Strategic Risk & Scenario Planning · Board-Ready Workspace
One-screen risk and scenario view: taxonomy, register, scoring, KRIs, mitigants, scenario library, escalation, and acceptance posture. Compiled from the 27 prior centres and the 21-pack evidence spine. Conservative: nothing here is regulator submission, certification, audit opinion, risk clearance, client acceptance, or authorization for external launch.
17-Class Strategic Risk Taxonomy
| Class | Owner | Source centre | Pack | Open |
|---|---|---|---|---|
| Enterprise / Strategic | Founder | Executive Cockpit | Board-Pack Attestation | 2 |
| Regulatory | Counsel | Regulatory Change Horizon | Regulatory Change | 3 |
| Operational | Operations | Operational Runbooks & Day-2 Support | Incident | 2 |
| Commercial | Founder | Commercial Readiness | Revenue Recognition | 1 |
| Liquidity / Capital | Finance | Financial Controls | Capital/Liquidity | 1 |
| Model / AI | Compliance | Model Governance | Model Risk | 1 |
| Outsourcing / Vendor | Vendor Risk | Vendor Risk | Outsourcing Concentration | 1 |
| Cyber / Security | CISO | Security Operations | Authentication | 2 |
| Data / Privacy | Evidence Owner | Data Governance | Settlement | 1 |
| MNPI / Market abuse | Counsel | Stakeholder Rooms | Data-Room MNPI | 1 |
| Conduct | Compliance | Conduct Risk MI (planned) | Conduct Risk MI | 1 |
| Launch / Release | SRE + Founder | Release Control | Activity Perimeter | 1 |
| Revenue | Finance | Financial Controls | Revenue Recognition | 1 |
| Tax / VAT | Finance | Financial Controls | Tax/VAT | 1 |
| Client lifecycle | Compliance | Client Lifecycle & Entitlements | KYC/KYB | 1 |
| Integration / API | SRE | Integration, API & Data Exchange | Activity Perimeter | 1 |
| Jurisdiction expansion | Counsel | Jurisdiction Playbooks | Regulatory Digital Twin | 1 |
Inherent vs Residual · 5×5 Heatmap (Residual)
Severity (rows) × Likelihood (cols). Numbers are open-risk counts in that cell.
Top Strategic Risks (Tiered)
| ID | Tier | Title | Class | Inherent | Residual | Velocity | Proximity | Owner | Pack | State |
|---|---|---|---|---|---|---|---|---|---|---|
| R-001 | T1 | Counsel rule-pack countersign delay blocks external posture | Regulatory | 20 | 16 | High | ≤7d | Counsel | Policy Attestation | Pending |
| R-002 | T1 | KYC contract amendment unresolved · pilot teardown risk | Client lifecycle | 20 | 16 | High | ≤14d | Counsel + Founder | KYC/KYB | Open |
| R-003 | T1 | MNPI inadvertent disclosure via room-share | MNPI / market abuse | 20 | 12 | Med | ≤30d | Counsel | Data-Room MNPI | Mitigating |
| R-004 | T2 | Auditor engagement letter delay impacts assurance window | Outsourcing / Vendor | 16 | 12 | Med | ≤30d | Counsel | Outsourcing Concentration | Drafted |
| R-005 | T2 | Schema drift on settlement feed | Data / Privacy | 16 | 9 | Med | Active | Evidence Owner | Settlement | Triaged |
| R-006 | T2 | Break-glass drill cadence overdue | Cyber / Security | 16 | 9 | Med | ≤14d | SRE + CISO | Authentication | Scheduled |
| R-007 | T2 | Tax/VAT reconciliation evidence stale | Tax / VAT | 12 | 9 | Low | ≤30d | Finance | Tax/VAT | In review |
| R-008 | T2 | Complaints capture pre-pilot baseline missing | Conduct | 16 | 9 | Low | ≤30d | Compliance | Conduct Risk MI | Pre-pilot |
| R-009 | T2 | Vendor concentration on primary cloud + KYC vendor | Outsourcing / Vendor | 16 | 12 | Low | ≤90d | Vendor Risk | Outsourcing Concentration | Documented |
| R-010 | T3 | Model override governance lag | Model / AI | 12 | 6 | Low | ≤60d | Compliance | Model Risk | Waiver pending |
| R-011 | T3 | Rate-limit budget breach on integration feed | Integration / API | 9 | 6 | Low | ≤30d | SRE | Activity Perimeter | Mitigated |
