Operating Model, Org Design & Hiring Readiness Centre
Maps the target operating model behind BLACKSWAN Capital Markets OS — accountable roles, committee cadence, RACI & segregation-of-duties, staffing & hiring plan, outsourced vs internal coverage, key-person risk, training, governance calendar, and escalation lines. Conservative posture: internal operating-readiness workflow only — not legal advice, not employment advice, not regulatory approval, not an audit opinion, and not a binding hiring plan.
Operating Model · Org Design · Hiring Readiness domains
Founder-led with interim outsourced cover for counsel, audit, and external assurance; internal hires named.
Internal · outsourced/adviser · committee · backup/deputy · approval authority · escalation responsibility.
Every Centre carries an accountable owner; standing risk acceptance for founder-root logged in Programme Decision Log.
Board · Risk · Launch Readiness · Change Advisory · Incident Command · Reg. Escalation · Vendor Risk · Model Risk · Financial Close · Data/Privacy.
Founder concentration acknowledged; dual-approver compensating controls on Tier-1 release, MNPI, and break-glass.
Hiring priorities tied to gate movement (post-Entra, post-counsel, pre-pilot). Interim outsourced cover documented.
External counsel · external auditor · external assessor (pending) · KYC partner · hosting · monitoring vendor.
Founder · CISO · SRE Lead carry single-point-of-failure flags with documented deputies and runbooks.
Role-mapped training: security, privacy, model risk, regulator, financial controls, incident response, code of conduct.
Daily readiness scan · weekly launch review · monthly board pack · monthly evidence spine · quarterly control testing · annual policy attestation.
SRE → CISO → COO → CEO → Board. Counsel paths for regulator-facing escalation; Risk Committee for risk acceptance.
Function map · committee charter · RACI · hiring plan · key-person register · training log · governance calendar · exceptions.
Thirteen functions · current vs target coverage · governance forum
| Function | Current coverage | Target coverage | Owner | Governance forum | SOD concern | Hiring gap | Next action | Evidence ref | State |
|---|---|---|---|---|---|---|---|---|---|
| Founder / CEO | 1 (Founder) | 1 + CoS | Founder | Board | Permanent founder-root accepted (DEC-005) | CoS hire P1 | Confirm CoS scope | OM-EV-FUN-001 | Owner Assigned |
| Compliance / CCO | Head of Regulatory + External Counsel | CCO hire + counsel oversight | Head of Regulatory | Risk Committee · Board | Founder + Compliance separation | CCO hire P0 | Open CCO search post-counsel rule pack | OM-EV-FUN-002 | Hiring Open |
| Risk Owner | Risk Committee Chair (NED) | NED Chair + risk-committee-active | Risk Committee Chair | Risk Committee | None | None | Quarterly RAID review | OM-EV-FUN-003 | Committee Active |
| Engineering / Security / CISO | CISO + SRE Lead + Engineering Lead | CISO + SRE + Eng + Security Eng hire | CISO | Change Advisory · Incident Command | CISO and SRE Lead concentration | Security Engineer hire P0 | Open security engineer search | OM-EV-FUN-004 | Owner Assigned |
| Operations / COO | Programme Manager (acting COO) | COO + Programme Manager | Programme Manager | Launch Readiness · Change Advisory | Programme + COO overlap | COO hire P1 (post-pilot) | Defer until post-pilot | OM-EV-FUN-005 | Conditional Coverage |
| Legal / Regulatory Counsel | External Counsel | External Counsel + GC hire (post-pilot) | External Counsel | Regulatory Escalation · Board | External-only · counsel concentration | GC hire P2 (post-pilot) | Maintain external counsel · plan GC search | OM-EV-FUN-006 | Interim Outsourced |
