The whole programme in order
Twenty-nine moves, top to bottom, from eighteen months out to a year past separation. Each one is tagged with what kind of work it is, what it depends on, and the trap or delay attached to it.
Read it as a sequence, not a schedule. Several moves run in parallel — what matters is that nothing starts before the thing it depends on.
The answer: rebuild what asserts, harvest what instructs, rebuild every register
Neither pure option is right. Rebuilding 400 documents from nothing burns the eighteen months you don't have. Cleaning the parent's library imports the parent's architecture — controls that assume global shared services, an enterprise SOC, a corporate legal function and a group risk appetite that the new entity will not have.
The dividing line is what the document does. A policy asserts — it is a commitment made by a named legal entity to a regulator, a customer, an auditor or a board, and an assertion inherited from a parent is a commitment to operate a control you may have no ability to operate. A work instruction instructs — how to qualify a CNC controller or run a sterility validation is good engineering that survives a change of ownership. A register records decisions — and every decision in the parent's risk, exception and vendor registers was made against the parent's appetite, capital base and insurance tower. Registers are always rebuilt.
Expected split across a device GRC library
| Disposition | Share | What falls here | The rule |
|---|---|---|---|
| Rebuild | ~25% | Board and committee charters; the information security policy and every subordinate policy; risk appetite statement; delegation of authority; code of conduct; all registers (risk, control, exception, evidence, asset, vendor, processing activity); SoA; disclosure controls. | Anything that names the entity, asserts to an outside party, or records a decision. |
| Harvest | ~55% | Standards and procedures: access management, change control, vulnerability management, incident response runbooks, secure SDLC, CSV/CSA protocols, supplier quality procedures, complaint handling, CAPA, design control SOPs. | Keep the technical content, replace every entity reference, system reference, role name and escalation path. Assume 30–50% rewrite by volume. |
| License then replace | ~15% | Deeply technical, entity-neutral material: cryptographic standards, secure coding guidelines, hardening baselines, test method validations, engineering specifications. | Use under the separation agreement's transitional IP licence, replace before it expires. Track the expiry date as a control. |
| Retire | ~5% | Documents that exist only because of group structure: shared-service SLAs, intra-group transfer procedures, group-level reporting instructions, sector-alignment standards. | Do not migrate. They describe a structure that ends on Day 1. |
Everything above applies to the GRC library. Quality system documents live under change control and, once effective, carry validated state. You cannot quietly "clean" an SOP referenced by a device master record — each change is a controlled change with an impact assessment, a training record and, where it touches a validated system, revalidation. Budget three to four times the cycle time for QMS-adjacent documents and start them first. Under the harmonised quality management system regulation now in force, your QMS document architecture should be expressed in ISO 13485 structure, which is also the structure a notified body and an MDSAP auditor will expect.
Triage a specific document
Do not start with policies. Start with the obligation register — every regulatory, contractual, certification and financial commitment the entity carries on Day 1 — and let it tell you which policies you actually need. A separated device company typically discovers it needs 25 to 35 policies, not the 120 it inherited. The parent's library grew by accretion over decades of acquisitions; you have the rare chance to not repeat that.
Document disposition register
Work this top to bottom. Set status on each line as you go. The rebuild set is small and non-negotiable; the harvest set is where the volume and the schedule risk sit.
Governance layer — rebuild, no exceptions
Policy layer — rebuild, sized to the obligation register
Structure as one apex policy with subordinate policies beneath it. The apex is what you show a customer or an auditor first; the subordinates carry the detail. Every subordinate policy must name its owner, its review cadence, the committee that approves it, and the obligations it satisfies.
Apex
Subordinate set — the minimum viable list
Register layer — rebuild every one
How to run the harvest with an AI assistant
Where it earns its keep
- Obligation extraction. Feed contracts, filings and customer security schedules; extract every commitment into a structured register with a source citation on each row. This is the highest-value use and the one most people skip.
- Reference sweep. Find every mention of the parent, its systems, its role titles and its escalation paths across the harvested library. Mechanical, exhaustive, and the thing humans miss most.
- Cross-regime mapping. Generate the first-pass control-to-regime mapping, then have a human confirm. Mapping is a good machine task because it is recall-bound, not judgement-bound.
- Gap analysis. Compare the harvested document against the obligation it is supposed to satisfy and list what is missing. Faster and more complete than a reviewer working from memory.
