Signify Insights
DiscoverSignify PlaygroundSignify FieldworkSignify LabsSignify KidsSpotlightsAboutSignify SolutionSignify HiveSignify Impact
Signify Fieldwork · Board Risk Executive
A publishing & interactive-learning property · Philadelphia · est. 2019

FIELDWORK · SIX WEEKS · SELF-PACED

Board Risk Executive — a six-week applied programme

Executives who carry risk decisions into a boardroom: CxOs and heads of function who own the paper, plus audit-committee members and non-executive directors who have to interrogate it.

The platform hosts the spine — briefs, sims, templates, progress — and structures the deep work. It does not host sixty hours of content. Plan roughly ten focused hours a week, most of it real work against your own board, your own register and your own disclosure calendar; Signify Fieldwork keeps the thread.

6 weeks~10h a week18 modules57 required steps23 drills

Progress0 of 57 required stepsSaving to this browser

Week 1 of 6 · 10 hours · 3 modules

The seat, and the standard it is held to

Before any particular decision, the shape of the job: what a board owns and what it must not touch, an appetite that binds something, and the right to information good enough to govern on.

1.1

What the board owns, and what it must not touch

3.5h

Decision rights, information rights, and the failure mode at each end — the board that rubber-stamps and the board that runs the company.

  • learnRequired

    Oversight is not management

    Read the brief~2 min

    Every dysfunctional board is dysfunctional in one of two directions, and both are failures of the same thing. The board that rubber-stamps has decided that management's judgement is the only judgement available. The board that runs the company has decided the opposite and taken the executive's job, which leaves nobody holding the executive to account. Neither board believes it is doing either.

    Oversight is not management

    The distinction that actually works in a room is about the question being asked. Management answers what shall we do. The board answers whether we can rely on how that was decided, whether the person deciding it is the right one, and whether we would know in time if it went wrong. When a director starts redesigning the plan, they have stopped being able to judge it.

    • Decide: a small list, and it should be written down. Strategy, capital allocation above a threshold, the CEO, risk appetite, and the disclosures that carry the board's name.
    • Approve: management proposes, the board tests and consents. The board's contribution here is the quality of the challenge, not the content of the proposal.
    • Be told: everything else, and this is the category that silently swallows the other two. A paper that arrives for noting on Thursday for a decision already taken on Monday has moved an item out of the first category without anyone voting on it.

    Where the line actually gets crossed

    Rarely in a formal vote. It gets crossed in the pre-meeting call, in the director with sector experience who starts directing a workstream, and in the executive who brings a decision to the board precisely because they would rather not own it. That last one is worth naming: escalation is sometimes a transfer of risk rather than a request for governance, and a board that accepts it has taken on a decision it cannot resource.

    Open the reading — GRC Operating Model

    Carry this into the drill

    Whose Call puts twelve decisions in front of you and asks where each belongs; watch how often your instinct pulls one up to the full board. The GRC maturity scan is the optional baseline underneath it — a read of the enterprise you are overseeing, before you argue about who decides what within it. The map you build in the Apply step is the artefact the rest of the week tests.

    Go deeper — with your own AICopy-paste prompt

    The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.

    Yours to edit — changes stay in this box

  • playRequiredTicks itself

    Whose Call — a decision-rights drill

    Twelve decisions and four places each could belong — the full board, a committee, management, the shareholders. It counts over-reach, because pulling a decision up to the board is the error that feels like diligence, and this module's deliverable is exactly that map.

    Open the drill

    Ticks itself when the drill records a result

  • playOptionalTicks itself

    GRC Maturity Assessment

    Optional: a structured baseline of the governance you are overseeing, across eight domains. Worth four minutes before you draw a decision-rights map, because the map is only as good as your read of what exists to be governed.

    Open the drill

    Ticks itself when the drill records a result

  • applyRequired

    Decision-rights map for one committee

    Open the brief

    Take one real committee — your board, its audit or risk committee, or the executive committee that feeds it — and map what it actually decides, approves and is merely told. Use the last four meetings as evidence rather than the terms of reference, because the two will disagree and the meetings are the truth.

    The value is in the disagreements. Every item where the terms of reference say decide and the minutes show noting is a decision right that has quietly migrated, and it migrated toward whoever wanted it more.

    What to produce

    • The committee, its stated remit, and the four meetings you sampled
    • Every substantive item across those meetings, sorted into decide, approve, be told
    • Each item's stated category from the terms of reference, beside the category the minutes actually show
    • The migrations: items that moved category, in which direction, and who benefited
    • Information rights: for each decide item, what the committee was given and when it arrived
    • The two items you would move back, and what you would have to change in the calendar to make that real
    Template · decision-rights
  • checkOptional

    Where your board is doing management's job

    Open the prompts
    1. Name the last decision your board took that management had already made. What would have had to happen, and when, for the board to have had a real choice?
    2. Which director is doing management's job, and is it because they are over-reaching or because the executive is under-delivering?
    3. Pick the item you were most relieved to escalate. Were you asking for governance, or for company?
    4. If a regulator read your last four sets of minutes, which items would they say the board decided, and would you agree?
1.2

Appetite that changes a decision

3h

Appetite against tolerance, and why most appetite statements never bind anything anyone would otherwise have done.

  • learnRequired

    A statement that refuses something

    Read the brief~2 min

    A risk appetite statement earns its place by refusing something. If no proposal in the last two years would have failed it, it is not an appetite statement; it is a values poster with numbers on it. The test is uncomfortable on purpose, because the appetite that never bites was written to avoid ever having to say no in public.

    Appetite, tolerance, and the gap between them

    Appetite is how much of a thing you are willing to take on in pursuit of the strategy — a forward-looking choice. Tolerance is how far you will let an actual exposure drift before someone must act — an operating limit. Boards conflate them and end up with a single number that is too vague to guide a decision and too soft to trigger one.

    • Appetite belongs to the strategy: we will accept concentration in this segment because that is where we are choosing to grow.
    • Tolerance belongs to the operation: above this exposure, the committee is convened whether or not anyone thinks it is necessary.
    • The pair only works if breaching tolerance has a consequence written down in advance. A limit with no named action is a reporting line.

    Why the debate goes wrong

    Appetite arguments are conducted in loaded language, and loaded language beats arithmetic in a room. Cyber sounds bigger than concentration; a named catastrophic scenario sounds bigger than a chronic exposure that is three times the size. The board that cannot notice this in itself will set an appetite shaped by which risk had the most frightening vocabulary.

    Carry this into the drill

    Which Is Riskier? is a calibration drill, and an appetite debate is a calibration exercise conducted with adjectives. Notice which pairs you got wrong and whether the losing option was the one that sounded duller.

    Go deeper — with your own AICopy-paste prompt

    The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.

    Yours to edit — changes stay in this box

  • playRequiredTicks itself

    Which Is Riskier? — a calibration drill

    Pairwise calls on residual risk, which is exactly the judgement an appetite debate runs on. A borrowing from the practitioner catalogue, and the most useful five minutes available before you write a limit somebody has to live inside.