| Finance | CFO + External Auditor (pending) | CFO + Auditor + Financial Controller hire | CFO | Financial Close · Board | CFO + close-process overlap | Financial Controller hire P1 | Open Financial Controller search post-pilot | OM-EV-FUN-007 | Owner Assigned |
| Commercial / Client Success | Head of Commercial | Head of Commercial + CSM hire | Head of Commercial | Launch Readiness · Board | None | Client Success Manager hire P1 | Open CSM search on first pilot | OM-EV-FUN-008 | Owner Assigned |
| Product / Programme | Programme Manager · CoS | Programme Manager · CoS · Product Lead hire | Programme Manager | Change Advisory · Launch Readiness | Programme + Product overlap | Product Lead hire P2 (post-pilot) | Defer until post-pilot | OM-EV-FUN-009 | Owner Assigned |
| Data / Privacy | Data Governance Lead + CISO | DG Lead + CISO + DPO hire (post-pilot) | Data Governance Lead | Data / Privacy Review | Data + Security overlap | DPO hire P1 (jurisdiction-dependent) | Counsel review of DPO need | OM-EV-FUN-010 | Conditional Coverage |
| Vendor / Outsourcing | Head of Procurement (acting) | Head of Procurement + Risk Committee oversight | Head of Procurement | Vendor Risk Review · Risk Committee | Procurement + Risk overlap | Procurement Manager hire P2 | Maintain interim cover | OM-EV-FUN-011 | Interim Outsourced |
| Model Risk / AI Governance | CISO + Head of Regulatory | CISO + Reg + Model Risk Lead hire (post-pilot) | CISO | Model Risk Review · Risk Committee | CISO concentration | Model Risk Lead hire P2 | Defer until post-pilot; counsel-bound interim | OM-EV-FUN-012 | Conditional Coverage |
| Board / Independent Reviewer | Board Chair + 2 NEDs | Board Chair + 3 NEDs + Independent Reviewer (external assurance) | Board Chair | Board | Founder + Chair separation maintained | Add 1 NED P1 · Independent Reviewer P0 | Open Independent Reviewer search | OM-EV-FUN-013 | Coverage Gap |
Internal · outsourced · committee · deputy · approval authority
| Role | Internal / Outsourced | Committee membership | Backup / deputy | Approval authority | Escalation responsibility |
|---|---|---|---|---|---|
| Founder / CEO | Internal | Board · Risk · Launch Readiness | CoS | External launch · external counsel · board ask | Board escalation |
| Chief of Staff (CoS) | Internal | Launch Readiness · Programme | Programme Manager | Board pack issue (jointly) | CEO escalation |
| CISO | Internal | Risk · Change Advisory · Incident Command · Model Risk · Data/Privacy | SRE Lead (interim) | Tier-1 change · break-glass · access reviews · MNPI scope | COO → CEO → Board |
| SRE Lead | Internal | Change Advisory · Incident Command · Release Control | Engineering Lead | Release cuts · rollback · monitoring SLOs | CISO escalation |
| Engineering Lead | Internal | Change Advisory | SRE Lead | Build quality · ADR adherence | CISO + Programme escalation |
| Head of Regulatory | Internal | Risk · Regulatory Escalation · Model Risk | External Counsel | Regulator-facing artefact (with counsel countersign) | External Counsel + CEO |
| External Counsel | Outsourced | Risk · Regulatory Escalation | Alternate counsel (named) | Regulator-facing language · counsel countersign | CEO + Board |
| CFO | Internal | Risk · Financial Close · Board | External Auditor (interim) | Revenue treatment · audit binder · auditor engagement | Board escalation |
| External Auditor (pending engagement) | Outsourced | Financial Close | n/a | Validation of CFO baseline · engagement letter | CFO escalation |
| Data Governance Lead | Internal | Data/Privacy · Vendor Risk | CISO (interim) | Data classification · DSR · retention hold | CISO escalation |
| Head of Procurement | Internal (acting) | Vendor Risk · Risk | SRE Lead (interim) | Vendor classification · DPA sign-off | Risk Committee escalation |