- Consistency enforcement. Terminology, defined terms, numbering, cross-reference integrity across a 200-document set.
- Draft-to-house-style conversion. Rewriting harvested procedures into the new entity's voice and template.
Where it must not be used unsupervised
- Risk acceptance and appetite. These are governance decisions with named accountable humans. Generated risk scores are indefensible in an audit.
- Anything inside the quality system. QMS documents carry validated state and change-control history. Generated content entering a controlled document without a controlled change is a finding waiting to be written.
- Regulatory determinations. Whether a product is a cyber device, whether a change is a new submission, whether an event is reportable — these are regulatory affairs judgements with legal consequences.
- Evidence. Never generate, summarise or reconstruct evidence. Evidence is produced by systems, not written.
Add one field to every document record: ai_assisted with values none / drafting / review / extraction, plus the name of the human approver. Auditors are beginning to ask. Having the answer already recorded turns an awkward question into a two-minute demonstration of your change control.
Committee architecture
Four tiers. Board committees own oversight and cannot be delegated. Executive committees own decisions. Operating councils own execution. One cross-boundary body governs the relationship with the former parent and dissolves at transition exit.
Stand these up before Day 1, not on it. A committee whose first meeting is also its first crisis has no operating history, no minute trail and no demonstrated effectiveness — and minutes are the primary evidence that governance controls operated.
Audit Committee
Owns
- Internal control over financial reporting, including the general IT control set
- External auditor relationship and the scoping conversation for the first audit
- Internal audit charter, plan and independence
- Cybersecurity risk oversight and the disclosure determination path
- Whistleblower and ethics escalation
Membership
Independent directors only, at least one financial expert. The CISO must have a standing agenda slot and an executive-session right — not a slot at the invitation of the CFO. In a device separation the committee should also see the head of quality at least twice a year, because quality failures and financial exposure are the same conversation.
Separation-specific duty
Approve the Day 1 minimum-viable-compliance position: which obligations are fully met at separation, which are met by transitional arrangements, and which carry a documented gap with an owner and a date. This approval is the thing that converts an undocumented weakness into a governed roadmap. Get it in the minutes.
First meeting agenda
- Charter adoption and independence confirmations
- External auditor scoping — control environment, in-scope systems, transition boundary treatment
- ICFR readiness assessment and the timing of management's first assessment
- Obligation register walkthrough and the Day 1 gap position
- Cyber disclosure procedure — who decides materiality while the parent operates detection
- Internal audit resourcing decision: build, co-source or outsource
A newly listed company is generally not required to include management's assessment of internal control in its first annual report, and the auditor attestation follows later still. Teams read this as a year of grace. It is not. The controls must be designed and operating from Day 1 because the financial statement audit itself relies on them, and because your first assessment will look back over a period that includes the transition. Treat the relief as a reporting deferral, never a design deferral.
Quality & Regulatory Compliance Committee
Owns
- Quality system effectiveness across all manufacturing sites
- Regulatory inspection readiness and the status of every open observation, warning letter or consent decree exposure
- Recall and field action oversight
- Postmarket surveillance and vigilance performance, including reporting timeliness
- Product security posture for connected devices, sitting alongside the Audit Committee's enterprise cyber oversight
Why it is separate from the Audit Committee
Because the failure modes are different and the expertise is different. A committee that has to choose between reviewing revenue recognition and reviewing a rising complaint trend will always choose revenue. In a device company, the quality committee is the one that catches the problem eighteen months before it becomes a financial one.
Separation-specific duty
Own the regulatory transfer plan — every registration, certificate and licence in every market, with a named owner, a lead time and a revenue-at-risk figure. This is the committee that must be told when a market registration will not transfer inside the transition window.
Interface with security
Two standing items: connected-product vulnerability posture with time-to-remediate against your published commitment, and the status of computer system validation for any quality-critical system being migrated or re-hosted. Both are places where a security decision becomes a regulatory one.
Information Security Steering Committee
Owns
- Approval of the control catalogue and every policy below the apex
- Risk acceptance within delegated limits; escalation above them
- Exception approval, renewal and expiry
- Security investment prioritisation and the roadmap for the build-by-date control set
- Transition exit readiness decisions — this committee decides whether a control has operated long enough to cut the parent dependency
Membership
Chaired by the CISO or the chief risk officer. Voting members: CIO, chief quality officer, head of regulatory affairs, general counsel, CFO delegate, head of manufacturing or supply chain, head of R&D or product. In a device company, quality and regulatory are voting members rather than guests — if they are guests, the committee cannot make a decision that touches a validated system, which is most decisions.