| R-012 | T3 | Jurisdiction-expansion drift vs counsel mapping | Jurisdiction expansion | 12 | 6 | Low | ≤90d | Counsel | Regulatory Digital Twin | Mapping |
| R-013 | T3 | Capital/Liquidity buffer review aging | Liquidity / Capital | 9 | 6 | Low | ≤60d | Finance | Capital/Liquidity | Aging |
| R-014 | T3 | Revenue recognition policy ambiguity (pre-pilot) | Revenue | 9 | 6 | Low | ≤90d | Finance + Counsel | Revenue Recognition | Drafted |
| R-015 | T3 | Launch posture mis-signaling externally | Launch / Release | 12 | 6 | Low | Continuous | Founder + Counsel | Activity Perimeter | Counsel-bound |
| R-016 | T3 | Product governance committee minutes lag | Operational | 9 | 4 | Low | ≤30d | Operations | Product Governance | On track |
| R-017 | T4 | Board-pack delta drift | Enterprise / Strategic | 6 | 3 | Low | ≤30d | Founder | Board-Pack Attestation | On track |
| R-018 | T4 | Doc clarity on entitlement model | Client lifecycle | 6 | 3 | Low | ≤30d | Operations | KYC/KYB | On track |
Key Risk Indicators
| KRI | Linked risk | Threshold | Latest | State | Owner |
|---|---|---|---|---|---|
| Counsel countersign age (days) | R-001 | ≤7d | 14d | Breached | Counsel |
| KYC contract negotiation age | R-002 | ≤14d | 21d | Breached | Counsel + Founder |
| Stale evidence packs (count) | R-005, R-007 | ≤2 | 4 | Amber | Evidence Owner |
| Break-glass drill last-run age | R-006 | ≤30d | 42d | Amber | SRE + CISO |
| Open P0 defects | R-001, R-002 | 0 | 2 | Breached | Founder |
| Sev-1 incidents (24h) | R-003, R-006 | 0 | 0 | Green | SRE |
| Rate-limit budget headroom | R-011 | ≥40% | 62% | Green | SRE |
| Vendor concentration ratio (top-2) | R-009 | ≤60% | 58% | Amber-watch | Vendor Risk |
12 Scenarios · Stress · Sensitivity · Reverse
| ID | Type | Title | Tier impact | Linked risks | Mitigation centre | State |
|---|---|---|---|---|---|---|
| SC-S1 | Stress | Counsel unreachable for 14 days | T1 | R-001, R-002 | Policy / Control Library | Tabletop |
| SC-S2 | Stress | Primary cloud region failure (24h) | T1 | R-009 | Operational Runbooks | Drill 2026-05-15 |
| SC-S3 | Stress | KYC vendor outage (72h) | T2 | R-002, R-009 | Client Lifecycle | Tabletop |
| SC-S4 | Stress | Settlement feed schema break | T2 | R-005 | Data Governance | Detector live |
| SC-Y1 | Sensitivity | ±15% transaction volume on rate-limit budget | T3 | R-011 | Integration, API & Data Exchange | Modelled |
| SC-Y2 | Sensitivity | Tax/VAT rate change in a single jurisdiction | T3 | R-007, R-014 | Financial Controls | Modelled |
| SC-Y3 | Sensitivity | Pilot client mix shift toward jurisdiction X | T3 | R-012, R-015 | Jurisdiction Playbooks | Modelled |
| SC-Y4 | Sensitivity | Capital buffer −10% | T3 | R-013 | Financial Controls | Modelled |
| SC-R1 | Reverse | "What breaks counsel-locked posture?" | T1 | R-001, R-003, R-015 | Policy / Control Library | Drafted |
| SC-R2 | Reverse | "What forces Tier-1 incident on go-live?" | T1 | R-005, R-006, R-011 | Production Go/No-Go | Drafted |
| SC-R3 | Reverse | "What invalidates board narrative in 30d?" | T2 | R-001, R-002, R-017 | Strategic Reporting | Drafted |
| SC-R4 | Reverse | "What triggers regulator escalation?" | T1 | R-001, R-003, R-012 | Regulatory Escalation | Drafted |
Top-10 Mitigations · Owner · Evidence
| # | Mitigation | Risk(s) | Owner | Evidence | State |
|---|---|---|---|---|---|
| 1 | Counsel countersign window scheduled 2026-05-19 | R-001 | Counsel | Policy Attestation | Scheduled |
| 2 | KYC contract counter-draft circulated | R-002 | Counsel + Founder | KYC/KYB | In counsel |
| 3 | Stakeholder-room MNPI inventory + read-only seal | R-003 | Counsel | Data-Room MNPI | Live |
