A-01due M1
Microsoft Entra identities can govern platform and consumption access.
- Owner
- CISO delegate
- Closure evidence
- Identity architecture and test-user access matrix approved

Control register · AR-001
Statements not supported by current evidence are tracked as assumptions, not facts. Each must close with named evidence before its dependent production gate.
Assumption log
| ID | Assumption | Owner | Due | Closure evidence |
|---|---|---|---|---|
| A-01 | Microsoft Entra identities can govern platform and consumption access. | CISO delegate | M1 | Identity architecture and test-user access matrix approved |
| A-02 | SAP, GIS and HEAT permit non-disruptive read-only extraction. | Application owners | M1 | Timed extraction tests and source-load evidence |
| A-03 | Customer, premise and asset keys can be linked at an acceptable match rate. | Data governance lead | M2 | Profiled match, duplicate and unresolved rates by GA |
| A-04 | Power BI is the governed executive analytics channel. | CIO delegate | M1 | Tooling and licence position confirmed |
| A-05 | Business teams can retain control cohorts during pilots. | Value owners | M2 | Signed pilot protocol and baseline extract |
Technical risk register
| ID | Rating | Risk | Mitigation / control | Owner | Status |
|---|---|---|---|---|---|
| R-01 | Critical | SAP extraction affects source performance or misses deltas | Benchmark extractor; bounded windows; control totals; replayable checkpoint | SAP owner | Open |
| R-02 | High | THINK ONE releases consume SMEs and change windows | Ring-fence read-only discovery; blackout calendar; sponsor resolves collisions | Programme director | Open |
| R-03 | High | Customer identity mismatch contaminates cross-system measures | Deterministic first; steward queue; no automatic destructive merge | Data governance lead | Open |
| R-04 | Critical | Company Brain exposes restricted customer or employee data | Policy before retrieval; row/column controls; red-team tests; immutable audit | CISO delegate | Open |
| R-05 | High | SCADA connectivity creates an IT/OT boundary risk | One-way approved export; no control-path connectivity; security architecture review | OT security owner | Open |
| R-06 | High | Fabric capacity or concurrency fails production SLOs | Representative benchmark; workload isolation; cost and throttling telemetry | Platform lead | Open |
| R-07 | Medium | AI pilots report activity rather than attributable value | Retained baseline; accepted action log; Finance-approved value formula | CFO delegate | Open |
| R-08 | High | Model or retrieval quality degrades after release | Versioned evaluation set; drift alerts; kill switch; manual fallback | AI product lead | Open |
Escalation rule
Any Critical risk without tested mitigation blocks the related release. High risks require accountable-owner acceptance and a dated closure action.