A step-in operating review determines whether the supplier can support a buyer or its authorized third party taking temporary control of specified service activities under the issued contract. The work product links each trigger and notice to the control boundary, retained supplier duties, access arrangements, dependencies, action records, financial treatment and evidence needed to return control. It prepares a tender decision. It is not an exercise of the right, a legal finding of default or permission to enter a system.
The contract lets the buyer take control of part of the service during an emergency. The proposed platform uses shared administration, the subcontractor recognizes only the supplier’s operators, and two teams could update the same work queue. The bid accepts the clause because there is a continuity plan. That plan does not say who may direct the work, how conflicting instructions are prevented, which costs the supplier still bears or how the supplier resumes safely.
Review the temporary change in control, not just the disruption that prompted it. A continuity answer explains how service continues; an audit-rights review concerns inspection and evidence; exit assistance supports a departure. This dossier owns the feasibility of intervention and return within the proposed operating arrangement. Sources were checked on 6 September 2026. The UK model provides contractual examples, while NIST publications inform security and recovery design. Neither substitutes for the issued terms or creates authority. All Aldermere events, sums and operating details below are fictional.
The trigger and the allegation of fault are separate facts
Extract the events that permit intervention before designing access. A clause may cover serious nonperformance, an emergency, advice from a regulator, a safety risk or the buyer’s statutory duty. Record any required notice, cure opportunity, decision standard, scope limit and urgency exception. Do not import a cure period from the termination clause unless the step-in mechanism actually uses it. Conversely, an urgent operational problem does not by itself establish the contractual power to take control.
The England and Wales Model Services Contract version 2.2A shows why cause must remain explicit. Its Schedule 1 definition includes supplier-related triggers and circumstances where the authority considers there is an emergency despite no supplier breach. It also addresses regulatory advice, serious safety risks and statutory duties. Core clause 28 asks the notice to identify the trigger and whether the authority believes the action is due to the supplier’s default. That belief and the underlying evidence are not the same record.
Create separate fields for the reported event, the contractual provision relied on, the issuer’s stated position and the supplier’s verified facts or disputed points. Counsel owns the legal assessment. Record the issue and escalate it through the contract’s route without inventing a right to obstruct valid intervention while a cost or fault dispute continues. If a notice appears incomplete, identify the missing information and obtain advice; the review should not pronounce it invalid by applying a checklist mechanically.
This is also a distinction from an audit. An auditor may inspect evidence without operating the service. A step-in operator may need to direct work or change service state. Neither role automatically inherits the other’s rights. The review must identify the relevant actor and power rather than describing all buyer-appointed personnel as approved administrators.
Define what changes hands and what the supplier must keep doing
The useful control boundary is usually smaller than the whole contract. List the activities, service populations, interfaces and work items affected. For each, distinguish authority to direct work, authority to approve a consequential decision, permission to execute the action and responsibility to record its result. Do not let a generic responsibility chart hide two people who can both order an incompatible change. The event record needs an effective time and a rule for resolving conflicting instructions.
In the fictional Aldermere case, a buyer-appointed operator would direct one case-processing queue during an emergency. The supplier would still run the intake service and a separate customer-support queue. Their shared interface makes the boundary material: a change to the controlled queue’s routing could affect intake. The review therefore requires a named change coordinator and a recorded approval path for cross-boundary changes. It does not assume that taking over the queue gives the operator unrestricted control of the shared platform.
Core clause 28 of the UK model requires the notice to describe the action, services to be controlled, intended start and period, premises access and anticipated impact where practicable. During the action it addresses records, information to the supplier and reasonable cooperation so unaffected services continue. It also includes consequential additional action reasonably believed necessary for the required action. Review any such extension of scope explicitly: the first activity list cannot be treated as an immutable limit if the contract says otherwise.
