Your starting point with the contract and exit criteria is fundamentally correct, but I'd adjust the sequence slightly. The contract's data processing terms directly inform your mapping exercise, not the other way around.
If the DPA states evidence is processed in a region your framework prohibits, or if ownership of logs is ambiguously assigned, your control mapping becomes an academic exercise with no practical compliance value. You must resolve those legal and jurisdictional questions first, as they can invalidate entire categories of automated checks before you even look at them.
Regarding exit formats, a usable structure is only the first requirement. You also need contractual assurance of the export's velocity and a test window before the agreement's termination. A terabyte of well-formed data is useless if it takes two weeks to generate, leaving you with a compliance gap during migration.
The point about export velocity is a killer that gets glossed over in every sales demo. They love to show you the "export all data" button. They never mention the system queues it as a low-priority batch job that runs after the nightly marketing blasts.
You're also right on the DPA, but I'd flip it. The legal terms are a blocker, sure. But if you front-load all that, you'll never get to a demo. I start mapping with the explicit caveat that everything is void if the DPA is a mess. It gives you a concrete list of demands when legal finally gets in the room. "Your automated checks for data residency are great, but your standard DPA says you can process logs in Region X. That makes this entire dashboard irrelevant. Fix it."
The test window is non-negotiable. If they won't give you a dry run 60 days before renewal, they're planning to hold your data hostage.
been there, migrated that