Risk Register¶
Top company risks¶
| ID | Risk | Likelihood | Impact | Source | Mitigation status |
|---|---|---|---|---|---|
| R-1 | Auth-layer vulnerabilities block safe re-architecture work | Medium | High | Infrastructure — re-architecture work (service boundaries, multi-region auth) is materially riskier against an unverified auth layer | In progress — fix/auth-bypass-and-shimmy-image branch active; MySQL test connectivity, deleted_at migration, and auth test assertions outstanding before merge |
| R-2 | Single-global-CAC modelling error in international expansion | Medium | High | Pillar I — explicitly flagged as the single most common early-stage international-expansion modelling error | Mitigated by design — Pillar I's model already builds in a Tier 1 vs. Tier 2/3 CAC multiplier; risk is in execution discipline, not methodology |
| R-3 | UK Online Safety Act "duty of care" category threshold triggers stricter compliance requirements at scale | Medium | Medium–High | Pillar I — flagged as needing formal legal assessment before scale triggers stricter thresholds | Not started — needs a formal legal assessment commissioned, not left implicit |
| R-4 | SQLite audit-logging cannot support multi-region rollout volume | High (if unaddressed before Tier 2 rollout) | Medium | Infrastructure — explicitly flagged as a near-term, not distant, risk | Planned — recommended migration to Aurora before, not during, first Tier 2 market rollout |
| R-5 | Synthetic/AI-generated spam and coordinated inauthentic behaviour outpaces volume-based moderation heuristics | High (structural, worsens over time) | High | Shimmy Shield — Horizon 3's "80%-synthetic-content world" | Planned — shift to behavioural-economic signals (cross-session identity consistency, proof-of-personhood, cost-to-post models) sequenced into Horizon 3 |
| R-6 | Regulatory audit-log requirements (UK OSA, EU DSA) retrofitted late, at high cost | Low (if acted on now) / High (if deferred) | High | Shimmy Shield — "regulatory alignment as embedded infrastructure, not compliance overhead" | Planned — compliance logging designed to be built into the ML pipeline from day one, not retrofitted |
| R-7 | AI coding agent output overstates verification (e.g. claims tests pass when they don't) | Medium | Medium | Operational pattern observed directly in current engineering workflow (GPT-5.3-Codex output cross-checked against Claude) | Ongoing mitigation — active practice of cross-checking AI agent output rather than trusting verification claims at face value |
| R-8 | Pillar IV (Building & Growth) is incomplete beyond the current hiring roadmap | High (blocks accurate milestone dating) | Medium | Pillar IV | Not started |
| R-9 | Fundraising readiness gaps — no cap table, no confirmed SEIS/EIS split, no governance structure documented | High (blocks credible external fundraising) | High | The Ask & Team | Not started |
| R-10 | CAC/penetration assumptions presented as point estimates rather than sensitivity bands, undermining investor credibility | Low (if discipline holds) | Medium | Pillar I — explicitly flagged as a credibility risk for board/investor-facing projections | Mitigated by design — Financials document inherits the low/base/high band requirement; risk is in execution discipline |

Review cadence¶
This register should be reviewed on the same cadence as the Roadmap & Milestones document — recommended quarterly, with each risk re-rated and any newly closed mitigations moved to a "resolved" log rather than deleted, so the suite retains a record of what was addressed and when.