TRContact Us
Policies

Strategic Partnership and Collaboration Policy

This policy explains how technology and service providers are assessed, contracted, and monitored.

Last updated: July 19, 2026Policy document

Purpose and scope

This policy defines the core assessment and management practices used in relationships with data centre and cloud providers, software platforms, security services, and project-based specialists.

Selecting a partner

Partners are assessed on technical capability, service scope, security approach, support capacity, commercial terms, and verifiable information, rather than brand recognition alone. The depth of the review depends on the impact and risk of the relationship.

  • Technical and operational compatibility is reviewed.
  • Data access and security responsibilities are assessed.
  • Support channels, service boundaries, and the process for escalation to specialist teams are reviewed.
  • Migration, licensing, operating, and exit costs are considered alongside price.

Contracts and responsibilities

The contract sets out the service scope, each party’s responsibilities, data access, the support process, fees, changes, termination, and transition terms. Where appropriate, the contract is reviewed by external legal counsel or a subject-matter specialist.

The responsibilities of Hosted Technology, the provider, and the customer are distinguished from one another in the project plan.

Technical connection and implementation

Access, testing, data transfer, rollback, and responsible points of contact are defined before a new provider is connected to a system. Production access is enabled only after the required controls have been completed.

Security and confidentiality

A partner receives only the access necessary to provide the service. The relevant agreement includes terms for confidentiality, access logging, incident notification, and termination of access to shared data and systems.

Service monitoring and change

Service quality is assessed against the contractual scope, support records, outages, security notifications, and commercial terms. A remediation plan may be requested, and any decision to continue is considered alongside the risks and available alternatives.

If a provider must be changed or a service ended, data return, access removal, and technical transition steps are planned.

Review

This policy is reviewed when there is a material change to the relevant service, process, organisational structure, or applicable law. After any necessary revisions, the current text and revision date are published on this page.