Policy, Procedure & Control Library Centre
BLACKSWAN's internal library for policies, procedures, and controls mapped to the 21-pack evidence spine. Every policy carries an owner, an evidence source, a last-reviewed date, an approval state, and a counsel-bound limitation footer. Procedures are runbooks tied to operating controls; controls carry test cadence and evidence event tags. Conservative posture: internal readiness only — not legal advice, not regulator approval, not certification, not audit opinion, not authorization for external launch.
Policy · Procedure · Control library domains
One policy per BLACKSWAN evidence pack with owner, last-review, attestation cadence, and counsel countersign state.
Operational procedures linked directly to specific controls and Centre owners; counsel-bound where regulator-facing.
Each control carries owner, test cadence, evidence source, last-tested date, approval state, and compensating-control note.
Exceptions with compensating controls; risk acceptances explicitly approved with counsel and risk-committee visibility.
Every BLACKSWAN evidence pack mapped to its governing policy, owning Centre, and key controls.
Items overdue for review against the policy/control review cadence; on every alert: owner, gap, remediation path.
Counsel sign-off · evidence freshness · redaction posture · per-recipient distribution control; no external bundle ships without all four green.
Board awareness packs board-ready; regulator-facing packs locked behind counsel countersign and 7-step strategic-reporting distribution workflow.
One policy per BLACKSWAN evidence pack — owner · last review · approval state
| Policy ID | Domain / pack | Owner | Owning Centre | Last reviewed | Next review | Counsel countersign | Approval state |
|---|---|---|---|---|---|---|---|
| POL-001 | Auth | CISO · Identity Lead | Security Operations | 2026-05-14 | 2026-08-14 | Pending — post Entra cutover | Counsel Review |
| POL-002 | KYC / KYB Onboarding | Head of Commercial · External Counsel | Commercial Readiness | 2026-04-30 | 2026-07-30 | Pending — KYC contract close | Counsel Review |
| POL-003 | Data-Room MNPI Access | CISO · Head of Stakeholder Rooms | Stakeholder Rooms · Data Governance | 2026-05-15 | 2026-08-15 | Locked | Live |
| POL-004 | Settlement Responsibility | CFO · External Counsel | Financial Controls | 2026-04-22 | 2026-07-22 | Pending — counsel rule-pack | Counsel Review |
| POL-005 | Activity Perimeter Decision | Head of Regulatory · External Counsel | Regulatory Escalation · Jurisdiction Playbooks | 2026-05-12 | 2026-08-12 | Pending — 2026-05-19 session | Counsel Review |
| POL-006 | Control Testing | CISO · Programme Manager | Approval & Sign-Off · Model Governance | 2026-05-09 | 2026-08-09 | Owner attested | Approved Internal |
| POL-007 | Partner-Route Assurance | Head of Procurement · Head of Commercial | Vendor Risk · Commercial Readiness | 2026-03-18 | 2026-06-18 | Pending — material reclassification | Stale · Review Overdue |
| POL-008 | Revenue Recognition | CFO · External Auditor (pending) | Financial Controls | 2026-04-12 | 2026-07-12 | Pending — auditor engagement | Counsel / Auditor Review |
| POL-009 | Tax / VAT | CFO · Tax Adviser | Financial Controls | 2026-04-15 | 2026-07-15 | Adviser draft | In Review |
| POL-010 | Regulatory Digital Twin Decision | Head of Regulatory · CISO | Model Governance · Regulatory Escalation | 2026-05-12 | 2026-08-12 | Pending — counsel rule-pack | Counsel Review |
| POL-011 | Model Risk | CISO · Head of Regulatory | Model Governance | 2026-05-10 | 2026-08-10 | Pending — counsel rule-pack | Counsel Review |
| POL-012 | Incident | CISO · SRE Lead | Production Monitoring · Security Operations | 2026-05-09 | 2026-08-09 | Owner attested · counsel for regulator-facing | Approved Internal |
