Legacy Systems Risk & Replacement Register (LSRR)
Make legacy-systems assurance a live, connected model — from the legacy system and the business services that depend on it, through its obsolescence, risks and compensating controls, to the replacement initiative that will retire it and the controlled retirement itself.
Its central question:
For each legacy system, what business services depend on it, how obsolete and risky is it, what compensating controls hold the line, what is the replacement doing about it — and is there an authorised, evidenced path to safely retire it?
It sits beside the agency's CMDB, risk register and project portfolio — it owns the legacy-risk-to-retirement view: the dependency → obsolescence → risk/control → replacement → cutover → retirement spine.
The assurance spine
Entity / Legacy System → Business Service / Service Dependency / System Dependency → Obsolescence Assessment → Risk → Compensating Control → Evidence → Replacement Initiative → Milestone / Dependency / Cutover Readiness → Retirement Plan → Assurance Decision, with a Status History trail on each system.
The documents
| Page | What's in it |
|---|---|
| 00 — Overview | What the app is, the domain, the 17 models by area, the demo scenario |
| 01 — Quick Reference | Menu map, every model, key status vocabularies, the demo data set |
| 02 — System Diagram | The legacy-risk-and-replacement data model as a diagram (+ interactive viewer) |
| 03 — Phase 2 Scope | The runtime not yet built: the lifecycle state machine, obsolescence scoring, retirement guards and the DomainEvents outbox |
Status
Phase 1 (built): all 17 models render as an AI-Safe CRUD register with a dashboard, seeded with one coherent QAO-style legacy-risk scenario (26 rows) — an unsupported critical Case Management System with mitigated security risk, a mid-flight replacement and a conditional assurance decision toward controlled retirement.
Phase 2 (scoped, not built): the system lifecycle state machine, obsolescence scoring,
the retirement guard rules (readiness READY, evidence accepted, retirement checklist
confirmed), evidence versioning, and the DomainEvent outbox — see page 03.
Prototype system; draft. All entities, systems, services, risks, controls and decisions in the demo data are fictional; values demonstrate structure only and are not real audit findings.