FIELDWORK · SIX WEEKS · SELF-PACED
Board Risk Executive — a six-week applied programme
Executives who carry risk decisions into a boardroom: CxOs and heads of function who own the paper, plus audit-committee members and non-executive directors who have to interrogate it.
The platform hosts the spine — briefs, sims, templates, progress — and structures the deep work. It does not host sixty hours of content. Plan roughly ten focused hours a week, most of it real work against your own board, your own register and your own disclosure calendar; Signify Fieldwork keeps the thread.
6 weeks~10h a week18 modules57 required steps23 drills
Week 1 of 6 · 10 hours · 3 modules
The seat, and the standard it is held to
Before any particular decision, the shape of the job: what a board owns and what it must not touch, an appetite that binds something, and the right to information good enough to govern on.
Week 1 of 6 · 10 hours · 3 modules
The seat, and the standard it is held to
Before any particular decision, the shape of the job: what a board owns and what it must not touch, an appetite that binds something, and the right to information good enough to govern on.
1.1What the board owns, and what it must not touch
3.5h
Decision rights, information rights, and the failure mode at each end — the board that rubber-stamps and the board that runs the company.
- learnRequired
Oversight is not management
Read the brief~2 min
Every dysfunctional board is dysfunctional in one of two directions, and both are failures of the same thing. The board that rubber-stamps has decided that management's judgement is the only judgement available. The board that runs the company has decided the opposite and taken the executive's job, which leaves nobody holding the executive to account. Neither board believes it is doing either.
Oversight is not management
The distinction that actually works in a room is about the question being asked. Management answers what shall we do. The board answers whether we can rely on how that was decided, whether the person deciding it is the right one, and whether we would know in time if it went wrong. When a director starts redesigning the plan, they have stopped being able to judge it.
- Decide: a small list, and it should be written down. Strategy, capital allocation above a threshold, the CEO, risk appetite, and the disclosures that carry the board's name.
- Approve: management proposes, the board tests and consents. The board's contribution here is the quality of the challenge, not the content of the proposal.
- Be told: everything else, and this is the category that silently swallows the other two. A paper that arrives for noting on Thursday for a decision already taken on Monday has moved an item out of the first category without anyone voting on it.
Where the line actually gets crossed
Rarely in a formal vote. It gets crossed in the pre-meeting call, in the director with sector experience who starts directing a workstream, and in the executive who brings a decision to the board precisely because they would rather not own it. That last one is worth naming: escalation is sometimes a transfer of risk rather than a request for governance, and a board that accepts it has taken on a decision it cannot resource.
Open the reading — GRC Operating ModelCarry this into the drill
Whose Call puts twelve decisions in front of you and asks where each belongs; watch how often your instinct pulls one up to the full board. The GRC maturity scan is the optional baseline underneath it — a read of the enterprise you are overseeing, before you argue about who decides what within it. The map you build in the Apply step is the artefact the rest of the week tests.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
Whose Call — a decision-rights drill
Open the drillTwelve decisions and four places each could belong — the full board, a committee, management, the shareholders. It counts over-reach, because pulling a decision up to the board is the error that feels like diligence, and this module's deliverable is exactly that map.
Ticks itself when the drill records a result
- playOptionalTicks itself
GRC Maturity Assessment
Open the drillOptional: a structured baseline of the governance you are overseeing, across eight domains. Worth four minutes before you draw a decision-rights map, because the map is only as good as your read of what exists to be governed.
Ticks itself when the drill records a result
- applyRequired
Decision-rights map for one committee
Open the brief
Take one real committee — your board, its audit or risk committee, or the executive committee that feeds it — and map what it actually decides, approves and is merely told. Use the last four meetings as evidence rather than the terms of reference, because the two will disagree and the meetings are the truth.
The value is in the disagreements. Every item where the terms of reference say decide and the minutes show noting is a decision right that has quietly migrated, and it migrated toward whoever wanted it more.
What to produce
- The committee, its stated remit, and the four meetings you sampled
- Every substantive item across those meetings, sorted into decide, approve, be told
- Each item's stated category from the terms of reference, beside the category the minutes actually show
- The migrations: items that moved category, in which direction, and who benefited
- Information rights: for each decide item, what the committee was given and when it arrived
- The two items you would move back, and what you would have to change in the calendar to make that real
- checkOptional
Where your board is doing management's job
Open the prompts
- Name the last decision your board took that management had already made. What would have had to happen, and when, for the board to have had a real choice?
- Which director is doing management's job, and is it because they are over-reaching or because the executive is under-delivering?
- Pick the item you were most relieved to escalate. Were you asking for governance, or for company?
- If a regulator read your last four sets of minutes, which items would they say the board decided, and would you agree?
1.2Appetite that changes a decision
3h
Appetite against tolerance, and why most appetite statements never bind anything anyone would otherwise have done.
- learnRequired
A statement that refuses something
Read the brief~2 min
A risk appetite statement earns its place by refusing something. If no proposal in the last two years would have failed it, it is not an appetite statement; it is a values poster with numbers on it. The test is uncomfortable on purpose, because the appetite that never bites was written to avoid ever having to say no in public.
Appetite, tolerance, and the gap between them
Appetite is how much of a thing you are willing to take on in pursuit of the strategy — a forward-looking choice. Tolerance is how far you will let an actual exposure drift before someone must act — an operating limit. Boards conflate them and end up with a single number that is too vague to guide a decision and too soft to trigger one.
- Appetite belongs to the strategy: we will accept concentration in this segment because that is where we are choosing to grow.
- Tolerance belongs to the operation: above this exposure, the committee is convened whether or not anyone thinks it is necessary.
- The pair only works if breaching tolerance has a consequence written down in advance. A limit with no named action is a reporting line.
Why the debate goes wrong
Appetite arguments are conducted in loaded language, and loaded language beats arithmetic in a room. Cyber sounds bigger than concentration; a named catastrophic scenario sounds bigger than a chronic exposure that is three times the size. The board that cannot notice this in itself will set an appetite shaped by which risk had the most frightening vocabulary.
Carry this into the drill
Which Is Riskier? is a calibration drill, and an appetite debate is a calibration exercise conducted with adjectives. Notice which pairs you got wrong and whether the losing option was the one that sounded duller.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
Which Is Riskier? — a calibration drill
Open the drillPairwise calls on residual risk, which is exactly the judgement an appetite debate runs on. A borrowing from the practitioner catalogue, and the most useful five minutes available before you write a limit somebody has to live inside.
