Enterprise Data Governance

Recover Stalled Data Governance Programs with Clear Accountability

4.9 out of 5 from 6,284 reviews

DataConsultant helps data leaders, technology teams, risk functions, and business owners diagnose stalled governance programs, reset priorities, repair operating-model gaps, and mobilise practical remediation. The service turns fragmented committees, policies, tools, and unresolved issues into an accountable recovery plan designed to restore adoption, control evidence, and measurable business relevance.

  • Independent recovery assessment
  • Accountability and decision-rights reset
  • Prioritised remediation and mobilisation
  • Knowledge transfer and measurable reporting
Direct answer

What Is Governance Program Recovery Service?

Governance program recovery is a structured intervention for an enterprise data governance initiative that has stalled, lost sponsorship, produced limited adoption, or failed to demonstrate effective control. It typically combines an independent current-state assessment, stakeholder and decision-rights review, issue prioritisation, operating-model redesign, remediation planning, and implementation support. The main buyers are chief data officers, CIOs, governance leaders, risk and compliance teams, internal audit stakeholders, and transformation sponsors. The intended value is a credible route from fragmented activity to accountable, measurable operation. Success depends on executive backing, access to evidence, stakeholder participation, realistic scope, and sustained ownership.

Service offering

Focused Support to Diagnose, Reset, and Stabilise Governance

The engagement is designed around the real causes of program underperformance rather than automatically adding more policy, tooling, or committees.

01

Diagnose

Review the original mandate, sponsorship, scope, operating model, governance forums, policies, controls, technology, adoption, open risks, and available evidence.

Inputs: charters, policies, role descriptions, issue logs, audit findings, platform outputs, meeting records, and stakeholder interviews.

Output: evidence-based recovery assessment with failure themes, dependencies, and immediate containment actions.

02

Reset

Reconfirm business outcomes, accountable sponsorship, decision rights, domain ownership, governance scope, service model, prioritisation logic, and control expectations.

Client role: provide decision-makers, validate priorities, confirm risk appetite, and approve revised accountability.

Output: target recovery design, revised operating model, governance forums, and prioritised backlog.

03

Stabilise

Support mobilisation, remediation delivery, governance routines, issue escalation, KPI reporting, communications, capability building, and operational transition.

Approach: phased implementation with documented acceptance criteria, assurance reviews, and knowledge transfer.

Output: functioning governance practices with clearer ownership and measurable review cadence.

Value propositions

What a Well-Designed Recovery Can Improve

Benefits depend on organisational commitment and implementation quality, but a structured recovery can improve decision clarity, focus, and operational discipline.

A

Clear accountability

Clarify who sponsors, decides, owns, stewards, implements, assures, and accepts risk across governance activities.

P

Practical priorities

Concentrate scarce capacity on material data risks, critical domains, regulatory needs, and business outcomes.

E

Better evidence

Strengthen traceability from policies and decisions to controls, actions, exceptions, reporting, and assurance records.

S

Sustainable operation

Replace temporary recovery activity with repeatable routines, ownership, measures, and capability transfer.

Problems addressed

Why Governance Programs Lose Momentum

Most stalled programs have several interacting causes. Recovery requires separating governance symptoms from the underlying organisational, technical, and decision-making constraints.

Unclear mandate and sponsorship

The program exists, but leaders disagree on its purpose, authority, scope, or expected business value.

Recovery response

Reframe the mandate around explicit outcomes, executive decisions, risk obligations, accountable sponsors, and governance boundaries. Executive participation is essential; consulting cannot substitute for retained accountability.

Committees without decisions

Meetings consume time but do not resolve ownership, approve standards, prioritise issues, or enforce escalation.

Recovery response

Redesign forums, decision rights, quorum, escalation paths, inputs, outputs, and action tracking so each governance body has a defined purpose and measurable contribution.

Tool-led governance

A catalogue, data quality platform, or workflow tool was deployed without ownership, operating processes, adoption planning, or decision integration.

Recovery response

Reconnect technology to governance use cases, roles, workflows, evidence needs, and business adoption. Platform replacement is considered only when justified by capability gaps and cost.

Too much scope, too little capacity

The program attempts enterprise coverage while teams lack dedicated owners, stewards, analysts, engineering support, or change capacity.

Recovery response

Prioritise critical domains and obligations, sequence remediation, define minimum viable governance, and align delivery expectations with available funding and retained capability.

