sgit newsroom v0.1.29 · snapshot 2026-09-24

Reading room · vaults

On this page

Reading room / vaults · raw text

From vaults, a file in the seed packEverything on this sheet is the source site's own text; the newsroom's chrome is outside it.

6. Go-to-market

Lessons already paid for

RiskMandate.ai took risk acceptance to market as part of an agent-insurability product, and learned two things this plan starts from.

  1. Risk acceptance has to come from governance. It is a GRC and board matter. Sold as a feature of a security or AI product, it lands with people who do not own it.
  2. The people who run risk programmes often resist it, and for a good reason. Putting an acceptance workflow in front of every risk owner is a large and disruptive change. Many executives today accept very little, or only what has already been judged acceptable. Asking them to accept, personally and for a stated interval, everything they actually hold changes their job.

So the service sells to the people who own governance, and it treats the resistance as the problem it is paid to solve, not as an objection to overcome.

Who buys

BuyerWhy they careWhat they buy first
Board members and non-executive directors, and the audit and risk committeeThey are accountable for risk they cannot see, and for regulatory duties that assume residual risk is judged acceptable.A board-level acceptance review of the top risks, with the chain beneath each one.
Chief risk officers and heads of GRCThey own the register and know its gaps better than anybody.A pilot on one business unit, integrated with their platform.
CISOs and CTOsThey hold technical risks that arrive at the board with no path attached.Fractal mapping of their top ten risks, from corporate line to evidence.
GRC platform vendorsTheir customers ask for evidence and acceptance they cannot provide.An integration partnership, and co-selling.
Consultancies and auditorsThey run risk workshops that end in spreadsheets.A licence to deliver the method on their own engagements.
Insurers and brokersCover needs evidence that residual risk is owned and dated.Evidence packs from the acceptance vaults.

The free thing that opens the door

A one-hour acceptance audit of five risks from the customer's own register. For each: who accepted it, until when, on what evidence, and what happens when it expires. It needs no system access. For most registers the answers are "nobody in particular", "never", "a paragraph" and "nothing". That turns a methodology conversation into a named list somebody has to own.

Channels

What not to do