← BLACKSWAN OS
Operating Model · Org Design · Hiring Readiness
Internal Readiness · Simulated
Centre Status

Operating Model, Org Design & Hiring Readiness Centre

Maps the target operating model behind BLACKSWAN Capital Markets OS — accountable roles, committee cadence, RACI & segregation-of-duties, staffing & hiring plan, outsourced vs internal coverage, key-person risk, training, governance calendar, and escalation lines. Conservative posture: internal operating-readiness workflow only — not legal advice, not employment advice, not regulatory approval, not an audit opinion, and not a binding hiring plan.

Functions catalogued
13
7 Owner Assigned · 3 Interim Outsourced · 2 Hiring Open · 1 Coverage Gap
Committees active
9
8 Committee Active · 1 forming
Hiring priorities
5
3 P0 · 2 P1 · interim cover in place
Open exceptions
9
Tracked · operating board + risk committee review
Operating state legend
Not Defined Draft Owner Assigned Coverage Gap Interim Outsourced Hiring Open Training Required Committee Active Conditional Coverage Ready · Internal Production Ready · Controlled Pilot Blocked Archived
Twelve operating model domains

Operating Model · Org Design · Hiring Readiness domains

Target Operating Model
13 functions mapped

Founder-led with interim outsourced cover for counsel, audit, and external assurance; internal hires named.

Org Design
Roles + advisers + committees

Internal · outsourced/adviser · committee · backup/deputy · approval authority · escalation responsibility.

Role Accountability
Named accountable per function

Every Centre carries an accountable owner; standing risk acceptance for founder-root logged in Programme Decision Log.

Committee Cadence
9 committees active

Board · Risk · Launch Readiness · Change Advisory · Incident Command · Reg. Escalation · Vendor Risk · Model Risk · Financial Close · Data/Privacy.

RACI / Segregation of Duties
2 SOD conflicts logged

Founder concentration acknowledged; dual-approver compensating controls on Tier-1 release, MNPI, and break-glass.

Staffing & Hiring Plan
5 priorities open

Hiring priorities tied to gate movement (post-Entra, post-counsel, pre-pilot). Interim outsourced cover documented.

Outsourced vs Internal Coverage
Linked to Vendor Risk

External counsel · external auditor · external assessor (pending) · KYC partner · hosting · monitoring vendor.

Key Person Risk
3 SPOFs tracked

Founder · CISO · SRE Lead carry single-point-of-failure flags with documented deputies and runbooks.

Training & Competency
2 attestations overdue

Role-mapped training: security, privacy, model risk, regulator, financial controls, incident response, code of conduct.

Governance Calendar
Cycles published

Daily readiness scan · weekly launch review · monthly board pack · monthly evidence spine · quarterly control testing · annual policy attestation.

Escalation Paths
Wired across 17 Centres

SRE → CISO → COO → CEO → Board. Counsel paths for regulator-facing escalation; Risk Committee for risk acceptance.

Operating Model Evidence Pack
Pack assembled

Function map · committee charter · RACI · hiring plan · key-person register · training log · governance calendar · exceptions.

