From vaults, a file in the seed packEverything on this sheet is the source site's own text; the newsroom's chrome is outside it.
7. The first ninety days
Weeks 1 to 3: the method, written down
- Adopt the principles and the ladder in
plan/plan.jsonas the house method, and write the playbook: how to establish a risk, how to place it, how to run an acceptance meeting, how to escalate. - Set up the risk vault layout from
spec/risk-vault.md, and the acceptance record fromspec/acceptance-record.md. - Build the acceptance audit from
prototypes/acceptance-audit.mdinto a one-hour meeting.
Done when: the audit has been run on one real register, and the playbook survived it.
Weeks 4 to 8: three design partners
- Sign three organisations for a quarter, one business unit each, at a reduced fee.
- For each: import the register from their GRC platform, establish their top twenty risks on facts, place them on the chain, and run the first round of acceptances.
- Keep a count of every refusal to accept, and why. That count is the most valuable data the company will have.
Done when: sixty risks are in the loop, each with a holder, an interval and an action.
Weeks 9 to 13: the first expiries
- Run the first expiries: re-acceptances, escalations, incidents and funding decisions.
- Produce the first quarterly board pack for each partner.
- Approach one GRC vendor with the integration outline in
prototypes/grc-integration.md, using the partners' platforms as the case.
Done when: at least one risk has been escalated, one funded and one closed on facts, and one partner has agreed to a paid second quarter.
Team
Two to start: an engagement lead who can talk to a board, and a risk engineer who can read a configuration. An integration engineer by the end of the first quarter.