Boardroom Answers · Strategic Command · Risk Management & Governance
Let me count your single points of failure: one founder, one cloud region in Tokyo, two American AI vendors, one database provider. That is a concentration-risk profile my committee would flag in any supplier. Respond.?
The question a Chairman of the Board / Audit Committee Chair asks.
The short answer
Guilty on all counts, with treatments: correctness lives in 3,500 CI-enforced tests rather than my head, escrow covers my continuity, Postgres is exportable so the lock-in is an operator not a format, and we run two AI providers with live fallback where most vendors run one with none. Each residual has a dated closure item.
The full executive answer
It is a fair audit, so let me respond item by item with current state and roadmap explicitly separated. Key-person risk — the sharpest one, and I will not pretend otherwise: I am the founder of a very small company. The mitigations that exist are structural rather than cosmetic: the entire platform is gated by a continuous-integration pipeline — around 3,500 automated tests, type-checking, an AI-evaluation harness, production build on every change — which means the system’s correctness is encoded in executable checks rather than in my head; the architecture and its invariants are documented in the repository itself; and source-code escrow on enterprise terms puts the code beyond my personal continuity. Honest residual: a small team is a small team; the roadmap answer is hiring behind revenue, and your contract can carry continuity provisions with remedies meanwhile.
Geography and infrastructure: correct — the live database cell is Tokyo-only today; European and Indian residency cells are configuration-ready in the codebase but unprovisioned, and the product is built to refuse residency claims it cannot honour — the gating is in code, which tells you how seriously we take not overclaiming. Provisioning a second region is an operational step taken against customer demand, and the disaster-recovery drill that would evidence cross-region recovery is on the pre-general-availability roadmap. Cloud and database concentration: managed Postgres is deliberately boring — standard SQL, point-in-time recovery, exportable wholesale — so the concentration is in an operator, not in a proprietary format; that is the difference between a dependency and a lock-in.
AI-vendor concentration is where the design is strongest: two independent providers in production — primary and secondary — with automatic fallback, a model registry that makes rerouting a configuration change, and per-generation cost-and-usage telemetry that would expose any provider degradation within days. Two vendors is not zero concentration, but note the comparison class: most AI products your committee will review this year are single-model with no fallback and no telemetry. In ISO 31000 terms, we have treated the risks that are treatable at our scale, documented the ones that remain, and put the closure of each on a dated roadmap — which is, I would gently submit, exactly the posture your committee asks of management and rarely gets from vendors.
Grounded in: ISO 31000 (risk treatment) · COSO ERM · TPRM concentration-risk assessment
The natural next questions
Related governed answers
- Let me be blunt. If this board approves a major decision based on your AI’s analysis, the analysis turns out to be hallucinated, and the company takes a nine-figure loss — who is liable, what happens to my name, and why did your product not prevent it?
- I chair the audit committee. When the external auditor, a regulator, or a plaintiff asks how this board used AI in its decisions, what evidence can I actually produce — and will it stand up?
- If I build my operating rhythm around this and it goes down the morning of my board meeting, what happens? What is your actual uptime commitment?
Want this answered live, on your data?