QHDM Company / Governance

Trust is an
operating discipline.

Controls activate before the commercial, data, capital or regulatory event that requires them. This page is a public blueprint, not a claim that every target control has completed independent assurance.

Implementation disclosure

Control completion must be evidenced in an internal register before external diligence. Exact legal, tax and regulatory obligations require qualified current advice for the specific activity.

01Baseline

Corporate & board

  • Statutory registers and filing calendar
  • Board approvals and delegated authority
  • Contract, IP and related-party registers
02Before revenue

Finance & commercial

  • Company banking and maker-checker controls
  • Bookkeeping, invoicing and applicable tax
  • Customer, vendor, NDA and procurement templates
03Before data pilots

Privacy & security

  • Data inventory and lawful-purpose mapping
  • Access, secrets, incident and retention controls
  • Vendor and model-provider diligence
04Before fundraising

Capital readiness

  • Clean cap table and beneficial ownership
  • Board/shareholder approval workflows
  • Professional valuation, FEMA/FDI and instrument review when triggered

Decision architecture

Four lines of accountability.

Build

Product or venture owner

Owns scope, delivery and operational evidence.

Validate

Evidence owner

Owns user proof, benchmarks and stage records.

Control

Trust owner

Reviews finance, privacy, security and contractual exposure.

Approve

Board / authorised officer

Approves reserved matters, capital and material obligations.

Access boundary

Public edge. Controlled collaboration. Restricted core.

Public

Approved corporate information, public dossiers, intentional product destinations and enquiry intake.

Controlled

Identity-verified, purpose-limited partner workspaces with written rights and expiry.

Restricted

Private source, strategy, credentials, partner data, invention records and privileged operations.

Open Trust Centre ↗