Framework map
Every governance framework audit walks the same layers — from board and founder oversight down to the controls that sit on live products. Use this map to see what we examine before you request a review.
Layer 01
Oversight & mandate
Who sets risk appetite, who can approve product launches, and how board or advisor input reaches operating decisions. We look for written mandates — not only founder intent voiced in chat.
Layer 02
Decision rights
Named owners for policy changes, vendor onboarding, exception handling, and regulatory filings. Gaps here surface as delayed answers during diligence and licensing questionnaires.
Layer 03
Policy hierarchy
Which documents govern which teams, how versions are approved, and whether policies match the products you actually ship. Orphaned PDFs and conflicting drafts are listed early.
Layer 04
Control ownership
Each material control needs an owner, a frequency, and a place evidence lands. We sample whether ownership is real in practice — not only assigned in a matrix.
Layer 05
Escalation & review cycles
How incidents, exceptions, and framework drift reach founders or the board. We test whether review calendars exist and whether past minutes show decisions, not only attendance.