Lighthouse Financial Services Company — This plan governs how the Beacon Index Advantage product development program engages, contracts, funds, and manages its external vendors. In a stage-gate program the vendor problem has a shape the vendors themselves rarely see: the program cannot commit to buy scope that a future gate may decline to fund. Stages 3 and 4 — $7,450,000 and $4,330,000 — are not authorized money today, and a gate can send the program backward or stop it. So the governing move of this plan is to decompose every multi-stage engagement into gate-authorized work packages, each released only when the gate that funds its stage says so.
Table of Contents
- Purpose & the Stage-Gate Vendor Problem
- Vendor Inventory & Criticality
- Gate-Authorized Work Packages — the Release-Notice Model
- Vendor Selection & Onboarding
- Contract Structure, Terms & Termination
- Vendor Risk Management
- Performance Management & Service Levels
- Vendor Financial Management
- Vendor Governance, Ownership & Escalation
- Related Documents, Version Control & Approval
1. Purpose & the Stage-Gate Vendor Problem
A conventional program signs its vendors to the full scope at the outset, because the full scope is funded at the outset. A stage-gate program cannot. Funding is released one stage at a time, and each release is a decision the Gate Review Board can withhold — it can issue GO WITH CONDITIONS, RECYCLE the program to fix a flaw, HOLD it, or CANCEL it outright. A vendor contract that commits the company to pay for Stage 3 and Stage 4 scope before Gate 2 has authorized Stage 3 would defeat the entire control the gates exist to provide.
This plan resolves that tension with one rule that runs through everything below: the company contracts intent for the whole engagement but authorizes money one work package at a time, at the gate that funds the stage the package belongs to. The vendor sees a single relationship and a single statement of work; the company retains, at every gate, the ability to stop paying for scope it has decided not to build — owing only for work already performed.
1.1 Scope of this plan
This plan covers the external, contracted vendors that deliver program scope: the annuity administration platform, the illustration and quoting engine, independent actuarial peer review, reinsurance structuring, outside insurance counsel, and hosting infrastructure. It does not govern the 90-person internal program team (the Resource Plan does) or the distribution partners and IMOs that sell the product (the Distribution & Advisor Enablement Plan does) — those are channel relationships, not procured scope.
2. Vendor Inventory & Criticality
Seven external engagements deliver contracted scope. Criticality is judged by one test: if this vendor fails to deliver to a gate, does the gate slip? Two engagements — the administration platform and the illustration engine — are on the critical path to the filing and to launch; the rest are high or medium.
| Vendor / engagement | Provides | Stage(s) | Contracted value | Criticality |
|---|---|---|---|---|
| Cordelane Systems | Annuity administration platform — configuration, build & licensing (system of record for the policy) | 2–4 | $2,850,000 | Critical |
| Brightpath | Illustration & quoting engine build (no compliant illustration, no filing) | 2–3 | $940,000 | Critical |
| External actuarial peer-review firm | Independent GLWB rider pricing validation (condition GC-03) | 2–3 | $560,000 | High |
| Derivatives / ISDA counterparties | Hedging program setup — derivatives infrastructure, ISDA onboarding (condition GC-05) | 2–4 | $480,000 | High |
| Outside insurance counsel | Regulatory filing support & contract-form drafting (with filing fees) | 2–3 | $415,000 | High |
| Halverson Re | Reinsurance structuring & broker services (capital relief) | 2–4 | $390,000 | High |
| Infrastructure & hosting providers | Environments, data services & cloud hosting | 2–4 | $445,000 | Medium |
These lines are the externally-contracted portion of the $7,620,000 non-labor budget; the balance of non-labor is fees and internal cost carried elsewhere. No vendor value here is invented for the plan — each ties to a line in the program financial model.
3. Gate-Authorized Work Packages — the Release-Notice Model
The Cordelane administration-platform engagement is the worked example of the rule in Section 1. Its $2,850,000 is not a single contracted sum released on signature; it is three work packages, each authorized only when its stage's gate releases the stage funding.
| Work package | Scope | Value | Authorized by |
|---|---|---|---|
| WP-1 — Stage 2 | Configuration & build of the administration platform | $1,680,000 | Gate 1 (released — Stage 2 authorized) |
| WP-2 — Stage 3 | Test support & defect remediation | $760,000 | Gate 2 (not yet released) |
| WP-3 — Stage 4 | Cutover, hypercare & handover to operations | $410,000 | Gate 4 (not yet released) |
4. Vendor Selection & Onboarding
Vendors were selected against a fixed set of criteria weighted for a regulated life-and-annuity manufacturer: demonstrated annuity-domain capability, a compliance and information-security posture that survives the company's third-party risk review, financial stability sufficient to carry a multi-year engagement, and the ability to contract to gate-authorized work packages rather than a single up-front commitment. The last criterion is not optional — a vendor unwilling to be paid stage by stage cannot be engaged on this program.
4.1 Onboarding gates
Each vendor clears a third-party risk assessment (security, data handling, business continuity), a data-processing agreement where policyholder or applicant data is in scope, and a conflict and independence check — the last decisive for the actuarial peer-review firm, whose value depends entirely on its independence from the internal pricing team it reviews (GC-03).
5. Contract Structure, Terms & Termination
Every engagement is a statement of work under a master services agreement, with payment tied to accepted deliverables rather than elapsed time, and with the intellectual property in configured product logic, contract forms, and illustrations owned by Lighthouse Financial Services Company. Three terms carry disproportionate weight on a gated program.
5.1 Termination for convenience
Each SOW is terminable for convenience by the company on notice, with the vendor paid only for work performed and accepted to the termination date. This is the contractual mechanism that makes the work-package model real: when a gate declines to release a stage, the associated work packages are either never authorized or, if already in flight, wound down under the convenience clause — not litigated as a breach. Termination for convenience is a normal, negotiated allocation of stage-gate risk, priced into the engagement, not a distressed event.
