BLACKSWAN OS · 32 / 32 People, Training & Competency Centre
Internal Only Counsel Pending HR / Legal Review
§01 · Posture

People, Training & Competency · Internal Posture

Internal competency workspace covering role taxonomy, responsibility map, competency matrix, training inventory, attestation register, onboarding/offboarding, support coverage, and key-person risk. Compiled from the 31 prior centres and the 21-pack evidence spine. Conservative: nothing here is regulator approval, fit-and-proper approval, person approval, audit opinion, employment advice, or authorization for external launch.

Headcount1 + 11 founder · 1 director · contractors per scope
Mapped roles128 internal · 4 external retained
Mandatory training9 / 101 module due re-attestation
Attestations14 / 162 counsel-bound pending
Key-person postureAmberFounder-root single-operator accepted-risk DEC-005
§02 · Role taxonomy

12-Role Internal/External Taxonomy

RoleTypeSourceLinked centreEngagement basisState
Founder · DirectorInternalDirector appointment letterLegal Entity / Governance RecordsPermanentActive
Independent DirectorInternalDirector appointment letterLegal Entity / Governance RecordsPermanentActive
Founder-Secretary / CoSec functionInternalSecretary letterLegal Entity / Governance RecordsPermanentSingle-party
Compliance / Legal lead (interim)ExternalMC-003 counsel engagementPolicy / Control LibraryRetained counselActive
SRE / Platform leadInternal · founder-playedOperating ModelOperational Runbooks & Day-2 SupportPermanentFounder dual-hat
CISO functionInternal · founder-playedOperating ModelSecurity OperationsPermanentFounder dual-hat
Evidence OwnerInternal · founder-playedCompletenessCompleteness / Data GovernancePermanentFounder dual-hat
Operations / support · pilot tierInternal · founder-playedOperating ModelOperational Runbooks & Day-2 SupportPre-pilotFounder dual-hat
Auditor · external (proposed)ExternalMC-004 engagement (drafted)Vendor RiskDraftedCounsel-pending
Insurance brokerExternalEV-INS-02 engagement letterInsurance, Claims & Loss EventRetainedActive
Tax advisorExternalAdvisor agreementFinancial ControlsRetainedActive
Founder advisor (technical / capital markets)ExternalMC-007 advisor agreementOperating ModelRetained · renewal dueRenewal due

Founder dual-hat rows (SRE / CISO / Evidence Owner / Operations) are the basis of the single-operator key-person risk addressed below.

§03 · Responsibility map (SMF-style, internal-only)

Responsibility & Accountability Map

SMF / approved-person style mapping used internally only. Not a regulatory submission and not an SMCR map.

ResponsibilityPrimarySecondaryCounsel-bindingSoD pairLinked centre
Overall management of the firmFounderDirector—Founder ≠ Director on Tier-1 rollbackExecutive Cockpit
Compliance oversightCounsel (retained)FounderYesDrafter ≠ Counsel on external languagePolicy / Control Library
Financial / capital / liquidityFounderExternal tax advisor—Author ≠ Approver on Capital planCapital, Liquidity & Prudential Readiness
Operational resilienceFounder (SRE)Director—SRE ≠ CISO on Tier-1 incidentOperational Runbooks & Day-2 Support
Cyber / information securityFounder (CISO)External IR retainer—SRE ≠ CISO on Tier-1 incidentSecurity Operations
Client lifecycle / KYC oversightCounselFounderYesCounsel ≠ Founder on KYC contractClient Lifecycle & Entitlements
Data governance & privacyFounder (Evidence Owner)CounselConditionalDrafter ≠ Approver on schema changeData Governance
Conduct & complaintsCounselFounderYesDrafter ≠ Counsel on complaint responseConduct Risk MI (planned) · Complaints (planned)
Regulator-facing engagementCounselFounderYesCounsel + Founder dual sign-offRegulatory Escalation · Regulatory Exam Response
Board / investor narrativeFounderDirectorYesDrafter ≠ Approver on board sectionStrategic Reporting
Vendor / outsourcing oversightFounderCounselYes (Tier-1)Single-party ≠ Tier-1 vendor executionVendor Risk
Risk & control testingFounderDirector · QA—Tester ≠ Approver on SecurityStrategic Risk Register · Testing/QA/Release Evidence
§04 · Competency matrix