| Head of Commercial | Internal | Launch Readiness · Board (info) | CFO (interim) | Pilot engagement · pilot template · KYC contract | CEO escalation |
| Programme Manager (acting COO) | Internal | Launch Readiness · Change Advisory · Programme | CoS | Gate movement · release sign-off (dual) | CEO escalation |
| Head of Evidence | Internal | Launch Readiness · Programme | Programme Manager (interim) | Evidence pack publish · cross-link · retention | Programme + CISO escalation |
| Head of Stakeholder Rooms | Internal | Launch Readiness · Data/Privacy | CISO (interim) | Per-share access review · room link signing | CISO escalation |
| Board Chair (NED) | Internal (governance) | Board · Risk (chair) | Senior NED | Founder-root acceptance · board-pack approval | Board escalation only |
| Independent Reviewer (external assurance · pending) | Outsourced | Risk (advisory) | n/a | Independent attestation scope | Board Chair |
Nine committees · cadence · chair · quorum · inputs · outputs
| Committee | Cadence | Chair | Quorum / attendees | Inputs | Outputs | Evidence | State |
|---|---|---|---|---|---|---|---|
| Board | Monthly + ad-hoc | Board Chair (NED) | Chair + 1 NED + CEO | Board pack · BDRs · risk acceptance | Decisions · attestations | OM-EV-CT-001 | Active |
| Risk Committee | Quarterly + on P0 event | Risk Committee Chair (NED) | Chair + Board NED + CISO + CFO + Head of Regulatory | RAID · exception register · KPI scorecard | Risk acceptance · exception approvals | OM-EV-CT-002 | Active |
| Launch Readiness Committee | Weekly | Programme Manager | Programme · CISO · CFO · Head of Commercial · Head of Evidence | Readiness scan · gate status · evidence packs | Readiness sign-off · weekly status | OM-EV-CT-003 | Active |
| Change Advisory / Release Control | Per release window | SRE Lead | SRE · CISO · Programme Manager · affected Centre lead | Change records · test evidence · rollback plan | Release sign-off (dual) · post-release watch | OM-EV-CT-004 | Active |
| Incident Command | On-page · 24×7 | Incident Commander (on-call) | IC + SRE + CISO + Comms + counsel (if regulator-impact) | Severity triage · monitoring signals | Incident timeline · regulator-notify decision | OM-EV-CT-005 | Active |
| Regulatory Escalation | On trigger + monthly review | Head of Regulatory | Reg + External Counsel + CISO + CEO (info) | Incident timeline · audit-event tags | Regulator-notify decision · binder draft | OM-EV-CT-006 | Active |
| Vendor Risk Review | Monthly + on classification change | Head of Procurement | Procurement + CISO + Risk Committee delegate | Vendor inventory · concentration · DD checklist | Classification · exit-plan watch | OM-EV-CT-007 | Active |
| Model Risk Review | Monthly + on override | CISO | CISO + Head of Regulatory + Head of Evidence + Validation owner | Validation results · drift signals · overrides | Validation sign-off · model state changes | OM-EV-CT-008 | Active |
| Financial Close | Monthly | CFO | CFO + External Auditor (when engaged) + Programme Manager | Billing events · revenue treatment · classifier outputs | Close attestation · audit binder addendum | OM-EV-CT-009 | Active |
Role · priority · trigger · interim owner · dependency · status
| Role | Priority | Trigger | Target coverage | Interim owner | Dependency | Risk if delayed | Hiring status |
|---|---|---|---|---|---|---|---|
| CCO / Compliance Officer | P0 | Post counsel rule-pack sign-off | 1 FTE | Head of Regulatory + External Counsel | Counsel rule pack · jurisdiction posture | Founder + Compliance separation pressure | Hiring Open |
| Security Engineer | P0 | Post Entra cutover | 1 FTE | CISO + SRE Lead | Entra cutover · IAM baseline | CISO concentration extends | Hiring Open |