The same model relieves the supplier of providing services only for as long as and to the extent they are subject to the required action. It is not a blanket suspension of the contract. Keep retained operations, incident reporting, protected information, cooperation and any other continuing duties on the operating calendar. Identify staff and dependencies for them before offering the buyer the right. A partial intervention may add coordination work instead of freeing the whole team.
| Activity | During the proposed intervention | Boundary to resolve | Evidence for return |
|---|---|---|---|
| Controlled case queue | Buyer-appointed operator directs the listed queue | Exact population, effective time and approval of consequential decisions | Queue state, decisions and pending work reconciled |
| Intake service | Supplier continues operation | Routing changes must not interrupt retained intake | Interface tests and named operating owner |
| Platform changes | Only authorized executors implement approved changes | One change coordinator resolves competing instructions | Approved configuration and complete change history |
| Incident communications | Named lead coordinates facts and required notifications | Intervention status does not settle every legal reporting role | Open incident actions assigned and reporting record preserved |
| Access and evidence | Scoped operator access with protected action records | No shared administrator credentials or access to other customers | Required access revoked or reauthorized, evidence retained |
A buyer’s contractual right still needs an operable access arrangement
Follow the proposed operator through the supplier chain. Which entity owns the platform, licenses the software, controls the site and can create the required account? Does the subcontract permit the buyer or its appointee to direct the relevant service? Does a licence allow the necessary use during the intervention? Core clause 15 of the UK model includes a step-in provision among its required key-subcontract terms, on substantially the same terms as clause 28. Read the issued flow-down obligation and the actual upstream agreement together rather than relying on a provider’s general security certificate. Check confidentiality commitments for the appointee too: model clause 28 permits the supplier to require an undertaking equivalent to clause 19 from an assisting third party.
For Aldermere, the hosted platform presently recognizes only supplier-employed operators. Its customer-specific permission route has not been approved for a buyer-appointed third party. That is a material dependency. The proposed solution may be an agreed operator status, scoped access arrangement or another authorized delivery design. None can be claimed complete until the relevant provider and internal owners confirm it. The main contract may make the supplier responsible for obtaining the right; that does not mean the right already exists.
NIST SP 800-207 explains that network location or asset ownership alone does not confer implicit trust, and treats authentication and authorization as distinct functions. Apply that distinction to the intervention design: verify who the operator is, what decision authorizes the role and which resources and actions the role covers. The contractual event is an input to that authorization process. It is not a reason to publish credentials or reuse an untraceable administrator identity.
Prepare an approved emergency access route that can work within the actual notice conditions. Security controls should enable valid exercise of the right while protecting unrelated services; they must not become an invented contractual veto. Define the accountable person who can activate the route, the scoped permissions, expiry and evidence. Test using synthetic records or another specifically authorized environment. A public article or tender review must not expose private topology, keys, customer data or operational bypass instructions.
Keep one action history while different parties operate
Before control moves, capture an authorized baseline of configuration, open work, current incidents, access and relevant service measurements. During intervention, record the instruction, its issuer, executor, time, affected object, approval where required, result and exception. The purpose is to reconstruct what happened and what must be handed back. Store the evidence under appropriate access and retention controls. Logging does not justify collecting unrelated personal information or making sensitive logs public.
NIST SP 800-53 Revision 5 provides useful control references: AC-2(2) for automatic expiry of temporary or emergency accounts, AC-6 for least privilege, AU-9 for protection of audit information and CM-3 for configuration change control. The current publication page also identifies Release 5.2.0. These are controls to select and tailor, not a claim that every enhancement is mandatory for every bidder. They do not create the buyer’s legal right. Use them to test whether the proposed intervention can be attributable, bounded and reviewable.
Name an incident lead where intervention overlaps a security event, and reconcile that role with the contract’s operational decision-maker. NIST SP 800-61 Revision 3 connects incident response with relevant third parties, incident status and criteria for starting recovery. Those practices help avoid two teams pursuing incompatible actions, such as changing service state while another team preserves evidence. The specific action still needs the authority appropriate to its consequence and the governing incident plan.
