| 01Boundary and data flow | Service purpose, users, geography, data categories, access paths, critical dependencies, subprocessors, and material fourth parties. | Confirm the boundary with the procurement, service, security, and supplier owners; reconcile the service description with the proposed relationship. | Scope state, accountable owner, source date, and review trigger. | A generic architecture diagram or supplier description is not a complete boundary. |
| 02Control and incident posture | Current control summary, independent reports where applicable, incident route, notification terms, logging context, and unresolved exceptions. | Check provenance, coverage period, applicability, exclusions, exceptions, and whether the evidence addresses the actual service rather than the supplier generally. | Evidence state, provenance, confidence, limitation, and owner question. | A questionnaire answer or marketing claim is not independent assurance. |
| 03Access and third parties | Privileged access model, identity controls, support access, subprocessor or fourth-party register, segregation, monitoring, and review cadence. | Map who can access what, why access is needed, how it is approved, and how the relationship changes when the contract or service changes. | Access/data map, open gap, accountable owner, and decision condition. | Do not request secrets, private keys, credentials, or unnecessary customer records. |
| 04Continuity and exit | Critical-service dependencies, recovery assumptions, RTO/RPO context, tested recovery, portability, exit assistance, concentration, and substitution assumptions. | Tie continuity claims to an exercise, restore, or other permitted evidence; inspect dependencies and contract conditions that could affect exit or recovery. | Observed result, unresolved dependency, treatment action, and next test or review date. | A documented plan without an observed test is not proof of recovery. |
| 05Findings and exceptions | Open findings, risk acceptances, compensating controls, remediation commitments, material incidents, and overdue actions relevant to the service. | Check scope, owner, date, severity, residual risk, evidence quality, and the trigger that would cause escalation or re-review. | Action record, confidence, acceptance authority, due date, and escalation path. | Absence of supplied evidence is not evidence of a clean result. |
| 06Acceptance gate | The conditions, limitations, decisions, and follow-up work required from procurement, security, legal, continuity, service, and risk owners. | Record what is accepted, conditioned, deferred, escalated, or declined; identify the owner and the date or event that reopens the question. | Decision, accountable owner, residual-risk treatment, and revisit date. | ZeroDev does not approve a supplier, provide legal advice, or accept residual risk for the customer. |