What it must produce as evidence
- Minutes with named attendees, decisions and dissents — not a slide deck
- A decision log with an identifier per decision, referenced from the risk and exception registers
- A quarterly attestation pack that feeds the Audit Committee
Give this committee a hard rule: no exception is approved without an expiry date and a named owner, and no exception is renewed twice without escalation to the Audit Committee. Separations generate exceptions at a rate no steady-state program ever sees, and this single rule is what stops the transition-era backlog from becoming permanent.
Quality Management Review
Not optional and not something you design freely — the quality management system regulation and ISO 13485 both prescribe management review inputs and outputs, and an inspector will ask for the records. The new entity needs its own management review cycle running before Day 1, with its own top management named, because a review conducted by the parent's management is not a review of your quality system.
Security's inputs to it
- Product security posture and open vulnerabilities in released product
- Validation status of quality-critical computer systems
- Data integrity incidents affecting quality records
- Supplier security findings for suppliers that touch product
Teams treat management review as a quality-only ritual and keep security out of it. Then a data integrity observation lands and there is no record that security ever reported into the quality system. Get a standing security input on the agenda from the first cycle — it is cheap, and it is the evidence that your two systems are connected.
Transition Governance Board
Joint body with the former parent, governing every service the parent continues to provide. Treat the parent as your largest and most critical third party, because that is exactly what it now is.
Owns
- Service performance against the agreed schedules
- Evidence delivery — the artefacts the parent owes you for controls it operates on your behalf
- Deficiency escalation: when a parent-operated control fails, whose deficiency is it and who reports it
- Exit sequencing and the trigger conditions for cutting each service
- Incidents that cross the boundary, including who notifies which regulator
The four questions its charter must answer
- When a control the parent operates fails, who records the deficiency and in whose register?
- When an incident touches both entities, who leads, who notifies, and on whose clock does the reporting deadline run?
- What evidence does the parent deliver, in what format, at what cadence, and what happens when it does not?
- Who can extend a service, at what cost, and with whose approval?
Audit rights are not evidence delivery. A clause granting you the right to audit the parent gets you the ability to ask; it does not get you the quarterly access review extract in a format your auditor can test, on the fifth working day, every quarter, for the full audit period. Negotiate delivery obligations with format, cadence and remedy — and negotiate them before signature, because you will not get them afterwards.
Operating councils
Change Advisory Board · weekly
The most audit-visible control you will operate. Emergency change is where separations generate ITGC findings — everything is urgent, so everything becomes an emergency change, and the population of unapproved changes explodes. Cap emergency change as a percentage of total and report it monthly.
Data Governance Council · monthly
Owns classification, retention, privacy and the record of processing. In a device company it also owns quality record integrity, which is why it must include a quality representative.
Product Security Board · monthly
Scoped to connected product only — robotics, navigation, digital surgery, patient-facing applications. Owns threat modelling, the software bill of materials programme, disclosure decisions and premarket security content. Keep it separate from the enterprise steering committee; the audiences and the regulators are different.
AI Governance Council · monthly
Owns the AI inventory, use-case intake and risk classification. Needed on Day 1 rather than later, because separation-era productivity pressure is precisely when unreviewed AI tooling enters manufacturing and clinical workflows.
Site Security & OT Councils · monthly, per major site
One per significant manufacturing site, chaired by the site leader, not by IT. Plant managers do not attend committees run from headquarters, and OT security fails without them.
Third Party Risk Committee · monthly
Runs the novation queue during separation and the assessment queue afterwards. Prioritise by data sensitivity and product contact, not by contract value.
Eleven bodies looks heavy until you count what they replace: in the parent, this work was absorbed by dozens of group functions. The discipline is that each body has a charter, decision rights, a quorum and minutes — and that any body which has not made a decision in two consecutive meetings gets merged into another. Review the whole architecture at transition exit and expect to retire two or three.
Relationships — the actual operating system of a separation
In a separation you have almost no authority. The control catalogue is yours, but the evidence sits with J&J, the validation state sits with quality, the plant dependencies sit with a controls engineer nobody has introduced you to, and the notified body slot sits with a scheduler who has never heard your name.
Map people by what you need from them, not by the org chart. Then work out who can introduce you. Cold approaches inside a separation get deprioritised by people who are already at capacity; a warm handoff from someone whose deadline they share does not.