| 4 | Schema drift detector on settlement feed | R-005 | Evidence Owner | Settlement | Live |
| 5 | Break-glass drill rescheduled 2026-05-22 | R-006 | SRE + CISO | Authentication | Scheduled |
| 6 | Tier-1 two-party rollback lockout | R-015, R-006 | SRE + Founder | Activity Perimeter | Live |
| 7 | Vendor concentration register + secondary route | R-009 | Vendor Risk | Outsourcing Concentration / Partner Route | Live |
| 8 | Tax/VAT rehash + reconciliation routine | R-007, R-014 | Finance | Tax/VAT | Routine |
| 9 | Complaints capture pre-pilot plan | R-008 | Compliance | Conduct Risk MI | Drafted |
| 10 | Counsel-locked external language template | R-001, R-003, R-015 | Counsel | Policy Attestation | Pending |
Risk Escalation Lane · Thresholds
| Trigger | Threshold | Route | Counsel-binding | SLA |
|---|---|---|---|---|
| Tier-1 residual ≥ 16 | Any T1 active | Founder → Counsel → Board reviewer | Yes | ≤24h |
| KRI breach (red) | Any red KRI | Owner → Founder → Counsel (if external) | Conditional | ≤24h |
| Stress scenario activation | SC-S1..S4 triggered | SRE → Founder → Stakeholder Rooms | Conditional | ≤4h |
| Regulator-touching event | Any reg-impacting risk | Counsel → Founder → Reg Escalation | Yes | ≤24h |
| MNPI exposure suspected | R-003 active | Counsel → Founder · room-share frozen | Yes | ≤1h |
| Risk acceptance new | Any T1 accepted | Founder + Counsel · board-pack ledger | Yes | ≤72h |
Accepted Risks Register
| ID | Risk | Why accepted | Compensating control | Counsel countersign | Review |
|---|---|---|---|---|---|
| DEC-005 | Founder-root standing access | Single-operator phase; no SoD-eligible peer for founder-root | SoD pairs · Tier-1 two-party rollback · audit trail | Yes | Quarterly |
| DEC-018 | Cockpit/board pack internal-only | Pre-engagement; not regulator/auditor/client artefact | Counsel-locked external language (CTL-010) | Yes | Quarterly |
| DEC-022 | US engagement deferred | Counsel-deferred until UK/EU posture mature | Mapping only · Reg Digital Twin · counsel review gate | Yes | Quarterly |
Board / Regulator Prep · Risk Section
- Headline: amber. 3 Tier-1 risks open; 2 driven by counsel countersign and 1 by KYC contract; both binding constraints on external posture.
- What changed (7d): DR drill closed (+green), evidence rehash on settlement scheduled, MFA coverage at 100% on founder-root paths.
- What's next (30d): counsel countersign window, KYC counter-draft acceptance, auditor engagement letter, complaints capture pre-pilot baseline.
- Counsel-bound language: all external statements remain counsel-locked (CTL-010). Nothing in this Centre constitutes regulator submission or client acceptance.
- Board-pack delta: cross-linked to Strategic Reporting + Board-Pack Attestation pack. Counter-sign required by founder.
Risk Briefing Posture
Founder / Admin
Heatmap, T1 list, escalation lane, acceptance register, board narrative.
Board reviewer
Top risks, KRI breaches, scenario library, 30-day forward look. Non-binding.
Compliance / Legal
Regulatory, MNPI, conduct, jurisdiction. Counsel-binding flags surfaced.
Risk / Controls owner
Mitigation tracker, control linkage, evidence linkage, acceptance workflow.
Operations
Operational, conduct, scenario drills. Tabletop schedule.
Technology / Security
Cyber, data/privacy, integration/API, schema drift, break-glass cadence.
Finance
Liquidity, revenue, tax/VAT, vendor concentration cost exposure.
Evidence Owner
Freshness, cross-link integrity, rehash schedule.
Regulator-review room
Counsel-curated read-only. Not a regulator submission.
Investor-review room
Counsel-curated read-only. Not an offer or solicitation.
Auditor / Assurance reviewer
Engagement-letter gated. Not an audit opinion.
