← BLACKSWAN OS
Policy · Procedure · Control Library
Internal Readiness · Simulated
Centre Status

Policy, Procedure & Control Library Centre

BLACKSWAN's internal library for policies, procedures, and controls mapped to the 21-pack evidence spine. Every policy carries an owner, an evidence source, a last-reviewed date, an approval state, and a counsel-bound limitation footer. Procedures are runbooks tied to operating controls; controls carry test cadence and evidence event tags. Conservative posture: internal readiness only — not legal advice, not regulator approval, not certification, not audit opinion, not authorization for external launch.

Policies catalogued
21
One per BLACKSWAN evidence pack · all counsel-bound
Procedure runbooks
10
Linked to operating controls across the 19 Centres
Controls catalogued
10
Owner · cadence · evidence source · last-tested
Open exceptions
9
Risk-committee or counsel-bound
Policy / control state legend
Draft In Review Counsel Review Owner Attested Approved Internal Live Stale · Review Overdue Exception Granted Risk Accepted Blocked Retired Archived
Eight library domains

Policy · Procedure · Control library domains

Policy Inventory
21 policies · spine-mapped

One policy per BLACKSWAN evidence pack with owner, last-review, attestation cadence, and counsel countersign state.

Procedure Runbooks
10 runbooks · live

Operational procedures linked directly to specific controls and Centre owners; counsel-bound where regulator-facing.

Control Library
10 controls catalogued

Each control carries owner, test cadence, evidence source, last-tested date, approval state, and compensating-control note.

Exceptions & Risk Acceptances
9 open

Exceptions with compensating controls; risk acceptances explicitly approved with counsel and risk-committee visibility.

Pack-to-Policy Traceability
21 packs · 21 policies

Every BLACKSWAN evidence pack mapped to its governing policy, owning Centre, and key controls.

Stale Policy / Control Alerts
3 alerts open

Items overdue for review against the policy/control review cadence; on every alert: owner, gap, remediation path.

External Bundle Readiness Gates
3 of 4 gates met

Counsel sign-off · evidence freshness · redaction posture · per-recipient distribution control; no external bundle ships without all four green.

Board / Regulator Export Posture
Workflow live

Board awareness packs board-ready; regulator-facing packs locked behind counsel countersign and 7-step strategic-reporting distribution workflow.

Policy inventory · 21 policies

One policy per BLACKSWAN evidence pack — owner · last review · approval state

Policy ID Domain / pack Owner Owning Centre Last reviewed Next review Counsel countersign Approval state
POL-001AuthCISO · Identity LeadSecurity Operations2026-05-142026-08-14Pending — post Entra cutoverCounsel Review
POL-002KYC / KYB OnboardingHead of Commercial · External CounselCommercial Readiness2026-04-302026-07-30Pending — KYC contract closeCounsel Review
POL-003Data-Room MNPI AccessCISO · Head of Stakeholder RoomsStakeholder Rooms · Data Governance2026-05-152026-08-15LockedLive
POL-004Settlement ResponsibilityCFO · External CounselFinancial Controls2026-04-222026-07-22Pending — counsel rule-packCounsel Review
POL-005Activity Perimeter DecisionHead of Regulatory · External CounselRegulatory Escalation · Jurisdiction Playbooks2026-05-122026-08-12Pending — 2026-05-19 sessionCounsel Review
POL-006Control TestingCISO · Programme ManagerApproval & Sign-Off · Model Governance2026-05-092026-08-09Owner attestedApproved Internal
POL-007Partner-Route AssuranceHead of Procurement · Head of CommercialVendor Risk · Commercial Readiness2026-03-182026-06-18Pending — material reclassificationStale · Review Overdue
POL-008Revenue RecognitionCFO · External Auditor (pending)Financial Controls2026-04-122026-07-12Pending — auditor engagementCounsel / Auditor Review
POL-009Tax / VATCFO · Tax AdviserFinancial Controls2026-04-152026-07-15Adviser draftIn Review
POL-010Regulatory Digital Twin DecisionHead of Regulatory · CISOModel Governance · Regulatory Escalation2026-05-122026-08-12Pending — counsel rule-packCounsel Review
POL-011Model RiskCISO · Head of RegulatoryModel Governance2026-05-102026-08-10Pending — counsel rule-packCounsel Review
POL-012IncidentCISO · SRE LeadProduction Monitoring · Security Operations2026-05-092026-08-09Owner attested · counsel for regulator-facingApproved Internal
POL-013Board-Pack AttestationCoS · Board ChairStrategic Reporting · Programme Governance2026-05-022026-08-02Board ChairApproved Internal
POL-014Regulatory ChangeHead of Regulatory · External CounselRegulatory Escalation · Jurisdiction Playbooks2026-04-282026-07-28Pending — counsel sweepCounsel Review
POL-015ComplaintsHead of CommercialCommercial Readiness · Operating Model2026-04-082026-07-08Owner draftDraft
POL-016Outsourcing ConcentrationHead of Procurement · Risk CommitteeVendor Risk · Enterprise Architecture2026-04-142026-07-14Pending — CHG-006 closeCounsel Review
POL-017Capital / Liquidity ReadinessCFO · External CounselFinancial Controls2026-04-222026-07-22Pending — counselCounsel Review
POL-018Policy AttestationCISO · DG Lead · Head of RegulatoryOperating Model · Security Operations2026-05-012026-08-01Internal attestationApproved Internal
POL-019Product GovernanceHead of Commercial · External CounselCommercial Readiness · Approval & Sign-Off2026-04-252026-07-25Pending — counsel sign-offCounsel Review
POL-020Conduct Risk MIRisk Committee · CoSOperating Model · Strategic Reporting2026-03-302026-06-30Owner attestedStale · Review Overdue
POL-021Regulatory Exam ResponseExternal Counsel · Head of RegulatoryRegulatory Escalation · Model Governance2026-05-112026-08-11Locked · restrictedRestricted Use
Procedure runbooks

