Last updated: 23 July 2026. View change log.
This Annex sets out the principles governing risk acceptance, deviations from recommended standards, and continued service delivery where you or End Customers choose not to follow our recommendations.
This Annex is generic and procedural. Any specific risk acceptance or deviation must be recorded separately, typically through a Partner Order, written confirmation or operational record.
1. Purpose
- We may identify technical, security, compliance or operational risks during onboarding or service delivery.
- In some circumstances, you or an End Customer may choose not to implement recommended actions.
- This Annex provides a framework for continuing service delivery while recording and managing accepted risks.
2. Identification of Risks
- Risks may arise from, without limitation:
- end-of-life or unsupported hardware, software or operating systems;
- lack of security, backup or monitoring services;
- configuration decisions contrary to best practice;
- third-party systems outside our control;
- regulatory or compliance gaps.
- We may document identified risks and recommended remediation steps.
3. Communication of Risk
- We may communicate identified risks and recommendations:
- directly to the End Customer;
- to you for onward communication; or
- to both, as agreed operationally.
- Risk communications may be provided verbally or in writing.
4. Risk Acceptance
- Where recommended actions are not implemented, you or the End Customer may choose to accept the identified risk.
- Risk acceptance may be recorded by:
- written confirmation;
- continued instruction to proceed despite warnings; or
- other reasonable operational records.
- Risk acceptance does not oblige us to provide services beyond agreed scope.
5. Effect on Service Delivery
- Where risk is accepted, we may:
- continue support on a best-efforts basis;
- apply limitations to service scope or response;
- exclude certain incidents from support;
- require additional charges; or
- require remediation as a condition of continued service.
- We are not responsible for failures, incidents or losses arising from accepted risks.
6. Review and Escalation
- We may review accepted risks from time to time.
- Where risk increases or circumstances change, we may reissue recommendations or escalate the matter.
- Continued service delivery remains subject to our right to suspend or withdraw services under the Partner Agreement.
7. Regulatory and Legal Considerations
- You and the End Customer remain responsible for compliance with applicable laws, including data protection and regulatory obligations.
- We do not take responsibility for compliance failures arising from accepted risks.
8. Order of Priority
- If there is a conflict between this Annex and the Partner Agreement or Schedules, the Partner Agreement and Schedules prevail.
- If there is a conflict between this Annex and a Partner Order, the Partner Order prevails.