THE SCENARIO
A regional development bank spends three years building a sovereign data platform. It chose a hyperscale cloud provider for infrastructure, a European SaaS vendor for governance, and open-source analytics for reporting. The platform passed every technical audit. It failed the sovereignty audit. When the bank tried to migrate, it discovered the governance layer had no export API, the analytics stack depended on proprietary extensions.
What are the five questions every leader must answer about their data dependencies?
Internally built systems must be tested across all five domains. Internally built systems must be evaluated across all seven layers. Internally built systems must be subject to human oversight.
The Evaluate domain builds on this foundation by asking: given that we have tested this system, what does it mean?
Part One: Understanding the Landscape
The progression from digital sovereignty challenge to a structural governance condition occurs through a subtle systematic mechanism. It begins with framing: the issue is presented to decision makers as a technical implementation challenge or a commercial efficiency opportunity rather than a sovereignty decision. The TEE Method rejects this framing categorically. This is a sovereignty issue that has digital sovereignty implications, not a digital sovereignty issue that has sovereignty implications. The distinction is structural and determinative. It determines whether the entity approaches the challenge from its governance red lines or from its operational wish list. It determines whether the chief negotiator is a technical specialist optimising for feature sets or a governance official optimising for autonomy. It determines whether the governance provisions are drafted by technical specialists who understand feature sets or by sovereignty experts who understand the architecture of technological dependency. The choice of framing is the choice of outcome. The entity that frames sovereignty as a technical problem will receive a technical solution that solves the wrong problem. The entity that frames sovereignty as a governance architecture will build the institutional capacity to govern whatever technology arrives next.
The specific provisions that drive sovereignty erosion in digital sovereignty follow a consistent pattern observed across multiple jurisdictions and decades of technology adoption. They are presented as enablers: efficiency, modernisation, compliance, standardisation, investor protection, consumer protection, innovation promotion, market access. They create structural dependencies that the adopting entity cannot easily reverse. They transfer governance authority to external parties through mechanisms that are legally binding but democratically opaque. The entity that understands this pattern before it engages can build countermeasures. The entity that discovers it after engagement has already surrendered. The pattern is not accidental. It is the structural logic of how asymmetric power converts technical capability into governance authority. The TEE Method requires entities to recognise this pattern at the earliest possible stage at the framing stage not the negotiation stage not the implementation stage and certainly not the remediation stage.
The TEE Method coordination mechanism the Sovereignty Caucus provides the only viable counterstrategy to structural framing. No single entity no matter how powerful can defeat structural framing alone. The coordinating power of dominant actors operates through divided engagement: they negotiate bilaterally they offer differentiated terms they prevent the formation of a unified coalition they use early agreements as templates for later ones they build a body of precedent that becomes the international standard. The Sovereignty Caucus defeats this strategy by forming the bloc before the negotiation begins. The Caucus operates on three principles: alignment before agreement entities develop common positions before entering negotiations stress tested against the sovereignty test matrix. Red lines before red pens: the Caucus identifies sovereignty non negotiables before any text is drafted before any concession is offered. Drafting power: the Caucus invests in the legal and technical capacity to actually write the treaty language rather than reacting to language written by others. The entity that writes the first draft sets the terms of the debate. The entity that only reacts inherits the assumptions of the drafter. This is not protectionism. It is the recognition that governance requires participation in the drafting.
The digital sovereignty sovereignty impact matrix is the tool that makes structural framing visible to political leadership without requiring technical expertise. It translates domain specific jargon into sovereignty stakes. Every provision is evaluated across the five sovereignty domains: Political Economic Cultural Intellectual Technological. The matrix identifies the mechanism of erosion and the specific countermeasure for each provision. The red flag checklist operationalises the matrix into a binary diagnostic. The eight structural sovereignty traps are not degrees of concern they are binary tripwires. Source code carve out, data flow absolutism, mutual recognition asymmetry, ISDS without governance carve out, algorithmic non discrimination overreach, digital product non discrimination, standards body capture, regulatory cooperation without sovereignty guardrails. If three or more flags trigger the agreement contains structural sovereignty traps and the nation must negotiate carve outs or refuse signature. The checklist is the tool that makes the sovereign decision binary: accept the trap or walk away.
