Readiness assessment issued December 13, 2024 — ahead of the revised exit from transitional services. Four of six services have already exited. This report assesses whether the remaining two can exit on the revised date, what evidence supports that, and what dependencies ACME carries across the boundary. The exit has not yet occurred; nothing here reports on it.
Contents
1. Service-by-service position
| Service | Planned exit | Position at this date |
|---|---|---|
| Payroll and HR administration | Month 3 | Exited |
| General ledger and financial close | Month 6 | Exited |
| Network, telecom and end-user compute | Month 8 | Exited |
| Security operations and monitoring | Month 9 | Exited |
| Data center hosting and operations | Month 12 | Extended — assessed here |
| Core administration platform support | Month 12 | Extended — assessed here |
The sequence is not arbitrary and it is the part most often got wrong. Payroll exited first because a carve-out's HR dependency is the one with a hard external clock — employees must be paid by a named entity from a named date, and no amount of program flexibility changes that. The two services still open are last because both depend on the platform work, and the platform work depends on identity resolution. A transitional services schedule is a dependency graph, not a list of durations, and the services that look easiest to exit are usually the ones whose exit nothing else is waiting on.
2. Exit criteria and the evidence for each
Each remaining service exits against stated criteria with evidence, not against a date. The distinction matters because a service can reach its planned exit date while ACME remains unable to operate it.
| Criterion | Evidence required | Status |
|---|---|---|
| ACME operates the service unaided | Reverse-shadowing sign-off — ACME performs, the provider observes | Met, both services |
| Runbooks current and tested | Executed from the document by a person who did not write it | Met |
| Incident response exercised | A severity-one drill run end to end under ACME command | Met |
| Backup and restore proven | A restore performed and validated, not a backup job reported as successful | Met |
| Month-end close executed independently | Two consecutive closes with no provider intervention | Met |
| No open severity-one or severity-two defects | Defect register at zero for both classes | Met |
| Clerical review queue closed | Queue depth at zero with the false-positive audit within tolerance | Substantially complete; see section 4 |
Every criterion above is written as something ACME does, not as something the provider delivers — and that inversion is the whole design. A transitional services agreement obliges the seller to provide a service. It does not oblige them to make the buyer capable of it, and nothing in a standard agreement ever will. A program that measures exit readiness by whether the provider met its obligations will exit on time and discover afterward that it cannot run what it inherited. The provider can be fully compliant and the buyer completely unready, with no contractual instrument registering the difference.
3. Knowledge transfer acceptance
Knowledge transfer was structured as a deliverable with named receivers and acceptance criteria rather than as a series of sessions. Acceptance was by reverse shadowing: the ACME receiver performs the procedure while the provider's incumbent observes and is available, and acceptance is recorded when the incumbent has nothing to correct.
The conventional arrangement does not work, and it is the one almost every transition uses. The usual form has the incumbent demonstrate while the receiver takes notes, which produces a receiver who has seen the job and cannot do it. The gap only surfaces on the first bad night after the incumbent has gone. Reversing it is uncomfortable for both parties — the receiver is exposed and the incumbent has to watch someone do their job badly — and that discomfort is the test working. A knowledge transfer that felt smooth for everyone involved usually transferred nothing, because nothing was ever attempted under conditions where failure was possible.
Acceptance is recorded per procedure and per named receiver. Where a receiver is a retention-covered Cumberland Valley employee, a second ACME receiver was accepted for the same procedure — retention buys the time to transfer knowledge, and a transfer that terminates in one person has not removed the dependency, only relocated it.
4. Residual dependencies carried across the boundary
Exit does not mean every thread is closed. Three are carried deliberately, each with an owner and a stated end condition.
| Dependency | Owner | End condition |
|---|---|---|
| Clerical review queue — residual records still in stewardship | Dr. A. Ravindran | Queue at zero with the false-positive audit clean; steward capacity retained until then |
| Write-back interface to the retiring platform — remaining registered consumers | K. Stallworth | Last consumer migrated; register closed to additions since Day 1 |
| Business associate agreement with the divesting parent | F. Underhill | Survives exit until the last hosted record is returned or destroyed and destruction is certified |
The third one is the dependency most likely to be missed, because nobody files the seller under "vendors." Cheatham Mutual Holdings hosted member data throughout the transitional term, which makes it a business associate under HIPAA regardless of its role as the divesting parent. The agreement therefore does not end when the service does — the obligations survive until the data is returned or destroyed and the destruction is certified. A program that treats exit from the service as exit from the relationship leaves a live regulatory obligation with no owner, and it is invisible precisely because the counterparty is the former parent rather than a supplier on a vendor register.
5. Recommendation and what would reverse it
The assessment supports exiting both remaining services on the revised date. Every operational criterion is met with evidence, knowledge transfer is accepted per procedure and per receiver, and the residual dependencies each carry an owner and an end condition rather than being carried as hope.
Two conditions would reverse the recommendation between this assessment and the exit date. A severity-one defect arising in either service and remaining open would remove the criterion it belongs to. A material regression in the false-positive audit would suspend the identity dependency's end condition, because the queue closing on depth alone is not the same as the queue closing correctly.
The exit consumes margin that was negotiated at signing and does not breach the contractual maximum. That distinction is the one to keep in front of the Committee. Exceeding a contractual maximum is a governance failure that would have required renegotiating with the divesting parent from a position of no leverage — the program would have been asking for something it had no right to and could not do without. Spending a buffer bought deliberately for a risk that then materialized is the buffer working, and margin remains at exit rather than the term being consumed to its limit.
Related artifacts: 22 — TSA Schedule & Exit Plan · 19 — Retention & Key Talent · BAA Register · 44 — Change Control Log