PROVIDER RISK REGISTER — Yenra, September 5, 2026 An operational worksheet, not a legal checklist or a probability model. SERVICE REVIEW Service outcome, scope, hours, volumes, exclusions: Internal owner and decision authority: Realistic in-house alternative and current weaknesses: Critical data, accounts, dependencies, subcontractors: Normal-month / busy-month / first-year / exit costs: Unacceptable conditions that rule out this arrangement: Review date and change triggers: FICTIONAL EXAMPLE ENTRY Risk: Only the provider has the current recovery runbook. If its team is unavailable, we cannot begin the documented restore process ourselves. Evidence: A demonstration referenced a document the customer could not access. Impact: Recovery could exceed the business's agreed tolerance. Likelihood: Not yet assessed; investigate access and recovery arrangements. Action: Provide a customer-accessible runbook and run an authorized restore test. Owner: Internal service owner, with provider recovery lead. Due: Before service acceptance. Validation: Named customer backup follows the runbook; restore results recorded. Residual risk: Record after test; do not mark closed based only on a promise. BLANK ENTRY — copy for each risk ID / service / review date: Cause -> event -> business consequence: Evidence, source, date, scope, and uncertainty: Likelihood description and reasoning: Impact description and recovery tolerance: Existing control and evidence it works: Action / owner / due date: Validation test and result: Remaining risk and acceptance authority: Status / next review trigger: EXIT REHEARSAL Export data, attachments, relationships, configuration, and documentation: Who can use the export? Test result: Transition assistance, overlap, fees, and deadlines: Account / domain / credential transfer and revocation: Return or deletion evidence, subject to applicable preservation requirements: Fallback if transition fails: Source: https://yenra.com/outsourcing-risks/