Target operating model · function map

Thirteen functions · current vs target coverage · governance forum

Function Current coverage Target coverage Owner Governance forum SOD concern Hiring gap Next action Evidence ref State
Founder / CEO 1 (Founder) 1 + CoS Founder Board Permanent founder-root accepted (DEC-005) CoS hire P1 Confirm CoS scope OM-EV-FUN-001 Owner Assigned
Compliance / CCO Head of Regulatory + External Counsel CCO hire + counsel oversight Head of Regulatory Risk Committee · Board Founder + Compliance separation CCO hire P0 Open CCO search post-counsel rule pack OM-EV-FUN-002 Hiring Open
Risk Owner Risk Committee Chair (NED) NED Chair + risk-committee-active Risk Committee Chair Risk Committee None None Quarterly RAID review OM-EV-FUN-003 Committee Active
Engineering / Security / CISO CISO + SRE Lead + Engineering Lead CISO + SRE + Eng + Security Eng hire CISO Change Advisory · Incident Command CISO and SRE Lead concentration Security Engineer hire P0 Open security engineer search OM-EV-FUN-004 Owner Assigned
Operations / COO Programme Manager (acting COO) COO + Programme Manager Programme Manager Launch Readiness · Change Advisory Programme + COO overlap COO hire P1 (post-pilot) Defer until post-pilot OM-EV-FUN-005 Conditional Coverage
Legal / Regulatory Counsel External Counsel External Counsel + GC hire (post-pilot) External Counsel Regulatory Escalation · Board External-only · counsel concentration GC hire P2 (post-pilot) Maintain external counsel · plan GC search OM-EV-FUN-006 Interim Outsourced
Finance CFO + External Auditor (pending) CFO + Auditor + Financial Controller hire CFO Financial Close · Board CFO + close-process overlap Financial Controller hire P1 Open Financial Controller search post-pilot OM-EV-FUN-007 Owner Assigned
Commercial / Client Success Head of Commercial Head of Commercial + CSM hire Head of Commercial Launch Readiness · Board None Client Success Manager hire P1 Open CSM search on first pilot OM-EV-FUN-008 Owner Assigned
Product / Programme Programme Manager · CoS Programme Manager · CoS · Product Lead hire Programme Manager Change Advisory · Launch Readiness Programme + Product overlap Product Lead hire P2 (post-pilot) Defer until post-pilot OM-EV-FUN-009 Owner Assigned
Data / Privacy Data Governance Lead + CISO DG Lead + CISO + DPO hire (post-pilot) Data Governance Lead Data / Privacy Review Data + Security overlap DPO hire P1 (jurisdiction-dependent) Counsel review of DPO need OM-EV-FUN-010 Conditional Coverage
Vendor / Outsourcing Head of Procurement (acting) Head of Procurement + Risk Committee oversight Head of Procurement Vendor Risk Review · Risk Committee Procurement + Risk overlap Procurement Manager hire P2 Maintain interim cover OM-EV-FUN-011 Interim Outsourced
Model Risk / AI Governance CISO + Head of Regulatory CISO + Reg + Model Risk Lead hire (post-pilot) CISO Model Risk Review · Risk Committee CISO concentration Model Risk Lead hire P2 Defer until post-pilot; counsel-bound interim OM-EV-FUN-012 Conditional Coverage
Board / Independent Reviewer Board Chair + 2 NEDs Board Chair + 3 NEDs + Independent Reviewer (external assurance) Board Chair Board Founder + Chair separation maintained Add 1 NED P1 · Independent Reviewer P0 Open Independent Reviewer search OM-EV-FUN-013 Coverage Gap
Org design & role map

Internal · outsourced · committee · deputy · approval authority

Role Internal / Outsourced Committee membership Backup / deputy Approval authority Escalation responsibility
Founder / CEO Internal Board · Risk · Launch Readiness CoS External launch · external counsel · board ask Board escalation
Chief of Staff (CoS) Internal Launch Readiness · Programme Programme Manager Board pack issue (jointly) CEO escalation
CISO Internal Risk · Change Advisory · Incident Command · Model Risk · Data/Privacy SRE Lead (interim) Tier-1 change · break-glass · access reviews · MNPI scope COO → CEO → Board
SRE Lead Internal Change Advisory · Incident Command · Release Control Engineering Lead Release cuts · rollback · monitoring SLOs CISO escalation
Engineering Lead Internal Change Advisory SRE Lead Build quality · ADR adherence CISO + Programme escalation
Head of Regulatory Internal Risk · Regulatory Escalation · Model Risk External Counsel Regulator-facing artefact (with counsel countersign) External Counsel + CEO
External Counsel Outsourced Risk · Regulatory Escalation Alternate counsel (named) Regulator-facing language · counsel countersign CEO + Board
CFO Internal Risk · Financial Close · Board External Auditor (interim) Revenue treatment · audit binder · auditor engagement Board escalation
External Auditor (pending engagement) Outsourced Financial Close n/a Validation of CFO baseline · engagement letter CFO escalation
Data Governance Lead Internal Data/Privacy · Vendor Risk CISO (interim) Data classification · DSR · retention hold CISO escalation
Head of Procurement Internal (acting) Vendor Risk · Risk SRE Lead (interim) Vendor classification · DPA sign-off Risk Committee escalation
Head of Commercial Internal Launch Readiness · Board (info) CFO (interim) Pilot engagement · pilot template · KYC contract CEO escalation
Programme Manager (acting COO) Internal Launch Readiness · Change Advisory · Programme CoS Gate movement · release sign-off (dual) CEO escalation
Head of Evidence Internal Launch Readiness · Programme Programme Manager (interim) Evidence pack publish · cross-link · retention Programme + CISO escalation
Head of Stakeholder Rooms Internal Launch Readiness · Data/Privacy CISO (interim) Per-share access review · room link signing CISO escalation
Board Chair (NED) Internal (governance) Board · Risk (chair) Senior NED Founder-root acceptance · board-pack approval Board escalation only
Independent Reviewer (external assurance · pending) Outsourced Risk (advisory) n/a Independent attestation scope Board Chair
Committee / governance cadence