Competency Matrix (per role)

CompetencyRequired forEvidence basisRe-attestation cadenceState
Capital markets product knowledgeFounder · Director · Counsel · AdvisorCV · prior engagements · counsel reviewAnnualAttested
Regulatory framework (UK / EU mapping)Counsel · FounderCounsel certification · CPDAnnualAttested
SoD & least-privilege operationFounder · Director · SRE / CISOSoD attestation · access reviewQuarterlyRe-attestation due
Incident response / DRSRE · CISO · OperationsTabletop log · DR drill participationBi-annualDrill 2026-05-15
MNPI handling / market-abuse awarenessFounder · Director · Counsel · AdvisorAnnual attestation · counsel briefingAnnualAttested
KYC / KYB / financial crimeCounsel · Operations · FounderAnnual attestation · vendor trainingAnnualAttested
Data protection / privacy (UK-GDPR style)AllAnnual attestationAnnualAttested
Conduct / treating clients fairlyFounder · Director · Counsel · OperationsCounsel briefing · attestationAnnualPre-pilot
Cyber hygiene / phishingAllQuarterly attestationQuarterlyCurrent
Model / AI risk awarenessFounder · SRE · ComplianceCounsel briefing · model logBi-annualPre-pilot
§05 · Training inventory

Mandatory & Recommended Training

IDModuleStatusCadenceAudienceSourceLast completed
TR-001MNPI / market abuse awarenessMandatoryAnnualAllCounsel-led briefing2026-02-18
TR-002KYC / KYB / AML overviewMandatoryAnnualFounder · Counsel · OperationsVendor training2026-02-25
TR-003Data protection / privacyMandatoryAnnualAllExternal course2026-02-25
TR-004Cyber hygiene / phishingMandatoryQuarterlyAllInternal · platform2026-04-30
TR-005SoD & least-privilege operationMandatoryQuarterlyFounder · Director · SRE / CISOInternal attestation2026-02-12
TR-006Incident response / DR tabletopMandatoryBi-annualSRE · CISO · OperationsInternal drill2026-05-15
TR-007Conduct / TCF / complaints handlingMandatoryAnnualFounder · Director · Counsel · OperationsCounsel-led briefing2026-03-08
TR-008Regulatory framework refresher (UK / EU)MandatoryAnnualCounsel · FounderCPD external2026-03-15
TR-009Model / AI risk awarenessRecommendedBi-annualFounder · SRE · ComplianceExternal course · counsel briefing2026-04-04
TR-010Capital / liquidity / wind-down literacyMandatoryAnnualFounder · DirectorCounsel + finance briefing2026-05-02
§06 · Attestation register

Conduct & Policy Attestation Register

IDAttestationAudienceLinked packCounselLast attestedState
AT-001Conflicts of interest declarationAll officersPolicy Attestation · Conduct Risk MI—2026-04-22Re-attestation 2026-08-15
AT-002Code of conduct attestationAllPolicy AttestationYes2026-03-22Current
AT-003SoD attestationFounder · Director · SRE/CISOAuthentication—2026-02-12Quarterly · due
AT-004MNPI handling attestationFounder · Director · Counsel · AdvisorData-Room MNPIYes2026-02-18Current
AT-005Data protection attestationAllPolicy Attestation—2026-02-25Current
AT-006Cyber hygiene quarterly attestationAllAuthentication—2026-04-30Current
AT-007Policy attestation pack acknowledgementAllPolicy AttestationYes2026-05-04Counsel-pending refresh
AT-008Fit-and-proper-style internal attestationFounder · Director · CounselPolicy AttestationYes2026-03-12Counsel review
AT-009Outside-business interests declarationFounder · DirectorConduct Risk MI—2026-04-22Current
AT-010Personal account dealing attestationFounder · Director · Counsel · AdvisorConduct Risk MI · Data-Room MNPIYes2026-04-22Current
§07 · Onboarding / offboarding workflow

Onboarding / Offboarding

Onboarding (10-step)

