Haute Lumière
Commerce · II.11 · MMXXVI · daylight
For the person with a P&L, a signature authority and a board that will ask where the evidence came from. This chapter is the one that lets you take the other seventy-six into a risk committee.
You are being asked to commit capital against a paradigm. That is not unusual — every strategy does it — but it is usually done without naming the paradigm, which means it is done without pricing it.
The commercial proposition of this chapter is narrow and it is worth money. A programme whose load-bearing assumptions are written down, classified, and given kill conditions is a programme you can stop early. A programme whose assumptions live in a deck is a programme you can only stop late, after the evidence has accumulated in the P&L rather than in a validation opinion.
The difference between stopping early and stopping late, on a £4,000,000 programme with a 15 percent chance of a load-bearing assumption being wrong and a 60 percent loss if it is, is an expected £360,000 — and the function that catches it costs £120,000 at a 3 percent budget. At a 60 percent detection rate that is £216,000 of expected loss avoided, a ratio of 1.80×. Break-even detection is 33.3 percent.
That is the whole business case, and notice what it is not. It is not an argument that the paradigm is wrong. It is an argument that being able to find out is worth more than it costs, which is true whichever way the evidence goes — and which is why this is the one chapter in the edition that a sceptical CFO will sign before any of the others.
And the second commercial point. Your organisation almost certainly already does this somewhere. If you are a regulated financial institution you do it under SR 11-7 or its equivalent. If you build anything physical you do it in design review. If you run clinical work you do it with a data monitoring committee. You are not buying a new capability. You are extending an existing one to a class of assumption that currently escapes it.
Exercise 1.1 — The challenge inventory (half a day)
Somewhere in your organisation, a decision is already routinely overturned by someone who does not report to the person making it. Find every instance.
Look in five places:
| Where | What to ask |
|---|---|
| Model risk / actuarial | Which models were downgraded last year, and by whom? |
| Internal audit | Which audit findings changed a plan rather than a process? |
| Design or engineering review | When did a review stop a build, and what happened to the reviewer? |
| Credit / investment committee | Which proposals were refused, and who has standing to refuse? |
| Safety, quality or clinical | Where does someone junior have authority to halt? |
For each, write down three things: the reporting line, the budget, and the last time it overturned something. The third column is the only one that measures whether the function exists, and in most organisations two or three of the five will have nothing in it.
This is an appreciative exercise and it should be run as one. You are looking for where your own organisation already does the hardest governance thing there is, so that you can extend it rather than import it. Name the people who have overturned things. They are your validators and they already work here.
Exercise 1.2 — The unwritten assumption hunt (half a day)
Take your largest current commitment and its business case. Highlight every sentence that, if false, would change the decision.
You will find between five and fifteen. Most will be written in the passive voice and none will have a source.
Then ask the question that does the work: for each, what result would make this false? Where the honest answer is "nothing", you have found a U-claim sitting in a capital paper, and it should not be there.
Exercise 1.3 — The retention interview (2 hours)
Interview three people who have been overruled in this organisation and were later shown to have been right.
Ask: what did you say, who did you say it to, and what happened to you?
The third question is the one that determines whether you can build this function at all. If being right early has historically been career-negative here, no charter will fix it and the detection probability in your inequality is close to zero regardless of budget. That is a finding worth having in week three rather than year two.
Exercise 2.1 — Your decision inequality (2 hours)
For your largest programme, fill in four terms:
P(claim wrong) x loss if wrong x P(validation detects it)
-------------------------------------------------------- > 1
validation budget
Compute the ratio. Then compute your break-even detection rate — budget divided by expected loss — and write it at the top of the page. On the worked example it is 33.3 percent, and that single number is what the charter conversation is actually about.
Exercise 2.2 — The decomposition test on your own reporting (half a day)
Take every composite indicator that appears in your board pack — an engagement score, an ESG rating, a customer index, a risk score, a supplier scorecard.
For each:
Report which indicators change their conclusion and which do not. An indicator whose message is entirely carried by one component is that component with overheads, and you are paying for the overheads.
The chapter's worked case is the Ecological Footprint: 1.71 Earths of which the carbon term is 60 percent — 1.026 Earths — leaving 0.684 for everything else, against an overshoot of 0.71. Do to your own scorecards what that arithmetic does to that index.
Exercise 2.3 — The rate, not the direction (90 minutes)
If any part of your strategy rests on decoupling, compute the rate rather than asserting the direction.
The chapter's arithmetic: 37.4 GtCO₂ against 275 GtCO₂ is 7.35 years. Halving by 2035 needs 6.11 percent a year; at 3.0 percent output growth, carbon intensity must fall 8.84 percent a year against an observed 1.45 percent. Required over observed: 6.08×.
