01
Programme Framework
Lifecycle · governance · accountability · audit
02
Inherent Risk Tiering
Live JS · 7-axis · critical / significant / standard
03
Planning
Business case · alternatives · build-vs-buy · concentration check
04
Due Diligence
Tier-matched DD · financial · operational · legal · security
05
Contract Clauses
Right-to-audit · sub-processor · data · exit · BCP · indemnity
06
Onboarding
Access provisioning · integration testing · go-live attestation
07
Ongoing Monitoring
SLA · KPI · KRI · adverse-media · re-DD cadence
08
Concentration Risk
By function · by sub-processor · by jurisdiction · by single-point-of-failure
09
Sub-Processor Governance
N-th party visibility · approval · change notification
10
Incident Response
Vendor breach · escalation · regulator notification · customer comms
11
Exit Playbook
Voluntary · forced · contingency · data return · transition assurance
12
Board Reporting
Quarterly · concentration · critical-vendor scorecard · incident summary
13
Committee Charter
CCO chair · cross-functional · cadence · authority