Ticks itself when the drill records a result
- applyRequired
One appetite statement rewritten until a named proposal fails it
Open the brief
Take one line of your organisation's existing risk appetite statement and rewrite it until a specific, named, real proposal would fail it. Not a hypothetical — something on a roadmap or in a pipeline now.
Then write the consequence. Who is told, within what period, and what are they required to do. If you cannot name the action, the limit is decorative and the rewrite is not finished.
What to produce
- The original line, quoted as it stands today
- The real proposal you are testing it against, described in three lines
- Why the original does not bite: which word is doing the escaping
- The rewrite, with the measure, the threshold and the period explicit
- The consequence of breach: who is notified, in what window, and what they must do
- One proposal the rewrite would wrongly block, and how you would handle that exception without dissolving the limit
1.3The information you are entitled to
3.5h
Reporting that surfaces the thing you would want to know early, and the anatomy of an escalation that arrived too late to matter.
- learnRequired
The escalation that arrived on time and said nothing
Read the brief~2 min
Boards are not usually surprised because nobody told them. They are surprised because they were told in a form that could not carry the weight: a green status against a milestone nobody had re-baselined, an assurance rating with no evidence behind it, a risk that had been amber for so long it had become furniture.
Read the paper for what it is not showing you
A board pack is an argument, and every argument has a shape chosen by its author. The questions that surface the shape are boring and reliable: what changed since last time and why, what is the source of this number, who else has seen it, and what would have to be true for this to be wrong. The last one does more work than the other three combined.
- A trend with no comparator is a claim. Three periods or it is not a trend.
- An assurance rating without its evidence base is somebody's opinion in a colour.
- A risk whose rating has not moved in eight quarters is either unmanaged or mis-rated, and both need saying out loud.
- The absence of bad news between meetings is information about the escalation route, not about the business.
Corroborate, contradict, unsupported
The discipline that transfers here comes from forensic audit: for any claim, the honest verdicts are that the evidence corroborates it, contradicts it, or does not reach it. The third verdict is the one boards skip, because unsupported feels like an accusation. It is not — it is a statement about the paper, and the right response is a request, not a finding.
Carry this into the drill
Tie-Out is an auditor's drill, played here from the other side of the table: management hands you a binder and a story, and your job is to tie each claim to something. Take the habit, not the technique — you will not be footing schedules in a board meeting, but you will be asking which of these three verdicts applies.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
Tie-Out — a forensic deduction
Open the drillA forensic deduction where a story has to be tied back to evidence, claim by claim. A borrowing from the audit catalogue, and the closest thing available to the discipline of reading a board pack properly.
Ticks itself when the drill records a result
- applyRequired
Board-pack critique: three claims and what corroborates each
Open the brief
Take the most recent board or committee pack you received. Choose three substantive claims — a rating, a trend, an assurance statement — and work out what would corroborate each, what would contradict it, and whether the pack contains either.
Write the three questions you would ask at the next meeting. Then write what you expect the answer to be, and seal it. Comparing your prediction to the answer is the fastest way to calibrate how well you actually read that pack.
What to produce
- The pack, its date, and how long before the meeting it arrived
- Three substantive claims, quoted
- For each: what evidence would corroborate it, and is that evidence in the pack
- For each: the verdict — corroborated, contradicted, or unsupported
- The three questions, phrased so they cannot be answered with reassurance
- Your sealed prediction of each answer
- What is structurally missing from every pack you receive, not just this one
- checkRequired
What your pack never shows you
Open the prompts
- Which of your three claims turned out to be unsupported rather than wrong, and why was that harder to say?
- How much of your confidence in the pack comes from the evidence in it, and how much from your view of the person who wrote it?
- What is the longest a material fact could stay unknown to your board given the current reporting calendar?
- If the pack arrived seventy-two hours earlier, which of your questions would you have asked differently?
Week 2 of 6 · 10 hours · 3 modules
Disclosure: the decisions with a clock
Three regimes, three clocks, one question underneath all of them — what did you know, when did you know it, and what does the record show you did next.
Week 2 of 6 · 10 hours · 3 modules
Disclosure: the decisions with a clock
Three regimes, three clocks, one question underneath all of them — what did you know, when did you know it, and what does the record show you did next.
2.1Material weakness and the 10-K
3.5h
Materiality, Item 9A, restatement against revision, and what the audit committee owns in each.
- learnRequired
Significant deficiency, material weakness, and the line between them
Read the brief~2 min
Three weeks before the 10-K, the auditor calls. That sentence is the whole module: the decision is taken under time pressure, with incomplete facts, by people who all have a reason to prefer one answer, and it is judged years later by readers who have all the facts and no time pressure at all.
The line, and why it moves
A deficiency is a control that does not work. A significant deficiency is one important enough to merit the attention of those responsible for oversight. A material weakness is one where there is a reasonable possibility that a material misstatement would not be prevented or detected in time. The gradations are about likelihood and magnitude, not about how embarrassing the finding is — and the pull toward the softer label is strongest exactly when the harder one is correct.
- Severity is judged on what could happen, not on what did. No misstatement occurred is not a defence; it is sometimes just luck, and the standard knows that.
- Compensating controls only compensate if they operate at a level of precision that would actually catch the misstatement. Naming one that operates monthly against a daily exposure is not a compensating control, it is a hope.
- Aggregation is the trap. Three significant deficiencies in the same process can be a material weakness together even though each survives alone.
What the audit committee owns
Not the conclusion — that is management's, with the auditor attesting. What the committee owns is whether the process reaching it was honest: whether scope was set before the answer was known, whether the people assessing severity were insulated from the people whose area it was, and whether the timetable left room for the answer to be inconvenient.
Carry this into the drill
The Material-Weakness Memo runs seven rounds from the auditor's call to the audit-committee meeting, with three scores moving that you cannot see: the SOX 404 conclusion, investor confidence and class-action probability. Watch which of your choices moved them in opposite directions.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
The Material-Weakness Memo — SOX 404 disclosure sim
Open the drillThe SOX 404 disclosure decision as it actually arrives — three weeks to the 10-K, investigative scope to set, Item 9A language to assemble, and a market sequencing choice that outlives the quarter.
Ticks itself when the drill records a result
- applyRequired
Draft Item 9A language for a weakness in your own environment
Open the brief
Draft the Item 9A disclosure for a hypothetical material weakness in your own environment. Pick a real process with a real control you privately suspect, and write the paragraph as it would be filed.
