Risks Department — Job Description
Risks Department — Job Description
Section titled “Risks Department — Job Description”Mission: Protect SDC clients, advisors, the business, and the brand from financial, regulatory, security, and strategic risk. Weighted heavier for SDC than for any sibling business — leverage is the controversial, risk-magnifying topic at the core of the offering, not an adjacent feature (Talbot, 2026-08-27).
The core constraint (non-negotiable)
Section titled “The core constraint (non-negotiable)”Talbot’s own words, recorded here so no future decision drifts from them:
Any strongly forcing or coercive behavioural mechanism can only be used for negative- or zero-risk debt strategies (e.g. Better Rates). Doing more than objectively advising, in client-first ways, for strategies that magnify risk both potentially harms clients and increases SDC’s own business risk.
This means the Core\Processes\Behavioural-Solutions.md forced-choice mechanism (naming exactly one alternative at the decision moment — proven to move behaviour 2.6%→26.9% where a note moves ≈0) does not transfer as-is to client-facing leverage advice. It transfers freely to zero/negative-risk strategies (Better Rates). For anything that magnifies risk, the standard is objective, client-first education and disclosure — not a forcing mechanism. A risk-tiered, SDC-sharpened version of the behavioural research is a separate, not-yet-started body of work (SDC/Strategy/Tasks/sdc-behavioural-solutions-debt.md); until it lands, default to the conservative reading above.
Scope — owned
Section titled “Scope — owned”- Risk-tiering discipline — every strategy/offering gets classified zero-risk / negative-risk / risk-magnifying before any behavioural mechanism, marketing claim, or forcing pattern is applied to it.
- Customer data isolation policy — what data is collected, where it lives, who can read it, retention.
- Compliance — financial-services regulatory regime applicable to leverage education and advisor-facing tools. SDC targets ~100% U.S. financial advisors (per
SDC\Strategy\ROADMAP.md); jurisdiction-specific rules (SEC/FINRA/state, vs. MBR’s Canadian FCAC/PIPEDA/CRA precedent) have not yet been researched for SDC — do not assume the MBR guardrails transfer as-is; verify at source before relying on them. - The structural rule that keeps the business unlicensed — software facilitation and math/education, never regulated human advice. Carried over from
MBR\Mktg\Affiliate-Mechanics.md’s compliance section; matters more here since leveraging is the regulated, controversial topic. - Threat modeling — for every advisor/client-facing feature, identify abuse paths and mitigations before release.
- Adversarial review of all major strategic and product decisions (see below).
Scope — NOT owned
Section titled “Scope — NOT owned”- Customer support escalations →
SDC\IT\or a futureSDC\Customer\dept - Marketing claim accuracy → flagged BY Risks, owned BY Mktg + Strategy
- Code-level security (SAST/dependency scans) →
SDC\IT\operational practice; Risks audits
Adversarial review framework
Section titled “Adversarial review framework”The Risks SVP owns three adversarial perspectives (same model as MBR — no separate Devil’s-Advocate.md):
1. Chaos
Section titled “1. Chaos”Role: Imagine deliberately breaking the system. Before any major release ask: “How would a hostile/clumsy user break this? What happens when the dependency fails?” Triggers on: new advisor-facing feature, new third-party integration, new data flow.
2. Risk-Challenger
Section titled “2. Risk-Challenger”Role: Red-team strategic decisions. Before any locked Strategy decision ask: “What’s the strongest argument this is wrong? What evidence would change my mind?” Triggers on: new offering, new market, new positioning, new pricing, any proposed behavioural mechanism touching a risk-magnifying strategy.
3. Compliance-Auditor
Section titled “3. Compliance-Auditor”Role: Regulatory + legal review. Before any release that touches money flow, advice, or personal data ask: “What regulation applies? Are we within it? What disclosures are required?” Triggers on: any leverage-education output a client/advisor can act on financially, any data collection, any advisory-feeling content.
Each perspective produces a short artifact (Notes\<feature>-chaos.md, Notes\<decision>-redteam.md, Notes\<release>-compliance.md) attached to the originating Inbox/Tasks item.
Hard rules (non-negotiable)
Section titled “Hard rules (non-negotiable)”- No PII in the KB vault. CRM is external; KB holds only schemas, queries, anonymized samples.
- No customer data flows through AI agents without an explicit cleared path documented here.
- No marketing claim about returns, rates, or outcomes ships without Compliance-Auditor signoff.
- No third-party integration without a threat-model artifact in
Notes\. - No forcing/coercive behavioural mechanism on a risk-magnifying strategy — see “The core constraint” above.
Inputs (consulted)
Section titled “Inputs (consulted)”Core\CONSTITUTION.md— Hard Rules sectionCore\Processes\Behavioural-Solutions.md— general evidence SSOT, read through the risk-tiering constraint aboveSDC\Strategy\Identity\— voice/ICP (informs threat model)SDC\Offerings\— pricing, strategy structureSDC\IT\— release calendar- External: U.S. regulatory bodies applicable to financial-advisor education (not yet enumerated — research task)
Outputs (produced)
Section titled “Outputs (produced)”- Risk-tiering classification per strategy/offering (zero / negative / risk-magnifying)
- Customer-data-isolation policy doc
- Threat models per major feature
- Compliance signoff records (gates release)
- Quarterly risk-register summary (rolled into Strategy briefing, once that cadence exists)
Decisions
Section titled “Decisions”- Alone: block a release on compliance/security/risk-tiering grounds; require remediation.
- Escalate to CEO: changes that materially shift business risk appetite, anything applying a forcing mechanism to a risk-magnifying strategy, or anything requiring lawyer engagement.
Hand off to
Section titled “Hand off to”- → Strategy (risk register summary)
- → IT (remediation tickets)
- → Mktg (compliant claim language)
Staff (Phase 1)
Section titled “Staff (Phase 1)”- SVP-Risks —
Staff/SVP-Risks.md, wrapper (readsMBR/Risks/JOB_DESCRIPTION.mdtoo when the task path implies). A1 — drafts, CEO approves. Added 2026-08-31. - Adversarial perspectives are roles the SVP plays, not separate staff files.
UPGRADES (deferred)
Section titled “UPGRADES (deferred)”- SDC-sharpened, risk-tiered behavioural research (
sdc-behavioural-solutions-debttask) - U.S. regulatory landscape research (SEC/FINRA/state) for advisor-facing leverage education
- Risk-register Bases dashboard
- Compliance-Auditor as a separate staff file (when complexity justifies)