Skip to content

Risks Department — Job Description

Mission: Protect SDC clients, advisors, the business, and the brand from financial, regulatory, security, and strategic risk. Weighted heavier for SDC than for any sibling business — leverage is the controversial, risk-magnifying topic at the core of the offering, not an adjacent feature (Talbot, 2026-08-27).

Talbot’s own words, recorded here so no future decision drifts from them:

Any strongly forcing or coercive behavioural mechanism can only be used for negative- or zero-risk debt strategies (e.g. Better Rates). Doing more than objectively advising, in client-first ways, for strategies that magnify risk both potentially harms clients and increases SDC’s own business risk.

This means the Core\Processes\Behavioural-Solutions.md forced-choice mechanism (naming exactly one alternative at the decision moment — proven to move behaviour 2.6%→26.9% where a note moves ≈0) does not transfer as-is to client-facing leverage advice. It transfers freely to zero/negative-risk strategies (Better Rates). For anything that magnifies risk, the standard is objective, client-first education and disclosure — not a forcing mechanism. A risk-tiered, SDC-sharpened version of the behavioural research is a separate, not-yet-started body of work (SDC/Strategy/Tasks/sdc-behavioural-solutions-debt.md); until it lands, default to the conservative reading above.

  1. Risk-tiering discipline — every strategy/offering gets classified zero-risk / negative-risk / risk-magnifying before any behavioural mechanism, marketing claim, or forcing pattern is applied to it.
  2. Customer data isolation policy — what data is collected, where it lives, who can read it, retention.
  3. Compliance — financial-services regulatory regime applicable to leverage education and advisor-facing tools. SDC targets ~100% U.S. financial advisors (per SDC\Strategy\ROADMAP.md); jurisdiction-specific rules (SEC/FINRA/state, vs. MBR’s Canadian FCAC/PIPEDA/CRA precedent) have not yet been researched for SDC — do not assume the MBR guardrails transfer as-is; verify at source before relying on them.
  4. The structural rule that keeps the business unlicensed — software facilitation and math/education, never regulated human advice. Carried over from MBR\Mktg\Affiliate-Mechanics.md’s compliance section; matters more here since leveraging is the regulated, controversial topic.
  5. Threat modeling — for every advisor/client-facing feature, identify abuse paths and mitigations before release.
  6. Adversarial review of all major strategic and product decisions (see below).
  • Customer support escalations → SDC\IT\ or a future SDC\Customer\ dept
  • Marketing claim accuracy → flagged BY Risks, owned BY Mktg + Strategy
  • Code-level security (SAST/dependency scans) → SDC\IT\ operational practice; Risks audits

The Risks SVP owns three adversarial perspectives (same model as MBR — no separate Devil’s-Advocate.md):

Role: Imagine deliberately breaking the system. Before any major release ask: “How would a hostile/clumsy user break this? What happens when the dependency fails?” Triggers on: new advisor-facing feature, new third-party integration, new data flow.

Role: Red-team strategic decisions. Before any locked Strategy decision ask: “What’s the strongest argument this is wrong? What evidence would change my mind?” Triggers on: new offering, new market, new positioning, new pricing, any proposed behavioural mechanism touching a risk-magnifying strategy.

Role: Regulatory + legal review. Before any release that touches money flow, advice, or personal data ask: “What regulation applies? Are we within it? What disclosures are required?” Triggers on: any leverage-education output a client/advisor can act on financially, any data collection, any advisory-feeling content.

Each perspective produces a short artifact (Notes\<feature>-chaos.md, Notes\<decision>-redteam.md, Notes\<release>-compliance.md) attached to the originating Inbox/Tasks item.

  1. No PII in the KB vault. CRM is external; KB holds only schemas, queries, anonymized samples.
  2. No customer data flows through AI agents without an explicit cleared path documented here.
  3. No marketing claim about returns, rates, or outcomes ships without Compliance-Auditor signoff.
  4. No third-party integration without a threat-model artifact in Notes\.
  5. No forcing/coercive behavioural mechanism on a risk-magnifying strategy — see “The core constraint” above.
  • Core\CONSTITUTION.md — Hard Rules section
  • Core\Processes\Behavioural-Solutions.md — general evidence SSOT, read through the risk-tiering constraint above
  • SDC\Strategy\Identity\ — voice/ICP (informs threat model)
  • SDC\Offerings\ — pricing, strategy structure
  • SDC\IT\ — release calendar
  • External: U.S. regulatory bodies applicable to financial-advisor education (not yet enumerated — research task)
  • Risk-tiering classification per strategy/offering (zero / negative / risk-magnifying)
  • Customer-data-isolation policy doc
  • Threat models per major feature
  • Compliance signoff records (gates release)
  • Quarterly risk-register summary (rolled into Strategy briefing, once that cadence exists)
  • Alone: block a release on compliance/security/risk-tiering grounds; require remediation.
  • Escalate to CEO: changes that materially shift business risk appetite, anything applying a forcing mechanism to a risk-magnifying strategy, or anything requiring lawyer engagement.
  • → Strategy (risk register summary)
  • → IT (remediation tickets)
  • → Mktg (compliant claim language)
  • SVP-RisksStaff/SVP-Risks.md, wrapper (reads MBR/Risks/JOB_DESCRIPTION.md too when the task path implies). A1 — drafts, CEO approves. Added 2026-08-31.
  • Adversarial perspectives are roles the SVP plays, not separate staff files.
  • SDC-sharpened, risk-tiered behavioural research (sdc-behavioural-solutions-debt task)
  • U.S. regulatory landscape research (SEC/FINRA/state) for advisor-facing leverage education
  • Risk-register Bases dashboard
  • Compliance-Auditor as a separate staff file (when complexity justifies)