When the operator needs more scope, preserve the request and the contractual basis for the additional action. Update the control map, permissions and retained-service impact through the applicable process. For an emergency process that permits immediate action, retain the authorized decision and subsequent review instead of fabricating prior approval. Unclear legal or safety conflicts belong with the designated escalation roles. The review is complete only when the organization can explain how it handles that conflict, not when every row says cooperation.
Model the payment mechanism without assuming the costs disappear
Read the intervention-specific financial provisions beside the service-credit and general charging clauses. Identify which services are relieved, which deductions remain possible, how buyer intervention costs are treated and when any supplier expense becomes reimbursable. The UK model excludes deductions for services subject to the required action during that action, while providing for other deductions and subtraction of the authority’s intervention costs. It also addresses demonstrated adverse effects on other services and has cause-dependent reimbursement provisions. This is not a universal rule that the buyer bears every emergency cost.
Aldermere’s fictional calculation uses one fixed monthly billing window with GBP 200,000 of gross charges. Continuing supplier costs are GBP 140,000 in both branches because the stated staffing and licence commitments remain payable; no saving is evidenced. The ordinary branch assumes ten working days of intervention inside that window, GBP 28,000 of buyer costs permitted to be subtracted, GBP 4,000 of valid deductions on retained services and GBP 18,000 of extra supplier cooperation and return work. The latter is GBP 12,000 for cooperation plus GBP 6,000 for handback.
Under those explicit fictional terms, payment is GBP 168,000 and contribution after the stated costs is GBP 10,000. The no-intervention comparison is GBP 60,000 before these extra costs or adjustments, so the difference is GBP 50,000. For fifteen working days within the same billing window, assume buyer costs of GBP 42,000, retained-service deductions of GBP 6,000 and supplier additional costs of GBP 27,000. Payment becomes GBP 152,000 and contribution negative GBP 15,000, a GBP 75,000 reduction from the comparison. No task is charged twice in this example.
The table does not quantify damages, disputed invoices, insurance recovery, changes to later billing periods or a right to extra reimbursement. Keep those outside the settled calculation until evidence supports their treatment. Record any actual avoidable costs separately rather than assuming the supplier saves the entire controlled service’s cost. Show when invoices, set-offs and payments occur: a favourable legal view about later reimbursement is not cash available to fund today’s cooperation. Finance and counsel must agree the actual mechanism before the bid accepts it.
| Item | Ten working days of intervention | Fifteen working days of intervention |
|---|---|---|
| Gross charges | 200,000 | 200,000 |
| Permitted buyer intervention cost subtraction | 28,000 | 42,000 |
| Deductions on retained services | 4,000 | 6,000 |
| Payment after those adjustments | 168,000 | 152,000 |
| Continuing supplier costs | 140,000 | 140,000 |
| Additional supplier cooperation and return costs | 18,000 | 27,000 |
| Contribution after the stated costs | 10,000 | -15,000 |
| Reduction from the 60,000 comparison contribution | 50,000 | 75,000 |
Return control from the state that exists, not the state in the old runbook
Intervention may change configuration, procedures, work queues and access. The supplier needs the actual action history and the resulting state before resuming. Compare the original baseline with approved and emergency changes, reconcile in-flight transactions and assign unresolved incidents and backlog. Decide which changes become the accepted operating baseline and which need correction. A rollback to an old snapshot may discard legitimate work completed during intervention; do not treat rollback as a synonym for handback.
UK model clause 28 requires a step-out notice describing the action taken and the proposed date, subject to the authority being satisfied with the supplier’s ability to resume and its plan. The supplier must develop the draft plan for approval not less than 20 working days before the step-out date. That model-specific requirement demonstrates why a date alone is insufficient. If the issued timetable conflicts with the proposed incident scenario, flag the interpretation and planning issue rather than promising an impossible sequence.
