People, Training & Competency · Internal Posture
Internal competency workspace covering role taxonomy, responsibility map, competency matrix, training inventory, attestation register, onboarding/offboarding, support coverage, and key-person risk. Compiled from the 31 prior centres and the 21-pack evidence spine. Conservative: nothing here is regulator approval, fit-and-proper approval, person approval, audit opinion, employment advice, or authorization for external launch.
12-Role Internal/External Taxonomy
| Role | Type | Source | Linked centre | Engagement basis | State |
|---|---|---|---|---|---|
| Founder · Director | Internal | Director appointment letter | Legal Entity / Governance Records | Permanent | Active |
| Independent Director | Internal | Director appointment letter | Legal Entity / Governance Records | Permanent | Active |
| Founder-Secretary / CoSec function | Internal | Secretary letter | Legal Entity / Governance Records | Permanent | Single-party |
| Compliance / Legal lead (interim) | External | MC-003 counsel engagement | Policy / Control Library | Retained counsel | Active |
| SRE / Platform lead | Internal · founder-played | Operating Model | Operational Runbooks & Day-2 Support | Permanent | Founder dual-hat |
| CISO function | Internal · founder-played | Operating Model | Security Operations | Permanent | Founder dual-hat |
| Evidence Owner | Internal · founder-played | Completeness | Completeness / Data Governance | Permanent | Founder dual-hat |
| Operations / support · pilot tier | Internal · founder-played | Operating Model | Operational Runbooks & Day-2 Support | Pre-pilot | Founder dual-hat |
| Auditor · external (proposed) | External | MC-004 engagement (drafted) | Vendor Risk | Drafted | Counsel-pending |
| Insurance broker | External | EV-INS-02 engagement letter | Insurance, Claims & Loss Event | Retained | Active |
| Tax advisor | External | Advisor agreement | Financial Controls | Retained | Active |
| Founder advisor (technical / capital markets) | External | MC-007 advisor agreement | Operating Model | Retained · renewal due | Renewal due |
Founder dual-hat rows (SRE / CISO / Evidence Owner / Operations) are the basis of the single-operator key-person risk addressed below.
Responsibility & Accountability Map
SMF / approved-person style mapping used internally only. Not a regulatory submission and not an SMCR map.
| Responsibility | Primary | Secondary | Counsel-binding | SoD pair | Linked centre |
|---|---|---|---|---|---|
| Overall management of the firm | Founder | Director | — | Founder ≠ Director on Tier-1 rollback | Executive Cockpit |
| Compliance oversight | Counsel (retained) | Founder | Yes | Drafter ≠ Counsel on external language | Policy / Control Library |
| Financial / capital / liquidity | Founder | External tax advisor | — | Author ≠ Approver on Capital plan | Capital, Liquidity & Prudential Readiness |
| Operational resilience | Founder (SRE) | Director | — | SRE ≠ CISO on Tier-1 incident | Operational Runbooks & Day-2 Support |
| Cyber / information security | Founder (CISO) | External IR retainer | — | SRE ≠ CISO on Tier-1 incident | Security Operations |
| Client lifecycle / KYC oversight | Counsel | Founder | Yes | Counsel ≠ Founder on KYC contract | Client Lifecycle & Entitlements |
| Data governance & privacy | Founder (Evidence Owner) | Counsel | Conditional | Drafter ≠ Approver on schema change | Data Governance |
| Conduct & complaints | Counsel | Founder | Yes | Drafter ≠ Counsel on complaint response | Conduct Risk MI (planned) · Complaints (planned) |
| Regulator-facing engagement | Counsel | Founder | Yes | Counsel + Founder dual sign-off | Regulatory Escalation · Regulatory Exam Response |
| Board / investor narrative | Founder | Director | Yes | Drafter ≠ Approver on board section | Strategic Reporting |
| Vendor / outsourcing oversight | Founder | Counsel | Yes (Tier-1) | Single-party ≠ Tier-1 vendor execution | Vendor Risk |
| Risk & control testing | Founder | Director · QA | — | Tester ≠ Approver on Security | Strategic Risk Register · Testing/QA/Release Evidence |
Competency Matrix (per role)
| Competency | Required for | Evidence basis | Re-attestation cadence | State |
|---|---|---|---|---|
