Governance and data
Data ownership, classification, location requirements, retention, authorized access, privacy obligations,
and audit needs.
Security and identity
Authentication, role-based access, administrative access, network controls, vulnerability
responsibilities, and incident coordination.
Integration and migration
Source systems, interfaces, data quality, migration cycles, ownership, dependencies, reconciliation, and
cutover.
Availability and continuity
Operating windows, maintenance, monitoring, backup, recovery, escalation, and institution-specific
continuity expectations.
Support and change
Support hours, severity definitions, escalation paths, release coordination, testing responsibilities,
and change approval.
Environment readiness
Capacity, supported platforms, network access, certificates, DNS, email delivery, browser/device
requirements, and administrative contacts.