advanced 2 min answer

A regulator asks a financial institution to demonstrate it could exit its cloud provider. What must exist, and what makes the answer credible?

druvaexit-planconcentrationportabilityregulator
Show the full answer Hide the answer

What must exist

  • A documented exit plan naming what would move, to where, in what sequence, over what period, with the dependencies identified.
  • An assessment of what is genuinely portable and what is not, honestly — managed services with no equivalent elsewhere are the hard part, and pretending otherwise produces a plan that fails on contact.
  • Data extractable in a usable format, with the extraction tested rather than assumed. A provider's export capability is a claim until someone has exported and re-imported at production scale.
  • A time estimate derived from the data volume and the extraction throughput, since the arithmetic is available and is frequently much longer than the plan states.
  • Backups in a second provider, which is the cheapest meaningful mitigation and covers the scenario of an account-level event.

What makes the answer credible

Evidence rather than a document. A rehearsed partial exit — one workload actually moved, or a full data extraction and validation performed — is what distinguishes a plan from an aspiration, and it is what a regulator increasingly asks for.

A plan that has never been exercised is a plan whose assumptions are untested, and the assumptions are where these plans fail.

What is usually over-claimed

"We are portable because we use containers." Containers move; the managed database, the identity integration, the queue semantics, the networking model and the operational tooling do not — and those are where the effort is.

The proportionate architectural response

Not multi-cloud active-active, which is very expensive and requires operating everything yourself, thereby returning the operational burden the cloud removed.

The pragmatic middle: single cloud for the running system, portable-by-default choices where they are cheap, provider-specific features kept at the edges, a rehearsed extraction capability, and backups elsewhere. That addresses concentration risk without paying for an architecture whose failover path would be broken anyway.

The framing for the regulator

Concentration risk is about the consequence of unavailability and the ability to recover, not about using one provider. An institution that can demonstrate its recovery capability and its exit path has answered the question; one that has multi-cloud infrastructure and an untested failover has not.