    Open the drill

    Ticks itself when the drill records a result

  • applyRequired

    One appetite statement rewritten until a named proposal fails it

    Open the brief

    Take one line of your organisation's existing risk appetite statement and rewrite it until a specific, named, real proposal would fail it. Not a hypothetical — something on a roadmap or in a pipeline now.

    Then write the consequence. Who is told, within what period, and what are they required to do. If you cannot name the action, the limit is decorative and the rewrite is not finished.

    What to produce

    • The original line, quoted as it stands today
    • The real proposal you are testing it against, described in three lines
    • Why the original does not bite: which word is doing the escaping
    • The rewrite, with the measure, the threshold and the period explicit
    • The consequence of breach: who is notified, in what window, and what they must do
    • One proposal the rewrite would wrongly block, and how you would handle that exception without dissolving the limit
    Template · appetite-statement
1.3

The information you are entitled to

3.5h

Reporting that surfaces the thing you would want to know early, and the anatomy of an escalation that arrived too late to matter.

  • learnRequired

    The escalation that arrived on time and said nothing

    Read the brief~2 min

    Boards are not usually surprised because nobody told them. They are surprised because they were told in a form that could not carry the weight: a green status against a milestone nobody had re-baselined, an assurance rating with no evidence behind it, a risk that had been amber for so long it had become furniture.

    Read the paper for what it is not showing you

    A board pack is an argument, and every argument has a shape chosen by its author. The questions that surface the shape are boring and reliable: what changed since last time and why, what is the source of this number, who else has seen it, and what would have to be true for this to be wrong. The last one does more work than the other three combined.

    • A trend with no comparator is a claim. Three periods or it is not a trend.
    • An assurance rating without its evidence base is somebody's opinion in a colour.
    • A risk whose rating has not moved in eight quarters is either unmanaged or mis-rated, and both need saying out loud.
    • The absence of bad news between meetings is information about the escalation route, not about the business.

    Corroborate, contradict, unsupported

    The discipline that transfers here comes from forensic audit: for any claim, the honest verdicts are that the evidence corroborates it, contradicts it, or does not reach it. The third verdict is the one boards skip, because unsupported feels like an accusation. It is not — it is a statement about the paper, and the right response is a request, not a finding.

    Carry this into the drill

    Tie-Out is an auditor's drill, played here from the other side of the table: management hands you a binder and a story, and your job is to tie each claim to something. Take the habit, not the technique — you will not be footing schedules in a board meeting, but you will be asking which of these three verdicts applies.

    Go deeper — with your own AICopy-paste prompt

    The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.

    Yours to edit — changes stay in this box

  • playRequiredTicks itself

    Tie-Out — a forensic deduction

    A forensic deduction where a story has to be tied back to evidence, claim by claim. A borrowing from the audit catalogue, and the closest thing available to the discipline of reading a board pack properly.

    Open the drill

    Ticks itself when the drill records a result

  • applyRequired

    Board-pack critique: three claims and what corroborates each

    Open the brief

    Take the most recent board or committee pack you received. Choose three substantive claims — a rating, a trend, an assurance statement — and work out what would corroborate each, what would contradict it, and whether the pack contains either.

    Write the three questions you would ask at the next meeting. Then write what you expect the answer to be, and seal it. Comparing your prediction to the answer is the fastest way to calibrate how well you actually read that pack.

    What to produce

    • The pack, its date, and how long before the meeting it arrived
    • Three substantive claims, quoted
    • For each: what evidence would corroborate it, and is that evidence in the pack
    • For each: the verdict — corroborated, contradicted, or unsupported
    • The three questions, phrased so they cannot be answered with reassurance
    • Your sealed prediction of each answer
    • What is structurally missing from every pack you receive, not just this one
    Template · pack-critique
  • checkRequired

    What your pack never shows you

    Open the prompts
    1. Which of your three claims turned out to be unsupported rather than wrong, and why was that harder to say?
    2. How much of your confidence in the pack comes from the evidence in it, and how much from your view of the person who wrote it?
    3. What is the longest a material fact could stay unknown to your board given the current reporting calendar?
    4. If the pack arrived seventy-two hours earlier, which of your questions would you have asked differently?

Week 2 of 6 · 10 hours · 3 modules

Disclosure: the decisions with a clock

Three regimes, three clocks, one question underneath all of them — what did you know, when did you know it, and what does the record show you did next.

2.1

Material weakness and the 10-K

3.5h

Materiality, Item 9A, restatement against revision, and what the audit committee owns in each.

  • learnRequired

    Significant deficiency, material weakness, and the line between them

    Read the brief~2 min

    Three weeks before the 10-K, the auditor calls. That sentence is the whole module: the decision is taken under time pressure, with incomplete facts, by people who all have a reason to prefer one answer, and it is judged years later by readers who have all the facts and no time pressure at all.

    The line, and why it moves

    A deficiency is a control that does not work. A significant deficiency is one important enough to merit the attention of those responsible for oversight. A material weakness is one where there is a reasonable possibility that a material misstatement would not be prevented or detected in time. The gradations are about likelihood and magnitude, not about how embarrassing the finding is — and the pull toward the softer label is strongest exactly when the harder one is correct.

    • Severity is judged on what could happen, not on what did. No misstatement occurred is not a defence; it is sometimes just luck, and the standard knows that.
    • Compensating controls only compensate if they operate at a level of precision that would actually catch the misstatement. Naming one that operates monthly against a daily exposure is not a compensating control, it is a hope.
    • Aggregation is the trap. Three significant deficiencies in the same process can be a material weakness together even though each survives alone.

    What the audit committee owns

    Not the conclusion — that is management's, with the auditor attesting. What the committee owns is whether the process reaching it was honest: whether scope was set before the answer was known, whether the people assessing severity were insulated from the people whose area it was, and whether the timetable left room for the answer to be inconvenient.

    Carry this into the drill

    The Material-Weakness Memo runs seven rounds from the auditor's call to the audit-committee meeting, with three scores moving that you cannot see: the SOX 404 conclusion, investor confidence and class-action probability. Watch which of your choices moved them in opposite directions.

    Go deeper — with your own AICopy-paste prompt

    The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.

    Yours to edit — changes stay in this box

  • playRequiredTicks itself

    The Material-Weakness Memo — SOX 404 disclosure sim

    The SOX 404 disclosure decision as it actually arrives — three weeks to the 10-K, investigative scope to set, Item 9A language to assemble, and a market sequencing choice that outlives the quarter.

    Open the drill

    Ticks itself when the drill records a result

  • applyRequired

    Draft Item 9A language for a weakness in your own environment

    Open the brief

    Draft the Item 9A disclosure for a hypothetical material weakness in your own environment. Pick a real process with a real control you privately suspect, and write the paragraph as it would be filed.