5.2 Deliverable acceptance & the gate
A vendor deliverable is not “done” when the vendor says so; it is done when it passes the acceptance criteria that let it feed a gate. A configured administration platform is accepted against the test evidence Gate 3 will need; an illustration engine is accepted against the filed methodology, not merely the specification.
5.3 Data protection & security
Where a vendor touches applicant or policyholder data, the SOW carries data-processing terms, breach notification obligations, and a right to audit — consistent with the company's obligations as a regulated carrier.
6. Vendor Risk Management
The program has already lived its defining vendor risk, and it is instructive precisely because it did not look like a vendor risk until it materialized.
6.1 Standing vendor risks
| Risk | Exposure | Mitigation |
|---|---|---|
| Single-source administration platform | Cordelane is the system of record; there is no second platform mid-flight | Gate-authorized work packages cap forward exposure; source-code and configuration escrow; WP-3 includes a documented handover to internal operations |
| Hedging counterparty readiness (GC-05) | ISDA execution with the second derivatives counterparty has not begun (DEP-06); readiness lags launch | A hedging readiness plan with ISDA execution milestones is required at Gate 2; the risk is tracked as R-05 and drives an at-risk gate condition |
| Peer-review independence & timing | GC-03 requires the external actuarial review to complete before Gate 2 | The firm is contracted independent of the internal pricing team; $180,000 of contingency was released to protect the timeline |
| Reinsurance terms move | Capital relief depends on Halverson Re structuring holding at pricing | Terms confirmed before the Gate 2 economics are re-presented; broker fees fixed in the SOW |
7. Performance Management & Service Levels
Vendor performance on this program is measured against gate deliverables, not against activity. The question at every review is not “is the vendor busy?” but “will this vendor's work be gate-ready on the date the gate needs it?” Each critical engagement carries service levels appropriate to its scope: platform availability and defect-severity response times for Cordelane; illustration accuracy and reconciliation-to-methodology for Brightpath; deliverable dates for the peer-review and counsel engagements.
7.1 Defect remediation
The Stage 3 test-support work package (Cordelane WP-2) exists so that defect remediation is a contracted, funded activity rather than a goodwill negotiation during the test window. Severity-1 defects that threaten the filing carry the tightest response commitment.
7.2 Review cadence
Vendor performance is reviewed weekly within the program and formally at each gate, where a vendor's inability to deliver its work package to standard is a gate risk in its own right — visible to the Board, not buried in a status report.
8. Vendor Financial Management
Vendor spend is controlled by the same gate discipline as the rest of the program. No vendor is paid ahead of the gate that authorizes its stage, and no work package is released until its gate releases the stage funding behind it.
| Control | How it works |
|---|---|
| Gate-tranche funding | Vendor work packages draw only against released stage tranches ($2,180,000 + $11,640,000 released; $7,450,000 + $4,330,000 gated) |
| Deliverable-tied payment | Payment follows accepted deliverables, not elapsed time or vendor invoices for effort |
| Contingency draws are logged | The $180,000 released to protect the GC-03 peer-review timeline is recorded against the $2,304,000 gate contingency, not absorbed silently |
| Convenience-termination exposure | At any gate, forward vendor commitment is limited to work already performed — the maximum the company can owe is bounded by the released work packages |
9. Vendor Governance, Ownership & Escalation
Every vendor relationship has one accountable functional owner and one governance path. The Program Management Office owns the vendor portfolio and this plan; the functional owner owns the day-to-day relationship; the Gate Review Board authorizes the stage funding that releases each work package.
| Vendor / engagement | Functional owner |
|---|---|
| Cordelane administration platform | IT — Annuity Administration Platform |
| Brightpath illustration engine | IT — Illustration & Quoting |
| Actuarial peer-review firm | Actuarial — Pricing & Product Development |
| Derivatives / ISDA counterparties | Investments — ALM & Hedging |
| Halverson Re | Investments — ALM & Hedging, with Actuarial — Valuation |
| Outside insurance counsel | Legal & Compliance |
| Infrastructure & hosting | IT — Annuity Administration Platform |
9.1 Escalation & change authority
A vendor issue inside an authorized work package is the functional owner's to resolve. Anything that changes vendor scope, cost, or the gate a work package feeds is a program change — a Tier 2 decision under the governance model, taken by the relevant board, never absorbed at the vendor boundary. A vendor failure that threatens a gate is escalated to the Gate Review Board as a gate risk. The PMO chairs the program from without a vote; funding authority rests with the Board and, above it, the sponsor, G. Marchetti, Chief Product Officer.
10. Related Documents, Version Control & Approval
10.1 Related documents
- Vendor SOW — Cordelane Systems — the worked statement of work whose work-package structure this plan generalizes.
- Program Budget — the $7,620,000 non-labor budget these vendor lines sit inside.
- Stage-Gate Governance Model — the gate authority that releases each work package.
- RAIDD Log — the risk and issue register carrying I-02, R-05, and the vendor risks above.
- Master Test & Validation Strategy — the acceptance evidence a vendor deliverable is judged against.
10.2 Version control
| Version | Date | Change |
|---|---|---|
| 1.0 | 05 Feb 2026 | Initial vendor approach at Gate 0 |
| 1.1 | 11 Jun 2026 | Work-package model formalized at the Gate 1 second convening; I-02 recorded |
| 1.2 | 16 Oct 2026 | Vendor risk and financial controls updated at the Stage 2 mid-point |
Prepared by the Program Management Office, Lighthouse Financial Services Company, and chaired from the PMO without a vote. Approving authority: G. Marchetti, Chief Product Officer. Status date 16 October 2026.