| Current-state assessment | Key estate, governance, lifecycle, access, evidence, supplier, and operational findings. | Assessment report and findings register | Assess | Inventories, interviews, policies, evidence | Dataconsultant with client validation |
| Key governance operating model | Decision rights, forums, roles, escalation, exceptions, and oversight cadence. | Operating-model document and RACI | Design | Organisation structure and accountabilities | Client accountable executive |
| Lifecycle policy and standards | Requirements from generation to destruction, including risk-based exceptions. | Policy, standard, and control statements | Design | Risk appetite and regulatory requirements | Client policy owner |
| Control and evidence matrix | Control objective, owner, frequency, platform, evidence source, test, and retention. | Structured control library | Design / enable | Available logs, reports, and control data | Control owners |
| Platform governance patterns | Approved KMS/HSM patterns, tenancy, access, rotation, recovery, logging, and residency. | Architecture principles and pattern catalogue | Design | Architecture and platform standards | Security and architecture teams |
| Remediation roadmap | Priorities, dependencies, risk, sequencing, owners, acceptance criteria, and review gates. | Roadmap and backlog | Enable | Resource, budget, and programme constraints | Programme sponsor |
| Operational playbooks | Rotation, emergency access, recovery, compromise, revocation, exception, and evidence procedures. | Runbooks and checklists | Enable | Operational workflows and platform detail | Service operations |
| Training and transition pack | Role-based guidance, control responsibilities, handover, and continuing review plan. | Workshops, guides, and transition checklist | Operate | Audience and operating model | Client capability owner |