| Sensitive data inventory and scope map | Define what needs protection | Data types, stores, owners, flows, locations, suppliers, purposes, and confidence levels | Data, privacy, security, system owners |
| Current-state control assessment | Identify gaps and exposure | Control design, implementation evidence, findings, risk rating, dependencies, and limitations | Risk, compliance, audit, leadership |
| Classification and handling standard | Create consistent rules | Levels, criteria, labels, handling requirements, exceptions, roles, and review process | All data users and technology teams |
| Target control framework | Connect requirements to controls | Preventive, detective, corrective controls; ownership; frequency; evidence; testing | Security, privacy, data governance, operations |
| Remediation roadmap | Prioritise implementation | Actions, owners, sequencing, dependencies, decision gates, effort factors, and acceptance criteria | Programme, technology, procurement |
| Operating and assurance pack | Sustain controls | Procedures, RACI, metrics, test plans, evidence templates, exception workflow, and reporting | Control owners, assurance, internal audit |