| Independent Reviewer (external assurance) | P0 | Pre external launch authorization | External engagement | Board Chair | Board approval | External launch held in Later band | Hiring Open |
| Chief of Staff | P1 | Pre first pilot | 1 FTE | Founder + Programme Manager | None | Board reporting cadence pressure | Draft |
| Financial Controller | P1 | Post external auditor engagement | 1 FTE | CFO + External Auditor | Auditor engagement letter | CFO + close-process overlap | Draft |
| Client Success Manager (CSM) | P1 | On first pilot live | 1 FTE | Head of Commercial | First pilot | Commercial concentration | Draft |
| Additional NED · Board independence | P1 | Pre external launch | 1 NED | Board Chair | Board approval | Board-quorum dependency | Draft |
| DPO (jurisdiction-dependent) | P1 | Counsel review of jurisdictional need | 1 FTE or fractional | Data Governance Lead + External Counsel | Counsel review | Privacy posture gap | Draft |
| General Counsel | P2 | Post-pilot scale | 1 FTE | External Counsel | External counsel scope review | External-only concentration | Draft |
| Model Risk Lead | P2 | Post-pilot scale | 1 FTE | CISO + Head of Regulatory | Counsel rule pack + first model promotions | CISO concentration on AI/model governance | Draft |
Core workflows · accountable · responsible · approver · SOD pair
| Workflow | Accountable | Responsible | Approver | SOD pair (required separation) | Compensating control |
|---|---|---|---|---|---|
| Evidence pack approval | Head of Evidence | Centre lead + Reviewer | Programme Manager | Author ≠ Approver | Dual sign-off + per-file footer |
| Release authorization (Tier-1) | Programme Manager · CISO | SRE Lead | Programme + CISO (dual) | Build ≠ Sign-off; SRE ≠ CISO | Dual sign-off + audit log |
| Incident escalation | CISO | Incident Commander · SRE | CISO → COO → CEO | IC ≠ Approver on regulator-notify | Counsel countersign on regulator-notify |
| Stakeholder room activation | Head of Stakeholder Rooms | Room owner | CISO (per-share) | Owner ≠ Approver on MNPI rooms | Per-share access review + audit log |
| Financial sign-off (close) | CFO | Financial Controller (when hired) · acting CFO | Board (quarterly) · Auditor (annual) | Booking ≠ Approval; CFO ≠ Auditor | External Auditor + audit binder |
| Vendor approval / classification change | Head of Procurement | Procurement + Vendor lead | Risk Committee · External Counsel (material) | Onboarding ≠ Risk classification | Risk Committee minutes + counsel sign-off |
| Model output override | CISO · Head of Regulatory | Validation owner · Reviewer | CISO + Reg (dual on regulator-facing) | Build ≠ Override approval | Override register + counsel countersign where applicable |
| Data deletion / retention hold | Data Governance Lead | DG team + SRE Lead | CISO + DG Lead (dual) | Custodian ≠ Approver | Hold log + audit-event tag |
| Regulatory notification review | Head of Regulatory | External Counsel · Reg team | External Counsel countersign · CEO informed | Operator ≠ Submitter | Counsel countersign + audit-logged decision |
Role · required training · attestation · gap · evidence
| Role | Required training | Policy attestation | Last completed | Gap | Owner | Evidence output |
|---|---|---|---|---|---|---|
| All staff | Security · privacy · MNPI · code of conduct · whistleblowing | Annual | 2026-02-15 | None | CISO · DG Lead | TR-EV-ALL-001 |
| Engineers / SRE | Secure SDLC · secret hygiene · incident response · ADR adherence | Quarterly | 2026-04-10 | None | SRE Lead · CISO | TR-EV-ENG-002 |
| Evidence publishers | Evidence pack standards · classification · per-file footer | Quarterly | 2026-04-15 | None | Head of Evidence | TR-EV-EV-003 |
| Stakeholder room owners | Per-share access · MNPI handling · room-link signing | Per-share | 2026-05-15 | None | Head of Stakeholder Rooms · CISO | TR-EV-SR-004 |