| Capital markets product knowledge | Founder · Director · Counsel · Advisor | CV · prior engagements · counsel review | Annual | Attested |
| Regulatory framework (UK / EU mapping) | Counsel · Founder | Counsel certification · CPD | Annual | Attested |
| SoD & least-privilege operation | Founder · Director · SRE / CISO | SoD attestation · access review | Quarterly | Re-attestation due |
| Incident response / DR | SRE · CISO · Operations | Tabletop log · DR drill participation | Bi-annual | Drill 2026-05-15 |
| MNPI handling / market-abuse awareness | Founder · Director · Counsel · Advisor | Annual attestation · counsel briefing | Annual | Attested |
| KYC / KYB / financial crime | Counsel · Operations · Founder | Annual attestation · vendor training | Annual | Attested |
| Data protection / privacy (UK-GDPR style) | All | Annual attestation | Annual | Attested |
| Conduct / treating clients fairly | Founder · Director · Counsel · Operations | Counsel briefing · attestation | Annual | Pre-pilot |
| Cyber hygiene / phishing | All | Quarterly attestation | Quarterly | Current |
| Model / AI risk awareness | Founder · SRE · Compliance | Counsel briefing · model log | Bi-annual | Pre-pilot |
Mandatory & Recommended Training
| ID | Module | Status | Cadence | Audience | Source | Last completed |
|---|---|---|---|---|---|---|
| TR-001 | MNPI / market abuse awareness | Mandatory | Annual | All | Counsel-led briefing | 2026-02-18 |
| TR-002 | KYC / KYB / AML overview | Mandatory | Annual | Founder · Counsel · Operations | Vendor training | 2026-02-25 |
| TR-003 | Data protection / privacy | Mandatory | Annual | All | External course | 2026-02-25 |
| TR-004 | Cyber hygiene / phishing | Mandatory | Quarterly | All | Internal · platform | 2026-04-30 |
| TR-005 | SoD & least-privilege operation | Mandatory | Quarterly | Founder · Director · SRE / CISO | Internal attestation | 2026-02-12 |
| TR-006 | Incident response / DR tabletop | Mandatory | Bi-annual | SRE · CISO · Operations | Internal drill | 2026-05-15 |
| TR-007 | Conduct / TCF / complaints handling | Mandatory | Annual | Founder · Director · Counsel · Operations | Counsel-led briefing | 2026-03-08 |
| TR-008 | Regulatory framework refresher (UK / EU) | Mandatory | Annual | Counsel · Founder | CPD external | 2026-03-15 |
| TR-009 | Model / AI risk awareness | Recommended | Bi-annual | Founder · SRE · Compliance | External course · counsel briefing | 2026-04-04 |
| TR-010 | Capital / liquidity / wind-down literacy | Mandatory | Annual | Founder · Director | Counsel + finance briefing | 2026-05-02 |
Conduct & Policy Attestation Register
| ID | Attestation | Audience | Linked pack | Counsel | Last attested | State |
|---|---|---|---|---|---|---|
| AT-001 | Conflicts of interest declaration | All officers | Policy Attestation · Conduct Risk MI | — | 2026-04-22 | Re-attestation 2026-08-15 |
| AT-002 | Code of conduct attestation | All | Policy Attestation | Yes | 2026-03-22 | Current |
| AT-003 | SoD attestation | Founder · Director · SRE/CISO | Authentication | — | 2026-02-12 | Quarterly · due |
| AT-004 | MNPI handling attestation | Founder · Director · Counsel · Advisor | Data-Room MNPI | Yes | 2026-02-18 | Current |
| AT-005 | Data protection attestation | All | Policy Attestation | — | 2026-02-25 | Current |
| AT-006 | Cyber hygiene quarterly attestation | All | Authentication | — | 2026-04-30 | Current |
| AT-007 | Policy attestation pack acknowledgement | All | Policy Attestation | Yes | 2026-05-04 | Counsel-pending refresh |
| AT-008 | Fit-and-proper-style internal attestation | Founder · Director · Counsel | Policy Attestation | Yes | 2026-03-12 | Counsel review |
| AT-009 | Outside-business interests declaration | Founder · Director | Conduct Risk MI | — | 2026-04-22 | Current |
| AT-010 | Personal account dealing attestation | Founder · Director · Counsel · Advisor | Conduct Risk MI · Data-Room MNPI | Yes | 2026-04-22 | Current |
Onboarding / Offboarding
Onboarding (10-step)
| # | Step | Owner |
|---|---|---|
| 1 | Right-to-work + identity check | HR / Counsel |
| 2 | Reference / fit-and-proper-style attestation | HR / Counsel |
| 3 | Engagement letter / contract signed | Counsel · Founder |
| 4 | Role definition + responsibility map slot | Founder |