Then read it as a plaintiff's lawyer would. The sentence you least want quoted back is the one to rewrite — not to soften it, but to make it accurate enough that the quotation does not damage you.
What to produce
- The process, the control, and why you suspect it
- The severity assessment: likelihood, magnitude, and the reasoning for the grade you chose
- Compensating controls considered, and the precision test each passed or failed
- The Item 9A paragraph as it would be filed
- The remediation statement: what is being done, by when, and who owns it
- The sentence a plaintiff would quote, and why you are content to leave it standing
- What management would have to concede for this to be graded one level higher
2.2The cyber disclosure clock
3.5h
The materiality determination for an incident, and the without-unreasonable-delay trap sitting behind the four-day headline.
- learnRequired
The clock starts at a judgement, not at an alert
Read the brief~2 min
The four-business-day figure is the least interesting part of the rule. The clock does not start when the incident begins, or when the SOC opens a ticket, or when the CISO calls you at 3:47am. It starts when the registrant determines the incident is material — and that determination is a judgement your organisation makes, which means it is a judgement your organisation can make badly, late, or never.
The trap is the delay, not the deadline
Because the clock hangs off a determination, the tempting failure is to keep the determination open. More facts are always arriving; certainty is always four days away. The standard closes this off by requiring the determination without unreasonable delay — so a deliberately unhurried process is itself the violation, and a decision log showing steady progress toward a call is the best defence available.
- Materiality here is the ordinary securities meaning: would a reasonable investor consider it important. Operational severity and materiality are different axes and frequently disagree.
- Qualitative factors count. Reputational harm, the nature of the data and the identity of the actor can make a technically small incident material.
- You do not need to know the full scope to determine materiality. Waiting for scope is the most common form of unreasonable delay.
- The clocks run in parallel and do not agree: SEC disclosure, privacy notification, contractual notice and sector regulators each have their own trigger and their own period.
Write the process before you need it
The organisations that handle this well have decided in advance who convenes the determination, who sits on it, what information is enough to convene, and how the decision is recorded. The ones that handle it badly discover at 4am that nobody is sure who is allowed to say the word material.
Carry this into the drill
The Disclosure Window runs twelve checkpoints across ninety-six hours with two scores moving all night. It rewards deciding early on partial facts and recording why — which is the opposite of most people's instinct.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
The Disclosure Window — SEC Item 1.05 simulation
Open the drillA four-business-day clock that starts at 3:47am, with facts arriving out of order and decisions that close paths behind them. The materiality determination made concrete, in the regime where getting it wrong is most visible.
Ticks itself when the drill records a result
- applyRequired
Materiality determination memo with your own escalation path named
Open the brief
Write the materiality determination memo template your organisation would actually use, and name the escalation path that feeds it — by role, and then by person, because roles do not answer phones.
Then stress it against one real incident from the last two years. Work out when the clock would have started under this process, and compare that with when your organisation actually started talking about disclosure.
What to produce
- Who convenes the determination, and the trigger that obliges them to
- Who sits on it, and who must not
- The minimum information required to convene — deliberately low
- The quantitative and qualitative factors considered, as a standing list
- How the decision and its reasoning are recorded, and by whom
- The parallel clocks that also start, with their triggers and owners
- The real incident replayed: when the clock would have started, against when the conversation actually began
- checkOptional
Who in your organisation could start that clock without knowing it
Open the prompts
- Who in your organisation could start that clock without realising they had?
- In your replayed incident, what was the gap between the first fact sufficient to convene and the first conversation about disclosure?
- Which of the parallel clocks would you most likely miss, and what makes it the one?
- Is there anyone whose incentive is served by the determination staying open, and does your process insulate the decision from them?
2.3Reg FD and the live room
3h
Selective disclosure, and the answer that is accurate, helpful and still a violation.
- learnRequired
Fair disclosure is a process question before it is a content one
Read the brief~2 min
Reg FD is the disclosure regime that punishes helpfulness. There is no bad faith required, no false statement, no concealment. An executive who answers a good analyst's sharp question with genuine specificity, in a room that is not everyone, has committed the violation — and the answer was true, useful and delivered in good faith.
Fair disclosure is a process question
The rule is about who heard it, not about whether it was accurate. That reframes preparation entirely: the work is deciding in advance what is inside the disclosed perimeter and what is outside it, so that the answer in the room is a retrieval rather than a judgement made under social pressure by someone who wants to be useful.
- The dangerous question is friendly. Hostile questions put you on guard; the analyst who has been supportive for six quarters is the one you want to reward with something extra.
- Directional guidance is still guidance. Trending well against that is material non-public information dressed as tone.
- Confirming someone else's model is disclosure. Nodding at a number you did not publish makes it yours.
- The safe answer is a boundary, not a dodge: name what you have disclosed, name what you will not discuss, and stop.
Rehearse the refusal
People fumble refusals because they have never said them out loud. The wording that works is short, unapologetic and repeatable, and the third time you use it in one call it should sound exactly like the first. Practise it until it is boring, because boring is what makes it survive a follow-up.
Carry this into the drill
The Earnings Hot Seat gives you eight named analysts with different temperaments and three answers each, with four metrics moving at once. The traps are placed where specificity is most rewarded.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
The Earnings Hot Seat — Reg FD under live Q&A
Open the drillReg FD under live Q&A: eight analysts, friendly through hostile, where some questions reward rich specificity and others punish exactly the same instinct. The clearest available demonstration that accuracy is not the test.
Ticks itself when the drill records a result
- applyRequired
Q&A prep sheet: five questions you cannot answer, and the wording you will use
Open the brief
Build the Q&A prep sheet for your next results discussion or equivalent external conversation. The core of it is five questions you cannot answer, with the exact words you will use — written out, not summarised as decline politely.
For each, add the follow-up you expect and your second and third response. A boundary that holds once and softens on the third ask is not a boundary.
What to produce
- The disclosed perimeter: what is already public and can be repeated freely
- Five questions you cannot answer, phrased as an analyst would ask them
- For each, the exact refusal wording — one or two sentences
- For each, the expected follow-up and your second and third response
- The three questions where specificity is safe and valuable, and the detail you will volunteer
- Who else is in the room, and what they have been told not to add
- The single answer most likely to be quoted, and whether you are content with that
Week 3 of 6 · 10 hours · 3 modules
When the outside world arrives
Activists, holders and regulators do not wait for the strategy offsite. Three arrivals, each with its own clock and its own record.