NIST SP 800-61 Revision 3 calls for checking restored assets and confirming operating status, with criteria for declaring recovery complete. Use an appropriate evidence set for the actual service: configuration review, integrity checks, representative service transactions, performance observation and confirmation from the responsible owners. A tabletop discussion verifies decision paths, not live recovery. A technical restoration test does not by itself prove contractual acceptance of return.
For Aldermere, the return record still needs the buyer-approved plan, verified queue reconciliation and proof that the interface operator permissions can be withdrawn without disabling the retained service. A return rehearsal must also show that named supplier staff can perform the current procedure. Agree the effective control-transfer time, preserve relevant evidence and close or reauthorize intervention access in the approved sequence. Residual support, claims or investigation can remain open after operating control changes.
| Condition | Required evidence | Who must decide | Current review state |
|---|---|---|---|
| Current operating state is known | Action history, configuration differences and incident register | Service and change owners | Evidence design required |
| Work is reconciled | Controlled queue, intake interface and unfinished items agree | Business service owner | Acceptance test not yet approved |
| Supplier can resume | Named trained staff and successful scoped rehearsal | Supplier service director | Capability demonstration pending |
| Contractual return is approved | Valid notice, approved plan and effective transfer time | Authority identified in the issued contract | Future approval required |
| Temporary access is closed safely | Revocation or reauthorization record and retained-service check | Security and operating owners | Provider permission dependency open |
Make the bid decision on the unresolved operating gaps
Build a versioned step-in operating record with the tender, bidder, lot, service design and current document baseline. For each relevant trigger, attach the notice requirements, control map, access and supplier-chain evidence, retained-service assessment, action-record design, financial branches and handback conditions. Each unresolved item needs an owner, next evidence, decision date and consequence for the offer. Keep protected material under controlled references; the public-facing answer should explain the method without revealing live access paths or confidential arrangements.
Aldermere’s current disposition is hold for design and commercial review. The platform provider has not authorized the proposed third-party operator, the cross-boundary change process is not agreed and the return criteria have not been demonstrated. Finance can inspect the GBP 50,000 and GBP 75,000 contribution reductions but has not accepted them. The model is a useful decision artifact precisely because it identifies these unfinished conditions instead of claiming the right can already be supported.
Possible treatments include an approved service-design change, a confirmed upstream right, an accepted control procedure, a permitted clarification or a departure allowed by the procurement. Do not assume post-award negotiation will cure a material gap. Where unconditional acceptance is required and a necessary right remains unavailable, escalate whether to bid. A commercial risk sign-off cannot authorize access held by another entity, and a security recommendation cannot alter the buyer’s contractual right unilaterally.
Bind the final decision to the technical answer, price and accepted contract position. Reopen it when the nominated operator, provider terms, architecture, service population, law, incident route or issued documents change. An assistant may compare authorized clauses, draft the maps and calculate disclosed assumptions. It must stop before giving notice, contacting the buyer, obtaining credentials, granting access, directing staff, changing live service or accepting liability without the relevant authority. The next safe step is the named review action recorded against the unresolved condition.
What good looks like
Useful outcomes from review buyer step-in rights in a tender
- Each intervention has a documented legal and operational basis without assuming fault.
- Control is allocated by activity so the supplier can continue the unaffected service.
- Authorized operators can obtain the necessary access without exposing other customers or shared credentials.
- The commercial model separates buyer costs, supplier costs, service deductions and unresolved compensation.
- Handback depends on a verified state and the contract’s approval process, not merely a date.
Operating model
How to run the work
- 01
Read the intervention mechanism
Collect definitions, triggers, notices, control rights, cooperation, supplier-chain duties, security, charging and return provisions. Fix the versions, affected services and governing priority.
- 02
Allocate operational decisions
Map each activity to the person directing, executing, approving and recording it before, during and after intervention. Preserve unaffected supplier responsibilities and resolve overlapping instructions.
- 03
Test access and dependencies
Identify the people, assets, premises, data and permissions required. Confirm provider consent, scoped access, emergency authorization and evidence protection without executing a live takeover.