| POL-013 | Board-Pack Attestation | CoS · Board Chair | Strategic Reporting · Programme Governance | 2026-05-02 | 2026-08-02 | Board Chair | Approved Internal |
| POL-014 | Regulatory Change | Head of Regulatory · External Counsel | Regulatory Escalation · Jurisdiction Playbooks | 2026-04-28 | 2026-07-28 | Pending — counsel sweep | Counsel Review |
| POL-015 | Complaints | Head of Commercial | Commercial Readiness · Operating Model | 2026-04-08 | 2026-07-08 | Owner draft | Draft |
| POL-016 | Outsourcing Concentration | Head of Procurement · Risk Committee | Vendor Risk · Enterprise Architecture | 2026-04-14 | 2026-07-14 | Pending — CHG-006 close | Counsel Review |
| POL-017 | Capital / Liquidity Readiness | CFO · External Counsel | Financial Controls | 2026-04-22 | 2026-07-22 | Pending — counsel | Counsel Review |
| POL-018 | Policy Attestation | CISO · DG Lead · Head of Regulatory | Operating Model · Security Operations | 2026-05-01 | 2026-08-01 | Internal attestation | Approved Internal |
| POL-019 | Product Governance | Head of Commercial · External Counsel | Commercial Readiness · Approval & Sign-Off | 2026-04-25 | 2026-07-25 | Pending — counsel sign-off | Counsel Review |
| POL-020 | Conduct Risk MI | Risk Committee · CoS | Operating Model · Strategic Reporting | 2026-03-30 | 2026-06-30 | Owner attested | Stale · Review Overdue |
| POL-021 | Regulatory Exam Response | External Counsel · Head of Regulatory | Regulatory Escalation · Model Governance | 2026-05-11 | 2026-08-11 | Locked · restricted | Restricted Use |
Operational runbooks linked to controls
| Runbook ID | Title | Owner | Linked policy | Linked control(s) | Last drill / run | Cadence | State |
|---|---|---|---|---|---|---|---|
| RB-T1-MASTER | Tier-1 incident master runbook | CISO · SRE Lead | POL-012 Incident | CTL-INCIDENT · CTL-WAF · CTL-SIEM | 2026-05-09 (tabletop) | Quarterly | Live |
| RB-RC-ROLLBACK | Release rollback runbook | SRE Lead · Programme Manager | POL-006 Control Testing | CTL-RELEASE | 2026-05-08 (drill) | Quarterly | Live |
| RB-DR-FAILOVER | DR / regional failover runbook | SRE Lead · CISO | POL-012 Incident | CTL-DR · CTL-RTO-RPO | 2026-03-12 (drill) · next 2026-06-12 | Quarterly | Live |
| RB-DG-INCIDENT | Data incident / privacy runbook | DG Lead · CISO · External Counsel | POL-003 MNPI · POL-018 Policy Attestation | CTL-DSR · CTL-RETENTION-HOLD | 2026-05-04 (tabletop) | Quarterly | Live |
| RB-REG-NOTIFY | Regulator notification runbook | Head of Regulatory · External Counsel | POL-014 Reg. Change · POL-012 Incident | CTL-REG-NOTIFY · CTL-COUNSEL-COUNTERSIGN | 2026-05-09 (tabletop) | Quarterly | Counsel Review |
| RB-ROOM-SHARE | Stakeholder room per-share runbook | Head of Stakeholder Rooms · CISO | POL-003 MNPI | CTL-ROOM-ACCESS · CTL-LINK-SIGNING | Per-share · continuous | Per-share | Live |
| RB-EVIDENCE-PUBLISH | Evidence pack publish runbook | Head of Evidence | POL-013 Board-Pack Attestation | CTL-DUAL-SIGNOFF · CTL-FOOTER | Per pack · weekly | Weekly | Live |
| RB-VENDOR-ONBOARD | Vendor onboarding & DD runbook | Head of Procurement · CISO | POL-007 Partner Route · POL-016 Outsourcing | CTL-VENDOR-CLASS · CTL-DPA-SCC | 2026-04-22 | Per-vendor + monthly | Live |
| RB-FINANCIAL-CLOSE | Monthly financial close runbook | CFO | POL-008 Rev Rec · POL-009 Tax · POL-017 Capital | CTL-RECON · CTL-AUDIT-BINDER | 2026-04-30 (Apr close) | Monthly | Approved Internal |
| RB-MODEL-OVERRIDE | Model output override runbook | CISO · Head of Regulatory | POL-010 Digital Twin · POL-011 Model Risk | CTL-MODEL-OVERRIDE · CTL-HUMAN-IN-LOOP | 2026-05-12 (live override) | On override + monthly | Live |
Ten controls · owner · cadence · evidence source · last-tested · approval
