Governance and accountability
The accountable executive accepts material residual risk. Control owners maintain evidence. Operations owns service and inventory risk, Finance owns payment and settlement risk, Privacy owns personal-data risk, Security owns cyber-risk coordination, and Engineering owns technical remediation. Conflicts and overdue high risks must be escalated rather than silently accepted.
Risk lifecycle
Monitoring signals
| Domain | Examples | Escalation trigger |
|---|---|---|
| Inventory | Oversell guards, expired holds, unavailable units, rate/version conflicts | Any integrity breach or repeated guard rejection |
| Payments | Rejected signatures, unmatched events, late success, reconciliation variance, refunds | Any suspected false confirmation or unresolved financial mismatch |
| Privacy | Verified rights requests, due dates, unusual access, breach indicators | Overdue request or likely risk to a person |
| Availability | Health checks, cron, email outbox, backup and restore evidence | Failed critical workflow or missing tested recovery path |
| Content and partners | Demo/payment gate, property verification, image rights, AI sources and moderation | Unverified offer, misleading claim or rights concern |
Assessment and treatment
Risks are recorded with cause, event, consequence, likelihood, impact, owner, existing controls, treatment, deadline and residual rating. Treatment choices are avoid, reduce, transfer or formally accept. Acceptance of high or critical residual risk requires executive approval and a review date.
Review cadence
Live signals are evaluated by scheduled jobs and authenticated dashboards when cron and notifications are commissioned. Operational owners review open exceptions routinely; the register is re-assessed after incidents, material changes, new providers, legal changes and at the governance cadence adopted by the operating company.