Risks: what would make this fail
A plan that can’t name its own failure modes isn’t ready to be shown to anyone. These are ours, in roughly the order they could kill the venture, with what we’re doing about each and — where the honest answer is “we don’t know yet” — the specific test that will tell us.
1. Go-to-market is unproven
The risk: Everything in this plan downstream of “win a client” is modelled; winning the client is not. Nobody on the founding team has yet sold an embedded engagement to an infrastructure fund’s investment committee, and the referral-density argument — one fund relationship opens a portfolio — is a structural hypothesis, not a track record. What we’re doing: A dedicated research sprint (fund landscape, named cohort census, competitive field) before any outreach; a deliberately bounded entry product (the fixed-fee readiness assessment, section 9) sized so a fund can say yes without committee anxiety; and a first play that starts from a warm, embedded position rather than a cold pitch. The market test: Does the first readiness assessment convert to a retainer, and does the first retainer generate a referral.
2. The trust barrier on critical infrastructure
The risk: We’re asking boards to let a new three-person firm run the digital function of essential-services infrastructure. However good the model, an investment committee can rationally prefer a worse answer from a bigger brand. What we’re doing: Entering through bounded, low-stakes-first engagements; leading with the founding team’s infrastructure delivery record (the embedded data-centre-operator function, two decades of mission-critical government delivery); and letting the regulatory-knowledge moat show in the first artefact rather than asserting it. The market test: The first engagement won without a brand behind us.
3. The clients-per-senior ceiling
The risk: The economics assume a Client Leader can carry 6–8 embedded clients because AI removes production drag. If the real ceiling is 4 — because relationships, board rhythms, and accountability consume the freed time — year-one profit disappears and the model needs repricing (section 8 shows the maths). What we’re doing: Instrumenting the first engagements to measure where senior time actually goes; capping intake until the number is known rather than discovering it through service failure. The market test: Measured senior hours per client per month across the first 3–5 engagements.
4. The quality ceiling — and the trust bar on the intelligence layer
The risk: Two related forms. At some engagement complexity, AI production may need materially more senior correction — eroding both margin and speed; we don’t know where that ceiling sits for embedded operations work in a regulated market. The persistent operate layer raises a sharper version: an embedded intelligence layer that answers a CFO or board in plain language must be right — a confident wrong number is worse than no number, and decisions get made on it. What we’re doing: Tracking correction rates and rework by task type from engagement one; designing deliverables and the intelligence layer so the highest-stakes outputs carry senior review and verifiable sourcing regardless of AI confidence. What we sell is reliability a regulated organisation can stand behind, not raw answers — which is exactly the standard a bought tool or a DIY chatbot doesn’t reach. The market test: Correction-rate data from the first engagement, reviewed quarterly; and no unreviewed high-stakes output reaching a decision-maker.
5. Sector misjudgement
The risk: The beachhead could be wrong — a thinner formation cohort than the structural evidence implies, or a niche incumbent we haven’t found yet. What we’re doing: This is the risk the sector stage-gate exists for. The beachhead passed a scored evaluation rather than being assumed (section 10), the evaluation’s own evidence gaps define the current research, and the pipeline keeps adjacent sectors warm so parking the beachhead would be painful but not fatal. The market test: The cohort census — if the named-company list is short, we want to know before the first hire, not after.
6. Founder structure and alignment
The risk: Three founders misaligned on model, commitment, or equity is an early-stage killer everywhere; in a senior-judgment business the founding team is the asset, so the risk concentrates. The structural-vehicle question (single entity, backed, per-sector) is also unresolved, and several commercial options hang off it. What we’re doing: Roles, equity, vesting and step-back scenarios are being worked explicitly with the founding team before launch (section 14), not improvised after; the vehicle decision has a deliberate deadline tied to the first engagement rather than drifting. The test: A signed founders’ agreement that all three would re-sign after reading the worst-case scenarios.
Two risks we’re often asked about and deliberately rank lower: AI cost inflation (the production and operate layer is ~1% of revenue, held there by tiered model routing — costs could rise many-fold before the model noticed) and incumbent response (their structural trap is the thesis; the real competitive risk is a fast follower copying us, which is a race we can run — section 7).