Canonical methodology reference

Responsible Cloud Methodology

A structured approach to making technology risk reduction visible, prioritized, accountable, and provable.

The Responsible Cloud Methodology is developed and maintained by Responsible Cloud LLC.

Methodology version

Current versionv1.0
Publication dateAugust 14, 2026
MaintainerResponsible Cloud LLC
StatusCurrent

Change history: v1.0 is the initial public release of the six-phase methodology. Version numbers change only for substantive changes to phases, definitions, or expected outputs — not for wording, accessibility, navigation, or design edits. View the full public change log →

Citation guidance: When referencing this methodology, cite the version you used: Responsible Cloud LLC. Responsible Cloud Methodology (Version 1.0). Published August 14, 2026. https://responsiblecloud.com/methodology.html. Because the methodology can change between versions, citations should include the version number and either the publication date or the access date.

The Responsible Cloud Methodology turns technology risk from an observation into an accountable, documented improvement process. Six phases below are documented in full — each shown here by its short name (used elsewhere on this site) alongside its formal name in this reference.

Phase 1

DiscoverFormal name: Discovery

Purpose: Establish a reliable, current baseline of what the organization uses, depends on, and is responsible for, before any risk judgment is made.

Inputs
Existing technology information, vendor information, interviews and questionnaires, available policies and records.
Activities
Inventory; dependency identification; ownership discovery; criticality identification.
Decisions
What counts as in-scope; how much existing documentation can be trusted versus re-verified; which systems are treated as critical pending further review.
Outputs
Technology inventory; SaaS and vendor inventory; AI-use inventory; initial ownership map.
Evidence produced
Dated inventory records; the source of each entry (interview, system export, document); noted gaps where information could not be obtained.
Responsible parties
Client stakeholders provide access and information. Responsible Cloud LLC, when engaged, facilitates collection and structures the baseline. The client retains ownership of the underlying systems and data.

Relationship to the next phase: The Discovery baseline is what Risk (Assess) works from — nothing can be assessed that was not first discovered, and any material gap identified here becomes a documented limitation carried into Risk rather than a silently assumed absence of risk.

Phase 2

AssessFormal name: Risk

Purpose: Convert the Discovery baseline into risk stated in business terms — what could go wrong, and why it matters to the organization, not just to a technical control.

Inputs
The Discovery-phase inventory and ownership map; existing safeguards and policies; known incidents or near-misses; applicable external guidance where relevant.
Activities
Review conditions and existing safeguards; connect technical issues to business consequences; separate missing evidence from confirmed gaps; record scope and uncertainty.
Decisions
Whether an observed condition is a confirmed gap or an evidence gap; how a technical condition translates to business risk; what is explicitly out of scope for this assessment.
Outputs
Findings; risk observations; control gaps; evidence gaps.
Evidence produced
A findings register connecting each risk statement to the underlying observation and, where available, supporting evidence, with uncertainty explicitly noted rather than assumed away.
Responsible parties
Responsible Cloud LLC, when engaged, or the internal team applying the methodology performs the assessment. The client validates the factual accuracy of findings before they proceed to Prioritization.

Relationship to the next phase: Every finding carries into Prioritization already stated in business terms — Prioritization does not re-litigate whether something is a risk, only how urgently it should be addressed relative to everything else on the list.

Phase 3

PrioritizeFormal name: Prioritization

Purpose: Turn an unordered list of risk findings into a defensible sequence of action the organization can actually resource.

Inputs
The Risk-phase findings register; business context such as budget cycles, dependencies, and upcoming initiatives; available effort and cost estimates.
Activities
Compare urgency and business impact; identify quick, meaningful improvements; account for cost, effort, and dependencies; record why work is sequenced or deferred.
Decisions
Relative ranking of findings; what is addressed immediately versus deferred; what is accepted as residual risk for this cycle.
Outputs
Prioritized findings; recommended sequence; immediate actions; deferred risks.
Evidence produced
A documented rationale for each prioritization decision, including deferrals, so a deferred risk is a recorded decision rather than a silent omission.
Responsible parties
Responsible Cloud LLC, when engaged, or the internal team proposes the sequence. Accountable leadership within the client organization approves or adjusts it before Accountability/RACI begins.

Relationship to the next phase: A prioritized item without a named owner is not yet actionable — Accountability/RACI exists specifically to close that gap for every item that survived Prioritization.

Phase 4

AssignFormal name: Accountability / RACI

Purpose: Ensure every prioritized finding has a named, accountable owner before any remediation work begins — turning a prioritized list into assigned responsibility.

