Cloud adoption requires agencies to proactively manage the risks of vendor lock-in, maintain data portability, and plan for orderly exit before they are needed. This checklist supports agencies to meet their obligations under the cloud policy by ensuring decisions to use provider specific services are deliberate, documented, and reversible where required.
Agencies should be able to demonstrate where provider specific services are used and why the trade-off is acceptable, how data and metadata can be exported, what contractual constraints apply, what transition plan is endorsed and associated costs, how critical workloads could be migrated, and when the exit plan will be reviewed or tested.
Working through this checklist at key decision points, including contract renewal, and significant architecture or organisational changes, will assist agencies to apply the cloud policy.
Business rationale
Is the use of provider-specific services deliberate, justified and aligned to business outcomes?
- Does it meet the ICT and business requirements? (BuyICT)
- Has a decision record been completed and endorsed explaining the value gained?
- Have alternatives been considered and documented?
- Has an accountable owner (SRO) been identified?
- Does it demonstrate value for money?
- Have Single Seller Arrangements been considered?
- Are considered vendors referenced on the Digital Seller Underperformance list?
Dependency mapping
Which applications, data stores, integration services, AI models, automation workflows, monitoring tools or security controls depend on the provider?
- Has a dependency register been created covering critical services?
- Have the data flows and ontology of data holdings been documented?
- Has special acquisition, or data collected from third parties under a Memorandum of Understanding (MoU) or contracts, been documented and considered?
- Have integrations and supporting operational tools been recorded?
Data portability
Can agency data, metadata, logs, configuration, prompts, model artefacts and records be exported in usable formats?
- Have export types and methods, for example standard formats CSV, JSON, Parquet, been documented?
- Has the ownership position, or stewardship (APS Agency), been confirmed and consultation has occurred?
- Have limitations on access, reuse or migration been recorded?
- Has data sovereignty been considered?
Contractual constraints
Do contract terms limit transition, data extraction, interoperability, portability, auditability, service continuity or access to records?
- Has a contract review been completed and have transition rights been identified and understood?
- Have the outgoing vendor data return obligations been confirmed, and a workload management data return strategy been agreed?
- Have the contract's audit rights been reviewed and recorded, including rights to access logs, conduct or commission audits, receive third party reports, and verify vendor obligations to ensure they are met at exit?
- Have subcontractor arrangements and rights been reviewed?
- Have termination obligations been recorded and endorsed?
- Does the solution allow for portability of data in the future?
Cost of exit
What direct and indirect costs would arise from changing provider or moving workloads?
- Have offboarding costs been estimated?
- Have the costs associated with migration of workflows and data been estimated?
- Has a strategy been developed for dual-running, reconfiguration and testing, including costs?
- Have staff, assurance and supplier transition costs been estimated?
Operational continuity
Can the agency maintain service continuity during transition, outage, provider failure or contract exit?
- Is a business continuity plan (BCP) in place, covering backup and recovery processes, in cases of outage or transition?
- Have failover and incident response arrangements been documented and agreed, according to a disaster recovery plan?
- Have service level agreements or credits been confirmed?
- Have critical business processes been identified and understood?
Security and assurance
Will identity, logging, monitoring, encryption, vulnerability management and compliance controls remain effective during and after transition?
- Has a security control assessment, including alignment to IRAP, PSPF & ISM frameworks, been completed?
- Does a mapping for shared responsibility exist, for example a RACI?
- Are assurance artefacts, such as Authority to Operate (ATO), IRAP assessment reports, penetration test results, System Security Plan (SSP) and vendor compliance certifications in place?
- As part of risk assessment activities, have residual risks been recorded (accepted/transferred/mitigated)?
AI-specific lock-in
Are AI workloads dependent on proprietary models, prompts, embeddings, training data, orchestration tools or evaluation methods?
- Has the AI supply chain been mapped, and dependency records created covering models, prompts and datasets?
- Has the evaluation approach been documented?
- Have portability options been assessed and communicated?
- Has an Accountable Official (AO)/Owner been identified?
- Does specific lock-in impact the continuity of the AI solution, according to the AI Lifecycle, and enterprise architecture?
Exit testing
Has the agency tested whether critical data, workloads or configurations can be moved or restored?
- Have exit tests been conducted and results recorded and signed off?
- Have lessons learned been documented and shared?
- Have remediation actions been completed or managed?
- Has a next scheduled review or test date been confirmed and communicated?
- Have legacy systems, and related data, been planned for decommission?
Governance and review
Who owns the lock-in decision, how often is it reviewed, and what triggers reassessment?
- Has a named accountable owner been assigned?
- Has a review cycle been established and approved?
- Has the risk rating been documented, and communicated?
- Has the decision status been recorded and endorsed?
- Have trigger events been identified and planned for (including renewal, major upgrade, new AI workload)?