| Provider and dataset inventory | Ownership, purpose, criticality, cost, contracts, systems and users | Register and dashboard | Assessment | Provider lists, invoices, systems | Data office / procurement |
| Rights and obligations register | Permitted use, territories, users, retention, redistribution, attribution and deletion | Controlled register | Assessment and design | Contracts and legal interpretation | Legal / data governance |
| Onboarding control pack | Due diligence, approvals, technical gates, metadata, quality, security and privacy evidence | Workflow and templates | Design | Policies and approval owners | Procurement / technology |
| Integration and lineage specification | Interfaces, mappings, transformations, quality checks, lineage and publishing | Technical design | Implementation | Samples, APIs and platform access | Data engineering |
| Quality and service framework | Measures, thresholds, monitoring, issue ownership and provider escalation | Rules and scorecard | Implementation | Business tolerances and SLA terms | Data operations |
| Risk and control matrix | Commercial, privacy, security, resilience, quality and downstream-use controls | Control register | Design and assurance | Risk criteria and evidence | Risk / security / privacy |
| Operating model and RACI | Decision rights, roles, forums, handoffs, escalations and review cycle | Operating model | Target state | Organisation and role inputs | Data leadership |
| Managed-service reporting pack | Quality, incidents, usage, costs, changes, risks, renewals and actions | Dashboard and report | Operate | Operational data and decisions | Service owner |