6Run a Stakeholder Discovery Sequence Across End Users, Business Owners, and Security/Privacy Stakeholders7Capture the Current-State Workflow and Define the Target Job to Be Done With Measurable Outcomes8Build a Constraints Inventory Covering Latency, Cost, Integration, Audit, and Change-Management Requirements
9Perform a Data Reality Check Covering Sources, Access, Permissions, PII, Retention, Quality, and Freshness10Write the Problem Statement and Initialize the Risk Register With Key Risks, Owners, Assumptions, and Open Questions