Reversibility is a capability to demonstrate during the contract

Reversibility means transferring an outsourced service to another organisation or bringing it in-house without losing indispensable data, knowledge and functions. A clause promising supplier cooperation is insufficient. An archive delivered on time can remain unusable because it contains proprietary codes, missing relationships or documents that cannot be decrypted. The intended result is resumed operating capability, rather than receipt of a file.

Preparation starts when the contract begins. Define deliverables, formats, owners, cost and evidence of use. The customer retains the competence to interpret the service and accept transfer. The outgoing provider can contribute without being the sole holder of success criteria. Reversibility should also work during commercial tension, provider failure or the departure of the person who knows the application best.

Fictional case: export succeeds, recovery fails

A fictional company outsources a contract-management application. Every figure and situation is a teaching example. At renewal it receives an export containing 80,000 contracts and 240,000 documents. The supplier reports 100% export completion. The target team cannot link some attachments, dates are ambiguous and access restrictions have disappeared. The service is not reversible despite apparently complete extraction.

The exercise begins with 500 representative contracts: active and terminated contracts, amendments, several currencies, old documents and restricted access. The target imports them into an isolated environment and executes four journeys: finding a clause, calculating a due date, reading authorised documents and producing a renewal report. Gaps expose the need for a dictionary, relationships and transformation rules. This proves neither full-volume performance nor complete recovery yet; it identifies evidence to extend.

Define the exit package and its owners

The package includes data, documents, identifiers, dictionary, relationships, required reference data and calculation rules. Depending on the service, it also includes configuration, permitted scripts, ticket history, procedures and useful logs. Distinguish customer-owned material, licensed material and provider property. A nontransferable component requires an identified alternative before termination.

The data owner accepts structure and integrity, business owners accept meaning, security verifies encryption and access, and the service owner accepts operating procedures. Legal defines retention and transfer rights. Procurement establishes timing, cost and contractual cooperation. A global exit owner brings these decisions together without pretending one technical signature covers every domain.

Worked proof protocol

ObjectExport evidenceReimport and use evidenceTeaching criterion
Active contracts80,000 expected identifiers, statuses and batch fingerprintIdentifiers retained; due dates recalculated and reconciledNo active contract lost; calculation differences explained
Documents240,000 objects with size, fingerprint and parent identifierOpening, decryption and contract links verifiedAll essential relationships conform
PermissionsRoles and restrictions in a documented formatAuthorised user accepted; prohibited user deniedNo silent widening of access
OperationsProcedures, incidents and scheduled jobs deliveredNew team performs processing and incident recoveryNo hidden intervention from outgoing provider

Build a repeatable export-and-reimport test

Export a dated, frozen reference. The provider supplies the manifest, formats, encodings, time zones and schema versions. Verify fingerprints on receipt to detect alteration or omission. A fingerprint establishes file identity, not the correctness of its business meaning. Retain business controls, extraction logs and expected exceptions so the test can be reproduced.

Import into a separate target environment using only the agreed package and tools. Record every additional supplier intervention. Oral knowledge or an undelivered patch reveals an unresolved dependency. Compare keys, relationships, amounts, statuses and attachments after import, then run business journeys with the new operators. Someone familiar with the old service must not quietly resolve failures merely to create an appearance of success.

Technical return rate equals conforming delivered objects divided by expected objects. Business recovery rate equals successful essential target journeys divided by essential journeys tested. A 100% technical rate with a 75% business rate is an incomplete exit in this model. Record missing journeys, consequences and planned correction. One percentage across all objects may conceal the absence of a few crucial contracts.

Keys, permissions and history belong to the service

Securely transfer or replace decryption capabilities. An intact but unreadable document does not meet the recovery need. Do not put active passwords and keys in a broadly accessible archive. Security arranges delivery, rotation and control. Test access refusal on the target: an export losing restrictions can turn an exit archive into personal-data exposure.

Classify histories by utility and applicable retention obligations. Some can remain in a consultation archive; others are needed for calculation and requests. Business and legal teams agree scope, duration and access. Export should not create indefinite retention by default. After accepted transfer, decide supplier deletion subject to legal retention requirements and obtain the contractually required evidence. These steps should be planned before the service ends.

Budget the actual exit and preserve acceptance time

The budget includes extraction, transformation, target infrastructure, testing, training, supplier cooperation and coexistence, plus target licensing and component restrictions. In the fictional case, a EUR 95,000 exit appears cheaper than EUR 120,000 renewal. Adding EUR 40,000 coexistence and EUR 18,000 document recovery gives a relevant cost of EUR 153,000. Leadership may still choose exit to reduce strategic dependence, but should make that reason explicit.

Work backwards from the last service day. If full import requires eight working days, testing five and correction plus rerun seven, initial delivery must leave at least twenty working days before expiry, plus the chosen contingency. These fictional durations need measurement. A clause delivering files on the final day prevents acceptance before shutdown. Define post-transfer cooperation and a service extension that can be activated if acceptance fails.

Accept the exit and recognise stop conditions

In this exercise, a missing active contract, unreadable essential attachment, broken critical relationship or unauthorised access expansion blocks exit. Noncritical history can remain in an archive if consultation and retention policy are satisfied. The service owner accepts resumed operation after domain validations. Ending charges and deleting outgoing-provider data are separate decisions following acceptance rather than preceding it.

If the provider disappears or does not cooperate, use periodically tested exports already held by the customer. Their age defines potential data loss by comparing the last usable export with the shutdown date. Explain that gap to the business and provide a complementary capture mechanism if it exceeds tolerance. A backup is not automatically a reusable export: its format and dependencies may keep it captive to the original service.

Maintain evidence throughout the relationship

Run an initial test before the service becomes indispensable and repeat after material schema, subcontractor or scope changes. Contractual frequency should reflect change rate and criticality rather than a universal period. Track actual duration, outgoing-provider intervention, missing objects, access differences and recovery cost. Use results in renewals and simplification investment decisions.

Train the receiving team through a complete operation and simulated incident. Knowledge transfer is more than depositing hundreds of pages: operators must execute, diagnose and escalate. Recheck contacts, roles and automated jobs after organisational change. Retain a customer owner able to explain the exit package to a future provider. Documentary and human autonomy make the contractual clause usable when departure becomes necessary.

Sector implications

Financial services need histories, reconciliation and controls under applicable requirements. Manufacturing may prioritise configuration, bills of material, recipes and software rights over document volumes. Retail must recover links between orders, payments, returns and stock without duplicating transactions. A read-only archive may suffice for some history but not for open orders.

Professional services need document restrictions and contractual commitments. Public organisations should maintain access continuity and intelligible archives for authorised people. Each sector selects essential journeys. The principle remains receiving, reimporting, understanding and using the package with a team able to continue the service without undeclared dependence on the outgoing supplier.

Sources and method

The starting point is 2022, when the GDPR and 2019 EBA guidelines were available within their respective scopes. A later reference checked in 2026 is Regulation (EU) 2023/2854, the Data Act, containing provisions on switching data-processing services. It was not a 2022 obligation; applicability depends on the service and provisions concerned. Reimport tests and thresholds here are an operational teaching method, distinct from the cited legal requirements.

Primary sources checked in October 2026. CNIL, RGPD, articles 28 et 32. EBA, Guidelines on outsourcing arrangements, 2019. EUR-Lex, règlement (UE) 2023/2854, Data Act.

All situations, amounts, durations and thresholds are fictional teaching examples. They illustrate a decision method and do not describe any CYTIZEN engagement or market benchmark. The operational recommendations are the author’s proposals, separate from the cited documents.