| Current-state assessment | Journey, data, system, control and ownership findings | Report and findings register | Policies, system access, stakeholders and evidence |
| Consent and preference taxonomy | Purpose, channel, brand, product, status and version definitions | Controlled taxonomy | Legal interpretation and business use cases |
| Target data and architecture design | Entities, events, source-of-truth, integration and decision-service patterns | Models and diagrams | Architecture and platform constraints |
| Preference-centre requirements | Choice structure, content, accessibility, identity and withdrawal behaviour | Functional requirements | Customer journeys and approved notices |
| Control and test framework | Preventive, detective and corrective controls with test cases | Control matrix and test pack | Risk, privacy, security and audit criteria |
| Operating model and roadmap | Roles, procedures, KPIs, priorities, dependencies and transition plan | Operating pack and roadmap | Resource, governance and investment decisions |