Search the practice set

275 questions, 991 terms and 600 topics in 30 areas.

60 results for “Exit & Concentration Risk”

Terminology · 24
term

Provider Exit Plan

A documented and tested plan for moving a workload off a provider, whose credibility is measured by what has actually been rehearsed rather than described.

Exit & Concentration Risk
term

Capital One's Data Centre Exit

A major US bank closed all eight of its data centres and moved fully to public cloud, treating governance automation as the enabling technology rather than a constraint.

Enterprise Architecture
term

Cloud Exit Plan

A documented, costed assessment of what leaving a provider or service would require — increasingly a regulatory expectation and a better lock-in control than portability itself.

Multi-Cloud
term

Fourth Party Risk

The dependencies of your dependencies, which you did not choose, may not know about, and remain accountable for.

Third-Party Risk
term

Licence Metric Risk

The exposure created when a software licence is priced on a unit that cloud architecture changes unpredictably, such as cores, sockets or instances.

Licence & Vendor Costs
term

Migration Risk Register

A maintained record of what could go wrong in a migration, with likelihood, impact, owner and mitigation, reviewed as the programme progresses.

Migration Risk
term

Quantified Risk Estimate

Expressing a risk as a probability distribution over financial loss rather than as a colour, which makes risks comparable and mitigations arguable on cost.

Risk Assessment Methods
term

Re-Identification Risk

The probability that pseudonymised data can be linked back to individuals, which is what keeps such data within the scope of data protection law.

Pseudonymisation
term

Risk Tolerance Statement

The board-level declaration of how much of each risk type the organisation will accept, which is what tells an architect which risks may be accepted without escalation.

Risk Appetite
term

Use Case Risk Classification

Assigning an AI application to a risk tier based on the consequence of it being wrong, which then determines the obligations that apply.

AI Risk Tiering
term

Assurance Map

A single view of which risks are covered by which assurance activity, exposing both the gaps nobody is looking at and the duplication several parties are paying for.

Assurance, Audit & Model Risk
term

Attack Surface

The complete set of points where an untrusted actor can interact with a system — and the quantity that reduction genuinely reduces risk.

Threat Modelling
term

Business Case Structure

The argument format that gets technical investment funded — problem, options, quantified benefit, cost, risk and a recommendation.

Business Cases
term

Canary Release

Routing a small fraction of traffic to a new version, watching its metrics, and expanding or rolling back based on what they show.

Software Architecture
term

Capability Heat Map

A capability map coloured by a chosen dimension — maturity, cost, risk, or strategic importance — to make patterns visible to non-technical stakeholders.

Capability Mapping
term

Commitment Coverage

The proportion of steady-state usage covered by discounted commitments, balanced against the risk of committing to capacity that is no longer needed.

Reserved & Committed Capacity
term

Database Migration Strategy

The approach for moving data to a new store, which is usually the longest pole and the highest risk in any modernisation.

Database Migration
term

Decision-Making Under Uncertainty

Choosing well when the information is incomplete — by bounding the downside and buying information, rather than by waiting for certainty.

Meta-Skills
term

Degradation Mode

A defined, intentional reduced state of service that the system enters under specified conditions, with known behaviour and known exit criteria.

Degradation Modes
term

Legacy System Assessment

A structured evaluation of a system's business value, technical condition and risk, used to decide what to do with it rather than to describe it.

Legacy Assessment
term

Lift and Shift

Moving an application to new infrastructure with minimal change, trading optimisation for speed and low migration risk.

Rehosting
term

Model Inventory

A complete register of models in use with their purpose, owner, risk tier and validation status — the artifact everything else in model governance depends on.

Model Risk Management
term

Parallel Run

Running the old and new systems side by side on the same inputs and comparing outputs, before the new one is trusted.

Legacy Modernization
term

Pre-Mortem

An exercise in which a team imagines a project has already failed and explains why, surfacing risks that a forward-looking risk assessment misses.

Failure Thinking
Questions · 9
quiz

A regulator asks for evidence that your exit plan from your primary cloud provider is credible. The plan is a twelve-page document. What will they find, and what should you do?

What they will find A document describing an intention. Supervisors have moved from accepting exit plans to asking what has been tested, precisely because most

Exit & Concentration Risk
quiz

A CDC pipeline feeding your warehouse falls three hours behind during a source system's batch job, and the source's transaction log retention is 24 hours. What is the risk and what do you change?

The immediate risk Lag consumes the retention window. At three hours behind against a 24 hour retention, you have 21 hours of margin. If the consumer stops enti

CDC Pipeline Design
quiz

You inherit an estate of roughly 400 applications, no reliable inventory, and a mandate to reduce cost and risk. What do you do in the first ninety days?