Nine committees · cadence · chair · quorum · inputs · outputs

Committee Cadence Chair Quorum / attendees Inputs Outputs Evidence State
Board Monthly + ad-hoc Board Chair (NED) Chair + 1 NED + CEO Board pack · BDRs · risk acceptance Decisions · attestations OM-EV-CT-001 Active
Risk Committee Quarterly + on P0 event Risk Committee Chair (NED) Chair + Board NED + CISO + CFO + Head of Regulatory RAID · exception register · KPI scorecard Risk acceptance · exception approvals OM-EV-CT-002 Active
Launch Readiness Committee Weekly Programme Manager Programme · CISO · CFO · Head of Commercial · Head of Evidence Readiness scan · gate status · evidence packs Readiness sign-off · weekly status OM-EV-CT-003 Active
Change Advisory / Release Control Per release window SRE Lead SRE · CISO · Programme Manager · affected Centre lead Change records · test evidence · rollback plan Release sign-off (dual) · post-release watch OM-EV-CT-004 Active
Incident Command On-page · 24×7 Incident Commander (on-call) IC + SRE + CISO + Comms + counsel (if regulator-impact) Severity triage · monitoring signals Incident timeline · regulator-notify decision OM-EV-CT-005 Active
Regulatory Escalation On trigger + monthly review Head of Regulatory Reg + External Counsel + CISO + CEO (info) Incident timeline · audit-event tags Regulator-notify decision · binder draft OM-EV-CT-006 Active
Vendor Risk Review Monthly + on classification change Head of Procurement Procurement + CISO + Risk Committee delegate Vendor inventory · concentration · DD checklist Classification · exit-plan watch OM-EV-CT-007 Active
Model Risk Review Monthly + on override CISO CISO + Head of Regulatory + Head of Evidence + Validation owner Validation results · drift signals · overrides Validation sign-off · model state changes OM-EV-CT-008 Active
Financial Close Monthly CFO CFO + External Auditor (when engaged) + Programme Manager Billing events · revenue treatment · classifier outputs Close attestation · audit binder addendum OM-EV-CT-009 Active
Staffing & hiring readiness plan

Role · priority · trigger · interim owner · dependency · status

Role Priority Trigger Target coverage Interim owner Dependency Risk if delayed Hiring status
CCO / Compliance Officer P0 Post counsel rule-pack sign-off 1 FTE Head of Regulatory + External Counsel Counsel rule pack · jurisdiction posture Founder + Compliance separation pressure Hiring Open
Security Engineer P0 Post Entra cutover 1 FTE CISO + SRE Lead Entra cutover · IAM baseline CISO concentration extends Hiring Open
Independent Reviewer (external assurance) P0 Pre external launch authorization External engagement Board Chair Board approval External launch held in Later band Hiring Open
Chief of Staff P1 Pre first pilot 1 FTE Founder + Programme Manager None Board reporting cadence pressure Draft
Financial Controller P1 Post external auditor engagement 1 FTE CFO + External Auditor Auditor engagement letter CFO + close-process overlap Draft
Client Success Manager (CSM) P1 On first pilot live 1 FTE Head of Commercial First pilot Commercial concentration Draft
Additional NED · Board independence P1 Pre external launch 1 NED Board Chair Board approval Board-quorum dependency Draft
DPO (jurisdiction-dependent) P1 Counsel review of jurisdictional need 1 FTE or fractional Data Governance Lead + External Counsel Counsel review Privacy posture gap Draft
General Counsel P2 Post-pilot scale 1 FTE External Counsel External counsel scope review External-only concentration Draft
Model Risk Lead P2 Post-pilot scale 1 FTE CISO + Head of Regulatory Counsel rule pack + first model promotions CISO concentration on AI/model governance Draft
RACI / Segregation of Duties matrix

