SMS OTP integration risk assessment
You are the senior business analyst on the citizen services team of a state e-services portal. The product owner wants to add Northwind SMS for OTP verification in the driver-license renewal flow. The portal currently handles 15,000 OTPs daily, and compliance said "We need phone-based 2FA for high-risk services".
📎 Compliance lead: "If an OTP never arrives, the citizen misses the 14-day legal deadline – we cannot afford that."
Your task
1. Create a coverage matrix mapping the portal's OTP requirements (delivery receipt, retry limit, latency) to the provider's API.
2. Identify the three most likely failure modes, their impact on the 14-day deadline, and propose a mitigation for each.
3. Give a go/no-go recommendation, balancing legal risk, SLA, and $0.04 per-SMS cost.
Input: SMS Provider X OpenAPI fragment
{"openapi":"3.0.0","info":{"title":"SMS Provider X API","version":"1.0"},"paths":{"/messages":{"post":{"summary":"Send SMS","requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"to":{"type":"string","description":"E.164 formatted phone number"},"from":{"type":"string","description":"Sender ID"},"body":{"type":"string","description":"Message text"},"validity_period":{"type":"integer","description":"Seconds the provider should keep the message for delivery attempts"}},"required":["to","body"]}}}},"responses":{"200":{"description":"Message acceptedBusiness AnalystSeniorGovernment e-services portalThird-party service integration assessment