    Then read it as a plaintiff's lawyer would. The sentence you least want quoted back is the one to rewrite — not to soften it, but to make it accurate enough that the quotation does not damage you.

    What to produce

    • The process, the control, and why you suspect it
    • The severity assessment: likelihood, magnitude, and the reasoning for the grade you chose
    • Compensating controls considered, and the precision test each passed or failed
    • The Item 9A paragraph as it would be filed
    • The remediation statement: what is being done, by when, and who owns it
    • The sentence a plaintiff would quote, and why you are content to leave it standing
    • What management would have to concede for this to be graded one level higher
    Template · item-9a
2.2

The cyber disclosure clock

3.5h

The materiality determination for an incident, and the without-unreasonable-delay trap sitting behind the four-day headline.

  • learnRequired

    The clock starts at a judgement, not at an alert

    Read the brief~2 min

    The four-business-day figure is the least interesting part of the rule. The clock does not start when the incident begins, or when the SOC opens a ticket, or when the CISO calls you at 3:47am. It starts when the registrant determines the incident is material — and that determination is a judgement your organisation makes, which means it is a judgement your organisation can make badly, late, or never.

    The trap is the delay, not the deadline

    Because the clock hangs off a determination, the tempting failure is to keep the determination open. More facts are always arriving; certainty is always four days away. The standard closes this off by requiring the determination without unreasonable delay — so a deliberately unhurried process is itself the violation, and a decision log showing steady progress toward a call is the best defence available.

    • Materiality here is the ordinary securities meaning: would a reasonable investor consider it important. Operational severity and materiality are different axes and frequently disagree.
    • Qualitative factors count. Reputational harm, the nature of the data and the identity of the actor can make a technically small incident material.
    • You do not need to know the full scope to determine materiality. Waiting for scope is the most common form of unreasonable delay.
    • The clocks run in parallel and do not agree: SEC disclosure, privacy notification, contractual notice and sector regulators each have their own trigger and their own period.

    Write the process before you need it

    The organisations that handle this well have decided in advance who convenes the determination, who sits on it, what information is enough to convene, and how the decision is recorded. The ones that handle it badly discover at 4am that nobody is sure who is allowed to say the word material.

    Carry this into the drill

    The Disclosure Window runs twelve checkpoints across ninety-six hours with two scores moving all night. It rewards deciding early on partial facts and recording why — which is the opposite of most people's instinct.

    Go deeper — with your own AICopy-paste prompt

    The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.

    Yours to edit — changes stay in this box

  • playRequiredTicks itself

    The Disclosure Window — SEC Item 1.05 simulation

    A four-business-day clock that starts at 3:47am, with facts arriving out of order and decisions that close paths behind them. The materiality determination made concrete, in the regime where getting it wrong is most visible.

    Open the drill

    Ticks itself when the drill records a result

  • applyRequired

    Materiality determination memo with your own escalation path named

    Open the brief

    Write the materiality determination memo template your organisation would actually use, and name the escalation path that feeds it — by role, and then by person, because roles do not answer phones.

    Then stress it against one real incident from the last two years. Work out when the clock would have started under this process, and compare that with when your organisation actually started talking about disclosure.

    What to produce

    • Who convenes the determination, and the trigger that obliges them to
    • Who sits on it, and who must not
    • The minimum information required to convene — deliberately low
    • The quantitative and qualitative factors considered, as a standing list
    • How the decision and its reasoning are recorded, and by whom
    • The parallel clocks that also start, with their triggers and owners
    • The real incident replayed: when the clock would have started, against when the conversation actually began
    Template · materiality-memo
  • checkOptional

    Who in your organisation could start that clock without knowing it

    Open the prompts
    1. Who in your organisation could start that clock without realising they had?
    2. In your replayed incident, what was the gap between the first fact sufficient to convene and the first conversation about disclosure?
    3. Which of the parallel clocks would you most likely miss, and what makes it the one?
    4. Is there anyone whose incentive is served by the determination staying open, and does your process insulate the decision from them?
2.3

Reg FD and the live room

3h

Selective disclosure, and the answer that is accurate, helpful and still a violation.

  • learnRequired

    Fair disclosure is a process question before it is a content one

    Read the brief~2 min

    Reg FD is the disclosure regime that punishes helpfulness. There is no bad faith required, no false statement, no concealment. An executive who answers a good analyst's sharp question with genuine specificity, in a room that is not everyone, has committed the violation — and the answer was true, useful and delivered in good faith.

    Fair disclosure is a process question

    The rule is about who heard it, not about whether it was accurate. That reframes preparation entirely: the work is deciding in advance what is inside the disclosed perimeter and what is outside it, so that the answer in the room is a retrieval rather than a judgement made under social pressure by someone who wants to be useful.

    • The dangerous question is friendly. Hostile questions put you on guard; the analyst who has been supportive for six quarters is the one you want to reward with something extra.
    • Directional guidance is still guidance. Trending well against that is material non-public information dressed as tone.
    • Confirming someone else's model is disclosure. Nodding at a number you did not publish makes it yours.
    • The safe answer is a boundary, not a dodge: name what you have disclosed, name what you will not discuss, and stop.

    Rehearse the refusal

    People fumble refusals because they have never said them out loud. The wording that works is short, unapologetic and repeatable, and the third time you use it in one call it should sound exactly like the first. Practise it until it is boring, because boring is what makes it survive a follow-up.

    Carry this into the drill

    The Earnings Hot Seat gives you eight named analysts with different temperaments and three answers each, with four metrics moving at once. The traps are placed where specificity is most rewarded.

    Go deeper — with your own AICopy-paste prompt

    The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.

    Yours to edit — changes stay in this box

  • playRequiredTicks itself

    The Earnings Hot Seat — Reg FD under live Q&A

    Reg FD under live Q&A: eight analysts, friendly through hostile, where some questions reward rich specificity and others punish exactly the same instinct. The clearest available demonstration that accuracy is not the test.

    Open the drill

    Ticks itself when the drill records a result

  • applyRequired

    Q&A prep sheet: five questions you cannot answer, and the wording you will use

    Open the brief

    Build the Q&A prep sheet for your next results discussion or equivalent external conversation. The core of it is five questions you cannot answer, with the exact words you will use — written out, not summarised as decline politely.

    For each, add the follow-up you expect and your second and third response. A boundary that holds once and softens on the third ask is not a boundary.

    What to produce

    • The disclosed perimeter: what is already public and can be repeated freely
    • Five questions you cannot answer, phrased as an analyst would ask them
    • For each, the exact refusal wording — one or two sentences
    • For each, the expected follow-up and your second and third response
    • The three questions where specificity is safe and valuable, and the detail you will volunteer
    • Who else is in the room, and what they have been told not to add
    • The single answer most likely to be quoted, and whether you are content with that
    Template · qa-prep

Week 3 of 6 · 10 hours · 3 modules

When the outside world arrives

Activists, holders and regulators do not wait for the strategy offsite. Three arrivals, each with its own clock and its own record.