Core workflows · accountable · responsible · approver · SOD pair

Workflow Accountable Responsible Approver SOD pair (required separation) Compensating control
Evidence pack approval Head of Evidence Centre lead + Reviewer Programme Manager Author ≠ Approver Dual sign-off + per-file footer
Release authorization (Tier-1) Programme Manager · CISO SRE Lead Programme + CISO (dual) Build ≠ Sign-off; SRE ≠ CISO Dual sign-off + audit log
Incident escalation CISO Incident Commander · SRE CISO → COO → CEO IC ≠ Approver on regulator-notify Counsel countersign on regulator-notify
Stakeholder room activation Head of Stakeholder Rooms Room owner CISO (per-share) Owner ≠ Approver on MNPI rooms Per-share access review + audit log
Financial sign-off (close) CFO Financial Controller (when hired) · acting CFO Board (quarterly) · Auditor (annual) Booking ≠ Approval; CFO ≠ Auditor External Auditor + audit binder
Vendor approval / classification change Head of Procurement Procurement + Vendor lead Risk Committee · External Counsel (material) Onboarding ≠ Risk classification Risk Committee minutes + counsel sign-off
Model output override CISO · Head of Regulatory Validation owner · Reviewer CISO + Reg (dual on regulator-facing) Build ≠ Override approval Override register + counsel countersign where applicable
Data deletion / retention hold Data Governance Lead DG team + SRE Lead CISO + DG Lead (dual) Custodian ≠ Approver Hold log + audit-event tag
Regulatory notification review Head of Regulatory External Counsel · Reg team External Counsel countersign · CEO informed Operator ≠ Submitter Counsel countersign + audit-logged decision
Training & competency

Role · required training · attestation · gap · evidence

Role Required training Policy attestation Last completed Gap Owner Evidence output
All staff Security · privacy · MNPI · code of conduct · whistleblowing Annual 2026-02-15 None CISO · DG Lead TR-EV-ALL-001
Engineers / SRE Secure SDLC · secret hygiene · incident response · ADR adherence Quarterly 2026-04-10 None SRE Lead · CISO TR-EV-ENG-002
Evidence publishers Evidence pack standards · classification · per-file footer Quarterly 2026-04-15 None Head of Evidence TR-EV-EV-003
Stakeholder room owners Per-share access · MNPI handling · room-link signing Per-share 2026-05-15 None Head of Stakeholder Rooms · CISO TR-EV-SR-004
Incident Commanders IR runbook · severity triage · regulator-notify trigger Quarterly + tabletop 2026-05-09 None CISO · SRE Lead TR-EV-IC-005
Regulatory team (incl. counsel flow) Jurisdiction rule pack · counsel countersign workflow Quarterly 2026-04-22 None Head of Regulatory · External Counsel TR-EV-REG-006
Finance team Revenue treatment · audit binder · auditor engagement Quarterly 2026-03-31 Q2 attestation overdue CFO TR-EV-FIN-007
Commercial / onboarding KYC · MNPI in pilot · per-pilot tenant template Per-pilot 2026-04-30 None Head of Commercial TR-EV-COM-008
Model reviewers Human-in-loop review · override workflow · explainability evidence Monthly 2026-04-12 May attestation overdue CISO · Head of Regulatory TR-EV-MR-009
Board / NEDs Founder-root risk · committee charter · regulator engagement protocol Annual 2026-01-20 None Board Chair · External Counsel TR-EV-BRD-010
Key-person risk & resilience

Critical role · SPOF · backup · documented runbook · delegation

Critical role SPOF? Backup / deputy Documented runbook Delegation authority Resilience state Mitigation
Founder / CEO Yes CoS (interim) · Board Chair (governance escalation) Founder-absence runbook · board-quorum process Time-boxed · Board-confirmed Watch Founder-root risk acceptance (DEC-005) + monthly attestation
CISO Yes SRE Lead (interim) · External assurance (advisory) CISO-absence runbook · IR backup IC Time-boxed · CEO-confirmed Watch Security Engineer hire (P0) · documented runbooks
SRE Lead Yes Engineering Lead (interim) SRE rotation runbook · oncall backup Per-incident · CISO-confirmed Watch Documented runbooks · cross-training
Head of Evidence No (deputy named) Programme Manager (interim) Evidence-publish runbook Per-pack · Programme-confirmed Healthy Cross-training in progress
CFO Partial External Auditor (advisory) · Financial Controller (hire pending) Close runbook · audit binder runbook Per-cycle · Board-confirmed Watch Financial Controller hire (P1)
Head of Regulatory Partial External Counsel (interim) · alternate counsel named Regulator-binder runbook · counsel handover Per-submission · CEO + Counsel Watch CCO hire (P0)
External Counsel Yes (single firm) Alternate counsel (named) · GC hire P2 Counsel handover runbook Per-engagement · CEO-confirmed Watch Maintain alternate · plan GC hire
Data Governance Lead Partial CISO (interim) DSR runbook · classification runbook Per-DSR · CISO-confirmed Healthy DPO hire (P1) jurisdiction-dependent
Board Chair (NED) No Senior NED Board-quorum process Per-board · NED-confirmed Healthy Additional NED hire (P1)
Outsourced vs internal coverage