Operational runbooks linked to controls

Runbook ID Title Owner Linked policy Linked control(s) Last drill / run Cadence State
RB-T1-MASTERTier-1 incident master runbookCISO · SRE LeadPOL-012 IncidentCTL-INCIDENT · CTL-WAF · CTL-SIEM2026-05-09 (tabletop)QuarterlyLive
RB-RC-ROLLBACKRelease rollback runbookSRE Lead · Programme ManagerPOL-006 Control TestingCTL-RELEASE2026-05-08 (drill)QuarterlyLive
RB-DR-FAILOVERDR / regional failover runbookSRE Lead · CISOPOL-012 IncidentCTL-DR · CTL-RTO-RPO2026-03-12 (drill) · next 2026-06-12QuarterlyLive
RB-DG-INCIDENTData incident / privacy runbookDG Lead · CISO · External CounselPOL-003 MNPI · POL-018 Policy AttestationCTL-DSR · CTL-RETENTION-HOLD2026-05-04 (tabletop)QuarterlyLive
RB-REG-NOTIFYRegulator notification runbookHead of Regulatory · External CounselPOL-014 Reg. Change · POL-012 IncidentCTL-REG-NOTIFY · CTL-COUNSEL-COUNTERSIGN2026-05-09 (tabletop)QuarterlyCounsel Review
RB-ROOM-SHAREStakeholder room per-share runbookHead of Stakeholder Rooms · CISOPOL-003 MNPICTL-ROOM-ACCESS · CTL-LINK-SIGNINGPer-share · continuousPer-shareLive
RB-EVIDENCE-PUBLISHEvidence pack publish runbookHead of EvidencePOL-013 Board-Pack AttestationCTL-DUAL-SIGNOFF · CTL-FOOTERPer pack · weeklyWeeklyLive
RB-VENDOR-ONBOARDVendor onboarding & DD runbookHead of Procurement · CISOPOL-007 Partner Route · POL-016 OutsourcingCTL-VENDOR-CLASS · CTL-DPA-SCC2026-04-22Per-vendor + monthlyLive
RB-FINANCIAL-CLOSEMonthly financial close runbookCFOPOL-008 Rev Rec · POL-009 Tax · POL-017 CapitalCTL-RECON · CTL-AUDIT-BINDER2026-04-30 (Apr close)MonthlyApproved Internal
RB-MODEL-OVERRIDEModel output override runbookCISO · Head of RegulatoryPOL-010 Digital Twin · POL-011 Model RiskCTL-MODEL-OVERRIDE · CTL-HUMAN-IN-LOOP2026-05-12 (live override)On override + monthlyLive
Control library

