This checklist is intended to be used as an ongoing control framework rather than a one-time migration task. Each control is evaluated as Compliant, Partially Compliant or Exception based on continuous evidence of operation, with gaps tracked and risks actively managed. Users should document evidence directly in the interactive PDF, update control statuses and formally manage any approved, time-bound exceptions with compensating controls in place.