Week 3 of 6 · 10 hours · 3 modules
When the outside world arrives
Activists, holders and regulators do not wait for the strategy offsite. Three arrivals, each with its own clock and its own record.
3.1The activist campaign
3.5h
What activists actually want, the fourteen-day rhythm, and which doors close behind you the moment you answer.
- learnRequired
Read the letter for what it is really asking
Read the brief~2 min
An activist letter is not an attack, it is a bid — for attention first, then for a seat, then sometimes for the company. Boards that read it as an insult respond to the tone and miss the structure. The letter is written to be forwarded, and its real audience is your top ten holders, not you.
Read it for what it is actually asking
Most campaigns contain a demand the board privately agrees with, a demand that is negotiable, a demand designed to be refused so the refusal can be quoted, and a demand about people. Sorting the four before you respond is most of the work, because the response has to concede the first without appearing to have been forced, and refuse the third without sounding defensive.
- The uncomfortable part: activists are often directionally right about something. The strongest defence is having already done the thing you agree with, which is a reason to run this exercise before a letter arrives.
- Speed matters more than polish. A slow response is read as disarray by exactly the holders you need.
- Some moves close doors. Agreeing to a meeting, adding a director, launching a review — each changes what is available afterwards, and the sequence is not reversible.
- Every public statement becomes campaign material for the other side. Write nothing you would not want in their next deck.
The fourteen days
Campaigns run on a rhythm: the letter, the holder calls, the proxy advisers, the media, the escalation. Parallel tracks, one move a day, and a board that tries to sequence them serially will find the vote has moved before it reaches track three.
Carry this into the drill
The Activist Letter runs fourteen days with four stakeholder tracks and one move a day. Notice which of your moves closed something behind you — the game is unusually honest about irreversibility.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
The Activist Letter — a 14-day proxy timeline
Open the drillA fourteen-day proxy timeline with four demands and four parallel stakeholder tracks, where some moves close the door behind them. The clearest way to feel why sequencing beats content in a campaign.
Ticks itself when the drill records a result
- applyRequired
The four demands an activist would make of you, and your answer to each
Open the brief
Write the activist letter that would be sent about your own organisation. Four demands, in their voice, using only publicly available information — which is the constraint that makes this useful rather than comfortable.
Then answer each demand honestly: agree, negotiable, refuse. Where you agree, note whether you could do it now and take the credit before anyone asks.
What to produce
- The four demands, drafted in an activist's voice from public information only
- The public evidence each demand would cite
- Your honest position on each: agree, negotiable, refuse
- For each agreement — could you act now, and what is stopping you
- For each refusal — the two-sentence public answer, and whether it survives being quoted
- The demand about people, and who would be named
- Your top five holders, and which of the four demands would move each of them
3.2The contest and the vote
3.5h
Institutional holders, the proxy advisers, and the arithmetic of a whip with five days left.
- learnRequired
Who can actually move, and who only looks movable
Read the brief~2 min
A contested vote is arithmetic before it is persuasion. Some holders will never move, some have already decided and will not say so, and a small band in the middle decides the outcome. Effort spent outside that band feels like campaigning and changes nothing.
Who actually moves
Index holders vote to policy and their stewardship teams are small, so the conversation is short and the policy is published — read it rather than pitching against it. Active managers can be moved by the thesis if they own enough to care. Retail is diffuse and expensive to reach. The proxy advisers do not vote at all and yet route a large block of the outcome, which makes their recommendation the highest-leverage single item on the board.
- Get the register properly, early. A board arguing about strategy without knowing who holds what is guessing.
- Adviser recommendations turn on a small number of published criteria. Meeting those criteria is cheaper than arguing with the recommendation afterwards.
- Moves that look like work: broad mailings, general advertising, a longer letter. Moves that count: the eight calls to the eight holders who can actually change position.
- Committing to something during the whip is binding in practice even when it is not in law. Holders remember.
Carry this into the drill
The Coalition Vote gives you five business days, eight named holders owning 41% of the float, and ten moves. The lesson is in the moves you decline.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
The Coalition Vote — 5-day vote-whip simulation
Open the drillFive days to an annual meeting, eight institutional holders and the advisers who route the rest. A vote-whip where the scarce resource is moves, and most of the available ones do nothing.
Ticks itself when the drill records a result
- applyRequired
Holder map for your own register, movable and immovable separated
Open the brief
Build the holder map for your own register — or, if you are not listed, for whatever body actually decides your mandate: a parent board, a partnership, a sponsor group.
Separate the movable from the immovable, and be honest about which of the immovable you have been spending time on because the conversation is pleasant.
What to produce
- The register or equivalent: who holds what, as a percentage
- Each holder classified — with us, against us, genuinely undecided
- For the undecided: what would move them, and who has the relationship
- The published voting policy of your largest index holders, and where you currently fail it
- The advisers' criteria that apply to you, and your position against each
- Your eight highest-leverage calls, in order
- The relationships you maintain that have no effect on any outcome
3.3Under enforcement
3h
Privilege, cooperation credit and the concession trap — why the damage is rarely done by the hostile questions.
- learnRequired
Everything you say is being written down twice
Read the brief~2 min
A voluntary interview is voluntary in the sense that you may decline and accept what follows. Counsel is present, the questions have been prepared for weeks, and the interviewer already has documents you have not re-read. The asymmetry is the point, and no amount of confidence closes it.
The damage is not in the hostile questions
Hostile questions put people on guard and are answered carefully. The damage comes from the friendly opener that establishes a timeline you have not verified, from the memory probe that invites you to fill a gap with a reconstruction, and from the restatement — where your answer is played back slightly stronger than you gave it and you agree because correcting it feels pedantic.
- I do not recall is a complete answer, and it is the accurate one far more often than people use it.
- Answer the question asked. Volunteering context opens doors you did not choose to open.
- If a restatement is not quite what you said, say so at once. Correcting it later reads as a change of story.
- Never guess at a document you have not been shown. Ask to see it, and read it before answering about it.
Cooperation, privilege and the record
Cooperation credit is real and worth having, but it is earned by the organisation's conduct — preservation, production, candour — not by an individual being expansive under questioning. And privilege is easier to waive than most executives realise: describing the substance of legal advice in an interview can put the whole file in play.