What the interviewer is testing Whether you can sequence work at portfolio scale, and whether you go for evidence before strategy. This is the enterprise archit

Enterprise Architecture
quiz

A 15-year-old monolith runs the core of the business. Leadership wants microservices. How do you approach it, and what would make you refuse?

What the interviewer is testing Whether you start from the business problem or from the target architecture, and whether you are willing to say no. First, estab

Legacy Modernization
quiz

A deployed model performed well in validation and its business metric has declined over four months. Nothing has been deployed. What do you investigate?

The model did not change; its world did Three distinct causes, and they need different responses: Data drift. The input distribution has moved — a new customer

Model Risk Management
quiz

A team proposes rewriting a critical system from scratch, arguing the existing one is unmaintainable. How do you evaluate this?

Test the diagnosis before the prescription "Unmaintainable" usually means one of several different things, and they have different remedies: Nobody understands

Refactoring & Re-architecting
quiz

A twenty-year-old core system supports most of the business. It is on unsupported technology, three people understand it, and the last replacement attempt was abandoned after two years. Design the programme.

Learn from the abandoned attempt first The most important input is why the last one failed, and the reasons are usually structural rather than technical: a big

Legacy Assessment
quiz

A vendor SaaS product embeds a model that scores customers, and its output drives an automated decision in your process. Your model governance framework covers models you build. What do you do?

The obligation does not transfer with the outsourcing You are accountable for the decision. That the scoring is performed by a vendor changes who operates the m

Model Risk Management
quiz

Finance wants a three-year commitment on cloud spend for the discount. Engineering is nervous. How do you advise?

Commit to the floor, not to the forecast The safe commitment is the portion of usage that will exist regardless of what happens: the steady baseline, evidenced

Reserved & Committed Capacity
Topics · 26
topic

Exit & Concentration Risk

Being able to leave a provider, and what the regulator asks when you cannot.

3 items
topic

AI Risk Tiering

Classifying a use case by potential harm, and the obligations each tier triggers.

3 items
topic

Assurance, Audit & Model Risk

General material on assurance, architectural governance and risk oversight.

2 items
topic

Migration Risk

Bounding blast radius, staging by cohort, and honest readiness reporting.

3 items
topic

Model Risk Management

Inventory, validation, monitoring and challenge for models that make consequential decisions.

4 items
topic

Risk Appetite

The stated tolerance that tells you which risks you are allowed to accept.

2 items
topic

Risk Assessment Methods

Qualitative matrices, FAIR and scenario analysis, and the illusion of a precise score.

2 items
topic

Third-Party Risk

Assessing, contracting and monitoring the vendors your architecture now depends on.

2 items
topic

Architecture Compliance Checks

Automating conformance to standards so review effort goes to the genuinely novel.

2 items
topic

Audit Evidence

Producing durable, tamper-evident proof as a by-product rather than as a project.

3 items
topic

Bias & Fairness Controls

Measuring disparate outcomes, choosing a fairness definition, and living with the trade-off.

2 items
topic

Build vs Buy

Differentiation, five-year TCO, and the exit cost of each option.

3 items
topic

Certification Impact on Architecture

What SOC 2 and ISO 27001 actually require of a design, and what they do not.

3 items
topic

Change Advisory vs Automated Gates

Replacing a weekly board with evidence a machine produces on every change.

2 items
topic

Change Data Capture

Turning a database's replication log into a stream, and its coupling risk.

7 items
topic

Communicating Threat Models

Making risk legible to people who will fund or accept it.

2 items
topic

Continuous Controls Monitoring

Testing controls continuously instead of sampling them once a year.

3 items
topic

Control Design vs Operation

A control that is well designed and never runs fails exactly like one that is absent.

2 items
topic

Design Authority

How an ARB should decide, what it should not review, and how it avoids becoming a queue.

3 items
topic

Exception & Waiver Management

Time-boxed, owned deviations with a remediation date, rather than permanent silence.

3 items
topic

Human-in-the-Loop Design

Meaningful review rather than a rubber stamp, and designing against automation bias.

2 items
topic

Mainframe Modernization

Batch windows, COBOL, and the risk profile of core banking systems.

3 items
topic

Model Documentation

Model cards, intended use, limitations, and the record a regulator will ask for.

2 items
topic

Model Evaluation & Red-Teaming

Adversarial testing of a probabilistic system with no fixed expected output.

2 items
topic

Modernisation Business Case

Pricing tail risk so deferred maintenance becomes fundable.

3 items
topic

OWASP Risks

The recurring web and API risk classes, several of which are design flaws.

2 items