Architecting Absolute Data Lineage: Automated Compliance Governance and Metadata Tracking in Legacy-to-Cloud Re-Platforming
DOI:
https://doi.org/10.70917/ijcisim-2026-5323Keywords:
Data lineage, Cloud migration governance, Metadata management, Regulatory compliance, Legacy modernizationAbstract
Enterprises retiring legacy mainframe platforms in favor of cloud-native infrastructure routinely encounter a governance blind spot: the ability to trace where a given piece of data originated, how it was transformed, and who touched it along the way degrades sharply once workloads move into distributed, multi-service cloud environments. This weakness matters most in regulated industries, where auditors and compliance teams depend on that traceability to demonstrate adherence to data protection and financial reporting requirements. Manual, retrospective audit processes, built around periodic spreadsheet reconciliation and log sampling, were designed for the comparatively static topology of mainframe systems and do not scale to the transient, horizontally distributed nature of cloud workloads. This paper proposes an architectural framework for automated data lineage capture and compliance verification, structured around a three-phase pipeline: non-intrusive metadata harvesting at the point of data movement, structural mapping of that metadata into a queryable graph representation, and continuous verification of data pathways against governance policy. The framework is informed by direct practitioner experience leading legacy-to-cloud re-platforming programs and the accompanying CI/CD governance, stage-gate review, and audit-readiness disciplines that such programs require. Rather than treating lineage tracking as a downstream compliance checkbox, the proposed design treats it as a first-class architectural concern, decoupled from transactional workloads so that audit visibility does not come at the cost of processing throughput. The paper situates this proposal against the existing literature on metadata lineage, data catalog systems, and blockchain-based audit trails, and discusses where a decoupled, graph-based capture architecture addresses gaps that batch-oriented and single-authority approaches leave open. The discussion also considers where this architecture would need empirical validation before enterprise adoption, and identifies directions for future work, including AI-assisted schema reconciliation across heterogeneous legacy sources.