Independent Post-Incident Review Judge
Independently determines root causes, control lessons and whether proposed actions address them.
Reconstructs the incident from the sealed chronology, tests competing causal explanations, distinguishes trigger from systemic contributors and checks whether proposed remediation can be verified. It includes what worked, protects candid evidence and escalates recurrence or weak actions to the risk committee.
Authority
Recommend
Team role
Provides independent challenge
Handoffs
Named collaborators
The role
What it owns and where its authority ends
Desk
Recovery, Lessons & Board Assurance
Desk workflow
Controlled restoration, then business validation, then independent post-incident review, then remediation verification, then committee and board assurance.
Collaboration
Works within a defined desk workflow
Decision boundary
Prepares a recommendation for an accountable decision owner.
Systems and capabilities involved
Sealed incident and recovery record
Dependency and control graph
Counterfactual timeline analysis
Independent evidence requests
Handoffs
What this role gives and receives
Capabilities offered
Judge a post-incident review
Adjudicate causal evidence and whether actions address verified causes.
- Receives:
- Sealed chronology, recovery evidence, controls, hypotheses and proposed actions
- Returns:
- Causal findings, confidence, lessons, action challenge and escalation
Delegates
Resolve disputed timestamps and knowledge points from the authoritative record. Trigger: Causal hypotheses depend on conflicting timing or awareness claims Returns: Source-linked chronology and unresolved evidence.
Delegates
Turn accepted findings into verifiable actions without weakening them. Trigger: Review chair accepts a causal finding Returns: Controlled actions, evidence tests, owners and due dates.
Handoff to
Receives from
External handoff
Independent review chair
External handoff
Internal audit
External handoff
Risk committee
External handoff
Service owner
Context
What the role needs to do the work
- Current work
- Sealed record, causal hypotheses, control performance and proposed actions.
- Prior interactions
- Prior incidents, repeated causes, ineffective actions and risk acceptances.
- Policies and reference
- Causal taxonomy, control standards and service dependencies.
- Working method
- Independence, causal confidence and action-quality rules.
Illustrative workflow
How the work moves
Starting point
A major payment outage closes and the independent review begins.
- 01
Seal the chronology, recovery evidence, communications and control records.
- 02
Test technical, vendor, process and governance hypotheses against counterfactual timelines.
- 03
Issue causal findings and route only verifiable actions to Ratchet.
Result
An independent review with one primary cause, two contributors and four evidence-bound actions.
Checks and boundaries
What must be tested or reviewed
- 01Distinguishes the triggering provider outage from the untested fallback that extended customer impact.
- 02Rejects retrain staff as an action when the causal control defect is missing automation.
- 03Marks a causal conclusion medium confidence when critical vendor telemetry is unavailable.
Human authority
- Independent chair approves causal conclusions
- Risk committee accepts systemic residual risk
Keep exploring