From vaults, a file in the seed packEverything on this sheet is the source site's own text; the newsroom's chrome is outside it.
6. Go-to-market
Lessons already paid for
RiskMandate.ai took risk acceptance to market as part of an agent-insurability product, and learned two things this plan starts from.
- Risk acceptance has to come from governance. It is a GRC and board matter. Sold as a feature of a security or AI product, it lands with people who do not own it.
- The people who run risk programmes often resist it, and for a good reason. Putting an acceptance workflow in front of every risk owner is a large and disruptive change. Many executives today accept very little, or only what has already been judged acceptable. Asking them to accept, personally and for a stated interval, everything they actually hold changes their job.
So the service sells to the people who own governance, and it treats the resistance as the problem it is paid to solve, not as an objection to overcome.
Who buys
| Buyer | Why they care | What they buy first |
|---|---|---|
| Board members and non-executive directors, and the audit and risk committee | They are accountable for risk they cannot see, and for regulatory duties that assume residual risk is judged acceptable. | A board-level acceptance review of the top risks, with the chain beneath each one. |
| Chief risk officers and heads of GRC | They own the register and know its gaps better than anybody. | A pilot on one business unit, integrated with their platform. |
| CISOs and CTOs | They hold technical risks that arrive at the board with no path attached. | Fractal mapping of their top ten risks, from corporate line to evidence. |
| GRC platform vendors | Their customers ask for evidence and acceptance they cannot provide. | An integration partnership, and co-selling. |
| Consultancies and auditors | They run risk workshops that end in spreadsheets. | A licence to deliver the method on their own engagements. |
| Insurers and brokers | Cover needs evidence that residual risk is owned and dated. | Evidence packs from the acceptance vaults. |
The free thing that opens the door
A one-hour acceptance audit of five risks from the customer's own register. For each: who accepted it, until when, on what evidence, and what happens when it expires. It needs no system access. For most registers the answers are "nobody in particular", "never", "a paragraph" and "nothing". That turns a methodology conversation into a named list somebody has to own.
Channels
- The article. "Every risk is already accepted" makes the case in public.
- The demo. The app in this vault replays one risk's acceptance loop, with no login.
- Design partners. Three organisations, one business unit each, for a quarter.
- Partners. One GRC vendor and one consultancy in the first year.
What not to do
- Do not sell it as replacing the GRC platform.
- Do not sell fear of regulators. Sell the fact that residual risk is already being carried, and today nobody has signed for it.
- Do not start with the whole organisation. Start with one business unit and its top risks.