Control areaScoped relationship register
Partnerships & certifications
Commercial designations, platform relationships, registrations and third-party assurance
A partner relationship, product access, registration and certification are treated as different evidence types. Public wording and logo use require an identified issuer, scope, holder, validity date and approval to publish.
- Evidence status
- Named relationship cards on this page are scoped first-party statements or linked public routes. They are not security certifications or independent assurance and still require current programme evidence for procurement reliance.
- Customer review
- Request the exact designation or document needed for a procurement decision; disclosure may be controlled by confidentiality and purpose.
Control areaEngagement-specific scope
Platform reliability
Availability targets, dependencies, monitoring, maintenance and recovery responsibilities
Discovery should identify critical journeys, provider dependencies, monitoring signals, support ownership, planned maintenance and recovery expectations before a production commitment is made.
- Evidence status
- No universal uptime percentage, response time or recovery objective is published on this page. Applicable targets and remedies must be documented in the relevant proposal, order form or service-level agreement.
- Customer review
- Ask for the proposed architecture, dependency map, support path and service levels for the selected product and delivery model.
Control areaControl overview
Security & privacy architecture
Data flows, access, retention, administrative controls and deployment responsibilities
The delivery review should document the intended data flow, purpose, access roles, system boundaries, retention needs and customer/provider responsibilities. Website controls and customer service controls have different scopes.
- Evidence status
- The public website implementation includes role-based administration, prepared database access, audit logging and private résumé delivery when correctly configured. This statement is not a security certification or an assurance report for every customer service.
- Customer review
- Request a product-specific security and privacy review and confirm controller, processor, hosting and retention responsibilities before launch.
Control areaOperating guidance
DLT & acceptable use
Indian business messaging readiness, consent, templates, sender identity and channel/provider rules
Implementation planning should account for the registrations, templates, consent records, sender configuration and usage restrictions applicable to the chosen channel and use case.
- Evidence status
- EASY SERVE may support operational preparation, but does not present this page as regulatory approval or legal advice. Eligibility and compliance remain dependent on current law, provider policy and the customer’s actual communication.
- Customer review
- Confirm the current DLT, telecom, platform and acceptable-use requirements with the relevant authority, provider and qualified adviser.
Control areaContract-specific control
Incident communication & service levels
Support intake, severity, escalation, updates, post-incident review and contractual remedies
A production engagement should identify contact routes, severity definitions, responsible teams, escalation steps, update expectations and the boundary between EASY SERVE, customer and upstream-provider actions.
- Evidence status
- This page does not publish a blanket incident response time or SLA. Commitments apply only when stated in the executed commercial and support documents for that service.
- Customer review
- Review the support schedule, escalation matrix, provider dependencies and service-level terms before approving production use.
Control areaPolicy statement
Responsible AI
Approved knowledge, human oversight, exception handling, testing and monitoring
AI-assisted journeys should have a defined purpose, approved sources, access boundaries, test cases, human handoff and a route to correct or stop unsuitable behaviour.
- Evidence status
- This is an operating principle, not an AI certification or a claim that automation is error-free. Controls must be designed and tested for the actual model, tools, data and risk context.
- Customer review
- Request the proposed knowledge sources, decision boundaries, human review points, logging approach and acceptance tests for the intended journey.