Cloud Infrastructure
Hosting, storage, compute, databases, networking, backup and observability dependencies.
DataConsultant considers the role, access, information use and operational importance of third-party platforms, providers, tools and specialists before they support data consulting and Data & AI delivery. Review and approval are proportionate to the service, information, access, risk, contract and client requirements involved.
Third-party dependencies can affect information handling, system access, resilience, legal obligations, client commitments and the ability to transition or exit cleanly. A one-time questionnaire alone is not enough to understand those dependencies.
Vendor governance should make the intended purpose, review decision, conditions and ownership visible before access expands.
Share the engagement context, provider role and due-diligence question so the Trust Team can route the request appropriately.
Submit a Vendor Risk QuestionExternal services can support delivery, but their roles are not interchangeable. Review should focus on what the provider does, what it can access, how important it is to delivery and which client or contractual conditions apply.
Hosting, storage, compute, databases, networking, backup and observability dependencies.
Collaboration, analytics, development, communication, documentation and project tools.
External experts or delivery partners used for defined skills, capacity or project needs.
Libraries, frameworks, packages, models and utilities with licence and maintenance considerations.
APIs, connectors, data platforms, enrichment services and operational integrations.
Legal, finance, communications or operational providers supporting business administration.
The lifecycle makes ownership and decision points visible throughout the relationship. The precise evidence and controls depend on risk, engagement scope and the provider’s role.
Define purpose, service, information, access, criticality, geography and engagement context.
Review relevant security, privacy, legal, technical, operational and service-delivery factors.
Document appropriate confidentiality, processing, access, notification, cooperation and exit terms.
Record the decision, assign ownership, provision necessary access and communicate conditions.
Review material changes, incidents, dependency shifts, scope expansion and relevant risk indicators.
Remove access, address return or deletion, confirm handover and retain appropriate closure records.
This matrix illustrates how review emphasis may change with context. It is not a fixed scoring model, a set of universal thresholds or a statement that every control applies to every provider.
| Provider context | Typical situation | Primary review emphasis | Possible decision condition |
|---|---|---|---|
| Limited information | Administrative or productivity service with no planned client-data use | Purpose, account security, terms, continuity and data-use restrictions | Approved for a defined purpose with restricted information use |
| Client data involved | Analytics, cloud, integration or collaboration service processing engagement data | Security, privacy, data roles, access, location, downstream providers, retention and incident terms | Approval subject to contractual, technical, privacy and client requirements |
| Privileged access | Specialist requiring controlled access to a client or delivery environment | Identity, least privilege, supervision, confidentiality, activity boundaries and offboarding | Time-bound, authorised access with defined ownership and removal steps |
| Critical dependency | Provider supporting core hosting, data pipelines, operational reporting or managed delivery | Resilience, support, concentration, portability, exit, material change and continuity impact | Documented dependency plan with appropriate continuity or transition measures |
Contract terms should reflect the provider’s role and risk. Written obligations do not replace technical controls, client approvals or day-to-day operational ownership.
Consider workload, information categories, administration model, identity options, hosting location, resilience, downstream dependencies, portability and exit feasibility.
Consider source, licence obligations, maintenance, dependencies, known security concerns, update path, replacement feasibility and client restrictions.
Consider role suitability, engagement boundaries, confidentiality, need-to-know access, supervision, quality accountability and timely access removal.
Confirm the processing role, approved purposes, locations, transfers, downstream use, contractual flow-downs and client notice or approval requirements where relevant.
Use the Trust Documents area to understand what information may be public, available on request, restricted or engagement-specific.
Review Trust DocumentsMaterial changes can alter whether a provider remains suitable for its approved purpose. Monitoring is risk-based; it does not imply continuous surveillance of every provider or guarantee that every provider change will be identified immediately.
Effective vendor governance depends on clear ownership between DataConsultant, the client and the external provider. Control responsibility follows the environment, access model, contract and service role.
Subject to engagement relevance, availability, approval and confidentiality restrictions, the Trust Team may help coordinate information such as:
Use related Trust Center pages to examine the security, privacy, resilience, compliance and AI-governance context around third-party use.
Answers for procurement, legal, privacy, security, technical and operational stakeholders reviewing third-party dependencies.
For an engagement-specific vendor assessment, security questionnaire, sub-processor question or procurement review, provide the proposed service, provider role, relevant data or access context and the decision your team needs to support.