Ten controls · owner · cadence · evidence source · last-tested · approval

Control ID Control Owner Test cadence Evidence source Last tested Approval state Compensating note
CTL-001MFA & conditional access (admin · evidence-owner)CISOQuarterly + on policy changeSEC-EV-MFA-0022026-05-13Pending TestStaging factors enforced until Entra cutover
CTL-002Quarterly access reviewsCISO · Programme ManagerQuarterlySEC-EV-AXR-0082026-05-15 (in progress)In ReviewOne stale assignment under triage
CTL-003Stakeholder room per-share access reviewHead of Stakeholder Rooms · CISOPer-shareSEC-EV-ROOM-0062026-05-15LiveRoom-link signing key rotated 2026-05-10
CTL-004Dual sign-off (Tier-1 release · MNPI · break-glass)Programme Manager · CISOPer eventSEC-EV-DUAL-001ContinuousLiveSOD reduces founder concentration
CTL-005Vendor / outsourcing classificationHead of Procurement · Risk CommitteePer change + monthlyVEN-EV-CLASS-0012026-05-14Counsel ReviewCHG-006 reclassification pending
CTL-006Per-file limitation footer on exportsHead of Evidence · External CounselPer exportEVIDENCE-EV-FOOTER-001ContinuousLiveADR-007
CTL-007Human-in-loop review on every model outputCISO · Head of RegulatoryPer outputMR-EV-HIL-001ContinuousLiveADR-005
CTL-008DR RTO 30m / RPO 5m for Tier-1SRE Lead · CISOQuarterly drillEA-EV-DR-0082026-03-12 · next 2026-06-12LiveADR-008
CTL-009Monthly financial close + reconciliationCFOMonthlyFIN-EV-CLOSE-0042026-04-30Approved InternalExternal auditor engagement pending
CTL-010External counsel countersign on regulator-facing artefactExternal Counsel · CEOPer artefactJP-EV-COUNSEL-009ContinuousLive7-step counsel review workflow
Exceptions & risk acceptances

Open exceptions · approver visibility · limitation text

Exception ID Exception / acceptance Affected policy / control Severity Owner Approver Limitation text Target close State
EXC-001Permanent founder-rootPOL-018 Policy Attestation · CTL-004 Dual Sign-OffAcceptedBoard (dual)Board · CISO"Standing accepted risk; MFA + re-auth + monthly attestation compensating controls (DEC-005)."StandingRisk Accepted
EXC-002MFA enforcement test pending until Entra cutoverPOL-001 Auth · CTL-001 MFAMediumCISORisk Committee"Staging factors enforced; production posture conditional on Entra cutover (CHG-001)."2026-06-08Exception Granted
EXC-003WAF custom rule pack in shadow onlyPOL-012 Incident · CTL-WAFMediumCISO · SRE LeadRisk Committee"OWASP pack live; custom pack shadow-mode until CISO sign-off (CHG-003)."2026-05-30Exception Granted
EXC-004External auditor engagement letter pendingPOL-008 Revenue Recognition · CTL-009 CloseP1CFOBoard"Hold revenue treatment hints until auditor signs (DEC-006)."2026-06-15Exception Granted
EXC-005Counsel rule-pack countersign openPOL-005 Perimeter · POL-010 Twin · POL-011 Model Risk · POL-014 Reg ChangeP0Head of Regulatory · External CounselCounsel · CEO"Restrict affected outputs; limitation footer enforced (RAID-002)."2026-05-19 (counsel session)Counsel Review
EXC-006Vendor reclassification (2 vendors) pending counselPOL-007 Partner Route · POL-016 Outsourcing · CTL-005 Vendor ClassP2Head of Procurement · Risk CommitteeCounsel · Risk Committee"Effective 2026-06-01 subject to counsel countersign (CHG-006)."2026-06-01Counsel Review
EXC-007Complaints register thin pre-pilotPOL-015 ComplaintsP3Head of CommercialRisk Committee"Complaint-capture flow being defined before first pilot."Pre first pilotDraft
EXC-008Conduct Risk MI policy review overduePOL-020 Conduct Risk MIP3Risk Committee · CoSRisk Committee"Q2 attestation overdue; quarterly MI continues."2026-05-30Stale · Review Overdue
EXC-009Partner-Route Assurance policy review overduePOL-007 Partner RouteP2Head of ProcurementRisk Committee · Counsel"Refresh post CHG-006 reclassification countersign."2026-06-15Stale · Review Overdue
Pack-to-policy traceability matrix

