Cloud & vendorsInvestigate the responsibilities behind a cloud or supplier arrangement
Research hosting, outsourcing, data access, subcontracting, and exit arrangements for a proposed service. Connect the questions to the customer's industry and the locations involved.
Data handlingFollow data access, retention, and transfers through the system
Explore regulatory requirements around collection, access, reuse, storage, deletion, and international transfers. Use a defined data flow to prepare a practical discussion with privacy and security owners.
AI deploymentExamine the duties raised by an internal or customer-facing AI tool
Investigate the roles and duties associated with adopting or providing an AI system. Include its business purpose, affected people, inputs, supplier relationship, and proposed oversight in the research.
Incident responseIdentify the facts that determine an incident's reporting requirements
Examine notification requirements for a described security or service incident. Identify which facts determine the relevant authority, reporting threshold, and timing for the responsible specialists to assess.
ResilienceConnect critical service dependencies with operational resilience duties
Research continuity, third-party, and operational-resilience requirements for the business service. Draft questions about critical dependencies, recovery arrangements, testing, and the evidence an owner should retain.
Change managementReassess the regulatory assumptions when systems or suppliers change
Explore a migration, new integration, vendor switch, or expanded data use before rollout. Summarize affected assumptions and regulatory questions for the people approving the technology change.