Weak adoption and business relevance

Policies and standards exist, but business teams see governance as administrative overhead rather than support for decisions and operations.

Recovery response

Anchor governance in real decisions, data products, regulatory commitments, customer outcomes, operational pain points, and measurable service expectations.

Identify the real causes before expanding the program

Discuss the current mandate, evidence, stakeholders, control gaps, and recovery priorities.

Request a Consultation
Suitability

Who Governance Program Recovery Service Is For

The service is suitable for organisations that already have a governance initiative, operating model, control requirement, or transformation dependency that needs correction rather than a generic first-time introduction.

Good fit

  • A governance program has stalled, fragmented, or lost executive confidence.
  • Data ownership and stewardship roles exist but are not working consistently.
  • Audit, risk, privacy, or regulatory findings remain unresolved.
  • Governance tooling is underused or disconnected from operating processes.
  • Business and technology teams disagree about priorities or accountability.
  • A merger, cloud program, AI initiative, or platform change depends on stronger governance.
  • Leaders are prepared to provide evidence and make ownership decisions.

May not be the right fit

  • A narrow health check or single control assessment would address the issue.
  • The organisation needs a complete enterprise transformation beyond governance recovery.
  • A software configuration task can be handled directly by the platform vendor.
  • A permanent internal leadership hire is the primary requirement.
  • The need is for licensed legal advice, statutory audit, certification, or penetration testing.
  • Required stakeholders, evidence, or decision authority are unavailable.
  • There is no willingness to retain accountability or implement agreed actions.
Common use cases

Practical Situations Where Recovery Support Is Used

Post-audit remediation

Risk and audit findings show weaknesses in ownership, policy adherence, data quality, access, retention, lineage, or evidence.

Scope: findings, controls, owners
Model: fixed-scope assessment
Deliverables: remediation plan, RACI, evidence map
KPIs: action closure, overdue items, evidence quality

Governance relaunch after leadership change

A new CDO, CIO, or governance leader needs a reliable view of inherited commitments, unresolved issues, and realistic priorities.

Scope: mandate, portfolio, stakeholders
Model: executive advisory
Deliverables: recovery brief, reset plan, decision pack
KPIs: sponsor decisions, ownership coverage, backlog age

Catalogue and stewardship adoption

A governance platform is live, but metadata completion, ownership, issue workflows, and business usage remain inconsistent.

Scope: workflows, roles, adoption
Model: recovery plus implementation
Deliverables: use-case design, operating routines, adoption plan
KPIs: active owners, workflow completion, critical asset coverage

Regulated data-domain recovery

A critical customer, finance, risk, health, or operational domain needs stronger ownership and control evidence.

Scope: domain, obligations, controls
Model: domain pilot
Deliverables: domain governance pack, control matrix
KPIs: issue closure, policy exceptions, control operation

AI readiness dependency

AI initiatives are blocked by poor data ownership, unclear permissions, weak lineage, inconsistent quality, or unresolved privacy concerns.

Scope: priority data, controls, access
Model: assessment and mobilisation
Deliverables: readiness gaps, ownership plan, remediation backlog
KPIs: approved data, lineage coverage, access cycle time

Federated model breakdown

Central and domain teams disagree on standards, funding, authority, shared services, and escalation in a federated governance model.

Scope: central-domain accountabilities
Model: operating-model redesign
Deliverables: decision rights, service model, forum design
KPIs: decision time, standard adoption, unresolved escalations
Capabilities

Governance Recovery Capabilities

Capabilities are grouped around diagnosis, design, remediation, and sustainable operation rather than isolated governance tasks.

Program diagnosis and evidence review

Assess the governance mandate, sponsorship, operating model, decisions, policies, roles, forums, issue management, technology adoption, controls, reporting, and open dependencies.

  • Stakeholder interviews
  • Document review
  • Control evidence
  • Governance maturity
  • Root-cause analysis
  • Risk prioritisation
Operating-model and accountability reset

Redesign governance bodies, data-domain ownership, stewardship, central and federated responsibilities, decision rights, escalation, service expectations, and retained accountabilities.

  • RACI and RAPID models
  • Role charters
  • Council design
  • Domain governance
  • Decision logs
  • Escalation paths
Remediation and implementation

Convert findings into sequenced work packages covering policies, standards, critical data elements, data quality, metadata, lineage, access, retention, master data, workflows, and assurance.