3.1

The activist campaign

3.5h

What activists actually want, the fourteen-day rhythm, and which doors close behind you the moment you answer.

  • learnRequired

    Read the letter for what it is really asking

    Read the brief~2 min

    An activist letter is not an attack, it is a bid — for attention first, then for a seat, then sometimes for the company. Boards that read it as an insult respond to the tone and miss the structure. The letter is written to be forwarded, and its real audience is your top ten holders, not you.

    Read it for what it is actually asking

    Most campaigns contain a demand the board privately agrees with, a demand that is negotiable, a demand designed to be refused so the refusal can be quoted, and a demand about people. Sorting the four before you respond is most of the work, because the response has to concede the first without appearing to have been forced, and refuse the third without sounding defensive.

    • The uncomfortable part: activists are often directionally right about something. The strongest defence is having already done the thing you agree with, which is a reason to run this exercise before a letter arrives.
    • Speed matters more than polish. A slow response is read as disarray by exactly the holders you need.
    • Some moves close doors. Agreeing to a meeting, adding a director, launching a review — each changes what is available afterwards, and the sequence is not reversible.
    • Every public statement becomes campaign material for the other side. Write nothing you would not want in their next deck.

    The fourteen days

    Campaigns run on a rhythm: the letter, the holder calls, the proxy advisers, the media, the escalation. Parallel tracks, one move a day, and a board that tries to sequence them serially will find the vote has moved before it reaches track three.

    Carry this into the drill

    The Activist Letter runs fourteen days with four stakeholder tracks and one move a day. Notice which of your moves closed something behind you — the game is unusually honest about irreversibility.

    Go deeper — with your own AICopy-paste prompt

    The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.

    Yours to edit — changes stay in this box

  • playRequiredTicks itself

    The Activist Letter — a 14-day proxy timeline

    A fourteen-day proxy timeline with four demands and four parallel stakeholder tracks, where some moves close the door behind them. The clearest way to feel why sequencing beats content in a campaign.

    Open the drill

    Ticks itself when the drill records a result

  • applyRequired

    The four demands an activist would make of you, and your answer to each

    Open the brief

    Write the activist letter that would be sent about your own organisation. Four demands, in their voice, using only publicly available information — which is the constraint that makes this useful rather than comfortable.

    Then answer each demand honestly: agree, negotiable, refuse. Where you agree, note whether you could do it now and take the credit before anyone asks.

    What to produce

    • The four demands, drafted in an activist's voice from public information only
    • The public evidence each demand would cite
    • Your honest position on each: agree, negotiable, refuse
    • For each agreement — could you act now, and what is stopping you
    • For each refusal — the two-sentence public answer, and whether it survives being quoted
    • The demand about people, and who would be named
    • Your top five holders, and which of the four demands would move each of them
    Template · activist-self
3.2

The contest and the vote

3.5h

Institutional holders, the proxy advisers, and the arithmetic of a whip with five days left.

  • learnRequired

    Who can actually move, and who only looks movable

    Read the brief~2 min

    A contested vote is arithmetic before it is persuasion. Some holders will never move, some have already decided and will not say so, and a small band in the middle decides the outcome. Effort spent outside that band feels like campaigning and changes nothing.

    Who actually moves

    Index holders vote to policy and their stewardship teams are small, so the conversation is short and the policy is published — read it rather than pitching against it. Active managers can be moved by the thesis if they own enough to care. Retail is diffuse and expensive to reach. The proxy advisers do not vote at all and yet route a large block of the outcome, which makes their recommendation the highest-leverage single item on the board.

    • Get the register properly, early. A board arguing about strategy without knowing who holds what is guessing.
    • Adviser recommendations turn on a small number of published criteria. Meeting those criteria is cheaper than arguing with the recommendation afterwards.
    • Moves that look like work: broad mailings, general advertising, a longer letter. Moves that count: the eight calls to the eight holders who can actually change position.
    • Committing to something during the whip is binding in practice even when it is not in law. Holders remember.

    Carry this into the drill

    The Coalition Vote gives you five business days, eight named holders owning 41% of the float, and ten moves. The lesson is in the moves you decline.

    Go deeper — with your own AICopy-paste prompt

    The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.

    Yours to edit — changes stay in this box

  • playRequiredTicks itself

    The Coalition Vote — 5-day vote-whip simulation

    Five days to an annual meeting, eight institutional holders and the advisers who route the rest. A vote-whip where the scarce resource is moves, and most of the available ones do nothing.

    Open the drill

    Ticks itself when the drill records a result

  • applyRequired

    Holder map for your own register, movable and immovable separated

    Open the brief

    Build the holder map for your own register — or, if you are not listed, for whatever body actually decides your mandate: a parent board, a partnership, a sponsor group.

    Separate the movable from the immovable, and be honest about which of the immovable you have been spending time on because the conversation is pleasant.

    What to produce

    • The register or equivalent: who holds what, as a percentage
    • Each holder classified — with us, against us, genuinely undecided
    • For the undecided: what would move them, and who has the relationship
    • The published voting policy of your largest index holders, and where you currently fail it
    • The advisers' criteria that apply to you, and your position against each
    • Your eight highest-leverage calls, in order
    • The relationships you maintain that have no effect on any outcome
    Template · holder-map
3.3

Under enforcement

3h

Privilege, cooperation credit and the concession trap — why the damage is rarely done by the hostile questions.

  • learnRequired

    Everything you say is being written down twice

    Read the brief~2 min

    A voluntary interview is voluntary in the sense that you may decline and accept what follows. Counsel is present, the questions have been prepared for weeks, and the interviewer already has documents you have not re-read. The asymmetry is the point, and no amount of confidence closes it.

    The damage is not in the hostile questions

    Hostile questions put people on guard and are answered carefully. The damage comes from the friendly opener that establishes a timeline you have not verified, from the memory probe that invites you to fill a gap with a reconstruction, and from the restatement — where your answer is played back slightly stronger than you gave it and you agree because correcting it feels pedantic.

    • I do not recall is a complete answer, and it is the accurate one far more often than people use it.
    • Answer the question asked. Volunteering context opens doors you did not choose to open.
    • If a restatement is not quite what you said, say so at once. Correcting it later reads as a change of story.
    • Never guess at a document you have not been shown. Ask to see it, and read it before answering about it.

    Cooperation, privilege and the record

    Cooperation credit is real and worth having, but it is earned by the organisation's conduct — preservation, production, candour — not by an individual being expansive under questioning. And privilege is easier to waive than most executives realise: describing the substance of legal advice in an interview can put the whole file in play.

    Carry this into the drill

    The Regulator's Interview scores three things silently — cooperation, accuracy and discipline — and they trade against each other. Look at where being maximally helpful cost you accuracy.

    Go deeper — with your own AICopy-paste prompt

    The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.