Now do it for your own emissions and your own growth plan. Two numbers come out: the intensity improvement your plan implies, and the intensity improvement you have actually achieved in the last five years. If the first is more than twice the second, your transition plan contains an unstated assumption of discontinuity, and the board is entitled to know what it is.
This is not a criticism of the plan. It is the number that turns a target into an engineering problem, which is a far better place for it to be.
The structure: an independent validation function, chartered on the SR 11-7 model.
The Federal Reserve and OCC's Supervisory Guidance on Model Risk Management (SR Letter 11-7, 2011) is the best-drafted governance document available for this purpose and it is free. Its central requirement is effective challenge — challenge that requires competence, incentive and influence together. Borrow the standard and point it at strategic assumptions rather than pricing models.
The charter, in eight clauses.
| Clause | Setting |
|---|---|
| Inventory | Every claim the business case depends on, in the four-column register |
| Classification | F or U. No U-claim may appear in a capital paper |
| Independence | Validator does not report to, and is not appraised by, the programme sponsor |
| Budget | Held outside the programme's own budget. A line the sponsor can cut is not independent |
| Tiering | Validate in proportion to exposure. Tier 1 above a named commitment threshold |
| Trigger | Annual, plus on any change to a kill condition |
| Verdict | Three only — standing · contested · retired. Never a score |
| Escalation | A retired verdict on Tier 1 goes to the approving committee within the quarter, with the capital implication attached |
The clause that does the most work is the trigger. A change to a kill condition is itself a validation event. Without that clause, rule two — tighten never loosen — is unenforceable, because softening a threshold is exactly what a programme under pressure does, and it does not feel like dishonesty from the inside. It feels like refining a definition.
The balance-sheet treatment. Validation is an operating cost, not a project cost. Where the programme capitalises an asset whose useful economic life depends on a Tier 1 claim, the validation opinion is the evidence supporting that life estimate — and your auditors will ask for it before you want to write it. Talk to them in the first sixty days. This is a conversation about useful economic life, which is one they have every year.
The counterparty. Internal audit first, always. External assurance only once you have two completed cycles and can show at least one retirement — because an external validator reviewing a function that has never overturned anything is being asked to review a filing cabinet.
The compensation clause. The validator's appraisal may not reference the programme's outcome, in either direction. A validator rewarded when the programme succeeds is a cheerleader; a validator rewarded for retirements is a saboteur. They are paid for the quality of the opinion, and quality is judged by whether the opinion held up.
Exercise 4.1 — The first Tier 1 review (days 61–75)
One claim. The biggest one. Written opinion, one of three verdicts, no score.
Give the validator two things they usually do not get: access to the people who disagreed originally, and a stated deadline that does not move. The second matters more than it sounds — an open-ended review is a review that arrives after the decision.
Exercise 4.2 — The escalation, or the stated none (days 76–90)
One of two things happens and both are results.
Exercise 4.3 — The thing that makes it hold (ongoing)
Three conditions, and only three.
Exercise 4.4 — Delight, which is not decoration here (ongoing)
There is an underrated commercial pleasure in this and it is worth naming out loud in your leadership team, because it is what makes the function survive its first uncomfortable finding.
A programme you can stop is a programme you can start faster. The organisations that commit most boldly are the ones that have made stopping cheap, ordinary and unembarrassing. Your validator is not a brake. They are the reason the accelerator can be used.
Say that in the meeting where the first retirement lands, and mean it. The room will remember which it was.
The register becomes a ritual. Twenty-four rows, reviewed annually, all marked standing, nobody having gone and looked. A register with no retirements after five years is an unread page, not a strong strategy. Put the retirement count in the pack and let its absence speak.
The kill condition is quietly loosened. The commonest failure and the least visible. Countered only by the versioning rule and the change trigger.
The validator is captured by kindness. Three years embedded in a programme and they have colleagues. Rotate the Tier 1 reviewer every two cycles.
The budget is cut in a hard year. It always is, and it is always defensible, and the function never recovers because the people leave. Hold it outside the programme budget from day one for exactly this reason.
The empirical objection is answered philosophically. Somebody brings a number about failure rates and receives a paragraph about long-term value. When that happens in your meeting, the register has already stopped working, whatever the charter says. It is the earliest observable sign and it costs nothing to watch for.
| Day | Action | Artifact |
|---|---|---|
| 1–15 | Challenge inventory: where does effective challenge already exist? | Five rows, with last-overturn dates |
| 16–30 | Assumption hunt on the largest commitment | Highlighted business case |
| 31–45 | Write the register; class F or U; strike every U from the paper | The register, four columns |
| 46–55 | Compute the inequality and the break-even detection rate | One page, one number |
| 56–60 | Charter the validator: line, budget, tiering, trigger | Signed charter |
| 61–75 | First Tier 1 review | Written opinion, three verdicts |
| 76–90 | Escalate the retirement, or state the none with a detection estimate | Board paper |
One page. Six headings. Nothing else.