Nothing hidden
Transparent risk posture —nothing concealed.
Every significant risk is named, mitigated, and owner-assigned. Reviewers should expect this level of candour.
High severity
Grant eligibility is not yet proven
Confirm applicant legal status, jurisdiction, tax registration, beneficial ownership, authorized signatory, match funding, and program-specific cost eligibility before submission.
Owner · Finance & Compliance lead
High severity
Carbon-credit integrity claims could be overstated
Use conservative claims language, require project evidence, track retirement proof, and separate verified climate outcomes from platform activity metrics.
Owner · Head of integrity
High severity
Live trading may trigger legal, financial, AML, or market-conduct obligations
Keep the MVP as a discovery/reporting pilot until legal review confirms the path for exchange, broker, payment, and custody functions.
Owner · General counsel
Medium severity
The source plan had aggressive revenue and market-share assumptions
Use bottom-up pilot metrics, conservative scenarios, and validation evidence instead of promising market dominance or guaranteed investor returns.
Owner · Product & strategy lead
Medium severity
Registry and verification-data access may be incomplete
Start with documented public profiles and manual review, then add APIs only after data-rights and partner agreements are signed.
Owner · Head of partnerships
Medium severity
Sensitive buyer or project data could be mishandled during scale-up
Add role-based access, encryption, audit logging, privacy assessments, vendor reviews, retention policies, and incident response before production data intake.
Owner · CTO / security lead
Medium severity
Heavy reliance on third-party verification limits MVP throughput
Pre-onboard verification partners, document handoffs, and design queue-friendly evidence workflows.
Owner · Head of integrity
Low severity
Buyer claims language is misused after a purchase
Embed approved claims templates in reports, restrict free-text claims, and flag misuse via audit logs.
Owner · Head of integrity