Operational notes Observatory

No defined exit strategy: the audit line that concerns you

7 min read

Sacks stacked on a wooden pallet outside a warehouse loading bay, black-and-white photograph
A pallet moves in an hour. The data that tracks it, without an exit strategy, stays exactly where it is.

If the supplier holding your organisation’s data together closed the relationship — or if you were the one to end it — could you say how long it would take, in what format, and at what cost? If the answer is “we’ve never actually tested it”, you are not the exception: it is the ordinary condition of anyone entrusting critical data to a supplier without ever verifying the exit. On 7 August 2026 an investigation made that question concrete, inside the internal audit of one of the largest organisations in the world.

A “high priority” audit, a renewal all the same

FRANCE 24 and PassBlue published in coordination — one investigation with two bylines, not two independent confirmations — an internal audit of the United Nations World Food Programme, drawn up by the agency’s Office of the Inspector General and dated August 2025, on the WFP’s five-year relationship with Palantir Technologies. The audit is not public: the outlets say they have seen it, while the WFP finalises the renewal of the 2019 contract — pro bono, five-year, declared value $45 million — for DOTS (Digital Operations and Transformation System), built to track the agency’s aid deliveries. “The general scope and terms of the contract remain the same,” a WFP spokesperson said.

The audit rates the problem “high priority”: “inadequate risk management”, no “proper guidelines and policy” on data, “key privacy concerns” never addressed “since the inception of the partnership”; the WFP “lacks a unified and trusted system” to manage them, while “reputational considerations” tied to the partnership “have led to institutional uncertainty”. Then the line that gives this piece its title: “At present, there is no clearly defined exit strategy for DOTS, nor clarity on the potential costs that may arise should the partnership be terminated”. The technology division “has assessed opportunities to export and save data from DOTS”, but the plan was never presented to the key parties, not even to Palantir, while “substantial” investment continues.

The software works. That’s the problem.

The news is not that Palantir performs badly. It’s the opposite, and it’s more uncomfortable. A former employee who used it extensively calls DOTS “the best tool in the sector. Nothing comes close to it”: roughly 98% of WFP operations run through DOTS, and removing Palantir would make the supply chain “collapse”. Another employee judges it “mediocre” instead — “it doesn’t bring anything new that wasn’t already available on the open internet”. We report both: the thesis doesn’t change. A mediocre supplier gets replaced. One that 98% of an organisation uses daily, with an exit plan never tested, no longer gets replaced: it holds you, not through a clause against you but through the absence of one in your favour. What counts is who holds the key, not who is right about the product — the same dependency as who retains ownership of the operating model in a deal with a major supplier.

DOTS is not SCOPE, the WFP’s biometric system, among the largest biometric databases in the world: Palantir reportedly pushed hard for access to SCOPE, but some internal officials kept biometric data outside its perimeter. A cyberattack on the WFP in May 2026 exposed the data of thousands of aid beneficiaries in Gaza: the WFP says it involved the Self-Registration Application for Palestine, with “no direct connection” to Palantir’s software.

The other voices: Skau, Palantir, Europe

Acting director Carl Skau reportedly acknowledged the relationship is problematic, but said leaving would be costly with systems now intertwined; he did not respond to FRANCE 24. Palantir declined an interview, calling itself “proud to partner with the World Food Programme”: it “does not use, retain or sell customer data for its own purposes”, “we do not use customer data to train models”. The WFP says it is not locked into any single supplier: “WFP processes and controls all its own data”. The pro bono contract still requires paying for cloud and support: the UN records over $10.5 million paid to Palantir from 2017 to 2024, while — according to a staff member who spoke to the two outlets — an internal assessment put building an equivalent in-house at $20 million. The same employee calls the pro bono contract “a vendor lock-in contract”: that is their reading, not a word the audit uses.

The European context helps make sense of the story. In June, France’s DGSI ended its partnership with Palantir for a domestic competitor: the decision, said France’s ambassador for digital affairs and AI Clara Chappaz, came “in part, over concerns about data sovereignty and digital resilience”. Germany’s domestic security service did the same. Britain’s NHS admitted in May that some Palantir staff could access identifiable patient data, contrary to earlier statements.

See the service · Talk to an engineer

The clause nobody reads to the end

There is also a contractual reason to write an exit strategy before signing. Privacy International, in its report “All Roads Lead to Palantir” (November 2021), analysed a 2019 licence between Palantir and the US Department of Defense, obtained via FOIA: Palantir may collect usage data on the Products “to monitor, analyze, maintain and improve the Products”. The same document defines “Products” as “the Client Software, Cloud Solutions and Software specified in the Order”, and “Software” as “the Palantir proprietary commercial software, models, and algorithms […] in any format”. A chain of definitions, not an opinion: if Products include Software, and Software includes “models, and algorithms”, improving the Products includes, by contract, improving models and algorithms. Privacy International finds an almost identical clause — 18.9 — in Gotham and Foundry’s terms on the UK government’s Digital Marketplace.

Palantir exercised its right of reply in the same report, and on the WFP wrote: “Palantir deploys our commercially available data integration platform, Foundry, in an environment where access and use are controlled by the WFP.” Lawyer Chris Wlach: suppliers have always wanted usage data to improve performance, “but today, data can also help train algorithms and AI models” — and whoever hands it over needs to know that.

The two lessons, and ours

The first: a good supplier, without an exit plan, holds you tighter than a mediocre one. The second concerns the audit itself: a document that rates a problem “high priority” and a contract that gets renewed anyway is not hypocrisy — it’s what happens when the exit isn’t designed before signing. At that point leaving costs more than staying, and cost becomes the decisive argument, not because the supplier is right but because nobody ever measured what stopping would cost. The WFP had even started drawing up a plan: not bringing it to the table before the renewal is the difference between having an option and not having one.

This is the control we put into operation for a board or an inspection: for every critical supplier — not only AI — which data goes in, under what usage clause, what comes out on termination, in what format and at what cost, with a test export actually carried out and dated. That is the difference between a plan assessed and a real one.

The same system holds an organisation’s scattered data together, in a single operating model — archives, business systems, plant, sensors, documents — on which AI agents execute decisions with a human operator in command, for large enterprises, defence, government and healthcare. Ontology, pipeline and mappings stay yours: it is the layer you cannot buy back when the integrator changes, as already seen in the unreadable clauses of AI defence contracts. If it is yours, leaving is a migration; if it is not, it is a collapse. Always in two modes: on-premises on autonomous machines, or dedicated cloud with a data centre in Italy, with shared management. And for anyone in Europe weighing cloud exit costs, the Data Act removes them from 12 January 2027.

Back to the question we opened with. If you had to leave the supplier holding your organisation’s data together today, could you say how long it would take, in what format, and at what cost? If the answer is still “no” — and for the vast majority of organisations it still is — that is the point to start from, not a contract to renegotiate.

From the first session, at no cost, comes the dated list of suppliers you couldn’t leave today — for each one, the data usage clause, the expected export format, and whether a test export has ever actually been done. It stays with you even if we don’t go any further. Talk to one of our engineers.

Sources