| Control ID | Control | Owner | Test cadence | Evidence source | Last tested | Approval state | Compensating note |
|---|---|---|---|---|---|---|---|
| CTL-001 | MFA & conditional access (admin · evidence-owner) | CISO | Quarterly + on policy change | SEC-EV-MFA-002 | 2026-05-13 | Pending Test | Staging factors enforced until Entra cutover |
| CTL-002 | Quarterly access reviews | CISO · Programme Manager | Quarterly | SEC-EV-AXR-008 | 2026-05-15 (in progress) | In Review | One stale assignment under triage |
| CTL-003 | Stakeholder room per-share access review | Head of Stakeholder Rooms · CISO | Per-share | SEC-EV-ROOM-006 | 2026-05-15 | Live | Room-link signing key rotated 2026-05-10 |
| CTL-004 | Dual sign-off (Tier-1 release · MNPI · break-glass) | Programme Manager · CISO | Per event | SEC-EV-DUAL-001 | Continuous | Live | SOD reduces founder concentration |
| CTL-005 | Vendor / outsourcing classification | Head of Procurement · Risk Committee | Per change + monthly | VEN-EV-CLASS-001 | 2026-05-14 | Counsel Review | CHG-006 reclassification pending |
| CTL-006 | Per-file limitation footer on exports | Head of Evidence · External Counsel | Per export | EVIDENCE-EV-FOOTER-001 | Continuous | Live | ADR-007 |
| CTL-007 | Human-in-loop review on every model output | CISO · Head of Regulatory | Per output | MR-EV-HIL-001 | Continuous | Live | ADR-005 |
| CTL-008 | DR RTO 30m / RPO 5m for Tier-1 | SRE Lead · CISO | Quarterly drill | EA-EV-DR-008 | 2026-03-12 · next 2026-06-12 | Live | ADR-008 |
| CTL-009 | Monthly financial close + reconciliation | CFO | Monthly | FIN-EV-CLOSE-004 | 2026-04-30 | Approved Internal | External auditor engagement pending |
| CTL-010 | External counsel countersign on regulator-facing artefact | External Counsel · CEO | Per artefact | JP-EV-COUNSEL-009 | Continuous | Live | 7-step counsel review workflow |
Open exceptions · approver visibility · limitation text
| Exception ID | Exception / acceptance | Affected policy / control | Severity | Owner | Approver | Limitation text | Target close | State |
|---|---|---|---|---|---|---|---|---|
| EXC-001 | Permanent founder-root | POL-018 Policy Attestation · CTL-004 Dual Sign-Off | Accepted | Board (dual) | Board · CISO | "Standing accepted risk; MFA + re-auth + monthly attestation compensating controls (DEC-005)." | Standing | Risk Accepted |
| EXC-002 | MFA enforcement test pending until Entra cutover | POL-001 Auth · CTL-001 MFA | Medium | CISO | Risk Committee | "Staging factors enforced; production posture conditional on Entra cutover (CHG-001)." | 2026-06-08 | Exception Granted |
| EXC-003 | WAF custom rule pack in shadow only | POL-012 Incident · CTL-WAF | Medium | CISO · SRE Lead | Risk Committee | "OWASP pack live; custom pack shadow-mode until CISO sign-off (CHG-003)." | 2026-05-30 | Exception Granted |
| EXC-004 | External auditor engagement letter pending | POL-008 Revenue Recognition · CTL-009 Close | P1 | CFO | Board | "Hold revenue treatment hints until auditor signs (DEC-006)." | 2026-06-15 | Exception Granted |
| EXC-005 | Counsel rule-pack countersign open | POL-005 Perimeter · POL-010 Twin · POL-011 Model Risk · POL-014 Reg Change | P0 | Head of Regulatory · External Counsel | Counsel · CEO | "Restrict affected outputs; limitation footer enforced (RAID-002)." | 2026-05-19 (counsel session) | Counsel Review |
| EXC-006 | Vendor reclassification (2 vendors) pending counsel | POL-007 Partner Route · POL-016 Outsourcing · CTL-005 Vendor Class | P2 | Head of Procurement · Risk Committee | Counsel · Risk Committee | "Effective 2026-06-01 subject to counsel countersign (CHG-006)." | 2026-06-01 | Counsel Review |