#StepOwner
1Right-to-work + identity checkHR / Counsel
2Reference / fit-and-proper-style attestationHR / Counsel
3Engagement letter / contract signedCounsel · Founder
4Role definition + responsibility map slotFounder
5Mandatory training assignmentsHR / People
6Access provisioning · least-privilege · MFASRE / CISO
7Policy & attestation pack signatureCounsel
8SoD-pair assignmentFounder · CISO
930/60/90 competency check-insFounder
10Evidence-pack linkage in CompletenessEvidence Owner

Offboarding (10-step)

#StepOwner
1Notice / departure trigger loggedFounder
2Knowledge transfer planFounder + leaver
3MNPI / confidentiality reminder · counsel-lockedCounsel
4Access deprovisioning · revoke MFA / keysSRE / CISO
5Device / data return / wipeSRE
6SoD-pair re-assignmentFounder · CISO
7Final attestations · exit declarationsCounsel · HR
8Regulator / register update if officerCounsel · CoSec
9Succession / coverage updateFounder
10Evidence preservation · legal-hold checkEvidence Owner · Counsel
§08 · Support coverage grid

Operational Support Coverage

WindowPrimarySecondaryCounsel reachableSRE / CISO reachableState
Pre-market 06:00–09:00FounderDirector (best-effort)Email · ≤2h SLAFounder dual-hatSingle-operator
Market 09:00–17:30FounderDirector · Counsel retainedSame-dayFounder dual-hatSingle-operator
Post-market 17:30–21:00FounderBest-effortEmailFounder dual-hatSingle-operator
Night 21:00–06:00On-call pager · founder—Email · next business dayIR retainer on cyber panelOn-call only
Weekend / holidayOn-call pager · founderDirector (best-effort)Email · next business dayIR retainer on cyber panelOn-call only

Pre-pilot posture explicitly accepts single-operator coverage (DEC-005). Compensating controls: Tier-1 two-party rollback (SRE + Founder), IR retainer, runbook-driven incident workflow, and SLA-based counsel reachability.

§09 · Key-person risk & succession

Key-Person Risk & Succession Tracker

FunctionSingle-point-of-failure?Compensating controlSuccession planState
Founder · overall managementYesDirector · standing instructions · DEC-005Director step-up · counsel-led interim planAccepted-risk
Founder · SRE / platformYesIR retainer · cloud vendor support · runbooksSRE hire scoped (post-pilot)Pre-pilot
Founder · CISOYesCyber insurance IR panel · MFA enforcedCISO hire scoped (post-pilot)Pre-pilot
Founder · Evidence OwnerYesRetention windows · cross-link integrity · audit logEvidence Owner hire scopedPre-pilot
Counsel · retainedNo · firm-engagedFirm capacity · written briefingsAlternate counsel firm scopedMitigated
Director · governancePartialFounder + Counsel quorum rulesReplacement director shortlistWatch
External advisor (technical)NoAdvisor agreement · renewal dueAlternate advisor scopedOn track
Broker / insurer / IR retainerNoBroker engagement · IR retainer · alternate broker scopedAlternate broker availableMitigated
§10 · Access review dependencies

Access & Permissions Dependencies

SurfaceOwnerCadenceCross-link centreState
Founder-root access reviewFounder + DirectorQuarterlyUser Role & Permissions · Security OperationsAccepted-risk DEC-005
SoD pair auditCISO functionQuarterlyUser Role & PermissionsRe-attestation due
Tier-1 vendor accessVendor RiskQuarterlyVendor Risk · OutsourcingCurrent
Counsel data-room accessCounselPer sessionStakeholder Rooms · Data-Room MNPICurrent
Auditor access (when engaged)Counsel · FounderPer engagementVendor Risk · Approval & Sign-OffPending engagement letter
§11 · Stakeholder views

People Briefing Posture

Founder / Admin

Role map, responsibilities, training inventory, attestation register, key-person risk.

Board reviewer

Competency posture, succession, key-person risk acceptance.

Compliance / Legal

Counsel-bound rows, fit-and-proper-style attestation, conflicts, conduct.

People / Governance owner

Onboarding/offboarding workflow, training cadence, attestation owners.

Operations

Support coverage grid, runbook coverage, on-call routes.

Technology / Security

Access review, SoD pairs, MFA, IR retainer, key-person cyber posture.

