Purpose

Perform the intake risk assessment and create a risk-based test plan for a proposed COTS product or update.

Scope

This procedure applies to product risk, vendor risk, legal risk, compliance risk and test planning before execution begins.

Steps

#ActionDetailsEvidence
1Record change classificationRecord whether the change is a new product, patch, update, migration or upgrade and identify the affected business services and data.Change classification record
2Assess intake risksAssess product, ICT, legal, compliance and operational risks, including vendor reputation, licensing, support commitments and vulnerability management.Risk assessment
3Assign criticality and test levelsAssign a criticality rating and select proportionate test levels: integration, UAT, OAT, security testing and unit testing where accessible.Criticality and test-level decision
4Define risk-based test planDefine the risk-based scope, deliverables, resources, costs, schedule, entry and exit criteria and test performance indicators.Test plan
5Obtain stakeholder sign-offObtain documented sign-off from Technology, Compliance, Risk/CORF and relevant business stakeholders before execution.Stakeholder sign-off
6Escalate planning gapsEscalate material risk, resource or planning gaps before testing or release.Escalation record

Evidence

  • risk assessment
  • test plan
  • stakeholder sign-off
  • escalation record where relevant

Relationships

Implementation

  • Implementation state: current under the approved COTS Acceptance and Testing Manual version 1.0
  • Execution evidence: retained for each COTS intake or material change

History

  • 2026-07-26: Added the evidence-system relationship required for Hermes assessment mapping.
  • 2026-07-26: Created from the approved COTS manual and mapped to CBCS-derived IT requirements.