| EXC-007 | Complaints register thin pre-pilot | POL-015 Complaints | P3 | Head of Commercial | Risk Committee | "Complaint-capture flow being defined before first pilot." | Pre first pilot | Draft |
| EXC-008 | Conduct Risk MI policy review overdue | POL-020 Conduct Risk MI | P3 | Risk Committee · CoS | Risk Committee | "Q2 attestation overdue; quarterly MI continues." | 2026-05-30 | Stale · Review Overdue |
| EXC-009 | Partner-Route Assurance policy review overdue | POL-007 Partner Route | P2 | Head of Procurement | Risk Committee · Counsel | "Refresh post CHG-006 reclassification countersign." | 2026-06-15 | Stale · Review Overdue |
21 BLACKSWAN evidence packs · governing policy · owning Centre · primary controls
| Evidence pack | Governing policy | Owning Centre(s) | Primary controls |
|---|---|---|---|
| Auth | POL-001 | Security Operations · Enterprise Architecture | CTL-001 · CTL-002 |
| KYC / KYB Onboarding | POL-002 | Commercial Readiness · Vendor Risk | CTL-005 |
| Data-Room MNPI Access | POL-003 | Stakeholder Rooms · Data Governance | CTL-003 · CTL-006 |
| Settlement Responsibility | POL-004 | Financial Controls | CTL-009 |
| Activity Perimeter Decision | POL-005 | Regulatory Escalation · Jurisdiction Playbooks | CTL-010 |
| Control Testing | POL-006 | Approval & Sign-Off · Model Governance | CTL-004 · CTL-007 |
| Partner-Route Assurance | POL-007 | Vendor Risk · Commercial Readiness | CTL-005 |
| Revenue Recognition | POL-008 | Financial Controls | CTL-009 |
| Tax / VAT | POL-009 | Financial Controls | CTL-009 |
| Regulatory Digital Twin Decision | POL-010 | Model Governance · Regulatory Escalation | CTL-007 · CTL-010 |
| Model Risk | POL-011 | Model Governance | CTL-007 |
| Incident | POL-012 | Production Monitoring · Security Operations | CTL-008 |
| Board-Pack Attestation | POL-013 | Strategic Reporting · Programme Governance | CTL-004 · CTL-006 |
| Regulatory Change | POL-014 | Regulatory Escalation · Jurisdiction Playbooks | CTL-010 |
| Complaints | POL-015 | Commercial Readiness · Operating Model | CTL-006 |
| Outsourcing Concentration | POL-016 | Vendor Risk · Enterprise Architecture | CTL-005 · CTL-008 |
| Capital / Liquidity Readiness | POL-017 | Financial Controls | CTL-009 |
| Policy Attestation | POL-018 | Operating Model · Security Operations | CTL-002 · CTL-004 |
| Product Governance | POL-019 | Commercial Readiness · Approval & Sign-Off | CTL-006 · CTL-010 |
| Conduct Risk MI | POL-020 | Operating Model · Strategic Reporting | CTL-006 |
| Regulatory Exam Response | POL-021 | Regulatory Escalation · Model Governance | CTL-010 |
Items overdue for review · owner · gap · remediation
| Alert ID | Item | Cadence | Last reviewed | Owner | Gap | Remediation path |
|---|---|---|---|---|---|---|
| STALE-001 | POL-007 Partner-Route Assurance | Quarterly | 2026-03-18 | Head of Procurement · Head of Commercial | 59 days · 31 over | Refresh post CHG-006 counsel countersign |
| STALE-002 | POL-020 Conduct Risk MI | Quarterly | 2026-03-30 | Risk Committee · CoS | 47 days · 19 over | Run Q2 attestation cycle by 2026-05-30 |
| POL-009 Tax / VAT | Adviser draft pending refresh | Quarterly | 2026-04-15 | CFO · Tax Adviser | 31 days · 0 over · approaching | Complete adviser draft before 2026-07-15 |
Four gates · all must be green before any external bundle ships
Counsel sign-off
External counsel countersigns regulator-facing or investor-facing language; per artefact, per audience.
Evidence freshness
Every quoted metric, state, or hash carries a freshness date; "as of" footer mandatory; stale items blocked.
Redaction posture
Counterparty names · MNPI · staff personal data redacted in external variants; counsel approval required.
Per-recipient distribution
Watermarked, per-recipient link signing, audit-logged access, acknowledgement collection on board / investor read.
