← Stage-Gate NPD Suite Vendor & SaaS Management

Vendor Management Plan — Version 1.2

Download Word
Program timeline · status 16 Oct 2026Read the full story →
Harborline
Aug 2025
Cancelled
Gate 0
Feb 2026
Go
Stage 1
Business case
Gate 1
Apr 2026
Recycled
Gate 1
Jun 2026
Go w/ conditions
Stage 2
Development
You are here
Gate 2
Apr 2027
Gate 3
Oct 2027
Gate 4
Feb 2028
Launch
Mar 2028
Gate 5
Sep 2028

Lighthouse Financial Services Company — This plan governs how the Beacon Index Advantage product development program engages, contracts, funds, and manages its external vendors. In a stage-gate program the vendor problem has a shape the vendors themselves rarely see: the program cannot commit to buy scope that a future gate may decline to fund. Stages 3 and 4 — $7,450,000 and $4,330,000 — are not authorized money today, and a gate can send the program backward or stop it. So the governing move of this plan is to decompose every multi-stage engagement into gate-authorized work packages, each released only when the gate that funds its stage says so.

Status at the date of this version. Program is in Stage 2 — Development, week 17 of 40. Of the $27,904,000 authorized program cost, $14,232,000 has been released; the external, contracted spend this plan governs sits inside the $7,620,000 non-labor budget. Only work packages tied to Stage 1 and Stage 2 are under contract; Stage 3 and Stage 4 vendor scope is authorized by release notice at its gate. Status date 16 October 2026.

Table of Contents

  1. Purpose & the Stage-Gate Vendor Problem
  2. Vendor Inventory & Criticality
  3. Gate-Authorized Work Packages — the Release-Notice Model
  4. Vendor Selection & Onboarding
  5. Contract Structure, Terms & Termination
  6. Vendor Risk Management
  7. Performance Management & Service Levels
  8. Vendor Financial Management
  9. Vendor Governance, Ownership & Escalation
  10. Related Documents, Version Control & Approval

1. Purpose & the Stage-Gate Vendor Problem

A conventional program signs its vendors to the full scope at the outset, because the full scope is funded at the outset. A stage-gate program cannot. Funding is released one stage at a time, and each release is a decision the Gate Review Board can withhold — it can issue GO WITH CONDITIONS, RECYCLE the program to fix a flaw, HOLD it, or CANCEL it outright. A vendor contract that commits the company to pay for Stage 3 and Stage 4 scope before Gate 2 has authorized Stage 3 would defeat the entire control the gates exist to provide.

This plan resolves that tension with one rule that runs through everything below: the company contracts intent for the whole engagement but authorizes money one work package at a time, at the gate that funds the stage the package belongs to. The vendor sees a single relationship and a single statement of work; the company retains, at every gate, the ability to stop paying for scope it has decided not to build — owing only for work already performed.

1.1 Scope of this plan

This plan covers the external, contracted vendors that deliver program scope: the annuity administration platform, the illustration and quoting engine, independent actuarial peer review, reinsurance structuring, outside insurance counsel, and hosting infrastructure. It does not govern the 90-person internal program team (the Resource Plan does) or the distribution partners and IMOs that sell the product (the Distribution & Advisor Enablement Plan does) — those are channel relationships, not procured scope.

2. Vendor Inventory & Criticality

Seven external engagements deliver contracted scope. Criticality is judged by one test: if this vendor fails to deliver to a gate, does the gate slip? Two engagements — the administration platform and the illustration engine — are on the critical path to the filing and to launch; the rest are high or medium.

Vendor / engagementProvidesStage(s)Contracted valueCriticality
Cordelane SystemsAnnuity administration platform — configuration, build & licensing (system of record for the policy)2–4$2,850,000Critical
BrightpathIllustration & quoting engine build (no compliant illustration, no filing)2–3$940,000Critical
External actuarial peer-review firmIndependent GLWB rider pricing validation (condition GC-03)2–3$560,000High
Derivatives / ISDA counterpartiesHedging program setup — derivatives infrastructure, ISDA onboarding (condition GC-05)2–4$480,000High
Outside insurance counselRegulatory filing support & contract-form drafting (with filing fees)2–3$415,000High
Halverson ReReinsurance structuring & broker services (capital relief)2–4$390,000High
Infrastructure & hosting providersEnvironments, data services & cloud hosting2–4$445,000Medium

These lines are the externally-contracted portion of the $7,620,000 non-labor budget; the balance of non-labor is fees and internal cost carried elsewhere. No vendor value here is invented for the plan — each ties to a line in the program financial model.