Carry this into the drill
The Regulator's Interview scores three things silently — cooperation, accuracy and discipline — and they trade against each other. Look at where being maximally helpful cost you accuracy.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
The Regulator’s Interview — SEC enforcement deposition sim
Open the drillTen questions across friendly openers, memory probes, restatements, impeachment and the concession trap, with three scores moving silently. The traps are placed exactly where an executive's instinct to be useful lives.
Ticks itself when the drill records a result
- applyRequired
Document-hold and interview-readiness checklist
Open the brief
Build the document-hold and interview-readiness checklist your organisation would run on the day it learns of an investigation. Assume the notice arrives on a Friday afternoon.
The test of this artefact is elapsed time. From notice to hold in force, how many hours, and which systems are the slow ones?
What to produce
- Trigger: what constitutes notice, and who must be told within the hour
- The hold itself: scope, custodians, systems, and who issues it
- Auto-deletion and retention jobs that must be suspended, named system by system
- Personal devices and messaging apps: the policy, and the honest assessment of whether it is followed
- Privilege: who directs the work, how advice is marked, what must not be described outside it
- Interview readiness: who is likely to be interviewed, and what preparation they are entitled to
- Elapsed-time estimate from notice to hold in force, with the slowest system named
- checkRequired
Where your instinct to be helpful becomes a liability
Open the prompts
- Where did your instinct to be helpful cost you accuracy in the interview, and would you notice it happening in a real room?
- How many times did you answer more than the question asked?
- In your own organisation, what would still be deleting itself seventy-two hours after notice?
- Which of your colleagues would reconstruct a timeline rather than say they do not recall, and have they ever been told not to?
- What legal advice have you described in an ordinary meeting this year that you would not want treated as waived?
Week 4 of 6 · 10 hours · 3 modules
Capital, deals and a strategy you can defend
The decisions a board makes that are not risk decisions at all — and the risk each one carries anyway.
Week 4 of 6 · 10 hours · 3 modules
Capital, deals and a strategy you can defend
The decisions a board makes that are not risk decisions at all — and the risk each one carries anyway.
4.1Diligence, and what you inherit at close
3.5h
The red flags that become 10-K items two years later, and diligence as a board decision rather than a workstream.
- learnRequired
At close you acquire their history too
Read the brief~2 min
Diligence is usually run as a workstream and decided as a board item, and the gap between those two facts is where deals go wrong. By the time the recommendation reaches the board, the scope of what was looked at has already been set by someone working to a deadline, and the board is asked to approve a conclusion without seeing the shape of the search that produced it.
At close you acquire their history
Not just their assets and their people — their unfiled incidents, their retention failures, their unremediated findings, their contracts with terms nobody has read since signature. Two years later one of those becomes a 10-K item or a claim, and the document that gets read in that moment is the board minute recording what you were told and what you asked.
- Ask what was not looked at, and why. The answer is more informative than the findings.
- Red flags cluster. A target with weak contract hygiene usually has weak incident records too, because both are symptoms of the same thing.
- The LOI deadline is a negotiating instrument, and it is frequently pointed at you. A board that cannot tolerate letting one lapse cannot really decline a deal.
- Reps and warranties transfer money, not risk. They do not unwind an integration or answer a regulator.
The question that does the work
What would have to be true for this to be a bad deal, and how would we find out? Asked early it directs the diligence; asked at the board it exposes whether the diligence was directed at all.
Carry this into the drill
The Acquisition Dossier gives you seven business days, ten possible review actions and seven hidden red flags. You cannot do everything — the mark is in what you chose to look at before you knew where the flags were.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
The Acquisition Dossier — 7-day M&A diligence sim
Open the drillSeven days of diligence on a $1.4B target with more review actions available than time, and red flags that only surface if you looked. The board recommendation you write is the document the minutes record two years later.
Ticks itself when the drill records a result
- playOptionalTicks itself
How ready is your data privacy function?
Open the drillOptional: a structured pass over third-party reliance across eight domains. Useful here because concentration and exit are the two diligence questions boards ask least and regret most.
Ticks itself when the drill records a result
- applyRequired
Board memo: the five questions you require answered before an LOI
Open the brief
Write the board memo that fixes the five questions you require answered before any LOI is signed. Not a diligence checklist — five questions, chosen because a bad answer to any of them should stop the deal.
Then test it against a transaction your organisation actually did. Would these five have caught what you now know?
What to produce
- The five questions, each phrased so a bad answer is unmistakable
- For each: what evidence constitutes an answer, and what does not
- For each: who must sign that the answer is complete
- The standing instruction on scope — what diligence must cover whether or not anyone asks
- What the board is told about what was NOT examined
- The past transaction replayed against these five
- What you would have found, and whether it would have changed the decision
4.2The rival that reads you back
3h
Strategy as an adaptive game: refusing the price war, and compounding instead of matching.
- learnRequired
Your move is an input to theirs
Read the brief~2 min
Most strategy papers presented to boards assume a static opponent. The market shifts, but the named competitor is modelled as scenery. Real rivals respond, and they respond to your move specifically — which means the value of a move depends on what it invites.
Your move is an input to theirs
A price cut that wins share this quarter and triggers a matching cut is not a win, it is a permanent reduction in industry margin that you paid to initiate. The board question is not is this a good move but what does this make them do, and are we better off after they have done it.
- Read temperament from history, not from statements. A rival that has matched every price move for six years will match this one.
- Prefer moves that are hard to copy: structural cost, exclusive access, switching costs. They compound rather than reset.
- Refusing to fight is a move. Ceding a segment deliberately is often the highest-return decision available and the hardest to get through a board.
- Ask what would make us stop. A strategy with no abandonment condition will be defended past its evidence.
Carry this into the drill
Five Moves Ahead pits you against an adaptive rival with a temperament you have to read. Note the moves where you compounded and the moves where you simply matched.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
Five Moves Ahead — a competitive-strategy war-game
Open the drillA competitive-strategy war-game against an adaptive rival. A borrowing — this is a strategy piece, not a risk piece — and it is here because two of this programme's weeks cover board decisions that are not risk decisions at all.
Ticks itself when the drill records a result
- applyRequired
Two-moves-ahead sheet for one live competitive decision
Open the brief
Take one live competitive decision and write the two-moves-ahead sheet: your move, their most likely response, your position after it, and what you would do next.
Include the abandonment condition. If you cannot write what would make you stop, the board is being asked to approve something open-ended.