| 5 | Mandatory training assignments | HR / People |
| 6 | Access provisioning · least-privilege · MFA | SRE / CISO |
| 7 | Policy & attestation pack signature | Counsel |
| 8 | SoD-pair assignment | Founder · CISO |
| 9 | 30/60/90 competency check-ins | Founder |
| 10 | Evidence-pack linkage in Completeness | Evidence Owner |
Offboarding (10-step)
| # | Step | Owner |
|---|---|---|
| 1 | Notice / departure trigger logged | Founder |
| 2 | Knowledge transfer plan | Founder + leaver |
| 3 | MNPI / confidentiality reminder · counsel-locked | Counsel |
| 4 | Access deprovisioning · revoke MFA / keys | SRE / CISO |
| 5 | Device / data return / wipe | SRE |
| 6 | SoD-pair re-assignment | Founder · CISO |
| 7 | Final attestations · exit declarations | Counsel · HR |
| 8 | Regulator / register update if officer | Counsel · CoSec |
| 9 | Succession / coverage update | Founder |
| 10 | Evidence preservation · legal-hold check | Evidence Owner · Counsel |
Operational Support Coverage
| Window | Primary | Secondary | Counsel reachable | SRE / CISO reachable | State |
|---|---|---|---|---|---|
| Pre-market 06:00–09:00 | Founder | Director (best-effort) | Email · ≤2h SLA | Founder dual-hat | Single-operator |
| Market 09:00–17:30 | Founder | Director · Counsel retained | Same-day | Founder dual-hat | Single-operator |
| Post-market 17:30–21:00 | Founder | Best-effort | Founder dual-hat | Single-operator | |
| Night 21:00–06:00 | On-call pager · founder | — | Email · next business day | IR retainer on cyber panel | On-call only |
| Weekend / holiday | On-call pager · founder | Director (best-effort) | Email · next business day | IR retainer on cyber panel | On-call only |
Pre-pilot posture explicitly accepts single-operator coverage (DEC-005). Compensating controls: Tier-1 two-party rollback (SRE + Founder), IR retainer, runbook-driven incident workflow, and SLA-based counsel reachability.
Key-Person Risk & Succession Tracker
| Function | Single-point-of-failure? | Compensating control | Succession plan | State |
|---|---|---|---|---|
| Founder · overall management | Yes | Director · standing instructions · DEC-005 | Director step-up · counsel-led interim plan | Accepted-risk |
| Founder · SRE / platform | Yes | IR retainer · cloud vendor support · runbooks | SRE hire scoped (post-pilot) | Pre-pilot |
| Founder · CISO | Yes | Cyber insurance IR panel · MFA enforced | CISO hire scoped (post-pilot) | Pre-pilot |
| Founder · Evidence Owner | Yes | Retention windows · cross-link integrity · audit log | Evidence Owner hire scoped | Pre-pilot |
| Counsel · retained | No · firm-engaged | Firm capacity · written briefings | Alternate counsel firm scoped | Mitigated |
| Director · governance | Partial | Founder + Counsel quorum rules | Replacement director shortlist | Watch |
| External advisor (technical) | No | Advisor agreement · renewal due | Alternate advisor scoped | On track |
| Broker / insurer / IR retainer | No | Broker engagement · IR retainer · alternate broker scoped | Alternate broker available | Mitigated |
Access & Permissions Dependencies
| Surface | Owner | Cadence | Cross-link centre | State |
|---|---|---|---|---|
| Founder-root access review | Founder + Director | Quarterly | User Role & Permissions · Security Operations | Accepted-risk DEC-005 |
| SoD pair audit | CISO function | Quarterly | User Role & Permissions | Re-attestation due |
| Tier-1 vendor access | Vendor Risk | Quarterly | Vendor Risk · Outsourcing | Current |
| Counsel data-room access | Counsel | Per session | Stakeholder Rooms · Data-Room MNPI | Current |
| Auditor access (when engaged) | Counsel · Founder | Per engagement | Vendor Risk · Approval & Sign-Off | Pending engagement letter |
People Briefing Posture
Founder / Admin
Role map, responsibilities, training inventory, attestation register, key-person risk.
Board reviewer
Competency posture, succession, key-person risk acceptance.
Compliance / Legal
Counsel-bound rows, fit-and-proper-style attestation, conflicts, conduct.
People / Governance owner
Onboarding/offboarding workflow, training cadence, attestation owners.
Operations
Support coverage grid, runbook coverage, on-call routes.
Technology / Security
Access review, SoD pairs, MFA, IR retainer, key-person cyber posture.