Inputs
The prioritized findings and sequence from Prioritization; the organization's existing decision-making structure.
Activities
Name the accountable decision owner; identify the responsible person or provider; apply RACI or another right-sized ownership model where useful; set dates and decision points; record accepted or deferred risk.
Decisions
Who is Accountable versus Responsible for each item; whether a role can be filled internally or requires an outside provider; target dates.
Outputs
Named accountable owner; responsible party; due date; decision status; accepted or deferred risk where applicable.
Evidence produced
A RACI record or equivalent ownership record for each item, dated and attributable to a specific decision-maker.
Responsible parties
Client leadership makes and owns the final accountability assignment. Responsible Cloud LLC, when engaged, facilitates the RACI exercise and documents the outcome — it does not assign accountability on the client's behalf.

Relationship to the next phase: Guardrails and Remediation only proceeds against items that already have a named owner — this phase is the gate between knowing what to do and someone being responsible for doing it.

Phase 5

ReduceFormal name: Guardrails and Remediation

Purpose: Implement practical, right-sized safeguards and corrective action against assigned items — reducing risk without assuming every risk must or can be eliminated.

Inputs
The accountability record from Accountability/RACI; the organization's operational and budget constraints.
Activities
Select a treatment for each item — mitigate, transfer, avoid, accept, or monitor; implement the corresponding guardrail, policy, or technical change; record the decision and its rationale.
Decisions
Which treatment applies to each item; what "right-sized" means for this organization; what residual risk remains acceptable after treatment.
Outputs
Remediation actions; guardrails; policy or process changes; technical changes; residual-risk decisions.
Evidence produced
A record of the action taken, who took it, when, and what it changed — the raw material the next phase reassesses against.
Responsible parties
The named responsible party from Accountability/RACI carries out or oversees remediation. Responsible Cloud LLC, when engaged, may advise or verify specified implementation evidence when that is expressly within the agreed scope.

Relationship to the next phase: Executive Reporting and Evidence exists to reassess exactly what changed here and document it — remediation that is never reassessed is a claim, not a proven improvement.

Phase 6

ProveFormal name: Executive Reporting and Evidence

Purpose: Reassess the treated condition, document what changed, and report it to leadership in a form that is provable — meaning documented and traceable, not merely asserted.

Inputs
The remediation record from Guardrails and Remediation; the original finding and risk statement from Risk.
Activities
Reassess the relevant finding; capture the original condition and risk, the action taken, the accountable owner, and supporting evidence; complete the reassessment result, remaining or residual risk, date, and next review point; prepare executive-level reporting.
Decisions
Whether the reassessment shows the condition resolved, partially resolved, or unresolved; what remains as residual risk; when the next review is due.
Outputs
A completed Risk Reduction Record; an executive-ready summary of what changed; a documented next review date.
Evidence produced
The Risk Reduction Record itself: before/after condition, accountable owner, supporting evidence, reassessment result, and residual risk — dated and traceable back to the original Discovery and Risk findings.
Responsible parties
The accountable owner confirms the reassessed condition. Responsible Cloud LLC, when engaged, may facilitate or verify specified evidence when that is expressly within scope. Leadership receives and reviews the executive report.

Relationship to the next phase: Executive Reporting and Evidence closes this cycle and feeds the next one — its output becomes part of the baseline the next Discovery phase starts from, at whatever cadence the organization sets.

Create a Risk Reduction Record Learn what counts as evidence →

External frameworks and guidance

Built to incorporate recognized guidance, not to replace it.

The Responsible Cloud Methodology is designed to incorporate established external frameworks and guidance where appropriate to a specific organization or engagement — for example the NIST Cybersecurity Framework (CSF) 2.0, the NIST AI Risk Management Framework (AI RMF), CISA Cybersecurity Performance Goals, cloud-provider shared-responsibility models such as those published by AWS, Microsoft, and Google, and other governance frameworks relevant to the organization's industry or regulatory context.

Responsible Cloud LLC does not own, control, certify, or speak on behalf of any of these external frameworks. Reference to them does not imply endorsement, certification, formal affiliation, audit assurance, or guaranteed compliance with any of them. Where a specific engagement maps to one of these frameworks, that mapping is documented as part of that engagement's own scope and evidence.

Boundaries

Applying this methodology does not itself establish certification, regulatory compliance, guaranteed security, breach prevention, independent validation, or elimination of risk. Conclusions are limited by scope, available information, evidence quality, and the specific reassessment performed.