| Incident Commanders | IR runbook · severity triage · regulator-notify trigger | Quarterly + tabletop | 2026-05-09 | None | CISO · SRE Lead | TR-EV-IC-005 |
| Regulatory team (incl. counsel flow) | Jurisdiction rule pack · counsel countersign workflow | Quarterly | 2026-04-22 | None | Head of Regulatory · External Counsel | TR-EV-REG-006 |
| Finance team | Revenue treatment · audit binder · auditor engagement | Quarterly | 2026-03-31 | Q2 attestation overdue | CFO | TR-EV-FIN-007 |
| Commercial / onboarding | KYC · MNPI in pilot · per-pilot tenant template | Per-pilot | 2026-04-30 | None | Head of Commercial | TR-EV-COM-008 |
| Model reviewers | Human-in-loop review · override workflow · explainability evidence | Monthly | 2026-04-12 | May attestation overdue | CISO · Head of Regulatory | TR-EV-MR-009 |
| Board / NEDs | Founder-root risk · committee charter · regulator engagement protocol | Annual | 2026-01-20 | None | Board Chair · External Counsel | TR-EV-BRD-010 |
Critical role · SPOF · backup · documented runbook · delegation
| Critical role | SPOF? | Backup / deputy | Documented runbook | Delegation authority | Resilience state | Mitigation |
|---|---|---|---|---|---|---|
| Founder / CEO | Yes | CoS (interim) · Board Chair (governance escalation) | Founder-absence runbook · board-quorum process | Time-boxed · Board-confirmed | Watch | Founder-root risk acceptance (DEC-005) + monthly attestation |
| CISO | Yes | SRE Lead (interim) · External assurance (advisory) | CISO-absence runbook · IR backup IC | Time-boxed · CEO-confirmed | Watch | Security Engineer hire (P0) · documented runbooks |
| SRE Lead | Yes | Engineering Lead (interim) | SRE rotation runbook · oncall backup | Per-incident · CISO-confirmed | Watch | Documented runbooks · cross-training |
| Head of Evidence | No (deputy named) | Programme Manager (interim) | Evidence-publish runbook | Per-pack · Programme-confirmed | Healthy | Cross-training in progress |
| CFO | Partial | External Auditor (advisory) · Financial Controller (hire pending) | Close runbook · audit binder runbook | Per-cycle · Board-confirmed | Watch | Financial Controller hire (P1) |
| Head of Regulatory | Partial | External Counsel (interim) · alternate counsel named | Regulator-binder runbook · counsel handover | Per-submission · CEO + Counsel | Watch | CCO hire (P0) |
| External Counsel | Yes (single firm) | Alternate counsel (named) · GC hire P2 | Counsel handover runbook | Per-engagement · CEO-confirmed | Watch | Maintain alternate · plan GC hire |
| Data Governance Lead | Partial | CISO (interim) | DSR runbook · classification runbook | Per-DSR · CISO-confirmed | Healthy | DPO hire (P1) jurisdiction-dependent |
| Board Chair (NED) | No | Senior NED | Board-quorum process | Per-board · NED-confirmed | Healthy | Additional NED hire (P1) |
Function · outsourced provider · internal accountable · oversight cadence
| Function | Outsourced provider / adviser | Internal accountable owner | Oversight cadence | Evidence | Linked Centre |
|---|---|---|---|---|---|
| Legal / regulatory | External Counsel (primary + alternate) | Head of Regulatory · CEO | Per-submission + quarterly review | OM-EV-OI-001 | Regulatory Escalation |
| External audit | External Auditor (pending engagement) | CFO | Annual · interim quarterly | OM-EV-OI-002 | Financial Controls |
| External assurance (SOC 2 / ISO / privacy) | Independent Reviewer (pending) | CISO · Board Chair | Annual | OM-EV-OI-003 | Security Operations · Data Governance |
| KYC partner | KYC partner (contract pending) | Head of Commercial · External Counsel | Per-onboarding + monthly | OM-EV-OI-004 | Commercial Readiness |