How to find who to reach out to
The person you need is rarely the person the org chart points at. Six ways to find them:
Follow the evidence
For every control tagged J&J-extract, ask who generates the artefact today. Not who owns the system — who runs the query. That person is your real counterparty for the next two years, and they are usually three levels below the name on the service schedule.
Follow the certificate
Every certificate, registration and licence has a named signatory and a named scheme or account manager on the issuing side. Both are findable in the certificate itself. The account manager controls your audit slot.
Follow the ticket queue
Pull the top fifty tickets by volume for each plant and each function. The assignment groups tell you who actually operates the estate, and the recurring requesters tell you where the friction is. This finds shadow ownership faster than any interview.
Follow the invoice
Accounts payable knows every vendor, every renewal date and every contract owner. It is the most complete and least used inventory in the company, and it surfaces the systems nobody declared.
Ask the auditor
Internal audit and the external auditor have already spent years identifying who they go to for each control. Ask for their contact list. It is free, accurate and pre-vetted.
Ask who gets blamed
When something breaks in a given area, who gets called at two in the morning? That is the person who knows how it actually works, regardless of title.
Ask for a fifteen-minute call with one specific question, not a meeting to "discuss the separation". Specific asks get answered; open-ended ones get deferred until after Day 1, which is too late.
Inside DePuy — the coalition you cannot build without
| Who | What you need from them | What breaks without it |
|---|---|---|
| CFO and Controller | ITGC scope, the external auditor relationship, and funding for the build-by-date control set. | You design controls the auditor will not accept, and you find out in the first test cycle. |
| Chief Quality Officer | Access to the quality change control process and a standing security input to management review. | Every procedure change stalls, and security is invisible to the inspector. |
| Head of Regulatory Affairs | The registration inventory, submission status, and which products are in cybersecurity scope. | You cannot build the obligation register, and connected-product commitments go unowned. |
| CIO and infrastructure leads | The migration plan, application ownership, and control over sequencing. | Identity, logging and evidence get built after the systems they are supposed to cover. |
| General Counsel | Separation agreement terms, the documentation licence, disclosure path, and privacy transfer mechanisms. | You miss the evidence-delivery window and the licence expiry, both irreversible. |
| CHRO | The HR system as the joiner-mover-leaver source of truth, plus training records and works council navigation. | Access controls have no authoritative population and EU changes stall on consultation. |
| Head of Manufacturing and site leaders | Shutdown windows, plant access, and sponsorship of the site security councils. | Network cuts happen without rehearsal and OT security is ignored on the floor. |
| Head of R&D and digital surgery | Product security scope, threat models, and the software bill of materials programme. | Connected products ship with unowned postmarket obligations. |
| Internal Audit | Their existing contact map, control walkthroughs and independent testing capacity. | You rebuild knowledge that already exists and lose your best early-warning channel. |
Quality and regulatory first, finance second, IT third. Counterintuitive for a security leader, but in a device separation the quality and regulatory calendars are the ones you cannot move — and they are the relationships that take longest to earn, because you are asking for access to a system that treats outsiders as a compliance risk.
At J&J — counterparties, not colleagues
The people across the boundary were colleagues and will become a critical third party. The window in which they will still help you informally is short, and it closes when their own retained-organisation roles are confirmed. Extract what you need early.
- J&J service owners — the named operator of each retained service. Get the person who runs the query, not the person who owns the platform. Ask them what evidence they can realistically produce and in what format, before the schedules are drafted.
- J&J security operations — detection, triage and the notification interval you will depend on for disclosure. Agree the maximum interval in writing and rehearse it.
- Separation Management Office — controls the schedules, the timeline and the escalation route. Your reconciliation finding goes here.
- J&J privacy and legal — the intra-group transfer mechanisms you fall out of on Day 1, and the scope of the documentation licence.
- J&J procurement — which supplier agreements can be novated, which cannot, and where the volume pricing and security terms actually live.
- J&J internal audit and quality — historical findings, open observations and supplier audit reports. Ask now; entitlement to these becomes contested later.
Treating the J&J relationship as goodwill rather than contract. Goodwill evaporates when their retained organisation is announced and people start protecting their own headcount. Every dependency that matters must survive the day the people you know are reassigned.
Outside — the ones with calendars you don't control
- External auditor — engage on control environment scoping twelve to eighteen months out. Their view of in-scope systems will change your plan, and hearing it early is free.