Evidence Owner

Records→pack traceability, attestation retention, training evidence linkage.

Client Support

Support window coverage, escalation routes (pre-pilot).

Regulator-review room

Counsel-curated read-only. Not a regulator submission.

Auditor / Assurance reviewer

Engagement-letter gated. Not an audit opinion.

§12 · External bundle gates

External People-Bundle Gates

Currently 2 of 4 met. Mirrors prior centres' posture.

GateAcceptance criterionCounsel-bindingState
1Counsel-locked language across any external people / competency statementYesPending
2Fit-and-proper-style attestation + policy attestation pack counsel-countersignedYesNot met
3All training / attestation evidence hashed and cross-linked in retention—Met
4SoD & access review attested in last 90 days—Met
§13 · Stale training / attestation alerts

Stale Training & Attestation Alerts

IDAlertLinked artefactOwnerAge (d)State
AL-01SoD attestation quarterly · dueAT-003 · TR-005Founder · CISO96Due
AL-02Policy attestation pack counsel-pending refreshAT-007Counsel14Pending
AL-03Fit-and-proper-style attestation counsel reviewAT-008Counsel · Founder67Counsel review
AL-04Conflicts re-attestation due 2026-08-15AT-001CoSec · all officers—Scheduled
AL-05Conduct/TCF training due refresh post-pilot kickoffTR-007Counsel—Pre-pilot
AL-06Model / AI risk training (recommended) overdueTR-009Founder · SRE44Overdue
AL-07Advisor renewal due (key-person continuity)KP-07 · MC-007Counsel · Founder30Renewal
§14 · Acceptance criteria

Centre Acceptance Criteria

  • Every role row names type, source, engagement basis, linked centre, and state.
  • Every responsibility row names primary, secondary, counsel-binding flag, SoD pair, and linked centre.
  • Every competency row names required roles, evidence basis, re-attestation cadence, and state.
  • Every training module names cadence, audience, source, last-completed, and state.
  • Every attestation row names audience, linked pack, counsel-binding flag, last attested, and state.
  • Onboarding/offboarding workflows name owners on every step.
  • Every key-person row names single-point-of-failure flag, compensating control, succession plan, and state.
  • External-facing people / competency language remains counsel-locked. Centre is internal-only.
§15 · Audit trail

People Centre Audit Events (last 10)

EventWhenActorCentrePack
People dashboard rendered2026-05-18T07:30Zfounder-adminPeople, Training & Competency—
SoD attestation reminder dispatched2026-05-18T07:32ZsystemUser Role & PermissionsAuthentication
Conflicts re-attestation scheduled2026-05-18T07:34ZsystemLegal Entity / Governance RecordsPolicy Attestation
Policy attestation pack counsel-pending2026-05-18T07:36ZcounselPolicy / Control LibraryPolicy Attestation
DR drill cross-linked to training TR-0062026-05-18T07:38ZSREOperational Runbooks & Day-2 SupportIncident
Fit-and-proper-style attestation counsel review2026-05-18T07:40ZcounselApproval & Sign-OffPolicy Attestation
Key-person posture cross-linked to Strategic Risk Register2026-05-18T07:42ZsystemStrategic Risk RegisterIncident
Advisor renewal reminder (MC-007)2026-05-18T07:44ZsystemLegal Entity / Governance Records—
Auditor access pending engagement letter2026-05-18T07:46ZcounselVendor RiskOutsourcing Concentration
External-bundle gate state sealed2026-05-18T07:48ZcounselProduction Go/No-GoActivity Perimeter
§16 · Conservative limitations

What this Centre is NOT

  • Not legal advice. Counsel countersign is the binding signal for any external-facing people / competency language.
  • Not employment advice. HR / employment matters are handled externally.
  • Not regulator approval, registration, licensing, or supervisory acceptance.
  • Not fit-and-proper approval. Internal fit-and-proper-style attestation only.
  • Not person approval, certification, or licence to act in any regulated capacity.
  • Not an audit opinion. Auditor engagement letter remains unsigned.
  • Not a regulator submission. Regulator-room view is counsel-curated and read-only.
  • Not client acceptance. Pre-pilot posture.
  • Not authorization for external launch. External bundle gates 1 and 2 not yet met.