External Risk-Bundle Gates
Mirrors the four external comms / release gates. Currently 2 of 4 met.
| Gate | Acceptance criterion | Counsel-binding | State |
|---|---|---|---|
| 1 | Counsel-locked language across all risk-bundle external surfaces | Yes | Pending |
| 2 | All T1 either closed, mitigated, or carrying counsel-countersigned acceptance | Yes | Not met |
| 3 | All linked packs hashed and cross-linked within retention windows | — | Met |
| 4 | At least one stress scenario rehearsed in the last 30 days | — | Met |
Stale Owner / Review Alerts
| ID | Alert | Risk | Owner | Age (d) | State |
|---|---|---|---|---|---|
| AL-01 | Counsel rule-pack countersign overdue | R-001 | Counsel | 14 | Pending |
| AL-02 | KYC contract amendment overdue | R-002 | Counsel + Founder | 21 | T1 open |
| AL-03 | Break-glass drill cadence overdue | R-006 | SRE + CISO | 42 | Scheduled |
| AL-04 | Tax/VAT evidence stale (>14d) | R-007 | Finance | 17 | Stale |
| AL-05 | Complaints pack stale (>14d) | R-008 | Compliance | 18 | Stale |
| AL-06 | Policy Attestation stale (>14d) | R-001 | Counsel | 14 | Stale |
| AL-07 | Settlement pack stale (>14d) | R-005 | Evidence Owner | 15 | Stale |
| AL-08 | Auditor engagement letter unsigned | R-004 | Counsel | 9 | Drafted |
Centre Acceptance Criteria
- Every risk row has class, owner, inherent + residual scores, velocity, proximity, linked pack, and 7-day movement.
- Every KRI names a threshold, source, owner, and current state, and ties to ≥1 risk row.
- Every scenario names type (stress/sensitivity/reverse), linked risks, tier impact, mitigation centre, and tabletop state.
- Every accepted risk carries counsel countersign and a compensating control.
- External-surface risk language is counsel-locked. Nothing here constitutes regulator submission, client acceptance, audit opinion, or risk clearance.
Risk Centre Audit Events (last 10)
| Event | When | Actor | Centre | Pack |
|---|---|---|---|---|
| Register opened | 2026-05-18T07:30Z | founder-admin | Strategic Risk & Scenario Planning | — |
| Heatmap rebuilt | 2026-05-18T07:31Z | system | Completeness | 21-pack spine |
| KRI dashboard refreshed | 2026-05-18T07:32Z | system | Executive Cockpit | — |
| R-001 reminder dispatched | 2026-05-18T07:34Z | system | Policy / Control Library | Policy Attestation |
| R-002 counter-draft logged | 2026-05-18T07:36Z | counsel | Client Lifecycle & Entitlements | KYC/KYB |
| R-003 room-share inventory verified | 2026-05-18T07:38Z | counsel | Stakeholder Rooms | Data-Room MNPI |
| SC-S2 drill log cross-linked | 2026-05-18T07:40Z | SRE | Operational Runbooks & Day-2 Support | Incident |
| Acceptance DEC-005 quarterly review opened | 2026-05-18T07:42Z | founder-admin | Approval & Sign-Off | Activity Perimeter |
| Board narrative draft synced | 2026-05-18T07:45Z | founder-admin | Strategic Reporting | Board-Pack Attestation |
| External-bundle gate state sealed | 2026-05-18T07:48Z | counsel | Production Go/No-Go | Activity Perimeter |
Risk-exception readiness map — internal posture only
Holds every exception-dependent gate (production launch, regulator submission, external bundle release, incident escalation, CAB / production change, go-live counter-sign, partner-route activation, secret rotation) at HOLD · NO-GO until each required risk-exception control — Entra OIDC transition exception, jurisdictional permission limitation, evidence-pack metadata exception, external-bundle release limitation, regulator-submission limitation, backup / restore readiness exception, observability / SLO exception, release / rollback exception, approval-authority exception, partner-route / mTLS readiness exception, secret / key custody exception, production config missing exception, data / MNPI boundary exception, incident escalation exception, and go-live authority exception — is captured with owner + approver class descriptor + approval forum + approval state + evidence reference + limitation text + compensating control + expiry + review cadence + escalation path + last-reviewed date. Staging or demo acknowledgements do not count as production risk acceptance. Risk acceptance never overrides an unresolved P0 blocker without explicit authority evidence and limitation language.