Audience · pack · restriction · workflow step · evidence
| Audience | Pack | Restriction | Workflow step (Strategic Reporting) | Counsel countersign required? | Evidence reference |
|---|---|---|---|---|---|
| Board (internal) | Board pack · 12 sections | Restricted / Internal Only | Step 5 · Board / investor approval | Where regulator-facing | SR-BP-EV-001 |
| Board (board-only) | Board decision requests (7) | Board Only | Step 5 | Where regulator-facing | SR-DR-EV-002 |
| Investor (redacted variant) | Investor narrative · 11 sections | Redacted External | Step 6 · Distribution (post counsel + CEO) | Yes — every section | SR-IN-EV-003 |
| Regulator-facing (per engagement) | Engagement pack per jurisdiction | Counsel-locked | JPRE 7-step counsel workflow · step 6 Pack Lock | Yes — mandatory | JP-EV-COUNSEL-009 |
| Counterparty (pilot) | Per-pilot pack · MNPI-scoped | Per-pilot tenant · counsel review | Stakeholder Rooms per-share runbook | Yes — per-pilot | SR-EV-INVESTOR-004 + RB-ROOM-SHARE |
| External assurance (assessor pending) | Independent attestation scope | Restricted Internal until engaged | Programme Governance gate | Yes — on engagement | OM-EV-OI-003 |
Audit log of policy / procedure / control events
| Timestamp (UTC) | Actor | Policy / control / runbook | Action | Evidence hash | Limitation recorded | Next step |
|---|---|---|---|---|---|---|
| 2026-05-08 09:00 | CISO · DG Lead · Head of Regulatory | Policy inventory · 21 policies | PPCL-INV — policy inventory published | sha256:ppcl…aa01 | "Internal readiness only." | Refresh on counsel rule-pack countersign |
| 2026-05-09 10:15 | SRE Lead · CISO | Procedure runbooks · 10 | PPCL-RB — runbook catalogue published | sha256:ppcl…aa02 | "Internal." | Refresh on drill cadence |
| 2026-05-10 14:40 | CISO · Programme Manager | Control library · 10 | PPCL-CTL — control library published | sha256:ppcl…aa03 | "Internal." | Refresh on control testing |
| 2026-05-11 13:22 | Risk Committee · CISO · Counsel | Exception register | PPCL-EXC — 9 open exceptions logged | sha256:ppcl…aa04 | "Internal." | Weekly review |
| 2026-05-12 09:48 | Head of Evidence · Programme Manager | Pack-to-policy traceability | PPCL-TRACE — 21 packs · 21 policies traced | sha256:ppcl…aa05 | "Internal." | Refresh on policy update |
| 2026-05-15 08:00 | Programme Manager | Stale policy / control sweep | PPCL-STALE — 3 alerts opened | sha256:ppcl…aa06 | "Internal." | Close 2 alerts before 2026-05-30 |
| 2026-05-15 09:30 | External Counsel · CEO · CoS | External bundle gates | PPCL-GATES — 3 of 4 gates met | sha256:ppcl…aa07 | "No external bundle ships without all four gates." | Close Gate 1 post 2026-05-19 |
| 2026-05-15 11:18 | Board Chair · CEO · External Counsel | Board / regulator export posture | PPCL-BRE — 6 audiences scoped | sha256:ppcl…aa08 | "No external publication implied." | Continue restriction-first distribution |
| 2026-05-16 08:00 | CEO · CISO · DG Lead · Head of Regulatory | Library attestation | PPCL-ATTESTATION — monthly attestation | sha256:ppcl…aa09 | "Internal; not regulatory approval." | Re-attest monthly |
| 2026-05-19 (scheduled) | External Counsel · Head of Regulatory · CEO | Counsel rule-pack session | PPCL-COUNSEL — pending | — | "Counsel-locked phrasing required before any regulator-facing pack lock." | Capture countersign post session |
What this Centre is — and is not
- Staging / simulated policy & control data. All policy IDs, control IDs, evidence hashes, dates, and audit events shown here are seed values for an internal policy-readiness workflow. They are not a live GRC tool, not a live policy register, and not a live audit log.
- Internal readiness workflow only. This Centre captures BLACKSWAN's internal policy / procedure / control posture. It is not legal advice, not regulatory approval, not certification, not an audit opinion, and not authorization for external launch.
- Counsel-bound by default. Every regulator- or investor-facing artefact requires external counsel countersign before any pack lock or distribution. Approved-Internal state means "approved for internal use" — never an external claim.
- Conservative posture on external bundles. No external bundle ships unless all four external-bundle gates are met. Gate 1 (Counsel sign-off) is currently open pending the 2026-05-19 counsel rule-pack session.
- Founder-root risk is a standing accepted risk. Per Programme Decision Log DEC-005, founder-root permanence carries MFA + re-auth + monthly attestation as compensating controls. EXC-001 records the operating consequence in this library.