- Notified body scheme manager — the individual who allocates audit capacity. A relationship here is worth more than a formal application.
- Auditing organisation for the multi-market programme — same logic, different scheme.
- Local regulatory representatives — in every market where DePuy is not established. These appointments have legal weight and lead time.
- Cloud provider account team — tenancy separation, enterprise agreement novation, and technical support for the carve-out. They have done this before; ask for their separation playbook.
- Insurance broker — cyber, product liability and D&O for a standalone entity, priced without the parent's tower. Start early; underwriters will ask control questions you need answers to.
- Outside counsel — separation agreement, privacy transfers, disclosure obligations.
- Peer security leaders in medtech — the people who have run a device separation. Two conversations here save six months of discovery.
Bottom-up — the people who actually know
Executive relationships get you permission. These relationships get you accuracy.
- Plant controls and automation engineers — they know what the machines talk to, which no diagram records.
- QA document control — knows every procedure, every reference and every change queue. Nothing in the harvest happens without them.
- The historian or MES administrator — usually one person per site, often with no backup. Identify them early; they are a single point of failure as well as a source.
- Field service engineers for robotic and navigation platforms — they know how systems connect inside hospitals, what remote support paths exist, and what customers actually asked about security.
- Service desk and contact centre supervisors — they see complaint intake, shadow tooling and where users work around process.
- The person who renews the certificates — often unnamed, sometimes nobody. Finding out it is nobody is itself the finding.
Convert these into a standing structure rather than a series of favours. The BISO layer and the site security councils exist precisely so that plant and product knowledge reaches you continuously, without you having to remember to ask.
Control catalogue and the severability model
Build your own numbered catalogue anchored to a recognised functional spine, and treat every external framework as a mapping rather than a spine. Certificates get rescoped, customers add commitments, regulations move — mappings absorb that without re-plumbing controls. And at transition exit nothing needs renumbering, because no parent identifier ever entered the catalogue.
Twelve domains, 90 to 130 controls
GOV governance and compliance management · ORG roles, workforce and security culture · AST asset, data and product inventory · IAM identity and access · INF infrastructure and network · APP secure development and product security · DAT data protection and privacy · SUP third party and supply chain · OPS operations, logging and monitoring · VUL vulnerability, threat and postmarket disclosure · IRB incident response and resilience · AUD assurance, evidence and internal audit
If a domain exceeds fifteen controls you are writing procedures, not controls. A separated entity cannot operate three hundred controls in year one, and a catalogue nobody can operate is worse than a smaller one everybody can.
The four severability attributes
| Attribute | Values | What it drives |
|---|---|---|
| Operator class | DePuy · Parent-operated · Shared · Vendor | Who performs the activity today. Derived bottom-up from controls, this list will not match the transition service schedule negotiated by corporate development — and that delta is your first finding. |
| Severance state | Native-D1 · Transition-dependent · Build-by-date | Whether Day 1 is the end state. The build-by-date set is your board-approved gap plan. |
| Evidence custody | DePuy-system · Parent-extract · Vendor-attest | Whether you can still produce evidence after the parent dependency ends. Parent-extract controls need a delivery obligation, not an audit right. |
| Exit trigger | Free text condition | Converts a contractual end date into a testable control condition. |
Three rules that follow
A control can be parent-operated and still asserted by the new entity. The parent performs, you monitor, receive evidence and sign. This is the normal and correct arrangement; what breaks programs is leaving the assertion ambiguous, so that when the control fails nobody knows whose deficiency it is.
Native-D1 for every control, without exception
This is the single highest-leverage move in a separation. The parent may operate a control through the entire transition, but the artefact lands in your repository, in your custody, on your retention clock, from Day 1. Otherwise your first audit arrives with a testable population that lives in a system you no longer have access to. Separate the evidence layer before you separate the control layer. It is cheap, it is unglamorous, and it is the difference between a clean first opinion and a scope limitation.
A transition-dependent control becomes native only when the replacement has operated with evidence for a defined period: typically two consecutive cycles for periodic controls, ninety days for continuous ones. Exiting on the contractual date with zero operating history is how separations manufacture material weaknesses, and it happens because the exit date sits in a commercial schedule that nobody mapped to a control.