Read-only fixture exposed via /api/risk-acceptance-exception-register; reference NAMES, ownership, approver class descriptors, approval forum names, approval state, evidence reference IDs, limitation text, compensating control text, expiry / review cadence rule class descriptors, escalation path class descriptors, linked gate / control / evidence-pack dependency endpoint paths, launch impact text, external-use impact text, and unlock criteria only. Authoritative row table is rendered in the Approval & Sign-Off Workflow. Mirrored summaries in the Strategic Risk Register & Scenario Planning Centre, the Final Production Launch Control Tower, the Production Go/No-Go Board, the Regulatory Notification & Board Escalation Centre, the Programme Governance & Roadmap Centre, and the Completeness Command Centre. Internal risk-exception readiness posture only — not risk acceptance, not legal/compliance exception, not board waiver, not counsel approval, not regulator acceptance, not production approval, not go-live approval, not external-use waiver, and not temporary workaround approval. No approver name, approver email, approver signature, board minute, board meeting link, board resolution body, exception token, e-signature token, private risk-memo body, privileged legal advice text, privileged work-product, external counsel memo body, customer data, MNPI, live deploy credential, regulator submission body, partner credential, signed-URL secret, OTP code, watermark salt body, IP address, device fingerprint, or live notification channel is returned from any endpoint. Staging or demo acknowledgements do not count as production risk acceptance. Risk acceptance never overrides an unresolved P0 blocker without explicit authority evidence and limitation language.
Classification · MNPI boundary readiness map — internal posture only
Holds every classification-dependent gate (production launch, regulator submission, external bundle release, data-room access activation, clean-team activation, watermarked export, retention / legal-hold lift, cross-border transfer, MNPI bridging review, board-pack release, investor-room release, customer / counterparty data-room release) at HOLD · NO-GO until each required classification / boundary control — public / internal / confidential / restricted / MNPI classification, clean-team boundary, board-pack boundary, regulator-pack boundary, investor-room boundary, client / customer data boundary, order / transaction data boundary, evidence-export boundary, audit-log boundary, personal data / privacy boundary, data-room access control, watermarking / classification labels, retention / legal hold, cross-border / data residency limitation, and release / go-no-go authority — is captured with owner + approval forum + classification level + MNPI posture + recipient class descriptor + access boundary rule + clean-team requirement (where applicable) + retention / legal-hold basis + residency / cross-border note + watermark / classification label + evidence reference + last-reviewed date. Staging or demo classifications do not count as production data classification or MNPI boundary evidence.
Read-only fixture exposed via /api/data-classification-mnpi-boundary-register; reference NAMES, classification level labels, MNPI posture labels, recipient class descriptors, ownership, approval forum names, approval state, evidence reference IDs, access boundary rule class descriptors, clean-team requirement class descriptors, retention / legal-hold basis class descriptors, residency / cross-border class descriptors, watermark / classification label class descriptors, linked evidence / control / stakeholder / regulatory dependency endpoint paths, launch impact text, external-use impact text, and unlock criteria only. Authoritative row table is rendered in the Data Governance, Retention & Privacy Centre. Mirrored summaries in the Final Production Launch Control Tower, the Security Operations · IAM · Zero-Trust Centre, the Regulatory Notification & Board Escalation Centre, the Stakeholder Rooms · External Evidence Centre, and the Completeness Command Centre. Internal data-classification / MNPI boundary readiness posture only — not data classification authorisation, not MNPI boundary acceptance, not privacy-compliance certification, not data residency authorisation, not clean-team activation, not data-room authorisation, not regulator submission, not launch authorisation, and not external-use authorisation. No real MNPI, client / customer / investor identity, regulator contact, clean-team identity, deal codename in flight, access log line, IP address, device fingerprint, room URL, signed URL, room token, OTP code, watermark salt body, or live notification channel is returned from any endpoint. Staging or demo classifications do not count as production data classification or MNPI boundary evidence.
What this Centre is NOT
- Not legal advice. Counsel countersign is the binding signal for any external-facing risk language.
- Not regulatory approval, registration, licensing, or supervisory acceptance in any jurisdiction.
- Not certification or accreditation of any risk-management framework.
- Not an audit opinion. Auditor engagement letter remains unsigned.
- Not a regulator submission. Regulator-room view is counsel-curated and read-only.
- Not risk clearance. Open T1 risks remain. External posture is not authorised.
- Not client acceptance. Client lifecycle remains in pre-pilot posture.
- Not authorization for external launch. Gates 1 and 2 not yet met.
- Not an offer or solicitation. Investor-room view is counsel-curated and read-only.