21 BLACKSWAN evidence packs · governing policy · owning Centre · primary controls

Evidence pack Governing policy Owning Centre(s) Primary controls
AuthPOL-001Security Operations · Enterprise ArchitectureCTL-001 · CTL-002
KYC / KYB OnboardingPOL-002Commercial Readiness · Vendor RiskCTL-005
Data-Room MNPI AccessPOL-003Stakeholder Rooms · Data GovernanceCTL-003 · CTL-006
Settlement ResponsibilityPOL-004Financial ControlsCTL-009
Activity Perimeter DecisionPOL-005Regulatory Escalation · Jurisdiction PlaybooksCTL-010
Control TestingPOL-006Approval & Sign-Off · Model GovernanceCTL-004 · CTL-007
Partner-Route AssurancePOL-007Vendor Risk · Commercial ReadinessCTL-005
Revenue RecognitionPOL-008Financial ControlsCTL-009
Tax / VATPOL-009Financial ControlsCTL-009
Regulatory Digital Twin DecisionPOL-010Model Governance · Regulatory EscalationCTL-007 · CTL-010
Model RiskPOL-011Model GovernanceCTL-007
IncidentPOL-012Production Monitoring · Security OperationsCTL-008
Board-Pack AttestationPOL-013Strategic Reporting · Programme GovernanceCTL-004 · CTL-006
Regulatory ChangePOL-014Regulatory Escalation · Jurisdiction PlaybooksCTL-010
ComplaintsPOL-015Commercial Readiness · Operating ModelCTL-006
Outsourcing ConcentrationPOL-016Vendor Risk · Enterprise ArchitectureCTL-005 · CTL-008
Capital / Liquidity ReadinessPOL-017Financial ControlsCTL-009
Policy AttestationPOL-018Operating Model · Security OperationsCTL-002 · CTL-004
Product GovernancePOL-019Commercial Readiness · Approval & Sign-OffCTL-006 · CTL-010
Conduct Risk MIPOL-020Operating Model · Strategic ReportingCTL-006
Regulatory Exam ResponsePOL-021Regulatory Escalation · Model GovernanceCTL-010
Stale policy / control alerts

Items overdue for review · owner · gap · remediation

Alert ID Item Cadence Last reviewed Owner Gap Remediation path
STALE-001POL-007 Partner-Route AssuranceQuarterly2026-03-18Head of Procurement · Head of Commercial59 days · 31 overRefresh post CHG-006 counsel countersign
STALE-002POL-020 Conduct Risk MIQuarterly2026-03-30Risk Committee · CoS47 days · 19 overRun Q2 attestation cycle by 2026-05-30
POL-009 Tax / VATAdviser draft pending refreshQuarterly2026-04-15CFO · Tax Adviser31 days · 0 over · approachingComplete adviser draft before 2026-07-15
External bundle readiness gates

Four gates · all must be green before any external bundle ships

Gate 1
Counsel sign-off

External counsel countersigns regulator-facing or investor-facing language; per artefact, per audience.

Open
Gate 2
Evidence freshness

Every quoted metric, state, or hash carries a freshness date; "as of" footer mandatory; stale items blocked.

Met
Gate 3
Redaction posture

Counterparty names · MNPI · staff personal data redacted in external variants; counsel approval required.

Met
Gate 4
Per-recipient distribution

Watermarked, per-recipient link signing, audit-logged access, acknowledgement collection on board / investor read.