3. Gate-Authorized Work Packages — the Release-Notice Model

The Cordelane administration-platform engagement is the worked example of the rule in Section 1. Its $2,850,000 is not a single contracted sum released on signature; it is three work packages, each authorized only when its stage's gate releases the stage funding.

Work packageScopeValueAuthorized by
WP-1 — Stage 2Configuration & build of the administration platform$1,680,000Gate 1 (released — Stage 2 authorized)
WP-2 — Stage 3Test support & defect remediation$760,000Gate 2 (not yet released)
WP-3 — Stage 4Cutover, hypercare & handover to operations$410,000Gate 4 (not yet released)
Why this matters. If Gate 2 recycles the program — as Gate 1 did — WP-2 and WP-3 are simply not released. The company owes Cordelane for the configuration and build it has already delivered under WP-1, and nothing for the $1,170,000 of test and cutover scope it has not. The gate control the program relies on internally is preserved, by contract, at the vendor boundary. Every multi-stage engagement in Section 2 is structured the same way.

4. Vendor Selection & Onboarding

Vendors were selected against a fixed set of criteria weighted for a regulated life-and-annuity manufacturer: demonstrated annuity-domain capability, a compliance and information-security posture that survives the company's third-party risk review, financial stability sufficient to carry a multi-year engagement, and the ability to contract to gate-authorized work packages rather than a single up-front commitment. The last criterion is not optional — a vendor unwilling to be paid stage by stage cannot be engaged on this program.

4.1 Onboarding gates

Each vendor clears a third-party risk assessment (security, data handling, business continuity), a data-processing agreement where policyholder or applicant data is in scope, and a conflict and independence check — the last decisive for the actuarial peer-review firm, whose value depends entirely on its independence from the internal pricing team it reviews (GC-03).

5. Contract Structure, Terms & Termination

Every engagement is a statement of work under a master services agreement, with payment tied to accepted deliverables rather than elapsed time, and with the intellectual property in configured product logic, contract forms, and illustrations owned by Lighthouse Financial Services Company. Three terms carry disproportionate weight on a gated program.

5.1 Termination for convenience

Each SOW is terminable for convenience by the company on notice, with the vendor paid only for work performed and accepted to the termination date. This is the contractual mechanism that makes the work-package model real: when a gate declines to release a stage, the associated work packages are either never authorized or, if already in flight, wound down under the convenience clause — not litigated as a breach. Termination for convenience is a normal, negotiated allocation of stage-gate risk, priced into the engagement, not a distressed event.

5.2 Deliverable acceptance & the gate

A vendor deliverable is not “done” when the vendor says so; it is done when it passes the acceptance criteria that let it feed a gate. A configured administration platform is accepted against the test evidence Gate 3 will need; an illustration engine is accepted against the filed methodology, not merely the specification.

5.3 Data protection & security

Where a vendor touches applicant or policyholder data, the SOW carries data-processing terms, breach notification obligations, and a right to audit — consistent with the company's obligations as a regulated carrier.

6. Vendor Risk Management

The program has already lived its defining vendor risk, and it is instructive precisely because it did not look like a vendor risk until it materialized.

The realized case — I-02, Brightpath. During Stage 2 the illustration engine could not support two of the five crediting strategies the product was designed around. The constraint sat inside a vendor platform, but its consequence was a product-scope decision: rather than force custom development against the filing window, the Gate Review Board reduced the launch crediting strategies from five to three (condition GC-01, since closed). A vendor's platform limit reshaped the product. The lesson is written into how this plan treats criticality: a critical vendor's constraints are product constraints, and must be surfaced at the gate that can still act on them.

