ISS-001Audit findingHighIn progress
Tier-1 cloud provider exit plan is stale and untested
1 of 2 action plans are still open. An issue can only be closed once all its action plans close.
Description
The exit and substitutability plan for our primary cloud provider is more than 12 months old and has never been operationally tested. This was raised as a minor non-conformity at the ISO 27001 surveillance audit and reinforces our outside-appetite concentration risk.
Action-plan SLA
Plans required by
20 Nov 2025
Action plans
2AP-001Refresh and board-approve the Tier-1 cloud exit plan
Closed100%
MA Marcus AllenTarget 31 Mar 2026
AP-002Run a substitutability test for the primary cloud provider
Overdue45%
SL Sophie LindqvistTarget 30 Jun 2026
What this issue addresses
Audit findings
Tier-1 cloud provider exit plan is stale and untested
F-001 · External Audit — ISO 27001 Surveillance 2025
Control gaps
Critical third-party register review
C-022
Risks mitigated
Critical ICT third-party concentration
R-001 · residual
Requirements
DORA Art. 28(1)