# 10. Open questions

1. **Which ladder?** risks.sgit.ai and RiskMandate.ai publish different bands and a different default. The plan uses risks.sgit.ai's; a single published ladder would help every client conversation.
2. **What exactly happens at expiry?** The plan proposes return-to-desk then escalate-one-level. It needs testing on real clients.
3. **Automatic roll-up, or pending until accepted?** The published material disagrees. The plan takes automatic roll-up and should measure whether it produces alarm fatigue.
4. **Interval inflation.** risks.sgit.ai warns that pressure goes "into interval inflation, where everything is accepted for six months". What is the right check: a cap per rung, a board view of six-month acceptances, or both?
5. **Who sets "acceptable"?** And what stops a business unit setting the line wherever its exposure already is?
6. **How far down to go.** Fractal mapping can generate thousands of nodes. Where does materiality stop the zoom?
7. **Twins and simulation.** twins.sgit.ai describes risk acceptance performed by a twin acting for a person, and simulation of an organisation's risks. None of it is built. When is it worth building, and for which clients?
8. **The first GRC partner.** Which vendor has customers asking for this, and an API good enough to write back to?
