually, initially focusing on areas and audits where high-quality digital data are available.
AI and data analytics tools are identified as supporting tools for auditors in data processing, risk identification, and audit activities. Audit conclusions and recommendations must continue to be based on inspection and verification, professional judgment, and the responsibility of auditors.
Deputy State Auditor General Bui Quoc Dung requested the IT Department and the consulting unit to urgently finalize the dossier and ensure its quality before submitting it to the competent authorities.

IT Department personnel at the working session.

Members of the consulting unit at the working session.
Accordingly, the consulting unit will continue finalizing the BC04 Digital Architecture Framework Report and condensing the presentation materials, with a focus on clarifying the nature, scope, and key contents of the Framework.
The IT Department will finalize the submission seeking opinions on the KPI framework and arrange a schedule for SAV leaders to present a preliminary report before the official submission.
Upon completion of the review, the Digital Architecture Framework dossier will be reported to the SAV Steering Committee for Digital Transformation and submitted for comments from the Standing Committee of the SAV Party Committee before being submitted to the State Auditor General for consideration and issuance in 2026.
The Digital Architecture Framework for the 2026–2031 period will serve as the basis for the SAV to implement digital transformation tasks under a unified direction, align technology investment with the practical requirements of audit activities, and gradually improve the effectiveness of data utilization and management across the SAV.