  • Backlog design
  • Control remediation
  • Pilot mobilisation
  • Acceptance criteria
  • Delivery assurance
  • Change support
Measurement and capability transfer

Define operational measures, governance reporting, outcome indicators, review cadence, training, playbooks, communities of practice, and transition arrangements.

  • KPI framework
  • Executive reporting
  • Role-based training
  • Playbooks
  • Knowledge transfer
  • Continuous improvement
Deliverables

Typical Governance Program Recovery Service Deliverables

The final deliverable set is tailored to recovery scope, evidence availability, risk, organisational maturity, and implementation responsibilities.

Representative deliverables and required inputs
DeliverableWhat it includesFormatStageClient inputPrimary owner
Recovery assessmentFailure themes, evidence gaps, maturity, risks, dependencies, and immediate actionsAssessment report and executive summaryDiagnoseDocuments, interviews, systems accessDataConsultant with client validation
Accountability modelSponsors, councils, owners, stewards, delivery, assurance, escalation, and decision rightsRACI/RAPID, role cards, forum chartersResetOrganisation structure and decision-makersClient accountable executive
Prioritised remediation backlogWork packages, risks, dependencies, effort bands, owners, acceptance criteria, and sequencingBacklog and roadmapResetCapacity, funding, risk appetiteJoint program team
Control and evidence mapPolicies, standards, controls, evidence, exceptions, owners, assurance, and review cadenceControl matrixDesignRisk, audit, legal, privacy, security inputClient control owners
Governance operating playbookProcesses, meeting cadence, issue workflow, decision records, service levels, and templatesPlaybook and templatesStabiliseOperating constraints and toolingGovernance lead
KPI and reporting frameworkOperational, adoption, control, quality, and outcome measures with definitions and ownersMetric dictionary and dashboard specificationStabiliseBaselines and reporting environmentGovernance and reporting owners
Capability and transition planSkills, training, communications, handover, retained roles, support model, and improvement cycleTraining and transition packTransitionRole availability and learning needsClient governance leadership

Build a deliverable set around the actual recovery decision

Scope the assessment, operating-model reset, remediation planning, or implementation support required.

Request a Consultation
Delivery process

How DataConsultant Delivers Governance Program Recovery Service

The process is adapted to program condition and urgency. It avoids fixed timeline claims before evidence and stakeholder availability are understood.

Mobilise and align

Objective: confirm mandate, sponsor, scope, decision needs, confidentiality, and working arrangements.

Output: engagement charter and evidence request.

Assess the current program

Objective: review governance design, activity, adoption, technology, controls, risks, and stakeholder experience.

Output: fact base and issue inventory.

Diagnose root causes

Objective: distinguish symptoms from structural, behavioural, technical, and resource constraints.

Output: recovery findings and priority risks.

Reset outcomes and accountability

Objective: define what governance must achieve and who is authorised to decide and deliver.

Output: revised mandate and accountability model.

Design the recovery plan

Objective: sequence containment, quick wins, remediation, operating-model changes, and capability needs.

Output: prioritised roadmap and backlog.

Mobilise remediation

Objective: launch work packages, forums, workflows, controls, reporting, and communications.

Output: active recovery workstream and decision cadence.

Validate operation

Objective: test whether roles, controls, decisions, evidence, and reporting operate as designed.

Output: assurance findings and corrective actions.

Transfer and improve

Objective: embed retained capability, hand over documentation, and establish continuous review.

Output: transition pack and improvement cycle.

Technology and frameworks

Platforms, Standards, and Control References

Technology and frameworks support recovery decisions, but they do not replace accountable governance, business ownership, or operating discipline.