    Yours to edit — changes stay in this box

  • playRequiredTicks itself

    The Regulator’s Interview — SEC enforcement deposition sim

    Ten questions across friendly openers, memory probes, restatements, impeachment and the concession trap, with three scores moving silently. The traps are placed exactly where an executive's instinct to be useful lives.

    Open the drill

    Ticks itself when the drill records a result

  • applyRequired

    Document-hold and interview-readiness checklist

    Open the brief

    Build the document-hold and interview-readiness checklist your organisation would run on the day it learns of an investigation. Assume the notice arrives on a Friday afternoon.

    The test of this artefact is elapsed time. From notice to hold in force, how many hours, and which systems are the slow ones?

    What to produce

    • Trigger: what constitutes notice, and who must be told within the hour
    • The hold itself: scope, custodians, systems, and who issues it
    • Auto-deletion and retention jobs that must be suspended, named system by system
    • Personal devices and messaging apps: the policy, and the honest assessment of whether it is followed
    • Privilege: who directs the work, how advice is marked, what must not be described outside it
    • Interview readiness: who is likely to be interviewed, and what preparation they are entitled to
    • Elapsed-time estimate from notice to hold in force, with the slowest system named
    Template · hold-checklist
  • checkRequired

    Where your instinct to be helpful becomes a liability

    Open the prompts
    1. Where did your instinct to be helpful cost you accuracy in the interview, and would you notice it happening in a real room?
    2. How many times did you answer more than the question asked?
    3. In your own organisation, what would still be deleting itself seventy-two hours after notice?
    4. Which of your colleagues would reconstruct a timeline rather than say they do not recall, and have they ever been told not to?
    5. What legal advice have you described in an ordinary meeting this year that you would not want treated as waived?

Week 4 of 6 · 10 hours · 3 modules

Capital, deals and a strategy you can defend

The decisions a board makes that are not risk decisions at all — and the risk each one carries anyway.

4.1

Diligence, and what you inherit at close

3.5h

The red flags that become 10-K items two years later, and diligence as a board decision rather than a workstream.

  • learnRequired

    At close you acquire their history too

    Read the brief~2 min

    Diligence is usually run as a workstream and decided as a board item, and the gap between those two facts is where deals go wrong. By the time the recommendation reaches the board, the scope of what was looked at has already been set by someone working to a deadline, and the board is asked to approve a conclusion without seeing the shape of the search that produced it.

    At close you acquire their history

    Not just their assets and their people — their unfiled incidents, their retention failures, their unremediated findings, their contracts with terms nobody has read since signature. Two years later one of those becomes a 10-K item or a claim, and the document that gets read in that moment is the board minute recording what you were told and what you asked.

    • Ask what was not looked at, and why. The answer is more informative than the findings.
    • Red flags cluster. A target with weak contract hygiene usually has weak incident records too, because both are symptoms of the same thing.
    • The LOI deadline is a negotiating instrument, and it is frequently pointed at you. A board that cannot tolerate letting one lapse cannot really decline a deal.
    • Reps and warranties transfer money, not risk. They do not unwind an integration or answer a regulator.

    The question that does the work

    What would have to be true for this to be a bad deal, and how would we find out? Asked early it directs the diligence; asked at the board it exposes whether the diligence was directed at all.

    Carry this into the drill

    The Acquisition Dossier gives you seven business days, ten possible review actions and seven hidden red flags. You cannot do everything — the mark is in what you chose to look at before you knew where the flags were.

    Go deeper — with your own AICopy-paste prompt

    The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.

    Yours to edit — changes stay in this box

  • playRequiredTicks itself

    The Acquisition Dossier — 7-day M&A diligence sim

    Seven days of diligence on a $1.4B target with more review actions available than time, and red flags that only surface if you looked. The board recommendation you write is the document the minutes record two years later.

    Open the drill

    Ticks itself when the drill records a result

  • playOptionalTicks itself

    How ready is your data privacy function?

    Optional: a structured pass over third-party reliance across eight domains. Useful here because concentration and exit are the two diligence questions boards ask least and regret most.

    Open the drill

    Ticks itself when the drill records a result

  • applyRequired

    Board memo: the five questions you require answered before an LOI

    Open the brief

    Write the board memo that fixes the five questions you require answered before any LOI is signed. Not a diligence checklist — five questions, chosen because a bad answer to any of them should stop the deal.

    Then test it against a transaction your organisation actually did. Would these five have caught what you now know?

    What to produce

    • The five questions, each phrased so a bad answer is unmistakable
    • For each: what evidence constitutes an answer, and what does not
    • For each: who must sign that the answer is complete
    • The standing instruction on scope — what diligence must cover whether or not anyone asks
    • What the board is told about what was NOT examined
    • The past transaction replayed against these five
    • What you would have found, and whether it would have changed the decision
    Template · loi-memo
4.2

The rival that reads you back

3h

Strategy as an adaptive game: refusing the price war, and compounding instead of matching.

  • learnRequired

    Your move is an input to theirs

    Read the brief~2 min

    Most strategy papers presented to boards assume a static opponent. The market shifts, but the named competitor is modelled as scenery. Real rivals respond, and they respond to your move specifically — which means the value of a move depends on what it invites.

    Your move is an input to theirs

    A price cut that wins share this quarter and triggers a matching cut is not a win, it is a permanent reduction in industry margin that you paid to initiate. The board question is not is this a good move but what does this make them do, and are we better off after they have done it.

    • Read temperament from history, not from statements. A rival that has matched every price move for six years will match this one.
    • Prefer moves that are hard to copy: structural cost, exclusive access, switching costs. They compound rather than reset.
    • Refusing to fight is a move. Ceding a segment deliberately is often the highest-return decision available and the hardest to get through a board.
    • Ask what would make us stop. A strategy with no abandonment condition will be defended past its evidence.

    Carry this into the drill

    Five Moves Ahead pits you against an adaptive rival with a temperament you have to read. Note the moves where you compounded and the moves where you simply matched.

    Go deeper — with your own AICopy-paste prompt

    The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.

    Yours to edit — changes stay in this box

  • playRequiredTicks itself

    Five Moves Ahead — a competitive-strategy war-game

    A competitive-strategy war-game against an adaptive rival. A borrowing — this is a strategy piece, not a risk piece — and it is here because two of this programme's weeks cover board decisions that are not risk decisions at all.

    Open the drill

    Ticks itself when the drill records a result

  • applyRequired

    Two-moves-ahead sheet for one live competitive decision

    Open the brief

    Take one live competitive decision and write the two-moves-ahead sheet: your move, their most likely response, your position after it, and what you would do next.

    Include the abandonment condition. If you cannot write what would make you stop, the board is being asked to approve something open-ended.