Met
Current posture: three gates met · one open. No external bundle ships until Counsel sign-off (Gate 1) closes following the 2026-05-19 counsel rule-pack session. Internal board awareness packs may move under Strategic Reporting board-only restriction.
Board / regulator prep export posture

Audience · pack · restriction · workflow step · evidence

Audience Pack Restriction Workflow step (Strategic Reporting) Counsel countersign required? Evidence reference
Board (internal)Board pack · 12 sectionsRestricted / Internal OnlyStep 5 · Board / investor approvalWhere regulator-facingSR-BP-EV-001
Board (board-only)Board decision requests (7)Board OnlyStep 5Where regulator-facingSR-DR-EV-002
Investor (redacted variant)Investor narrative · 11 sectionsRedacted ExternalStep 6 · Distribution (post counsel + CEO)Yes — every sectionSR-IN-EV-003
Regulator-facing (per engagement)Engagement pack per jurisdictionCounsel-lockedJPRE 7-step counsel workflow · step 6 Pack LockYes — mandatoryJP-EV-COUNSEL-009
Counterparty (pilot)Per-pilot pack · MNPI-scopedPer-pilot tenant · counsel reviewStakeholder Rooms per-share runbookYes — per-pilotSR-EV-INVESTOR-004 + RB-ROOM-SHARE
External assurance (assessor pending)Independent attestation scopeRestricted Internal until engagedProgramme Governance gateYes — on engagementOM-EV-OI-003
Audit trail & evidence preservation

Audit log of policy / procedure / control events

Timestamp (UTC) Actor Policy / control / runbook Action Evidence hash Limitation recorded Next step
2026-05-08 09:00CISO · DG Lead · Head of RegulatoryPolicy inventory · 21 policiesPPCL-INV — policy inventory publishedsha256:ppcl…aa01"Internal readiness only."Refresh on counsel rule-pack countersign
2026-05-09 10:15SRE Lead · CISOProcedure runbooks · 10PPCL-RB — runbook catalogue publishedsha256:ppcl…aa02"Internal."Refresh on drill cadence
2026-05-10 14:40CISO · Programme ManagerControl library · 10PPCL-CTL — control library publishedsha256:ppcl…aa03"Internal."Refresh on control testing
2026-05-11 13:22Risk Committee · CISO · CounselException registerPPCL-EXC — 9 open exceptions loggedsha256:ppcl…aa04"Internal."Weekly review
2026-05-12 09:48Head of Evidence · Programme ManagerPack-to-policy traceabilityPPCL-TRACE — 21 packs · 21 policies tracedsha256:ppcl…aa05"Internal."Refresh on policy update
2026-05-15 08:00Programme ManagerStale policy / control sweepPPCL-STALE — 3 alerts openedsha256:ppcl…aa06"Internal."Close 2 alerts before 2026-05-30
2026-05-15 09:30External Counsel · CEO · CoSExternal bundle gatesPPCL-GATES — 3 of 4 gates metsha256:ppcl…aa07"No external bundle ships without all four gates."Close Gate 1 post 2026-05-19
2026-05-15 11:18Board Chair · CEO · External CounselBoard / regulator export posturePPCL-BRE — 6 audiences scopedsha256:ppcl…aa08"No external publication implied."Continue restriction-first distribution
2026-05-16 08:00CEO · CISO · DG Lead · Head of RegulatoryLibrary attestationPPCL-ATTESTATION — monthly attestationsha256:ppcl…aa09"Internal; not regulatory approval."Re-attest monthly
2026-05-19 (scheduled)External Counsel · Head of Regulatory · CEOCounsel rule-pack sessionPPCL-COUNSEL — pending—"Counsel-locked phrasing required before any regulator-facing pack lock."Capture countersign post session
Assumptions and Limitations

What this Centre is — and is not

  • Staging / simulated policy & control data. All policy IDs, control IDs, evidence hashes, dates, and audit events shown here are seed values for an internal policy-readiness workflow. They are not a live GRC tool, not a live policy register, and not a live audit log.
  • Internal readiness workflow only. This Centre captures BLACKSWAN's internal policy / procedure / control posture. It is not legal advice, not regulatory approval, not certification, not an audit opinion, and not authorization for external launch.
  • Counsel-bound by default. Every regulator- or investor-facing artefact requires external counsel countersign before any pack lock or distribution. Approved-Internal state means "approved for internal use" — never an external claim.
  • Conservative posture on external bundles. No external bundle ships unless all four external-bundle gates are met. Gate 1 (Counsel sign-off) is currently open pending the 2026-05-19 counsel rule-pack session.
  • Founder-root risk is a standing accepted risk. Per Programme Decision Log DEC-005, founder-root permanence carries MFA + re-auth + monthly attestation as compensating controls. EXC-001 records the operating consequence in this library.