What to produce
- The decision, and the move being proposed
- The named rival, and their response history over the last three comparable moves
- Their most likely response, and the second most likely
- Your position after each, against your position today
- Your counter-move in each branch
- What makes this move hard to copy, or the honest admission that it is not
- The abandonment condition: the observable that would make you stop, and who is watching for it
4.3Transformation, and the gap it dies in
3.5h
Sequencing and momentum, and why the big bet keeps firing before its foundations are laid.
- learnRequired
The programme was never behind schedule; it was in the wrong order
Read the brief~2 min
Transformation programmes rarely fail at the vision and rarely fail at the technology. They fail in the gap between the two, and the specific mechanism is almost always sequencing: a headline initiative launched before the capability it depends on exists, because the headline initiative is the one the board asked about.
The programme was not behind schedule; it was in the wrong order
Momentum is a resource and it depletes. Early visible wins buy the patience that later structural work requires, which means the correct sequence is often the one that looks least ambitious in month three. Boards push against this without realising, by asking for the flagship first.
- Every big bet has a foundation. Name it explicitly, and refuse to fire the bet before the foundation is in place.
- A dependency that is not on anyone's plan is not managed by anyone. Cross-workstream dependencies are the ones that go unowned.
- Change capacity is finite per business unit and it is not fungible with budget. Three programmes landing in the same function in the same quarter will all under-deliver.
- The status that has been amber for four quarters is telling you the plan is wrong, not that the team is slow.
Carry this into the drill
Mind the Gap makes you sequence a change programme across the valley between vision and value. The reading on strategic alignment covers the same ground in prose; the game is where you find out whether you would actually hold the line on foundations.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
Mind the Gap — a transformation-sequencing game
Open the drillA transformation-sequencing game where momentum is finite and big bets fired before their foundations fail. A borrowing from the strategy-execution catalogue, and the closest thing available to the oversight question a board actually faces on a programme.
Ticks itself when the drill records a result
- playOptionalTicks itself
S/4HANA Cutover Sim
Open the drillOptional: the final week before a major go-live, keeping controls intact under pressure. Worth doing if your organisation has a cutover ahead — it is the operational end of the sequencing argument this module makes.
Ticks itself when the drill records a result
- applyRequired
Sequencing critique with the dependency you are about to break named
Open the brief
Take one live programme and critique its sequence. Name the dependency that is about to be broken — there is almost always one, and it is usually known to somebody two levels below the person presenting.
Write the re-sequence you would argue for, including what it costs in visible progress over the next two quarters. A re-sequence that costs nothing has not been thought through.
What to produce
- The programme, its stated sequence, and its current status
- The dependency map as it actually is, not as the plan describes it
- The dependency about to be broken, and who already knows
- Change capacity in the receiving functions, quarter by quarter
- Your re-sequence, with the reasoning for each move
- What the re-sequence costs in visible progress, and how you would explain that to the board
- The status item that has been amber longest, and what it is really telling you
- checkOptional
The programme you are protecting from scrutiny
Open the prompts
- Which programme are you protecting from scrutiny, and what would have to be true for you to stop?
- Where did you fire a big bet before its foundation in the game, and what was the pull that made you do it?
- Who two levels below you already knows about the broken dependency, and why has that not reached the board?
- If you had to cancel one initiative this quarter to protect change capacity, which would it be, and what stops you?
Week 5 of 6 · 10 hours · 3 modules
The technology the board is now accountable for
Where boards are newly on the hook and least practised: approving AI, verifying it without becoming management, and buying the year's assurance.
Week 5 of 6 · 10 hours · 3 modules
The technology the board is now accountable for
Where boards are newly on the hook and least practised: approving AI, verifying it without becoming management, and buying the year's assurance.
5.1AI at the committee
3.5h
Approve, reject, conditional — and the difference between conditions that bind and conditions that sound governance-flavoured.
- learnRequired
A condition nobody will check is an approval
Read the brief~2 min
AI proposals arrive at committees in a form designed to be approved: a business case, a named sponsor, a risk section written by the same team that wants the answer to be yes. The committee's contribution is not more enthusiasm or more caution — it is the conditions, and whether they bind.
A condition nobody will check is an approval
Conditional approval is the default outcome and the most abused one. Subject to appropriate human oversight is not a condition; it is a sentence. A condition binds when it names the thing that must be true, the evidence that will show it, the person who will produce that evidence, and the date. If any of the four is missing, the proposal has been approved and the committee has recorded a preference.
- Reject is a real option and a committee that has never used it has no credible conditional approvals either.
- The two scores move in opposite directions: block everything and the business routes around you; approve everything and the first failure is yours. Both easy ways out are traps.
- Ask what happens when it is wrong, not whether it will be. Every model is wrong at some rate; the governance question is the path from wrong output to harm, and where that path can be cut.
- A use case that cannot describe its failure mode has not been assessed by anyone, whatever the paperwork says.
Where boards over-reach
By asking about the model. Accuracy, architecture and training data are management's to test and mostly beyond a board's ability to verify. What a board can verify is whether an inventory exists, whether every deployed use case went through the gate, whether the conditions attached to past approvals were ever evidenced, and whether anyone has authority to turn one off.
Open the reading — Your AI Agents Are Employees Now. Audit Them Like It.Carry this into the drill
The Use-Case Gate puts eight proposals in front of you with two scores moving in opposite directions. Read your conditional approvals afterwards and check each one against the four-part test — most people find at least two that were really approvals.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
The Use-Case Gate — an AI governance committee sim
Open the drillAn AI governance committee with eight proposals, where the conditions that sound governance-flavoured and the conditions that bind are deliberately hard to tell apart under time pressure.
Ticks itself when the drill records a result
- playOptionalTicks itself
Confidently Wrong — naming the AI failure mode
Open the drillOptional: sorting AI failures into fabrication, staleness, faulty reasoning and should-have-declined. Four minutes, and it is what lets you ask a sponsor which failure mode their control actually addresses.
Ticks itself when the drill records a result
- applyRequired
Intake criteria your committee would actually apply on a Tuesday
Open the brief
Write the intake criteria your committee would actually apply on a Tuesday afternoon with four proposals and ninety minutes. Short enough to use, specific enough to fail something.
Then run your last approved AI use case through them. If it passes without effort, the criteria are too loose; if it fails on a technicality, they are the wrong criteria.
What to produce
- The intake criteria, on one page
- The four-part test every condition must satisfy: what, evidence, owner, date
- What is out of scope for the committee entirely, and who handles it instead
- The standing questions asked of every proposal, including the failure-mode question
- The kill switch: who can suspend a deployed use case, and how fast
- Your last approved use case run through the criteria, with the result
- The conditions attached to past approvals, and whether any was ever evidenced
5.2A board's own scan
3h
The eight domains of AI governance, and which of them a board can verify for itself without stepping into management.