Technology environments

  • Data catalogues and business glossaries
  • Metadata management and lineage platforms
  • Data quality and observability tools
  • Master and reference data platforms
  • Identity, access, privacy, and consent tooling
  • Workflow, ticketing, collaboration, and reporting platforms
  • Cloud data warehouses, lakehouses, integration, BI, and AI environments

Reference frameworks

  • DAMA-DMBOK concepts and data management practices
  • COBIT governance and management objectives
  • DCAM or equivalent capability assessment references
  • ISO 27001 and related information security controls
  • ISO 8000 data quality concepts
  • NIST risk and cybersecurity references where relevant
  • Enterprise architecture, service management, and internal control frameworks

Regulatory considerations

  • Applicable privacy and data protection obligations
  • Sector-specific governance, records, risk, and reporting duties
  • Data residency and cross-border transfer requirements
  • Third-party, outsourcing, and supplier obligations
  • Retention, legal hold, deletion, and information lifecycle
  • Auditability, traceability, and control evidence
  • Legal and regulatory interpretation by authorised specialists

Connect governance recovery to the real technology estate

Review existing platforms, workflows, controls, integration points, and evidence before considering replacement.

Request a Consultation
Engagement models

Ways to Structure Governance Recovery Support

Engagement options
ModelBest suited toTypical scopeCommercial approachClient responsibility
Focused recovery assessmentLeaders needing an independent fact baseEvidence review, interviews, diagnosis, findings, priority actionsFixed scope where inputs are definedAccess, evidence, stakeholder participation, decisions
Recovery design sprintPrograms with known issues but unclear reset designMandate, accountability, forums, controls, backlog, roadmapFixed scope or capped time-and-materialsExecutive validation and approval
Implementation supportTeams needing hands-on mobilisation and remediationWorkstream setup, artefacts, controls, workflows, assurance, reportingTime-and-materials or milestone-basedRetained ownership and delivery capacity
Embedded governance specialistsOrganisations with temporary capability gapsGovernance lead, analyst, steward support, PMO, control coordinationDedicated capacityDirection, access, supervision, acceptance
Managed governance operationsMature organisations seeking ongoing supportDefined governance services, reporting, issue coordination, continual improvementService-based recurring arrangementPolicy, accountability, risk acceptance, strategic decisions
Capability buildingTeams preparing to operate independentlyRole training, playbooks, coaching, communities, transitionWorkshop or program-basedAttendance, practice, leadership reinforcement
Illustrative examples

How Recovery Decisions May Be Structured

These examples are representative decision patterns, not claims about a specific client or guaranteed outcome.

Example A

Reset a weak ownership model

Situation: data owners are named but lack authority, time, decision rights, and supporting stewards.

Recovery decision: reduce the initial domain scope, assign accountable executives, define owner decisions, provide steward capacity, and connect unresolved issues to escalation forums.

Evidence: approved role cards, meeting decisions, active backlog, owner participation, and issue closure records.

Example B

Recover an underused catalogue

Situation: a metadata platform contains technical assets but has limited business context, workflow adoption, or decision value.

Recovery decision: prioritise critical data products, define minimum metadata, connect ownership and issue workflows, and establish adoption measures.

Evidence: active ownership, critical asset coverage, completed workflows, user feedback, and governance decisions supported.

Example C

Close persistent audit actions

Situation: remediation actions remain open because ownership, evidence standards, and dependencies are unclear.

Recovery decision: map each finding to accountable owners, controls, evidence, dependencies, acceptance criteria, and assurance review.

Evidence: approved action plan, documented control operation, evidence repository, and formal closure decisions.

Example D

Stabilise federated governance

Situation: central and domain teams duplicate work and dispute standards, funding, and escalation.

Recovery decision: define central services, domain accountabilities, mandatory standards, local flexibility, funding expectations, and exception handling.

Evidence: service catalogue, decision-rights map, adopted standards, tracked exceptions, and domain reporting.

Outcomes and KPIs

How Governance Recovery Can Be Measured

Measures should combine operation, adoption, control, quality, and business relevance. Baselines, ownership, data sources, and attribution limits should be documented.

AccountabilityCritical domains with approved owners and active stewards
Decision effectivenessGovernance decisions completed within agreed service expectations
RemediationPriority actions closed with accepted evidence
Control operationRequired controls operating and reviewed as scheduled
AdoptionActive use of governance workflows, standards, and platforms
Data qualityCritical issues resolved, recurring issues reduced, and ownership established
Metadata and lineagePriority assets with sufficient context, ownership, and traceability
Risk visibilityMaterial data risks, exceptions, and dependencies reported consistently
CapabilityRetained teams able to operate governance routines independently
Pricing and cost factors

What Influences Governance Program Recovery Service Cost?

A reliable estimate requires initial scoping. Cost is shaped by the condition of the existing program, the breadth of evidence, and whether support stops at assessment or continues through implementation.

