View more Cloud policy guidance.
On this page
- About this guidance
- Manage vendor lock-in
- Balance value, portability and diversification
- Reduce lock-in where it matters
- Clear cloud exit strategy
- Take a proportionate approach
- Related links
- More cloud policy guidance
About this guidance
This guidance helps agencies meet requirement 2 of the Whole-of-government cloud computing policy: Entities must leverage contemporary cloud technology to empower innovation, including Artificial Intelligence.
The Cloud computing policy requires agencies to prioritise cloud while managing adoption responsibly, including interoperability, portability, exit planning and data migration.
Agencies should show how provider dependencies are identified, justified, accepted and reviewed, and how exit or transition options remain available where needed.
Who this guidance is for
This guidance is for agency staff involved in making, approving, delivering or operating cloud services. Different roles should use the guidance in different ways.
- Accountable executives should use this guidance to set risk appetite, approve material lock-in decisions, ensure provider dependencies are understood, and confirm that exit, transition and continuity risks are governed and reviewed.
- Delivery and program teams should use this guidance when planning, procuring or changing cloud services to assess portability, document trade-offs, estimate exit costs, and build transition requirements into delivery plans and contracts.
- Operational and specialist teams should use this guidance to identify technical dependencies, maintain dependency registers, test export and recovery arrangements, monitor provider-specific risks, and provide evidence to support assurance and review.
When to use this guidance
Use this guidance when planning, procuring, designing, changing or reviewing cloud services where provider dependency may affect portability, continuity, interoperability or exit options. It is most useful when agencies are making decisions about provider-specific services, cloud diversification, data migration, contract renewal, major system changes or cloud exit planning.
Agencies should use this guidance early enough to influence design, procurement and governance decisions, not only when a service is being exited or a problem has already emerged.
Implementation may be demonstrated through lock-in decision records, dependency registers, portability assessments, exit cost estimates, transition plans, contract review records, accountable owners and review points.
Manage vendor lock-in
Vendor lock-in happens when an agency becomes dependent on a provider’s services, tools or operating model in ways that reduce flexibility or increase the cost, effort or risk of changing later.
Lock-in is not inherently a problem. It becomes a concern when dependencies are poorly understood, unmanaged, or disproportionate to the value gained. Agencies should make deliberate, risk-informed choices and record the trade-offs.
Agencies should review material vendor dependencies at agreed intervals and record whether each dependency is deliberate, risk-accepted and actively managed, or whether mitigation is required.
Agencies can use a lock-in decision record to document material provider dependencies and show how each dependency is being actively managed.
Use the detailed lock-in, portability and exit planning checklist linked under More resources to assess material dependencies and retain supporting evidence. Record the decision, business value, key risks, mitigations, accountable owner and review trigger in agency governance records.
Balance value, portability and diversification
Agencies should weigh the benefits of provider-specific services against the cost, effort and risk of switching later. Some services may provide strong value even if they are less portable.
For example, managed cloud services can reduce effort through:
- automated patching
- built-in monitoring and alerting
- identity and access management
- automatic scaling and resilience features.
Agencies can also consider cloud diversification where appropriate. Diversification means using more than one cloud provider, platform or service to reduce concentration risk and support resilience, continuity or flexibility. It may be appropriate where reliance on a single provider would create unacceptable operational, commercial or continuity risks.
However, diversification can also increase complexity, cost and workforce capability requirements, so agencies should adopt it only where there are a clear business need and risk-based justification.
Agencies should consider whether data can be exported in open, reusable formats to support portability if a vendor relationship ends.
Before pursuing diversification, agencies should document the expected benefits, added complexity and capability required to manage the approach effectively.
Agencies should engage with other agencies, including where possible those of similar size and scale, to learn from their cloud diversification experiences and inform their approach.
Reduce lock-in where it matters
Focus mitigation on dependencies that could create unacceptable cost, disruption or operational risk. Apply controls proportionate to workload criticality, data sensitivity and service importance.
Use the detailed checklist linked under More resources to assess risk, document trade-offs and maintain evidence.
Clear cloud exit strategy
The Cloud computing policy requires agencies to maintain exit strategies and data migration plans so cloud services can be changed, transitioned or retired where needed. Agencies should ensure exit planning is proportionate to the criticality of the service, the sensitivity of data, contractual obligations, continuity requirements and the level of provider dependency.
Implementation may be demonstrated through an approved exit strategy, data migration plan, export and deletion approach, transition cost estimate, continuity plan, contract exit obligations, test results, accountable owners and review triggers.
Take a proportionate approach
Maximum portability is not always the best outcome. Design flexibility and diversification only to the extent justified by continuity, resilience, cost and strategic need.
Document where portability or diversification is required, where provider-specific capability is accepted, and who owns the decision.
Related links
More cloud policy guidance
- Guide to meeting the requirements of the Whole-of-government cloud computing policy
- Guide to planning a cloud strategy
- Guide to cloud migration and legacy retirement
- Guide to procuring cloud services
- Guide to managing security, privacy and operational risk
- Guide to reviewing and continuously improving cloud adoption
- Guide to managing cloud and usage costs, including AI costs
- Guide to developing cloud capability in your agency