Operational Sovereignty Assessment Framework

When your provider cannot or will not cooperate, what can you still do?

OSAF helps organizations assess whether critical services remain controllable, recoverable and adaptable when an external dependency changes, fails or stops cooperating.

One bounded serviceEvidence-ledNo averaged score
Service dependency mapAll systems nominal
Payroll ServiceCritical service
SaaS ProviderApplication layer
Identity / MFAAccess control
Cloud PlatformControl plane
HRIS / BankingData & settlement
Identity path unavailableCould the service still operate?

Access is not the same as control.

Organizations use cloud, SaaS, identity and AI services every day. The harder question is what remains possible when one of those dependencies changes.

01 / Dependency

Your service is a system of systems.

Availability can depend on providers, identities, networks, software updates and legal permissions you do not directly control.

02 / Control

A contract does not execute a recovery.

Rights matter, but operational control requires a path that people can actually exercise under pressure.

03 / Evidence

A plan is not the same as a test.

OSAF distinguishes what is claimed, documented, implemented, monitored, tested and independently assured.

Residency tells you where. Sovereignty asks who can act.

A service can be locally hosted and still depend on remote identity, foreign-controlled keys, proprietary software or an inaccessible control plane.

OSAF quick test01 question

Your data is hosted in Canada. Does that automatically make the service sovereign?

From one critical service to a defensible action.

The method connects the business consequence to the capabilities, dependencies and evidence that determine what the organization should do next.

01

Select a critical service

Set a boundary narrow enough to assess.

02

Decide required outcomes

Define why control matters.

03

Test operational capabilities

Ask what must remain possible.

04

Examine dependencies

Trace controls across domains.

05

Require evidence

Separate claims from demonstration.

06

Determine posture & action

Close the consequential gap.

Control is relational—not a checklist.

Select a layer to see how OSAF changes the lens while keeping the same critical service at the centre.

Active lens
Business outcome
Privacy & compliance
Continuity & resilience
Supplier choice
Strategic flexibility

An outcome connects to every capability materially required to achieve it. OSAF does not assume fixed one-to-one mappings.

How much operational control is demonstrated?

The levels are cumulative. The first unsatisfied critical requirement caps the achieved posture.

OS-2

Business Continuity

Recovery and continuity mechanisms are implemented and tested, although important activities may still depend on the provider.

The goal is not always OS-4. The appropriate target depends on the service and business consequence.

Measure what can be demonstrated—not simply what is claimed.

Choose a stage to see how assurance strengthens as a control moves from assertion to exercised evidence.

Tested

The control has been exercised against a defined scenario and acceptance criteria.

Operational sovereignty becomes visible when dependencies change.

Verified events show how technical, legal, identity and supplier dependencies can alter what an organization is able to do.

Operational · Supplier

A shared software dependency concentrates recovery risk

A faulty CrowdStrike update became a common-mode operational dependency across organizations and sectors.

Legal · Supplier

A legal order can become an operational shutdown

A legal action outside the operator's direct control restricted ZTE's access to critical technology supply.

AI · Access

Model access can change by policy, not by outage

A government directive changed who could use selected advanced Anthropic models.

How much control does your critical service actually have?

Start with one bounded service. Examine what must remain possible. Require evidence. Identify the gap.