6.1 Standing vendor risks

RiskExposureMitigation
Single-source administration platformCordelane is the system of record; there is no second platform mid-flightGate-authorized work packages cap forward exposure; source-code and configuration escrow; WP-3 includes a documented handover to internal operations
Hedging counterparty readiness (GC-05)ISDA execution with the second derivatives counterparty has not begun (DEP-06); readiness lags launchA hedging readiness plan with ISDA execution milestones is required at Gate 2; the risk is tracked as R-05 and drives an at-risk gate condition
Peer-review independence & timingGC-03 requires the external actuarial review to complete before Gate 2The firm is contracted independent of the internal pricing team; $180,000 of contingency was released to protect the timeline
Reinsurance terms moveCapital relief depends on Halverson Re structuring holding at pricingTerms confirmed before the Gate 2 economics are re-presented; broker fees fixed in the SOW

7. Performance Management & Service Levels

Vendor performance on this program is measured against gate deliverables, not against activity. The question at every review is not “is the vendor busy?” but “will this vendor's work be gate-ready on the date the gate needs it?” Each critical engagement carries service levels appropriate to its scope: platform availability and defect-severity response times for Cordelane; illustration accuracy and reconciliation-to-methodology for Brightpath; deliverable dates for the peer-review and counsel engagements.

7.1 Defect remediation

The Stage 3 test-support work package (Cordelane WP-2) exists so that defect remediation is a contracted, funded activity rather than a goodwill negotiation during the test window. Severity-1 defects that threaten the filing carry the tightest response commitment.

7.2 Review cadence

Vendor performance is reviewed weekly within the program and formally at each gate, where a vendor's inability to deliver its work package to standard is a gate risk in its own right — visible to the Board, not buried in a status report.

8. Vendor Financial Management

Vendor spend is controlled by the same gate discipline as the rest of the program. No vendor is paid ahead of the gate that authorizes its stage, and no work package is released until its gate releases the stage funding behind it.

ControlHow it works
Gate-tranche fundingVendor work packages draw only against released stage tranches ($2,180,000 + $11,640,000 released; $7,450,000 + $4,330,000 gated)
Deliverable-tied paymentPayment follows accepted deliverables, not elapsed time or vendor invoices for effort
Contingency draws are loggedThe $180,000 released to protect the GC-03 peer-review timeline is recorded against the $2,304,000 gate contingency, not absorbed silently
Convenience-termination exposureAt any gate, forward vendor commitment is limited to work already performed — the maximum the company can owe is bounded by the released work packages

9. Vendor Governance, Ownership & Escalation

Every vendor relationship has one accountable functional owner and one governance path. The Program Management Office owns the vendor portfolio and this plan; the functional owner owns the day-to-day relationship; the Gate Review Board authorizes the stage funding that releases each work package.

Vendor / engagementFunctional owner
Cordelane administration platformIT — Annuity Administration Platform
Brightpath illustration engineIT — Illustration & Quoting
Actuarial peer-review firmActuarial — Pricing & Product Development
Derivatives / ISDA counterpartiesInvestments — ALM & Hedging
Halverson ReInvestments — ALM & Hedging, with Actuarial — Valuation
Outside insurance counselLegal & Compliance
Infrastructure & hostingIT — Annuity Administration Platform

9.1 Escalation & change authority

A vendor issue inside an authorized work package is the functional owner's to resolve. Anything that changes vendor scope, cost, or the gate a work package feeds is a program change — a Tier 2 decision under the governance model, taken by the relevant board, never absorbed at the vendor boundary. A vendor failure that threatens a gate is escalated to the Gate Review Board as a gate risk. The PMO chairs the program from without a vote; funding authority rests with the Board and, above it, the sponsor, G. Marchetti, Chief Product Officer.

10. Related Documents, Version Control & Approval

10.1 Related documents

10.2 Version control

VersionDateChange
1.005 Feb 2026Initial vendor approach at Gate 0
1.111 Jun 2026Work-package model formalized at the Gate 1 second convening; I-02 recorded
1.216 Oct 2026Vendor risk and financial controls updated at the Stage 2 mid-point

Prepared by the Program Management Office, Lighthouse Financial Services Company, and chaired from the PMO without a vote. Approving authority: G. Marchetti, Chief Product Officer. Status date 16 October 2026.