| Current-state assessment | Journeys, systems, data, controls, issues, risks, and dependencies | Findings report and evidence register | Assessment | Access, interviews, samples, policies | Dataconsultant with client SMEs |
| Preference taxonomy | Purpose, channel, product, brand, frequency, language, and personalisation choices | Controlled model and glossary | Design | Business rules and legal decisions | Business, privacy, and governance owners |
| Target architecture | Systems of record, identity, APIs, events, history, propagation, and reconciliation | Architecture diagrams and specifications | Design | Technology standards and constraints | Architecture and engineering leads |
| Preference-centre requirements | Journeys, content, authentication, accessibility, validation, and confirmation | Journey maps, wireframes, backlog | Design | Brand, product, CX, and accessibility input | Product or customer-experience owner |
| Migration and cutover plan | Source mapping, precedence, deduplication, exceptions, reconciliation, and rollback | Plan, mappings, and control checklist | Implementation | Legacy extracts and approved rules | Programme and data migration leads |
| Test and assurance pack | Functional, integration, privacy, security, data-quality, and operational scenarios | Test cases, evidence, defects, sign-offs | Validation | Test environments and reviewers | QA, privacy, security, operations |
| Operating model and reporting | Roles, procedures, issue handling, change control, KPIs, and review cadence | Playbook, RACI, dashboard specification | Transition | Named owners and service expectations | Service owner and governance forum |