- learnRequired
Verify the control, not the model
Read the brief~2 min
There is a version of AI oversight where the board asks for a briefing, receives one, and has learned only what management chose to present. There is another version where the board runs its own structured scan and arrives with a list of domains and a set of specific questions. The second takes an hour and changes the meeting.
Verify the control, not the model
The domains a board can genuinely check are governance ones: is there an inventory, is it complete, who owns each system, what went through the gate, what did not, what is monitored, what is the escalation path, and has anything ever been stopped. None of these requires technical assessment and all of them are answerable with evidence.
- Completeness of the inventory is the single highest-value question. Shadow deployments are the norm, not the exception.
- Ask for the list of use cases that did NOT go through the gate. The reaction to that question is itself the finding.
- Third-party AI embedded in a vendor product is still yours to govern and is usually missing from the inventory.
- A maturity score is a starting position, not an achievement. The useful output is the gap list with owners and dates.
Carry this into the drill
The self-assessment gives you a score, a radar and a gap list across eight domains. The score is the least useful part — take the gaps and put a name and a date against each before the next meeting.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
How governed is your AI & automation?
Open the drillA structured scan across the eight domains a real AI risk assessment must reach, mapped to recognised frameworks. Run it yourself rather than commissioning it, because arriving with your own gap list changes what the briefing has to answer.
Ticks itself when the drill records a result
- applyRequired
Gap list with a named owner and a date against each line
Open the brief
Turn the scan output into a gap list with a named owner and a date against every line. Names, not functions — functions do not miss deadlines and people do.
Add the three questions you will ask at the next meeting, and the evidence that would satisfy each. Deciding the evidence in advance is what stops a reassuring answer from closing the item.
What to produce
- The eight domains, with your position in each
- The gap list, one line per gap
- Named owner and date against each line
- The three highest-consequence gaps, and why those three
- The three questions for the next meeting
- For each question, the evidence that would close it — decided now
- The inventory completeness question, and how you will test the answer
5.3The audit committee and the year's assurance
3.5h
Coverage against depth, and what makes a plan defensible before the year delivers its surprises.
- learnRequired
You are approving a bet about where the year goes wrong
Read the brief~2 min
An annual audit plan is a bet about where the year will go wrong, placed before the year starts, with a fixed number of hours. Approving one is not an administrative act. It is the board deciding what it will and will not find out about, and the areas left uncovered are a choice even when nobody frames them as one.
Coverage against depth
The same hours buy broad shallow coverage or narrow deep coverage, and the two fail differently. Shallow coverage finds nothing but can say everything was looked at. Deep coverage finds real problems in three areas and is silent about eleven. Neither is right in general; what makes a plan defensible is that the trade was made deliberately and the reasoning was recorded before anyone knew where the problems were.
- Ask what is not on the plan and why. An area absent for three consecutive years needs an explicit decision, not an omission.
- Reserve capacity is a feature. A plan that is fully committed in January cannot respond to anything that happens in June.
- Risk-ranked does not mean risk-led. Check whether the ranking drove the allocation or was written afterwards to justify it.
- Half the quality of a plan is only visible in hindsight; the other half — whether it was defensible when made — is visible now, and that is the half the committee owns.
Carry this into the drill
Plan the Year gives you 1,800 hours, fourteen auditable entities and eight surprises you cannot see coming. Half the mark is what you caught, half is whether the plan was defensible before you knew any of it — which is exactly the committee's half.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
Plan the Year — an audit-plan allocation sim
Open the drillAn audit-plan allocation sim, written for the director who builds the plan and used here by the committee member who has to approve it and later explain it. A borrowing, and a useful reversal of seat.
Ticks itself when the drill records a result
- applyRequired
Challenge memo on your own audit plan: three areas under-covered, and why
Open the brief
Write the challenge memo on your own organisation's audit plan: three areas you believe are under-covered, with the reasoning, and what you would give up to cover them.
A challenge that adds scope without naming what it displaces is not a challenge, it is a wish. The hours are fixed.
What to produce
- The plan as approved: total hours, and the allocation by entity
- The stated risk ranking, and whether it visibly drove the allocation
- Three under-covered areas, with the reasoning for each
- What you would displace to cover them, named specifically
- Areas absent for three years or more, and the explicit decision you want recorded
- Reserve capacity: how much, and who releases it
- The one question you would put to the head of internal audit in private session
- checkRequired
What half of that score was really measuring
Open the prompts
- In the sim, how much of your score came from catching surprises and how much from having built a defensible plan? Which would you rather explain?
- What is your organisation deliberately choosing not to find out about this year?
- If a major issue surfaced in June in an area with zero planned coverage, what would the committee's answer be?
- Does your audit function have a private session with the committee, and has it ever produced anything the executive did not already know?
Week 6 of 6 · 10 hours · 3 modules
The crisis, and the close
Two crises where the board's own decisions are the material ones, then the agenda that carries everything you built into the next four meetings.
Week 6 of 6 · 10 hours · 3 modules
The crisis, and the close
Two crises where the board's own decisions are the material ones, then the agenda that carries everything you built into the next four meetings.
6.1The board in the breach room
3h
Where boards hold the line and where they reach past it, round by round.
- learnRequired
The board's job in an incident is smaller and harder than it looks
Read the brief~2 min
In an incident the board's job is smaller than it feels and harder than it looks. Smaller, because containment, forensics and recovery belong to people who do this for a living. Harder, because the handful of decisions that are genuinely the board's arrive early, on bad information, and cannot be revisited.
What is actually the board's
Whether to disclose and when. Whether to pay. Whether to involve law enforcement. Whether the CEO speaks. Whether to invoke insurance, and when to tell the insurer. Whether the incident changes any commitment already made to a market or a regulator. Everything else on the incident bridge is management's, and a director on that bridge is consuming capacity, not adding it.
- Convene early and separately. A board that first meets on day four is deciding with the executive's framing already set.
- One voice externally, decided in the first hour. Two spokespeople is a second incident.
- Do not ask for updates that cost more to produce than they are worth. Set a rhythm — twice daily, in a fixed shape — and hold to it.
- The record you are creating is evidence. Decision logs written during the incident are worth more later than any reconstruction afterwards.