    What to produce

    • The decision, and the move being proposed
    • The named rival, and their response history over the last three comparable moves
    • Their most likely response, and the second most likely
    • Your position after each, against your position today
    • Your counter-move in each branch
    • What makes this move hard to copy, or the honest admission that it is not
    • The abandonment condition: the observable that would make you stop, and who is watching for it
    Template · moves-sheet
4.3

Transformation, and the gap it dies in

3.5h

Sequencing and momentum, and why the big bet keeps firing before its foundations are laid.

  • learnRequired

    The programme was never behind schedule; it was in the wrong order

    Read the brief~2 min

    Transformation programmes rarely fail at the vision and rarely fail at the technology. They fail in the gap between the two, and the specific mechanism is almost always sequencing: a headline initiative launched before the capability it depends on exists, because the headline initiative is the one the board asked about.

    The programme was not behind schedule; it was in the wrong order

    Momentum is a resource and it depletes. Early visible wins buy the patience that later structural work requires, which means the correct sequence is often the one that looks least ambitious in month three. Boards push against this without realising, by asking for the flagship first.

    • Every big bet has a foundation. Name it explicitly, and refuse to fire the bet before the foundation is in place.
    • A dependency that is not on anyone's plan is not managed by anyone. Cross-workstream dependencies are the ones that go unowned.
    • Change capacity is finite per business unit and it is not fungible with budget. Three programmes landing in the same function in the same quarter will all under-deliver.
    • The status that has been amber for four quarters is telling you the plan is wrong, not that the team is slow.
    Open the reading — Every Transformation Dies in the Gap

    Carry this into the drill

    Mind the Gap makes you sequence a change programme across the valley between vision and value. The reading on strategic alignment covers the same ground in prose; the game is where you find out whether you would actually hold the line on foundations.

    Go deeper — with your own AICopy-paste prompt

    The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.

    Yours to edit — changes stay in this box

  • playRequiredTicks itself

    Mind the Gap — a transformation-sequencing game

    A transformation-sequencing game where momentum is finite and big bets fired before their foundations fail. A borrowing from the strategy-execution catalogue, and the closest thing available to the oversight question a board actually faces on a programme.

    Open the drill

    Ticks itself when the drill records a result

  • playOptionalTicks itself

    S/4HANA Cutover Sim

    Optional: the final week before a major go-live, keeping controls intact under pressure. Worth doing if your organisation has a cutover ahead — it is the operational end of the sequencing argument this module makes.

    Open the drill

    Ticks itself when the drill records a result

  • applyRequired

    Sequencing critique with the dependency you are about to break named

    Open the brief

    Take one live programme and critique its sequence. Name the dependency that is about to be broken — there is almost always one, and it is usually known to somebody two levels below the person presenting.

    Write the re-sequence you would argue for, including what it costs in visible progress over the next two quarters. A re-sequence that costs nothing has not been thought through.

    What to produce

    • The programme, its stated sequence, and its current status
    • The dependency map as it actually is, not as the plan describes it
    • The dependency about to be broken, and who already knows
    • Change capacity in the receiving functions, quarter by quarter
    • Your re-sequence, with the reasoning for each move
    • What the re-sequence costs in visible progress, and how you would explain that to the board
    • The status item that has been amber longest, and what it is really telling you
    Template · sequencing-critique
  • checkOptional

    The programme you are protecting from scrutiny

    Open the prompts
    1. Which programme are you protecting from scrutiny, and what would have to be true for you to stop?
    2. Where did you fire a big bet before its foundation in the game, and what was the pull that made you do it?
    3. Who two levels below you already knows about the broken dependency, and why has that not reached the board?
    4. If you had to cancel one initiative this quarter to protect change capacity, which would it be, and what stops you?

Week 5 of 6 · 10 hours · 3 modules

The technology the board is now accountable for

Where boards are newly on the hook and least practised: approving AI, verifying it without becoming management, and buying the year's assurance.

5.1

AI at the committee

3.5h

Approve, reject, conditional — and the difference between conditions that bind and conditions that sound governance-flavoured.

  • learnRequired

    A condition nobody will check is an approval

    Read the brief~2 min

    AI proposals arrive at committees in a form designed to be approved: a business case, a named sponsor, a risk section written by the same team that wants the answer to be yes. The committee's contribution is not more enthusiasm or more caution — it is the conditions, and whether they bind.

    A condition nobody will check is an approval

    Conditional approval is the default outcome and the most abused one. Subject to appropriate human oversight is not a condition; it is a sentence. A condition binds when it names the thing that must be true, the evidence that will show it, the person who will produce that evidence, and the date. If any of the four is missing, the proposal has been approved and the committee has recorded a preference.

    • Reject is a real option and a committee that has never used it has no credible conditional approvals either.
    • The two scores move in opposite directions: block everything and the business routes around you; approve everything and the first failure is yours. Both easy ways out are traps.
    • Ask what happens when it is wrong, not whether it will be. Every model is wrong at some rate; the governance question is the path from wrong output to harm, and where that path can be cut.
    • A use case that cannot describe its failure mode has not been assessed by anyone, whatever the paperwork says.

    Where boards over-reach

    By asking about the model. Accuracy, architecture and training data are management's to test and mostly beyond a board's ability to verify. What a board can verify is whether an inventory exists, whether every deployed use case went through the gate, whether the conditions attached to past approvals were ever evidenced, and whether anyone has authority to turn one off.

    Open the reading — Your AI Agents Are Employees Now. Audit Them Like It.

    Carry this into the drill

    The Use-Case Gate puts eight proposals in front of you with two scores moving in opposite directions. Read your conditional approvals afterwards and check each one against the four-part test — most people find at least two that were really approvals.

    Go deeper — with your own AICopy-paste prompt

    The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.

    Yours to edit — changes stay in this box

  • playRequiredTicks itself

    The Use-Case Gate — an AI governance committee sim

    An AI governance committee with eight proposals, where the conditions that sound governance-flavoured and the conditions that bind are deliberately hard to tell apart under time pressure.

    Open the drill

    Ticks itself when the drill records a result

  • playOptionalTicks itself

    Confidently Wrong — naming the AI failure mode

    Optional: sorting AI failures into fabrication, staleness, faulty reasoning and should-have-declined. Four minutes, and it is what lets you ask a sponsor which failure mode their control actually addresses.

    Open the drill

    Ticks itself when the drill records a result

  • applyRequired

    Intake criteria your committee would actually apply on a Tuesday

    Open the brief

    Write the intake criteria your committee would actually apply on a Tuesday afternoon with four proposals and ninety minutes. Short enough to use, specific enough to fail something.

    Then run your last approved AI use case through them. If it passes without effort, the criteria are too loose; if it fails on a technicality, they are the wrong criteria.

    What to produce

    • The intake criteria, on one page
    • The four-part test every condition must satisfy: what, evidence, owner, date
    • What is out of scope for the committee entirely, and who handles it instead
    • The standing questions asked of every proposal, including the failure-mode question
    • The kill switch: who can suspend a deployed use case, and how fast
    • Your last approved use case run through the criteria, with the result
    • The conditions attached to past approvals, and whether any was ever evidenced
    Template · ai-intake
5.2

A board's own scan

3h

The eight domains of AI governance, and which of them a board can verify for itself without stepping into management.