Phased framework: Phase one Assessment weeks one to four maps every dependency across the seven layer stack completes the Sovereignty Test Matrix for each identifies sovereignty traps using the red flag checklist. Phase two Strategic Planning months two to three develops withdrawal protocols for the three highest risk dependencies identifies and pilots alternative solutions begins knowledge transfer programmes to reduce knowledge concentration negotiates contractual protections including data portability transparent pricing and genuine exit provisions builds the Sovereignty Caucus or joins an existing one. Phase three Implementation months four to twelve executes multi provider strategies for critical dependencies to prevent single provider lock in implements open format standards for all new data and workflow systems establishes continuous monitoring infrastructure for dependency indicators with automated threshold escalation conducts regular exit testing to verify withdrawal capability operationalises governance driven retraining authority. Phase four Institutionalisation months thirteen to eighteen embeds sovereignty assessment into all technology procurement and adoption decisions builds internal capacity for independent evaluation and audit develops sovereign alternatives for critical infrastructure where economically viable participates in the drafting of technology governance frameworks achieves Level three or higher on the Adaptive Governance Maturity Model for all critical systems. The framework recognises that sovereignty is not a destination it is a discipline. The same Test Evaluate Exit cycle that governs technology must govern the governance framework itself.
The TEE Method provides the architecture for governance by design. The choice is not between digital sovereignty and sovereignty it is between governance by design and governance by accident. The entity that chooses governance by design enters every engagement with its sovereignty red lines drafted its coalition aligned its drafting capacity ready its fallback positions clear its political leadership briefed on the sovereignty stakes of every provision. The entity that chooses governance by accident enters the engagement with a market access wish list and leaves with an AI governance framework it did not write dispute mechanisms it cannot win data flows it cannot govern and standards it did not write. The TEE Method provides the architecture for governance by design. The Sovereignty Caucus provides the coalition. The sovereignty impact matrix provides the map. The red flag checklist provides the compass. The phased framework provides the road. The choice belongs to those who lead. The question is not whether the next engagement will contain governance provisions it will. The question is whether the entity has built the governance architecture to negotiate from sovereignty or will simply accept the governance architecture that the engagement imposes. The answer to that question is the difference between an entity that governs its technological future and an entity that is governed by someone else’s technological past.
The seventh challenge is managing mixed sovereignty profiles. Most entities will find that they are sovereign at some layers of their technology stack and dependent at others. A government may run sovereign infrastructure on its own data centres while depending on a foreign cloud provider for disaster recovery. A corporation may have sovereign financial systems while depending on a foreign AI platform for customer service. A university may have sovereign research infrastructure while depending on commercial journal platforms for publication. Mixed profiles are not failures. They are realistic starting points. The TEE Method does not require sovereign capability at every layer immediately. It requires honest assessment of the current profile, deliberate governance of the dependency layers, strategic prioritisation of sovereignty investments, and continuous improvement over time. The entity that recognises its mixed profile honestly can plan its sovereignty journey. The entity that demands perfect sovereignty before beginning any journey will never begin. The TEE Method is designed for real entities with real constraints, real budgets, real political pressures, and real dependencies. It is a practical governance architecture, not an ideological purity test. The phased framework allows entities to begin their sovereignty journey at their current capability level and progress systematically toward greater strategic autonomy.
The eighth challenge is the cultural dimension of sovereignty. Sovereignty is not only a technical or legal condition. It is a cultural capacity. An entity that has surrendered its technological decision-making to external parties over a sustained period loses the institutional knowledge, the specialised expertise, and the governance confidence to reassert control. Cultural sovereignty requires deliberate investment in human capital, in governance education, in institutional memory, and in the narrative that frames sovereignty as capability rather than constraint. The TEE Method addresses this through the human institutional layer of the seven-layer audit, which explicitly evaluates expertise concentration, contractual constraints on staffing, and the entity capacity to operate independently. The framework also requires that sovereignty assessments be conducted by internal staff supported by external experts working to build internal capacity rather than replace it. Over time, this investment in human capital transforms sovereignty from an externally imposed requirement into an internally recognised capability. The entity that governs its technology develops the cultural identity of a governance actor rather than a compliance recipient. This cultural transformation is perhaps the most difficult but also the most durable outcome of the TEE Method process.