| Hosting / infrastructure | Cloud provider (Tier-1 vendor) | SRE Lead · CISO | Continuous · monthly review | OM-EV-OI-005 | Enterprise Architecture · Vendor Risk |
| Monitoring / SIEM | Observability + SIEM vendor | SRE Lead · CISO | Continuous · monthly review | OM-EV-OI-006 | Production Monitoring · Security Operations |
| Identity provider (production) | Microsoft Entra (target) | Identity Lead · CISO | Continuous · quarterly access review | OM-EV-OI-007 | Security Operations |
| Email / notification | Email provider (single-source watch) | SRE Lead · Head of Procurement | Monthly · dual-provider plan in progress | OM-EV-OI-008 | Enterprise Architecture · Vendor Risk |
Cycle · trigger · owner · output
| Cycle | Cadence | Trigger | Owner | Output | Evidence |
|---|---|---|---|---|---|
| Daily readiness scan | Daily | Production posture watch | Programme Manager · SRE Lead | Daily scan note · attention list | OM-EV-GC-001 |
| Weekly launch review | Weekly | Gate movement watch | Programme Manager · CISO · CFO | Readiness sign-off · weekly status | OM-EV-GC-002 |
| Monthly evidence spine briefing | Monthly | 21 evidence packs review | Head of Evidence | Evidence pack readiness scorecard | OM-EV-GC-003 |
| Monthly board pack | Monthly | Board cycle | CoS · CEO | Board pack · decisions · attestations | OM-EV-GC-004 |
| Incident review windows | Per Sev-1/2 + monthly aggregate | Incident closure | CISO · SRE Lead | Post-incident review · timeline | OM-EV-GC-005 |
| Quarterly control testing | Quarterly | Control owner cadence | CISO · Risk Committee | Control testing evidence | OM-EV-GC-006 |
| Quarterly rollback & DR drill | Quarterly | Operational resilience cadence | SRE Lead · CISO | Drill report · RTO/RPO evidence | OM-EV-GC-007 |
| Annual policy attestation | Annual | Anniversary cycle | CISO · DG Lead · Head of Regulatory | Attestation log · policy refresh | OM-EV-GC-008 |
| Annual board effectiveness review | Annual | NED rotation cadence | Board Chair | Board effectiveness note | OM-EV-GC-009 |
Open exceptions · compensating control · target close
| Exception | Affected role / function | Severity | Owner | Compensating control | Resolution path | Target close | State |
|---|---|---|---|---|---|---|---|
| Missing accountable owner | Billing webhook receiver (RAID-004) | P3 | CFO · SRE Lead | SRE on-call covers | Name billing technical lead | 2026-05-22 | Coverage Gap |
| Committee inactive — Data/Privacy Review | Data Governance Lead · CISO | P2 | Data Governance Lead | Existing DSR runbook live; reviews still happen ad-hoc | Formalise monthly cadence + minutes | 2026-05-26 | Draft |
| SOD conflict — Programme + Approver overlap | Programme Manager | P2 | CEO | Dual sign-off with CISO on Tier-1; no single-person release | CoS hire (P1) splits Programme + Approver | Pre first pilot | Conditional |
| Overdue training — finance Q2 | Finance team | P3 | CFO | Q1 attestation valid; ad-hoc walk-throughs | Run Q2 attestation | 2026-05-30 | Training Required |
| Hiring gap — Security Engineer (P0) | Security Operations | P0 | CISO | SRE Lead covers · interim cross-training | Hire post-Entra cutover | Post-CHG-001 | Hiring Open |
| Key-person risk — Founder | Founder / CEO | Accepted | Board (dual) · Board Chair | Founder-root acceptance (DEC-005) · monthly attestation · CoS interim deputy | Standing accepted risk | Standing | Standing |
| No deputy — External Counsel (single firm) | External Counsel | P2 | CEO | Alternate counsel named + handover runbook | Plan GC hire (P2) | Post-pilot | Interim Outsourced |
| Stale policy attestation — model reviewers (May) | Model reviewers | P3 | CISO · Head of Regulatory | April attestation valid; restricted output limits | Run May attestation | 2026-05-24 | Training Required |