  • learnRequired

    Verify the control, not the model

    Read the brief~2 min

    There is a version of AI oversight where the board asks for a briefing, receives one, and has learned only what management chose to present. There is another version where the board runs its own structured scan and arrives with a list of domains and a set of specific questions. The second takes an hour and changes the meeting.

    Verify the control, not the model

    The domains a board can genuinely check are governance ones: is there an inventory, is it complete, who owns each system, what went through the gate, what did not, what is monitored, what is the escalation path, and has anything ever been stopped. None of these requires technical assessment and all of them are answerable with evidence.

    • Completeness of the inventory is the single highest-value question. Shadow deployments are the norm, not the exception.
    • Ask for the list of use cases that did NOT go through the gate. The reaction to that question is itself the finding.
    • Third-party AI embedded in a vendor product is still yours to govern and is usually missing from the inventory.
    • A maturity score is a starting position, not an achievement. The useful output is the gap list with owners and dates.

    Carry this into the drill

    The self-assessment gives you a score, a radar and a gap list across eight domains. The score is the least useful part — take the gaps and put a name and a date against each before the next meeting.

    Go deeper — with your own AICopy-paste prompt

    The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.

    Yours to edit — changes stay in this box

  • playRequiredTicks itself

    How governed is your AI & automation?

    A structured scan across the eight domains a real AI risk assessment must reach, mapped to recognised frameworks. Run it yourself rather than commissioning it, because arriving with your own gap list changes what the briefing has to answer.

    Open the drill

    Ticks itself when the drill records a result

  • applyRequired

    Gap list with a named owner and a date against each line

    Open the brief

    Turn the scan output into a gap list with a named owner and a date against every line. Names, not functions — functions do not miss deadlines and people do.

    Add the three questions you will ask at the next meeting, and the evidence that would satisfy each. Deciding the evidence in advance is what stops a reassuring answer from closing the item.

    What to produce

    • The eight domains, with your position in each
    • The gap list, one line per gap
    • Named owner and date against each line
    • The three highest-consequence gaps, and why those three
    • The three questions for the next meeting
    • For each question, the evidence that would close it — decided now
    • The inventory completeness question, and how you will test the answer
    Template · ai-gaps
5.3

The audit committee and the year's assurance

3.5h

Coverage against depth, and what makes a plan defensible before the year delivers its surprises.

  • learnRequired

    You are approving a bet about where the year goes wrong

    Read the brief~2 min

    An annual audit plan is a bet about where the year will go wrong, placed before the year starts, with a fixed number of hours. Approving one is not an administrative act. It is the board deciding what it will and will not find out about, and the areas left uncovered are a choice even when nobody frames them as one.

    Coverage against depth

    The same hours buy broad shallow coverage or narrow deep coverage, and the two fail differently. Shallow coverage finds nothing but can say everything was looked at. Deep coverage finds real problems in three areas and is silent about eleven. Neither is right in general; what makes a plan defensible is that the trade was made deliberately and the reasoning was recorded before anyone knew where the problems were.

    • Ask what is not on the plan and why. An area absent for three consecutive years needs an explicit decision, not an omission.
    • Reserve capacity is a feature. A plan that is fully committed in January cannot respond to anything that happens in June.
    • Risk-ranked does not mean risk-led. Check whether the ranking drove the allocation or was written afterwards to justify it.
    • Half the quality of a plan is only visible in hindsight; the other half — whether it was defensible when made — is visible now, and that is the half the committee owns.
    Open the reading — Stop Writing Audit Plans. Start Running Value Streams.

    Carry this into the drill

    Plan the Year gives you 1,800 hours, fourteen auditable entities and eight surprises you cannot see coming. Half the mark is what you caught, half is whether the plan was defensible before you knew any of it — which is exactly the committee's half.

    Go deeper — with your own AICopy-paste prompt

    The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.

    Yours to edit — changes stay in this box

  • playRequiredTicks itself

    Plan the Year — an audit-plan allocation sim

    An audit-plan allocation sim, written for the director who builds the plan and used here by the committee member who has to approve it and later explain it. A borrowing, and a useful reversal of seat.

    Open the drill

    Ticks itself when the drill records a result

  • applyRequired

    Challenge memo on your own audit plan: three areas under-covered, and why

    Open the brief

    Write the challenge memo on your own organisation's audit plan: three areas you believe are under-covered, with the reasoning, and what you would give up to cover them.

    A challenge that adds scope without naming what it displaces is not a challenge, it is a wish. The hours are fixed.

    What to produce

    • The plan as approved: total hours, and the allocation by entity
    • The stated risk ranking, and whether it visibly drove the allocation
    • Three under-covered areas, with the reasoning for each
    • What you would displace to cover them, named specifically
    • Areas absent for three years or more, and the explicit decision you want recorded
    • Reserve capacity: how much, and who releases it
    • The one question you would put to the head of internal audit in private session
    Template · plan-challenge
  • checkRequired

    What half of that score was really measuring

    Open the prompts
    1. In the sim, how much of your score came from catching surprises and how much from having built a defensible plan? Which would you rather explain?
    2. What is your organisation deliberately choosing not to find out about this year?
    3. If a major issue surfaced in June in an area with zero planned coverage, what would the committee's answer be?
    4. Does your audit function have a private session with the committee, and has it ever produced anything the executive did not already know?

Week 6 of 6 · 10 hours · 3 modules

The crisis, and the close

Two crises where the board's own decisions are the material ones, then the agenda that carries everything you built into the next four meetings.

6.1

The board in the breach room

3h

Where boards hold the line and where they reach past it, round by round.

  • learnRequired

    The board's job in an incident is smaller and harder than it looks

    Read the brief~2 min

    In an incident the board's job is smaller than it feels and harder than it looks. Smaller, because containment, forensics and recovery belong to people who do this for a living. Harder, because the handful of decisions that are genuinely the board's arrive early, on bad information, and cannot be revisited.

    What is actually the board's

    Whether to disclose and when. Whether to pay. Whether to involve law enforcement. Whether the CEO speaks. Whether to invoke insurance, and when to tell the insurer. Whether the incident changes any commitment already made to a market or a regulator. Everything else on the incident bridge is management's, and a director on that bridge is consuming capacity, not adding it.

    • Convene early and separately. A board that first meets on day four is deciding with the executive's framing already set.
    • One voice externally, decided in the first hour. Two spokespeople is a second incident.
    • Do not ask for updates that cost more to produce than they are worth. Set a rhythm — twice daily, in a fixed shape — and hold to it.
    • The record you are creating is evidence. Decision logs written during the incident are worth more later than any reconstruction afterwards.

    Where boards hold the line

    Against the pull to announce before the facts support it, against the pull to promise remediation timelines nobody has costed, and against the pull to make the incident about a person while it is still running. All three feel like decisiveness in the room and read as panic in the transcript.