The ninth challenge is the temporal dimension of sovereignty governance. Technology moves in months. Governance moves in years. Treaties move in decades. This temporal mismatch is exploited by technology providers who release new capabilities before governance frameworks can respond. The TEE Method addresses this through continuous monitoring and threshold alerts rather than point-in-time assessments. The entity that assesses sovereignty once a year will always be behind the technology curve. The entity that monitors continuously can detect dependency drift before it becomes structural entrapment. This requires institutional infrastructure: automated dependency indicators, quarterly sovereignty audits, annual exit rehearsals, and governance committees with the authority to halt procurement when thresholds are breached. The TEE Method builds this infrastructure into the phased implementation framework as a permanent organisational capability, not a project deliverable.
The tenth challenge is the geopolitical dimension of technology sovereignty. Technology governance is not purely domestic. Cross-border data flows, jurisdictional arbitrage, export controls, foreign investment screening, and international standards bodies all shape the sovereignty space available to any entity. The TEE Method incorporates geopolitical awareness into the seven-layer audit by explicitly evaluating jurisdictional dependencies at each layer. Data residency requirements, cloud provider headquarters locations, standards body membership structures, treaty obligations, and alliance commitments all constrain or enable sovereignty options. The entity that ignores the geopolitical dimension will find its domestic governance choices overridden by international obligations it did not fully understand when it signed. The TEE Method requires that geopolitical assessment be integrated into every sovereignty test, not treated as a separate workstream.
The eleventh challenge is the economic dimension of sovereignty investment. Building sovereign capability costs money. Maintaining redundancy costs money. Running exit rehearsals costs money. The entity that views sovereignty as a cost centre will underinvest and be captured. The entity that views sovereignty as a strategic investment will build capabilities that compound over time. The TEE Method provides the economic framework for this calculation. Phase One Assessment quantifies current dependency costs including switching costs, pricing exposure, and operational risk. Phase Two Strategic Planning models the return on sovereignty investment including avoided vendor lock-in, negotiating leverage, and innovation capacity. Phase Three Implementation measures actual cost savings from multi-provider strategies and open-format standards. Phase Four Institutionalisation embeds sovereignty ROI into annual technology budgeting. The economic case for sovereignty is not speculative. It is calculable, measurable, and when tracked over the full technology lifecycle, it is positive for entities that commit to the discipline.
The twelfth challenge is the accountability dimension of sovereignty governance. Who within the entity is responsible for technology sovereignty? The CIO? The CISO? The Board? The answer in most entities is: nobody specifically. Sovereignty falls through the cracks between technical operations, security compliance, legal review, and strategic planning. The TEE Method solves this by making sovereignty a named executive responsibility with defined responsibilities, required reporting, and budget authority. The sovereignty owner chairs the governance committee, owns the seven-layer audit, authorises the red flag escalation, and reports to the Board quarterly. This is not a new role. It is an existing role with clarified authority. The entity that assigns sovereignty ownership creates accountability. The entity that does not creates the vacuum that external providers will fill. The TEE Method makes governance ownership explicit, not implicit.
The Seven Layer Stack Audit
The Seven Layer Stack Audit: The TEE Method requires a systematic audit across seven layers of the technology stack. Layer one Hardware Compute: who owns the physical infrastructure, where are the data centres located, under what jurisdiction do they operate, what are the power cooling and connectivity dependencies. Layer two Network: who controls the data pathways, which internet exchange points does traffic traverse, what are the routing dependencies, are there single points of failure in the network path. Layer three Operating System Virtualisation: who controls the base software layer, is it open source or proprietary, what are the update and patch dependencies, can the entity run its own builds. Layer four Middleware APIs: who governs the integration layer, are the APIs open standards or vendor proprietary, what are the versioning and deprecation policies, can the entity build its own adapters. Layer five Application AI: who controls the intelligence layer, are the models open weight or closed, what are the fine tuning and customisation capabilities, what are the inference dependencies. Layer six Data Governance: who sets the rules for data use, where does data reside at rest and in transit, what are the jurisdictional implications, who has access under what legal authority. Layer seven Human Institutional: who has the expertise to operate audit and replace the system, what are the knowledge concentration risks, what are the contractual constraints on staffing and skills development. Each layer represents a distinct sovereignty decision point. Dependency at any layer propagates upward constraining choices at every layer above it.
