Document summary
This page explains provider selection, classification, contracting, connection, monitoring, renewal, and exit, including data, access, and continuity controls.
Classification
A provider is classified by data, access, criticality, value, replaceability, location, and dependencies. Rating determines review, approval, contract, and monitoring depth.
Selection and competition
Need, options, total cost, risk, and conflict are documented. Purchase request, approval, and payment are separated by threshold, and a sole-source choice is justified.
Due diligence
Review covers legal status, security, privacy, continuity, insurance, licences, intellectual property, subprocessors, and applicable sanctions.
Contract
The contract defines scope, service levels, audit rights, incidents, confidentiality, data, IP, remedies, change, exit, deletion, and transition support. A sensitive integration is not enabled before contract and approval.
Monitoring and renewal
Service levels, incidents, risk, permissions, costs, complaints, and renewal dates are monitored. Renewal review starts early enough to support exit or negotiation.
Termination and exit
Accounts, keys, and links are revoked, assets returned, data transferred, deletion confirmed, and required records retained. A critical service alternative is tested before termination where possible.
Official references
References used to prepare this content
Links point to official legal or guidance sources. Applicability depends on the organization, product, and contract.
Versions
Change log
- Version 1.0.0
Published the first operational version with clear scope, responsibilities, rights, and escalation routes.