- 04
Model financial branches
Calculate payment and continuing costs for stated scenarios. Keep relief, deductions, buyer intervention costs and any reimbursement claim separate until their contractual treatment is supported.
- 05
Define return evidence
Specify the action history, configuration and data checks, backlog ownership, service tests, access revocation and approvals needed for the supplier to resume each activity.
- 06
Decide the tender commitment
Resolve material gaps or use the permitted clarification route. Obtain legal, security, operational and commercial decisions, then reconcile the approved position with the final offer.
Evaluation
Questions that change the decision
- Does this clause allow intervention without a supplier breach?
- Which service decisions move to the buyer and which remain with the supplier?
- Can the nominated operator obtain the required rights through the supplier chain?
- Who can approve an emergency action and how is that decision recorded?
- Which payments or costs change, for what period and on what evidence?
- What must be proved before control returns?
Failure modes
Where teams lose control
The bid treats intervention as proof of default although the trigger may be an external emergency.
Both operating teams issue instructions to the same activity without one recorded decision owner.
Privileged access reveals another customer’s records or bypasses a provider’s contractual limits.
The supplier assumes all service obligations or costs disappear during partial control.
Unapproved reimbursement is entered as available cash.
The supplier resumes from an undocumented state and removes access before unfinished work is transferred.
Measurement
Measure the finished job
Measure the completed workflow, including review effort and exceptions. Output volume on its own is not evidence of a better process.
- Controlled activities with one recorded operational decision owner
- Retained activities with confirmed staffing and performance responsibility
- Necessary operator permissions supported by current agreements
- Intervention actions with source, time, actor and result evidence
- Financial adjustments awaiting cause or approval evidence
- Handback conditions still open at the proposed return time
Questions
Common questions
Does step-in mean the supplier has been found at fault?
Not necessarily. The issued definition may include an emergency, regulatory advice or another trigger unrelated to breach. Preserve the event, the buyer’s stated basis, verified evidence and any disputed cause separately. Counsel determines the legal effect.
Does the supplier stop all work during intervention?
Only if the contract and actual control boundary support that conclusion. Partial step-in can leave most operations, cooperation and reporting duties with the supplier. Record responsibility by activity and effective time rather than assuming a whole-contract suspension.
Can the buyer’s appointee use the supplier’s administrator account?
Do not assume so. Verify contractual rights and provider permissions, then design attributable, scoped and time-bounded access. Shared credentials can conceal actions and expose unrelated services. The access design must support valid rights without inventing a veto.
Who pays the intervention costs?
The issued mechanism governs. It may distinguish buyer costs, continuing charges, service deductions and cause-dependent reimbursement of supplier expenses. Calculate each separately and preserve disputes. A default contingency percentage cannot establish the payment result.
Is the planned end date enough to resume control?
No. Read the notice and approval provisions and establish the current service state. Handback may require an approved plan, reconciliation, staff readiness, service tests and controlled access changes. An old runbook or restored backup does not prove those conditions.
What can an agent prepare before the bid is approved?
A source-linked trigger inventory, control map, dependency review, calculation and proposed handback evidence list using authorized inputs. It must keep unresolved conditions visible and avoid external contact, access changes, operational instructions or commitments without authority.
Sources
Primary references
- Model Services Contract v2.2A, core clauses 15 and 28 UK Cabinet Office and Government Legal Department
- Model Services Contract v2.2A, Schedule 1 step-in definitions UK Cabinet Office and Government Legal Department
- NIST SP 800-207: authentication, authorization and resource access National Institute of Standards and Technology
- NIST SP 800-53 Revision 5: access, evidence and change controls National Institute of Standards and Technology
- NIST SP 800-61 Revision 3: coordinated response and verified recovery National Institute of Standards and Technology
Zelius
Managed tender intelligence and bid execution for teams that want the commercial outcome.
Suppliers, founders and commercial teams pursuing public or private opportunities. Start with the workflow, constraints and evidence you already have.