The contract allows exit; the workflow does not yet support it

This illustrative scenario is not a CYTIZEN client result. Anne runs IT procurement for a group using SaaS contract management and an AI analysis assistant. The exit clause appears satisfactory: the supplier promises to return data. In an exercise, the team receives readable files but lacks approval histories, contract–annex links and some configuration. Data return exists; operational continuity has not been demonstrated.

Supplier dependency is therefore measured by the ability to continue a service, not merely commitment duration. A cancellable contract can contain hard-to-recover data. A standard application can have bespoke integrations. A replaceable model can feed a process dependent on its output format. The useful question is what must be recovered, rebuilt and checked to work with another solution or a fallback.

The Data Act has applied since 12 September 2025. Chapter VI addresses switching between providers of data processing services. Service scope and applicable obligations require review; this framework does not replace export and recovery tests. Data Act — European Commission.

Create a usable dependency map

Anne prepares a record for each business service, covering applications, identities, data, interfaces, skills and necessary suppliers. It exposes indirect dependencies: SaaS hosted on a cloud shared by several services, a support contractor alone understanding scripts, or an identity provider whose failure blocks multiple tools. Contract counting cannot show this concentration. The map shows relationships capable of interrupting business activity.

The contract-management record is completed: purpose, retrieve a signed version and its approval; critical data, documents, metadata, links and history; neighbours, CRM, electronic signature and ERP; skills, functional administration and integration support; fallback, controlled access to exported contracts and manual approval. Each element has an owner and checking frequency. The record distinguishes document consultation from continuing to create and approve new contracts.

Criticality follows the journey. Assistant failure may slow analysis without preventing manual approval. Losing signed-contract access may block checking an obligation. A SAP connection failure can prevent using correct business partners. Anne ranks these effects with the business, considering tolerable delay and recovery workload. Not every cloud service is assigned identical criticality.

Make export a test rather than a promise

The team selects representative authorised contracts: signed document, annex, approval history, version change and a case with special rights. The supplier performs the contracted export. An operator other than the normal administrator loads it into a consultation environment or test target. Business users verify that relationships and necessary information remain usable. Successfully unzipping an archive is insufficient evidence.

The protocol specifies expected case count, documents, identifiable approved versions, preserved links, understandable dates, recoverable permissions and reconciliation results. Missing data are listed rather than silently replaced by manual extraction. Format conversion can be acceptable if documented, repeatable and tested. Exit also states what remains with the supplier during required or agreed retention.

For AI, Anne adds versioned prompts or instructions, configuration, corpus, evaluations and human corrections when owned or exportable. Company assets are distinguished from inaccessible components such as proprietary model weights. The plan does not demand return of something never purchased; it explains how to replace the component and retest the journey with controlled assets.

Cost a plausible exit

Exit cost includes extraction, conversion, cleansing, target service, integrations, tests, training, supplier assistance and coexistence. Spending continuing through transition is added. Timing depends on business windows and expert availability; shortening a schedule does not create those skills. Anne prepares a normal scenario and an emergency scenario with limited supplier cooperation or continuing application failure.

A hypothetical budget contains EUR 15,000 extraction and conversion, EUR 25,000 integrations, EUR 20,000 tests and training, and EUR 10,000 parallel operation. The EUR 70,000 total is neither a market price nor a quotation. It makes cost categories visible. Non-exportable histories may radically change effort and time; that risk belongs in the contractual decision before migration begins.

Exit readiness is proportionate to risk rather than an abstract demand for complete independence. Low-criticality services may justify manual exit and periodic exports; essential services need stronger evidence and fallback capacity. Management can accept dependency when it understands consequences and funds proportionate protection. It must not call a dependency controlled if replacement has neither been tested nor costed.

Negotiate what the workflow actually needs

Anne checks formats, volumes, deadlines, assistance, pricing and export responsibilities. Assistance “subject to availability” does not secure resources during an emergency. The contract identifies returned items and handling of restitution errors, as well as rights over bespoke configuration, scripts and documentation. Competent functions make legal, security and data-protection decisions.

Offering changes are monitored: removed APIs, new prices, changed subcontractors, format changes and end of support. Notifications have owners and impact assessments. In AI, model changes can alter behaviour without changing the interface; reference evaluations compare versions. The business owner decides whether differences remain acceptable while operations checks interface compatibility and support load.

For financial services, DORA provides a specific third-party risk framework within its scope. It does not automatically turn every SaaS customer into a regulated financial entity. Direct obligations, contractual commitments and continuity practices remain distinct. Programme management organises evidence and coordination; it does not infer general compliance from a successful export.

In practice: preserve the outcome before changing tools

The exercise shows that one team alone understands a CRM connector. A supplier could return every file without restoring that knowledge. Management funds flow documentation and reconstruction testing before selecting another application. Less visible than replacement, this removes a concrete dependency. The plan identifies the latest start date compatible with the renewal window.

The business accepts a fallback: consult signed contracts, prepare manual approvals and defer some automated analysis. It rejects preserving AI while losing approval evidence. This priority guides migration order and tests. Successful exit does not mean replacing the newest component first; it means retaining capabilities on which business activity depends.

Test the dominant dependency

For ERP, verify master data, postings, interfaces and reconciliation before describing an export as complete. For QMS, retain relationships between records, versions, signatures or approvals and required process evidence. For identity services, test accounts, permissions and fallback mechanisms that enable other applications. For a document assistant, distinguish withdrawing the assistant from losing the source repository. Every dependency needs a specific test; a standard contract clause is not enough.

Periodic reviews examine changes since the last test. They may remain light for unchanged services and become more demanding after integration, acquisition or international expansion. An exit plan documented years earlier is not presumed current.

Sources, method and limitations

Primary sources checked on 4 October 2026. Figures and scenario are educational. Exit recommendations require adaptation to contracts, business context and applicable obligations; they are not legal analysis of a particular offering.