Part Two: The Sovereignty Test Matrix
The Sovereignty Test Matrix scores five domains from one critical dependency to five full sovereignty. Political Sovereignty: can the entity make independent governance decisions, documented decision rights, veto authority, policy independence from platform or vendor governance frameworks. Economic Sovereignty: does the entity control the economic terms of the relationship, contractual pricing control, competitive alternatives, cost predictability. Cultural Sovereignty: does the system respect the entity cultural context, values and priorities, including localisation capability, value alignment with institutional mission, community acceptance. Intellectual Sovereignty: does the entity understand the system at a level sufficient to govern it independently, internal audit capacity, independent evaluation capability, knowledge distribution across the organisation. Technological Sovereignty: can the entity build adapt or replace the technology, open formats, portability, alternative deployment capability. Mixed profiles are the norm. The goal is not perfect scores but an honest actionable profile that reveals where governance investment is needed most.
Part Three: Red Flag Checklist
Red Flag Checklist. Single Provider Critical Function: a core function depends entirely on one technology provider with no viable alternative identified or tested. Proprietary Data Lock In: organisational data is stored in a format that cannot be exported without transformation, data loss, or significant cost. No Withdrawal Protocol: there is no documented tested plan for transitioning away from the dependent technology even in an emergency. Vendor Dependent Expertise: the entity relies on the technology provider for all troubleshooting, customisation, and optimisation because internal staff lack the knowledge to operate independently. Unilateral Pricing Power: the provider has exercised significant price increases or the entity cannot predict future pricing due to opaque licensing models. Governance Capture: the provider terms certifications or compliance frameworks have become the entity de facto governance standards. Acquisition Consolidation Risk: the provider operates in a consolidating market creating uncertainty. Cross Border Jurisdictional Risk: the provider operates under a different legal jurisdiction with data access laws that may conflict with the entity sovereignty interests. If three or more of these eight indicators apply, the entity is in a critical dependency position and should initiate an urgent TEE Method assessment across all five sovereignty domains.
Part Four: Phased Implementation Framework
Phased Implementation. Phase One Assessment weeks one to four: complete the Sovereignty Test Matrix for all critical dependencies across the seven layer stack, map all single provider dependencies, conduct a comprehensive audit, develop the red flag checklist, establish sovereignty assessment as a standing item. Phase Two Strategic Planning months two to three: develop withdrawal protocols for the three highest risk dependencies, identify and pilot alternative solutions, begin knowledge transfer programmes, negotiate contractual protections including data portability, transparent pricing, and genuine exit provisions, build or join a Sovereignty Caucus. Phase Three Implementation months four to twelve: execute multi provider strategies to prevent lock in, implement open format standards for all new systems, establish continuous monitoring infrastructure, conduct regular exit testing to verify withdrawal capability remains operational. Phase Four Institutionalisation months thirteen to eighteen: embed sovereignty assessment into all technology decisions, build internal capacity for independent evaluation, develop sovereign alternatives where economically viable, participate actively in the drafting of national and international technology governance frameworks. The phased framework acknowledges that sovereignty is not achieved in a single project. It is built through sustained disciplined investment across the full technology governance lifecycle.
The Closing Question
What are the five questions every leader must answer about their data dependencies?
The transition from adoption to governance requires deliberate structure, sustained commitment, and frameworks making sovereignty measurable rather than aspirational. The TEE Method provides that structure. The choice belongs to those who lead. This article draws on the TEE Method framework from SOVEREIGN: Who Owns the Future? For the complete framework, including detailed TEE Method assessment protocols, layer by layer auditing procedures, and sovereignty test matrices for organisations of all sizes, see tonishatagoe.com.