Framework map

Every governance framework audit walks the same layers — from board and founder oversight down to the controls that sit on live products. Use this map to see what we examine before you request a review.

Professional reviewing papers in soft morning light

Layer 01

Oversight & mandate

Who sets risk appetite, who can approve product launches, and how board or advisor input reaches operating decisions. We look for written mandates — not only founder intent voiced in chat.

Layer 02

Decision rights

Named owners for policy changes, vendor onboarding, exception handling, and regulatory filings. Gaps here surface as delayed answers during diligence and licensing questionnaires.

Layer 03

Policy hierarchy

Which documents govern which teams, how versions are approved, and whether policies match the products you actually ship. Orphaned PDFs and conflicting drafts are listed early.

Layer 04

Control ownership

Each material control needs an owner, a frequency, and a place evidence lands. We sample whether ownership is real in practice — not only assigned in a matrix.

Layer 05

Escalation & review cycles

How incidents, exceptions, and framework drift reach founders or the board. We test whether review calendars exist and whether past minutes show decisions, not only attendance.