| Outsourced oversight gap — email provider single-source | Email connector · Notification API | P2 | SRE Lead · Head of Procurement | Email vendor risk score Medium; contingency to alternate provider | Dual-provider readiness; failover drill | 2026-06-08 | Conditional |
Audit log of operating-model events
| Timestamp (UTC) | Actor | Role / function | Action | Evidence hash | Limitation recorded | Next step |
|---|---|---|---|---|---|---|
| 2026-05-08 10:00 | CEO · CoS · Programme Manager | Target operating model | OM-TOM — 13 functions published | sha256:om11…aa01 | "Internal operating-readiness workflow only." | Re-publish on hire / committee change |
| 2026-05-08 11:24 | CoS | Org design / role map | OM-ORG — 17 roles published | sha256:om22…aa02 | "Internal." | Update on hire close |
| 2026-05-09 09:30 | Board Chair · CEO | Committee cadence | OM-CT — 9 committees confirmed | sha256:om33…aa03 | "Internal." | Refresh on charter change |
| 2026-05-10 14:18 | CEO · CFO · CISO | Hiring plan | OM-HIRE — 10 priorities logged | sha256:om44…aa04 | "Not a binding hiring plan." | Weekly status |
| 2026-05-11 16:42 | CEO · CISO · External Counsel | RACI / SOD matrix | OM-RACI — 9 workflows covered · 2 SOD conflicts logged | sha256:om55…aa05 | "Internal." | Reduce conflicts on CoS hire |
| 2026-05-12 09:14 | CISO · DG Lead · Head of Regulatory | Training & competency | OM-TR — 10 role-mapped trainings tracked | sha256:om66…aa06 | "Internal." | Close 2 overdue attestations |
| 2026-05-13 11:08 | CEO · Board Chair · CISO | Key-person register | OM-KP — 9 critical roles · 3 SPOFs logged | sha256:om77…aa07 | "Internal." | Re-confirm runbooks quarterly |
| 2026-05-14 08:22 | Head of Procurement · CISO · CFO | Outsourced vs internal coverage | OM-OI — 8 outsourced functions mapped | sha256:om88…aa08 | "Internal." | Refresh on vendor change |
| 2026-05-15 09:00 | CoS · Programme Manager | Governance calendar | OM-GC — 9 cycles published | sha256:om99…aa09 | "Internal." | Update on cadence change |
| 2026-05-15 14:30 | Risk Committee | Operating model exception register | OM-EXC — 9 open exceptions logged | sha256:om00…aa10 | "Internal." | Weekly review |
| 2026-05-16 07:50 | CEO · Board Chair | Operating model attestation | OM-ATTESTATION — monthly attestation | sha256:om00…aa11 | "Internal; not regulatory approval." | Re-attest monthly |
What this Centre is — and is not
- Staging / simulated operating-model data. All function names, hire IDs, committee identifiers, evidence hashes, and audit events shown here are seed values for an internal operating-readiness workflow. They are not a live HRIS, not a live committee register, and not a live audit log.
- Internal operating-readiness workflow only. This Centre captures BLACKSWAN's internal operating-model posture. It is not legal advice, not employment advice, not a binding hiring plan, not regulatory approval, and not an audit opinion.
- Not a binding hiring commitment. Hiring priorities, target coverage, and trigger conditions are internal readiness drafts gated on board approval and counsel/regulator engagement. No individual role is offered, opened, or committed by display in this Centre.
- Interim outsourced cover is explicitly named. External counsel, external auditor, external assurance, KYC partner, hosting, monitoring, and identity provider engagements are listed with internal accountable owners; outsourcing does not transfer accountability.
- Founder-root risk is a standing accepted risk. Per Programme Decision Log DEC-005, founder-root permanence carries monthly attestation + MFA + re-auth as compensating controls. This Centre records the operating consequences (CoS, CCO hire, board independence) but does not change the acceptance.