Structured as five phases with explicit exit criteria, so progress is demonstrable rather than asserted.

Includes a stakeholder communication template and a RAID log pre-populated with the risks that materialise on most programmes — legacy application exceptions, identity provider single points of failure, and service desk load during migration waves.