Function · outsourced provider · internal accountable · oversight cadence

Function Outsourced provider / adviser Internal accountable owner Oversight cadence Evidence Linked Centre
Legal / regulatory External Counsel (primary + alternate) Head of Regulatory · CEO Per-submission + quarterly review OM-EV-OI-001 Regulatory Escalation
External audit External Auditor (pending engagement) CFO Annual · interim quarterly OM-EV-OI-002 Financial Controls
External assurance (SOC 2 / ISO / privacy) Independent Reviewer (pending) CISO · Board Chair Annual OM-EV-OI-003 Security Operations · Data Governance
KYC partner KYC partner (contract pending) Head of Commercial · External Counsel Per-onboarding + monthly OM-EV-OI-004 Commercial Readiness
Hosting / infrastructure Cloud provider (Tier-1 vendor) SRE Lead · CISO Continuous · monthly review OM-EV-OI-005 Enterprise Architecture · Vendor Risk
Monitoring / SIEM Observability + SIEM vendor SRE Lead · CISO Continuous · monthly review OM-EV-OI-006 Production Monitoring · Security Operations
Identity provider (production) Microsoft Entra (target) Identity Lead · CISO Continuous · quarterly access review OM-EV-OI-007 Security Operations
Email / notification Email provider (single-source watch) SRE Lead · Head of Procurement Monthly · dual-provider plan in progress OM-EV-OI-008 Enterprise Architecture · Vendor Risk
Governance calendar

Cycle · trigger · owner · output

Cycle Cadence Trigger Owner Output Evidence
Daily readiness scan Daily Production posture watch Programme Manager · SRE Lead Daily scan note · attention list OM-EV-GC-001
Weekly launch review Weekly Gate movement watch Programme Manager · CISO · CFO Readiness sign-off · weekly status OM-EV-GC-002
Monthly evidence spine briefing Monthly 21 evidence packs review Head of Evidence Evidence pack readiness scorecard OM-EV-GC-003
Monthly board pack Monthly Board cycle CoS · CEO Board pack · decisions · attestations OM-EV-GC-004
Incident review windows Per Sev-1/2 + monthly aggregate Incident closure CISO · SRE Lead Post-incident review · timeline OM-EV-GC-005
Quarterly control testing Quarterly Control owner cadence CISO · Risk Committee Control testing evidence OM-EV-GC-006
Quarterly rollback & DR drill Quarterly Operational resilience cadence SRE Lead · CISO Drill report · RTO/RPO evidence OM-EV-GC-007
Annual policy attestation Annual Anniversary cycle CISO · DG Lead · Head of Regulatory Attestation log · policy refresh OM-EV-GC-008
Annual board effectiveness review Annual NED rotation cadence Board Chair Board effectiveness note OM-EV-GC-009
Operating model exception register