Where boards hold the line
Against the pull to announce before the facts support it, against the pull to promise remediation timelines nobody has costed, and against the pull to make the incident about a person while it is still running. All three feel like decisiveness in the room and read as panic in the transcript.
Carry this into the drill
The Breach Room runs a major breach from the board's side, round by round. Notice which decisions you reached for that were not yours — that instinct is the thing this module exists to correct.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
The Breach Room — a C-suite tabletop
Open the drillA C-suite tabletop of a major breach, run as the board rather than as the responders. It is unusually good at showing where a board holds the line and where it reaches past it.
Ticks itself when the drill records a result
- playOptionalTicks itself
The War Room — an incident-command sim
Open the drillOptional: incident command from the responder's seat, moving a finite team across recovery, customers, the regulator clock and staff. Worth an hour precisely because it is not your job — it shows what your requests for information cost the people answering them.
Ticks itself when the drill records a result
- applyRequired
Board crisis protocol: who convenes, who speaks, what is decided where
Open the brief
Write your board's crisis protocol: who convenes, within what period, who attends, what is decided at board level and what is explicitly not, and how the record is kept.
Include the contact reality. Named people, alternates, and channels that work when the corporate estate does not — which is the failure mode nobody plans for and everybody meets.
What to produce
- The trigger: what obliges a convening, and who can call it
- Time to convene, and the quorum that counts at 3am
- The decisions reserved to the board, listed
- The decisions explicitly NOT the board's, listed — this half matters more
- Reporting rhythm: how often, in what shape, from whom
- External voice: who speaks, who approves the words, who does not speak
- Out-of-band contact: named people, alternates, and a channel independent of corporate systems
- How the decision log is kept, by whom, and where it lives
6.2The ransom decision
3h
OFAC, insurance, backups — and a phase structure that locks each commitment before the fact that would have changed it arrives.
- learnRequired
Decide it before 2:14am, or it decides you
Read the brief~2 min
A ransom decision has a shape that punishes deliberation. Each phase demands a commitment, and the fact that would most have changed that commitment usually arrives in the phase after. Backups look viable until they are tested. Insurance looks like it covers this until the policy is read. The actor looks unsanctioned until the wallet is traced.
Decide it before 2:14am
The only reliable defence against a structure like that is a position written in advance, when nobody is frightened and nothing is burning. Not a policy that says we do not negotiate — that survives contact with reality for about an hour — but a written record of the conditions under which the board would consider payment, who must be consulted, and what must be verified before any transfer.
- Sanctions exposure is the hard constraint. Payment to a sanctioned entity is a separate and worse problem than the breach, and attribution is often unclear when the decision is due.
- Insurance requires notification within a period and frequently requires consent before payment. Reading the policy during the incident is too late.
- Test backups, do not assume them. Recovery time from an untested backup is unknown, and unknown is not a plan.
- Payment does not buy silence, deletion or certainty. It buys a decryption tool of variable quality from someone who has already lied to you.
Carry this into the drill
The Ransom Decision runs seven phases with seven commitments, each locking before the truth that matters most is visible. The mechanic is the lesson — which is why the Apply step asks you to write your position now rather than after.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
The Ransom Decision — a 7-phase ransomware sim
Open the drillSeven phases and seven commitments, each locked in before the fact that would have changed it arrives. OFAC, insurance, backups, the payment itself — and a structure designed to show you why the decision has to exist before the night does.
Ticks itself when the drill records a result
- applyRequired
Pre-decision record: your position on payment, written before you need it
Open the brief
Write the pre-decision record: your organisation's position on ransom payment, agreed before it is needed. It should be short enough that someone can read it at 3am and act on it.
Then have it approved. An unapproved position is a personal opinion, and the whole value of this artefact is that it carries authority the moment it is opened.
What to produce
- The stated position, in three sentences
- The conditions under which payment would be considered at all
- Who must be consulted before any payment decision, with alternates
- The sanctions check: who performs it, on what evidence, and what happens if it is inconclusive
- The insurance position: notification window, consent requirement, and who holds the policy
- Backup verification: last tested, recovery time observed rather than estimated
- Where this document lives so it is readable when the network is not
- Who approved it, and when it is next reviewed
6.3Capstone and close
4h
A board risk agenda for the next four meetings, and an honest account of what you would still struggle to govern.
- playRequiredTicks itself
Road to the Final — a knockout tournament
Open the drillA knockout across five domains — cyber, audit, AI governance, resilience and privacy — where every tie is a decision under pressure. It is here as the capstone drill because the defining feature of a board agenda is that the next item is not in the domain you prepared for.
Ticks itself when the drill records a result
- applyRequired
Capstone: a board risk agenda for the next four meetings
Open the brief
Build the board risk agenda for the next four meetings. Not a list of topics — a sequence of decisions, each with the paper that must precede it, the evidence that paper must contain, and the person who owes it.
Everything from the previous five weeks feeds this: the decision-rights map, the appetite rewrite, the pack critique, the disclosure process, the LOI questions, the AI gap list, the audit-plan challenge, the crisis protocol and the ransom position. The work is reconciling them into one agenda that a real calendar could carry, including admitting where two of your own artefacts want the same meeting.
Finish with one page a chair could read. If it needs the appendices to be understood, it is not finished.
What to produce
- The four meetings, with dates and the standing items already fixed
- The decisions to be taken at each, in sequence, with the reason for that order
- For each decision: the paper required, who owes it, and by when
- For each paper: the evidence it must contain for the decision to be real
- The artefacts from weeks 1–5 that feed each item
- Where two items compete for the same meeting, and how you resolved it
- What is deliberately NOT on the agenda, and the decision to leave it off
- The information rights you are asserting: what must arrive, how many days before
- One page for the chair: the shape of the year, the three decisions that matter, and what you are asking for
- checkRequired
Reflection and personal development plan
Open the prompts
- Which of your six weeks' artefacts turned out to be load-bearing for the agenda, and which have you not opened since you wrote them?
- Where did two of your own artefacts contradict each other, and which one was wrong?
- In the knockout, which domain did you lose in, and is that the same domain you would be weakest on at a real board?
- What is the single change to your board's operation you would now argue for first, and who has the authority to make it?
- Six months from now, what evidence would show this programme changed how a decision was taken?
Finish it, and it is on the record
When every required step is done, a printable completion certificate appears on your profile — self-attested, honest about what it is, and yours to keep. Apply and Check steps are yours to mark; Play steps tick themselves when a drill records a result.
Open your profile