1

Scope and complexity

Number of business units, data domains, legal entities, jurisdictions, platforms, policies, controls, and governance bodies.

2

Evidence and stakeholder access

Availability and quality of documents, metrics, issue logs, platform data, audit evidence, and accountable stakeholders.

3

Recovery depth

Assessment only, operating-model redesign, detailed remediation planning, implementation support, managed operation, or capability building.

4

Risk and regulatory review

Sector obligations, privacy, security, records, residency, outsourcing, third-party, audit, and legal review dependencies.

5

Technology involvement

Platform configuration, workflow design, integration, reporting, metadata migration, data quality rules, and vendor coordination.

6

Delivery model

Remote or onsite work, fixed scope, time-and-materials, dedicated specialists, milestone support, or recurring managed service.

Request a scope-based estimate

Share the program condition, critical issues, target decisions, stakeholders, and expected implementation support.

Request a Consultation
Why consider DataConsultant

Recovery Support Designed for Decisions and Operation

DataConsultant combines data governance, operating-model, control, technology, delivery, and capability-building perspectives while documenting assumptions and responsibility boundaries.

I

Independent diagnosis

Review program evidence and stakeholder experience without assuming the original design, current toolset, or existing backlog is correct.

B

Business and control alignment

Connect governance work to operating decisions, material risk, regulatory needs, data products, and measurable service outcomes.

D

Documented delivery

Record findings, assumptions, exclusions, dependencies, ownership, acceptance criteria, and decisions for transparent review.

F

Flexible support

Use focused assessment, advisory, implementation assistance, embedded specialists, managed support, or capability transfer.

Discuss the recovery decision, not just the symptoms

Review whether you need diagnosis, a governance reset, remediation mobilisation, or ongoing operating support.

Request a Consultation
Security, quality, privacy, and compliance

Assurance Considerations in Governance Recovery

Recovery design should reflect the organisation’s obligations, information sensitivity, risk appetite, contractual commitments, and assurance model.

Information security

Review classification, access governance, privileged access, segregation, encryption, logging, incident handling, supplier access, evidence protection, and secure collaboration requirements.

Privacy and data lifecycle

Consider purpose, lawful use, minimisation, consent where relevant, retention, deletion, residency, data-subject rights, sensitive data, and privacy-by-design responsibilities.

Data quality and integrity

Define critical data, rules, ownership, monitoring, thresholds, issue workflow, root-cause analysis, remediation, exceptions, and evidence of control operation.

Compliance and assurance

Map internal policies, legal obligations, sector rules, contracts, audit commitments, control testing, evidence standards, third-party dependencies, and required specialist review.

This service does not replace licensed legal advice, statutory audit, formal certification, or specialist cybersecurity testing unless separately commissioned from appropriately authorised providers.

Delivery environment

Working Across the Governance Technology Ecosystem

Recovery work can be delivered alongside internal teams, platform vendors, systems integrators, managed-service providers, risk functions, legal advisers, auditors, and specialist security providers.

Existing platforms first

Assess whether current catalogues, quality tools, lineage systems, workflows, and reporting environments can support the target operating model before recommending replacement.

Vendor-neutral decisions

Separate governance requirements from product features, licensing constraints, implementation quality, integration dependencies, and operating cost.

Clear delivery boundaries

Document what DataConsultant advises, designs, configures, coordinates, validates, or operates, and what remains with the client or another provider.

Customer perspectives

Representative Governance Program Recovery Service Feedback

The following service-specific testimonials are representative examples of the experience organisations may value. They do not assert verified client identities or measurable results.

★★★★★
“The recovery assessment gave us a disciplined view of why our governance program had stalled. The team separated structural issues from symptoms, handled stakeholder interviews professionally, and produced a prioritised plan that our executive sponsors could review and challenge.”
Chief Data OfficerFinancial services
★★★★★
“We needed more than another policy refresh. The engagement clarified decision rights, council responsibilities, domain ownership, and escalation paths. Communication remained clear throughout, and revisions were handled carefully when internal accountabilities changed.”
Director of Data GovernanceHealthcare
★★★★★
“Our catalogue program had become disconnected from business use. The consultants helped us focus on critical assets, ownership workflows, practical metadata requirements, and adoption measures without assuming that the platform itself needed replacing.”
Enterprise Data ArchitectManufacturing
★★★★★
“The remediation backlog was practical and transparent. It showed dependencies, evidence requirements, accountable owners, and acceptance criteria, which made it easier for risk, technology, and operations teams to coordinate their work.”
Head of Operational RiskRetail banking
★★★★★
“The team worked constructively with our existing governance lead and delivery partners. They documented limitations, avoided unrealistic promises, and supported the transition from recovery activity into a repeatable operating cadence.”
Transformation Programme DirectorPublic sector
★★★★★
“The capability-building support was especially useful. Role-based sessions, playbooks, decision templates, and coaching helped our domain teams understand what governance required in practice rather than treating it as a central compliance exercise.”
VP, Data and AnalyticsTechnology services
Frequently asked questions