Open exceptions · compensating control · target close

Exception Affected role / function Severity Owner Compensating control Resolution path Target close State
Missing accountable owner Billing webhook receiver (RAID-004) P3 CFO · SRE Lead SRE on-call covers Name billing technical lead 2026-05-22 Coverage Gap
Committee inactive — Data/Privacy Review Data Governance Lead · CISO P2 Data Governance Lead Existing DSR runbook live; reviews still happen ad-hoc Formalise monthly cadence + minutes 2026-05-26 Draft
SOD conflict — Programme + Approver overlap Programme Manager P2 CEO Dual sign-off with CISO on Tier-1; no single-person release CoS hire (P1) splits Programme + Approver Pre first pilot Conditional
Overdue training — finance Q2 Finance team P3 CFO Q1 attestation valid; ad-hoc walk-throughs Run Q2 attestation 2026-05-30 Training Required
Hiring gap — Security Engineer (P0) Security Operations P0 CISO SRE Lead covers · interim cross-training Hire post-Entra cutover Post-CHG-001 Hiring Open
Key-person risk — Founder Founder / CEO Accepted Board (dual) · Board Chair Founder-root acceptance (DEC-005) · monthly attestation · CoS interim deputy Standing accepted risk Standing Standing
No deputy — External Counsel (single firm) External Counsel P2 CEO Alternate counsel named + handover runbook Plan GC hire (P2) Post-pilot Interim Outsourced
Stale policy attestation — model reviewers (May) Model reviewers P3 CISO · Head of Regulatory April attestation valid; restricted output limits Run May attestation 2026-05-24 Training Required
Outsourced oversight gap — email provider single-source Email connector · Notification API P2 SRE Lead · Head of Procurement Email vendor risk score Medium; contingency to alternate provider Dual-provider readiness; failover drill 2026-06-08 Conditional
Audit trail & evidence preservation

Audit log of operating-model events

Timestamp (UTC) Actor Role / function Action Evidence hash Limitation recorded Next step
2026-05-08 10:00 CEO · CoS · Programme Manager Target operating model OM-TOM — 13 functions published sha256:om11…aa01 "Internal operating-readiness workflow only." Re-publish on hire / committee change
2026-05-08 11:24 CoS Org design / role map OM-ORG — 17 roles published sha256:om22…aa02 "Internal." Update on hire close
2026-05-09 09:30 Board Chair · CEO Committee cadence OM-CT — 9 committees confirmed sha256:om33…aa03 "Internal." Refresh on charter change
2026-05-10 14:18 CEO · CFO · CISO Hiring plan OM-HIRE — 10 priorities logged sha256:om44…aa04 "Not a binding hiring plan." Weekly status
2026-05-11 16:42 CEO · CISO · External Counsel RACI / SOD matrix OM-RACI — 9 workflows covered · 2 SOD conflicts logged sha256:om55…aa05 "Internal." Reduce conflicts on CoS hire
2026-05-12 09:14 CISO · DG Lead · Head of Regulatory Training & competency OM-TR — 10 role-mapped trainings tracked sha256:om66…aa06 "Internal." Close 2 overdue attestations
2026-05-13 11:08 CEO · Board Chair · CISO Key-person register OM-KP — 9 critical roles · 3 SPOFs logged sha256:om77…aa07 "Internal." Re-confirm runbooks quarterly
2026-05-14 08:22 Head of Procurement · CISO · CFO Outsourced vs internal coverage OM-OI — 8 outsourced functions mapped sha256:om88…aa08 "Internal." Refresh on vendor change
2026-05-15 09:00 CoS · Programme Manager Governance calendar OM-GC — 9 cycles published sha256:om99…aa09 "Internal." Update on cadence change
2026-05-15 14:30 Risk Committee Operating model exception register OM-EXC — 9 open exceptions logged sha256:om00…aa10 "Internal." Weekly review
2026-05-16 07:50 CEO · Board Chair Operating model attestation OM-ATTESTATION — monthly attestation sha256:om00…aa11 "Internal; not regulatory approval." Re-attest monthly
Assumptions and Limitations

What this Centre is — and is not

  • Staging / simulated operating-model data. All function names, hire IDs, committee identifiers, evidence hashes, and audit events shown here are seed values for an internal operating-readiness workflow. They are not a live HRIS, not a live committee register, and not a live audit log.
  • Internal operating-readiness workflow only. This Centre captures BLACKSWAN's internal operating-model posture. It is not legal advice, not employment advice, not a binding hiring plan, not regulatory approval, and not an audit opinion.
  • Not a binding hiring commitment. Hiring priorities, target coverage, and trigger conditions are internal readiness drafts gated on board approval and counsel/regulator engagement. No individual role is offered, opened, or committed by display in this Centre.
  • Interim outsourced cover is explicitly named. External counsel, external auditor, external assurance, KYC partner, hosting, monitoring, and identity provider engagements are listed with internal accountable owners; outsourcing does not transfer accountability.
  • Founder-root risk is a standing accepted risk. Per Programme Decision Log DEC-005, founder-root permanence carries monthly attestation + MFA + re-auth as compensating controls. This Centre records the operating consequences (CoS, CCO hire, board independence) but does not change the acceptance.