Evidence Owner
Records→pack traceability, attestation retention, training evidence linkage.
Client Support
Support window coverage, escalation routes (pre-pilot).
Regulator-review room
Counsel-curated read-only. Not a regulator submission.
Auditor / Assurance reviewer
Engagement-letter gated. Not an audit opinion.
External People-Bundle Gates
Currently 2 of 4 met. Mirrors prior centres' posture.
| Gate | Acceptance criterion | Counsel-binding | State |
|---|---|---|---|
| 1 | Counsel-locked language across any external people / competency statement | Yes | Pending |
| 2 | Fit-and-proper-style attestation + policy attestation pack counsel-countersigned | Yes | Not met |
| 3 | All training / attestation evidence hashed and cross-linked in retention | — | Met |
| 4 | SoD & access review attested in last 90 days | — | Met |
Stale Training & Attestation Alerts
| ID | Alert | Linked artefact | Owner | Age (d) | State |
|---|---|---|---|---|---|
| AL-01 | SoD attestation quarterly · due | AT-003 · TR-005 | Founder · CISO | 96 | Due |
| AL-02 | Policy attestation pack counsel-pending refresh | AT-007 | Counsel | 14 | Pending |
| AL-03 | Fit-and-proper-style attestation counsel review | AT-008 | Counsel · Founder | 67 | Counsel review |
| AL-04 | Conflicts re-attestation due 2026-08-15 | AT-001 | CoSec · all officers | — | Scheduled |
| AL-05 | Conduct/TCF training due refresh post-pilot kickoff | TR-007 | Counsel | — | Pre-pilot |
| AL-06 | Model / AI risk training (recommended) overdue | TR-009 | Founder · SRE | 44 | Overdue |
| AL-07 | Advisor renewal due (key-person continuity) | KP-07 · MC-007 | Counsel · Founder | 30 | Renewal |
Centre Acceptance Criteria
- Every role row names type, source, engagement basis, linked centre, and state.
- Every responsibility row names primary, secondary, counsel-binding flag, SoD pair, and linked centre.
- Every competency row names required roles, evidence basis, re-attestation cadence, and state.
- Every training module names cadence, audience, source, last-completed, and state.
- Every attestation row names audience, linked pack, counsel-binding flag, last attested, and state.
- Onboarding/offboarding workflows name owners on every step.
- Every key-person row names single-point-of-failure flag, compensating control, succession plan, and state.
- External-facing people / competency language remains counsel-locked. Centre is internal-only.
People Centre Audit Events (last 10)
| Event | When | Actor | Centre | Pack |
|---|---|---|---|---|
| People dashboard rendered | 2026-05-18T07:30Z | founder-admin | People, Training & Competency | — |
| SoD attestation reminder dispatched | 2026-05-18T07:32Z | system | User Role & Permissions | Authentication |
| Conflicts re-attestation scheduled | 2026-05-18T07:34Z | system | Legal Entity / Governance Records | Policy Attestation |
| Policy attestation pack counsel-pending | 2026-05-18T07:36Z | counsel | Policy / Control Library | Policy Attestation |
| DR drill cross-linked to training TR-006 | 2026-05-18T07:38Z | SRE | Operational Runbooks & Day-2 Support | Incident |
| Fit-and-proper-style attestation counsel review | 2026-05-18T07:40Z | counsel | Approval & Sign-Off | Policy Attestation |
| Key-person posture cross-linked to Strategic Risk Register | 2026-05-18T07:42Z | system | Strategic Risk Register | Incident |
| Advisor renewal reminder (MC-007) | 2026-05-18T07:44Z | system | Legal Entity / Governance Records | — |
| Auditor access pending engagement letter | 2026-05-18T07:46Z | counsel | Vendor Risk | Outsourcing Concentration |
| External-bundle gate state sealed | 2026-05-18T07:48Z | counsel | Production Go/No-Go | Activity Perimeter |
What this Centre is NOT
- Not legal advice. Counsel countersign is the binding signal for any external-facing people / competency language.
- Not employment advice. HR / employment matters are handled externally.
- Not regulator approval, registration, licensing, or supervisory acceptance.
- Not fit-and-proper approval. Internal fit-and-proper-style attestation only.
- Not person approval, certification, or licence to act in any regulated capacity.
- Not an audit opinion. Auditor engagement letter remains unsigned.
- Not a regulator submission. Regulator-room view is counsel-curated and read-only.
- Not client acceptance. Pre-pilot posture.
- Not authorization for external launch. External bundle gates 1 and 2 not yet met.