# 7. The first ninety days

## Weeks 1 to 3: the method, written down

- Adopt the principles and the ladder in `plan/plan.json` as the house method, and write the playbook: how to establish a risk, how to place it, how to run an acceptance meeting, how to escalate.
- Set up the risk vault layout from `spec/risk-vault.md`, and the acceptance record from `spec/acceptance-record.md`.
- Build the acceptance audit from `prototypes/acceptance-audit.md` into a one-hour meeting.

**Done when:** the audit has been run on one real register, and the playbook survived it.

## Weeks 4 to 8: three design partners

- Sign three organisations for a quarter, one business unit each, at a reduced fee.
- For each: import the register from their GRC platform, establish their top twenty risks on facts, place them on the chain, and run the first round of acceptances.
- Keep a count of every refusal to accept, and why. That count is the most valuable data the company will have.

**Done when:** sixty risks are in the loop, each with a holder, an interval and an action.

## Weeks 9 to 13: the first expiries

- Run the first expiries: re-acceptances, escalations, incidents and funding decisions.
- Produce the first quarterly board pack for each partner.
- Approach one GRC vendor with the integration outline in `prototypes/grc-integration.md`, using the partners' platforms as the case.

**Done when:** at least one risk has been escalated, one funded and one closed on facts, and one partner has agreed to a paid second quarter.

## Team

Two to start: an engagement lead who can talk to a board, and a risk engineer who can read a configuration. An integration engineer by the end of the first quarter.
