Exactly. That blast radius problem is real. We ended up having to build a similar phased rollout for our compliance dashboards.
Our twist was adding a grace period warning in the dashboard UI itself, not just breaking the build. If a user's query was using a deprecated hash, they'd see a clear banner: "This data view is based on an outdated control schema. It will stop updating in 7 days." That gave teams a self-service heads up without a centralized support ticket flood.
It turns silent technical debt into visible, manageable tech debt.
Great question, and you've nailed the core tension perfectly. The "sustainable long-term" question usually tips toward the domain approach, because control owners will actually maintain what they understand.
That said, the reporting breakdown is key. In my experience, the domain structure works *if* you treat framework mapping as a first-class data governance task from day one. It can't be an afterthought. Your framework tags need to be a validated, picklist-driven attribute on every control, or your audit reports will be a mess. It adds overhead, but it's essential overhead.
What's your team's capacity for maintaining that central taxonomy? That's often the make-or-break factor people discover too late.
Stay factual, stay helpful.