

THE DIGITAL GOVERNANCE CASE FILES
True stories… or almost.
Situations inspired by real-life cases that shed light on the often-overlooked risks associated with digital assets, access, licenses, and responsibilities within organizations.

CASE FILE 003
The impossible transfer
Switching providers should be simple. Until the day the company discovers that it doesn't actually control its own digital assets.
A company decides to change its web provider, agency, IT consultant, or digital partner. On the surface, the request seems simple: transfer the necessary assets, accounts, access, and information to the new provider. But when it comes time to make the transition, several questions arise. Who has administrator access? Where are the accounts hosted? What email address were they created for? Who controls the domain, DNS, hosting, or specific platforms? Is there a complete list of assets to be transferred?
The company then discovers that a significant portion of its digital environment still depends on its former provider. Switching providers suddenly becomes a project to recover assets and regain access.
ASSET CONCERNED
Digital accounts, platforms, hosting, domain, data and administrator access
GOVERNANCE ISSUE
Asset portability, ownership, administrative control and business continuity
GOVERNANCE FINDINGS
The provider can manage a company's digital assets.
However, it should not become, by default, the only point of control .
When primary accounts, administrator access, or critical information are held solely by an external provider, the company creates an operational dependency.
The problem often arises when the relationship ends: what seemed to work perfectly becomes difficult to transfer because the ownership structure, responsibilities, and access had never been clearly documented.
Good governance should allow the company to change suppliers without losing control of its digital environment .
IDENTIFIED RISKS
Dependence on a supplier
Some operations become impossible without his collaboration.
Loss or lack of administrator access
The company may have user access without possessing the privileges necessary for transfer or administration.
Incomplete inventory of assets
Some accounts, services, domains, or platforms may be forgotten during the transition.
Interruption of services
Poor coordination can affect the website, emails, DNS, or other essential services.
Data or configuration loss
Important elements may not be included in the transfer.
Unforeseen delays and costs
A transition that was supposed to take a few hours can become a recovery project requiring several stakeholders.
Disputes over ownership or liability
When contracts and documentation are unclear, determining who controls what can become complex.
Security risk
Access points belonging to the previous provider may remain active after the end of the mandate.
RECOMMENDED MEASURES
Maintain organizational ownership of accounts
Where the platform allows, primary accounts should be registered in the company's name and associated with contact information that it controls.
Retain at least one internal administrator access
The organization should not depend exclusively on a single supplier to manage a critical asset.
Maintain a centralized registry of digital assets
Each asset should have an owner, an administrator, a responsible supplier, and documented status.
Plan for reversibility in mandates
The procedures for returning and transferring access, data and configurations should be defined from the beginning of the relationship.
Documenting the technical environment
Domains, DNS, hosting, accounts, licenses, integrations and other dependencies should be listed.
Plan the transition before revoking access
Assets must be inventoried, transferred and verified before the final closure of access from the former provider.
Perform a post-transfer check
Once the migration is complete, the old access must be removed and asset ownership confirmed.
WHAT TO CHECK IN YOUR ORGANIZATION
☐ Does the company have a complete inventory of its digital assets?
☐ Does each asset have a clearly identified owner?
☐ Does the company have at least administrator access to critical platforms?
☐ Do the main accounts use a company-controlled email address?
☐ Can the domain and DNS be managed without intervention from the provider?
☐ Can the data and configurations be exported or transferred?
☐ Do the contracts stipulate the return of access and assets at the end of the mandate?
☐ Are the integrations between platforms documented?
☐ Is there a transition procedure when changing suppliers?
☐ Will the old provider's access be revoked after the transfer?