Governance Program Recovery Service FAQs

What is governance program recovery?

Governance program recovery is a structured intervention that diagnoses why a data governance program has stalled or lost credibility, resets scope and accountability, prioritises remediation, and establishes a practical route to sustainable operation.

When should an organisation consider governance program recovery?

Common triggers include low adoption, unclear ownership, unresolved audit findings, excessive committees, weak data quality outcomes, repeated policy exceptions, tool-led activity without operating change, or a program that has stopped delivering visible business value.

Who should sponsor the recovery?

An accountable executive such as a chief data officer, CIO, CTO, COO, risk leader, or transformation sponsor should normally own the decision. Effective recovery also requires participation from business-domain leaders, governance teams, architecture, security, privacy, compliance, internal audit, operations, and delivery teams.

What is included in the recovery assessment?

The assessment can review mandate, sponsorship, governance bodies, decision rights, data ownership, stewardship, policies, standards, issue management, controls, audit findings, technology use, adoption, reporting, capability, funding, dependencies, and stakeholder confidence.

What deliverables are typically included?

Typical deliverables include a recovery assessment, stakeholder and decision-rights map, issue and dependency register, prioritised remediation backlog, revised operating model, governance forums, role definitions, control framework, implementation roadmap, KPI set, communications plan, and transition pack.

How long does governance program recovery take?

There is no reliable fixed duration before discovery. Timing depends on program scope, stakeholder access, evidence quality, number of domains and jurisdictions, risk and regulatory complexity, review cycles, and whether the engagement includes implementation and operational transition.

How is governance program recovery priced?

Pricing depends on program scope, organisation size, number of domains and jurisdictions, stakeholder access, evidence quality, technology complexity, remediation depth, implementation support, and the selected engagement model. A written estimate can be prepared after initial scoping.

Can DataConsultant work with an existing governance platform?

Yes. The recovery can assess and improve operating processes around existing catalogues, data quality tools, lineage platforms, workflow systems, ticketing tools, collaboration platforms, and reporting environments without assuming replacement is necessary.

Can the engagement focus on one data domain or regulatory issue?

Yes. A focused domain, business unit, legal entity, control area, audit finding, platform workflow, or regulatory obligation can be used as a recovery pilot when broader enterprise scope would be premature or impractical.

Can DataConsultant help implement the recovery plan?

Yes. Implementation support can include mobilisation, backlog management, operating-model setup, governance forums, role enablement, control design, workflow configuration, delivery assurance, KPI reporting, communications, training, and operational transition.

How are outcomes measured?

Measures can include accountable owner coverage, decision turnaround, action closure, control operation, policy exceptions, platform adoption, critical metadata coverage, issue age, data quality remediation, stakeholder participation, and retained team capability. Baselines and attribution limits should be documented.

What information does DataConsultant need from the client?

Useful inputs include program charters, organisation charts, policies, standards, role descriptions, forum terms, meeting records, issue and risk logs, audit findings, platform reports, data quality results, architecture information, vendor contracts, budgets, delivery plans, and access to accountable stakeholders.

Does the service replace legal advice or statutory audit?

No. The service can identify governance, privacy, security, regulatory, and evidence considerations, but it does not replace licensed legal advice, statutory audit, formal certification, or specialist cybersecurity testing unless separately commissioned from authorised providers.

Can DataConsultant work with internal teams and other suppliers?

Yes. The engagement can work alongside internal governance, data, technology, risk, privacy, security, compliance, audit, operations, and change teams, plus platform vendors, systems integrators, managed-service providers, and specialist advisers. Responsibilities and decision boundaries should be agreed at mobilisation.