    Carry this into the drill

    The Breach Room runs a major breach from the board's side, round by round. Notice which decisions you reached for that were not yours — that instinct is the thing this module exists to correct.

    Go deeper — with your own AICopy-paste prompt

    The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.

    Yours to edit — changes stay in this box

  • playRequiredTicks itself

    The Breach Room — a C-suite tabletop

    A C-suite tabletop of a major breach, run as the board rather than as the responders. It is unusually good at showing where a board holds the line and where it reaches past it.

    Open the drill

    Ticks itself when the drill records a result

  • playOptionalTicks itself

    The War Room — an incident-command sim

    Optional: incident command from the responder's seat, moving a finite team across recovery, customers, the regulator clock and staff. Worth an hour precisely because it is not your job — it shows what your requests for information cost the people answering them.

    Open the drill

    Ticks itself when the drill records a result

  • applyRequired

    Board crisis protocol: who convenes, who speaks, what is decided where

    Open the brief

    Write your board's crisis protocol: who convenes, within what period, who attends, what is decided at board level and what is explicitly not, and how the record is kept.

    Include the contact reality. Named people, alternates, and channels that work when the corporate estate does not — which is the failure mode nobody plans for and everybody meets.

    What to produce

    • The trigger: what obliges a convening, and who can call it
    • Time to convene, and the quorum that counts at 3am
    • The decisions reserved to the board, listed
    • The decisions explicitly NOT the board's, listed — this half matters more
    • Reporting rhythm: how often, in what shape, from whom
    • External voice: who speaks, who approves the words, who does not speak
    • Out-of-band contact: named people, alternates, and a channel independent of corporate systems
    • How the decision log is kept, by whom, and where it lives
    Template · crisis-protocol
6.2

The ransom decision

3h

OFAC, insurance, backups — and a phase structure that locks each commitment before the fact that would have changed it arrives.

  • learnRequired

    Decide it before 2:14am, or it decides you

    Read the brief~2 min

    A ransom decision has a shape that punishes deliberation. Each phase demands a commitment, and the fact that would most have changed that commitment usually arrives in the phase after. Backups look viable until they are tested. Insurance looks like it covers this until the policy is read. The actor looks unsanctioned until the wallet is traced.

    Decide it before 2:14am

    The only reliable defence against a structure like that is a position written in advance, when nobody is frightened and nothing is burning. Not a policy that says we do not negotiate — that survives contact with reality for about an hour — but a written record of the conditions under which the board would consider payment, who must be consulted, and what must be verified before any transfer.

    • Sanctions exposure is the hard constraint. Payment to a sanctioned entity is a separate and worse problem than the breach, and attribution is often unclear when the decision is due.
    • Insurance requires notification within a period and frequently requires consent before payment. Reading the policy during the incident is too late.
    • Test backups, do not assume them. Recovery time from an untested backup is unknown, and unknown is not a plan.
    • Payment does not buy silence, deletion or certainty. It buys a decryption tool of variable quality from someone who has already lied to you.

    Carry this into the drill

    The Ransom Decision runs seven phases with seven commitments, each locking before the truth that matters most is visible. The mechanic is the lesson — which is why the Apply step asks you to write your position now rather than after.

    Go deeper — with your own AICopy-paste prompt

    The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.

    Yours to edit — changes stay in this box

  • playRequiredTicks itself

    The Ransom Decision — a 7-phase ransomware sim

    Seven phases and seven commitments, each locked in before the fact that would have changed it arrives. OFAC, insurance, backups, the payment itself — and a structure designed to show you why the decision has to exist before the night does.

    Open the drill

    Ticks itself when the drill records a result

  • applyRequired

    Pre-decision record: your position on payment, written before you need it

    Open the brief

    Write the pre-decision record: your organisation's position on ransom payment, agreed before it is needed. It should be short enough that someone can read it at 3am and act on it.

    Then have it approved. An unapproved position is a personal opinion, and the whole value of this artefact is that it carries authority the moment it is opened.

    What to produce

    • The stated position, in three sentences
    • The conditions under which payment would be considered at all
    • Who must be consulted before any payment decision, with alternates
    • The sanctions check: who performs it, on what evidence, and what happens if it is inconclusive
    • The insurance position: notification window, consent requirement, and who holds the policy
    • Backup verification: last tested, recovery time observed rather than estimated
    • Where this document lives so it is readable when the network is not
    • Who approved it, and when it is next reviewed
    Template · ransom-position
6.3

Capstone and close

4h

A board risk agenda for the next four meetings, and an honest account of what you would still struggle to govern.

  • playRequiredTicks itself

    Road to the Final — a knockout tournament

    A knockout across five domains — cyber, audit, AI governance, resilience and privacy — where every tie is a decision under pressure. It is here as the capstone drill because the defining feature of a board agenda is that the next item is not in the domain you prepared for.

    Open the drill

    Ticks itself when the drill records a result

  • applyRequired

    Capstone: a board risk agenda for the next four meetings

    Open the brief

    Build the board risk agenda for the next four meetings. Not a list of topics — a sequence of decisions, each with the paper that must precede it, the evidence that paper must contain, and the person who owes it.

    Everything from the previous five weeks feeds this: the decision-rights map, the appetite rewrite, the pack critique, the disclosure process, the LOI questions, the AI gap list, the audit-plan challenge, the crisis protocol and the ransom position. The work is reconciling them into one agenda that a real calendar could carry, including admitting where two of your own artefacts want the same meeting.

    Finish with one page a chair could read. If it needs the appendices to be understood, it is not finished.

    What to produce

    • The four meetings, with dates and the standing items already fixed
    • The decisions to be taken at each, in sequence, with the reason for that order
    • For each decision: the paper required, who owes it, and by when
    • For each paper: the evidence it must contain for the decision to be real
    • The artefacts from weeks 1–5 that feed each item
    • Where two items compete for the same meeting, and how you resolved it
    • What is deliberately NOT on the agenda, and the decision to leave it off
    • The information rights you are asserting: what must arrive, how many days before
    • One page for the chair: the shape of the year, the three decisions that matter, and what you are asking for
    Template · capstone
  • checkRequired

    Reflection and personal development plan

    Open the prompts
    1. Which of your six weeks' artefacts turned out to be load-bearing for the agenda, and which have you not opened since you wrote them?
    2. Where did two of your own artefacts contradict each other, and which one was wrong?
    3. In the knockout, which domain did you lose in, and is that the same domain you would be weakest on at a real board?
    4. What is the single change to your board's operation you would now argue for first, and who has the authority to make it?
    5. Six months from now, what evidence would show this programme changed how a decision was taken?

Finish it, and it is on the record

When every required step is done, a printable completion certificate appears on your profile — self-attested, honest about what it is, and yours to keep. Apply and Check steps are yours to mark; Play steps tick themselves when a drill records a result.

Open your profile