Control record shape
Shaped to merge with the separation tracker's JSON export. The workstream_ref back-link is what turns a separation checklist into the front end of a permanent programme: tasks close at cutover, controls persist, and the link shows an auditor which separation activity established each control.
| Field | Example |
|---|---|
id / domain | IAM-04 · Identity and access |
title | Periodic review of privileged access to financially significant and quality-critical systems |
obligations[] | ITGC access scope · service criteria for logical access · quality system record control · privacy access limitation |
mappings{} | SOX ITGC · SOC 2 common criteria · ISO 27001 Annex A · HIPAA administrative safeguards · electronic records access limitation |
operator | Parent-operated |
severance | Transition-dependent |
evidence_custody | Parent-extract |
evidence{} | Quarterly review export with complete population · parent identity platform to DePuy evidence repository · quarterly · retained per device record rules |
exit_trigger | DePuy directory operating two consecutive quarterly reviews with complete, reconciled populations and no unresolved orphan accounts |
owner / workstream_ref | Named accountable individual · link to the separation tracker workstream |
ai_assisted | none / drafting / review / extraction plus approver |
Metrics for the first twenty-four months
- Native coverage — percentage of controls with no parent dependency. The cleanest single indicator of separation health; report it to the Audit Committee monthly.
- Exit triggers met against services remaining — if triggers are lagging the schedule, you are heading for a date-driven exit.
- Evidence completeness for the transition period specifically — not overall completeness, which will look fine and hide the gap.
- Inherited exceptions re-decided against expired by default — measures whether governance is actually operating.
- Emergency change as a share of total change — the leading indicator of ITGC trouble.
- Shadow IT and shadow OT discovery rate — your real culture signal during separation.
- Orphan count in both directions — obligations with no control, controls with no obligation.
FDA and US regulatory dependencies
These are the items that block product from shipping or reports from filing. They are owned by regulatory affairs, but GRC has to hold the map because each one generates obligations, controls and evidence. Confirm every item against the separation agreement and the Form 10 — treat the detail below as the checklist, not as the record.
| Dependency | Lead time | What actually has to happen |
|---|---|---|
| Establishment registration and listing | Annual cycle, act early | Every manufacturing, contract-sterilisation and specification-developer site registers under the new owner. New owner operator account, new user accounts, device listings reassigned. Miss the annual cycle and the site is unregistered, which is a shipment stop. |
| 510(k) and PMA ownership transfer | Weeks to months | Ownership transfer notification per clearance. Volume is the issue, not difficulty — an orthopaedics portfolio can carry many hundreds of clearances across hips, knees, trauma, spine, extremities and sports medicine. Build the inventory first and reconcile it against the product catalogue, because the two will not match. |
| Electronic Submissions Gateway account | Weeks, and it blocks | The new entity needs its own gateway account with its own credentials and a completed connectivity and test-submission cycle before it can file electronic adverse event reports. Frequently discovered late. Until it works, the new entity cannot meet a reporting deadline on its own systems. |
| Adverse event reporting continuity | Day 1 hard stop | Complaints arriving at parent-operated call centres about the new entity's devices must reach the new entity's complaint system inside the reporting clock. Define the handoff, the timestamp of record and the escalation. The clock runs from awareness, and awareness now sits with a third party. |
| Unique device identification records | Months | Device identifier records are keyed to the labeller's organisation identifier. A change of legal manufacturer means every record needs updating and, where the identifier itself changes, new identifiers and relabelled product. This is the dependency most likely to be underestimated, and getting it wrong degrades recall traceability. |
| Quality system regulation alignment | Continuous | The harmonised quality management system regulation is now in force, so the new entity's QMS documentation should be built in ISO 13485 structure from the start rather than converted later. Advantage of a spin-off: you are not migrating a legacy structure. |
| Electronic records and signatures | Per system | Every migrated or cloned quality-critical system must preserve audit trail continuity, retain record integrity and re-establish signature binding under the new entity. A lift-and-shift that flattens history breaks the audit trail requirement. |
| Computer system validation state | Long pole | A cloned instance in a new environment under a new entity is a new system. Validation does not transfer automatically. At minimum: installation and operational requalification in the new environment, with performance qualification for anything quality-critical. This drives more of the separation timeline than anything else in IT. |
| Premarket cybersecurity for connected product | Per submission | Implants are not cyber devices; robotics, navigation, digital surgery and patient-facing applications are. Any submission in flight at separation needs its security documentation re-issued under the new entity, and the postmarket support commitments in those submissions become the new entity's obligations. |
| Design history and device master records | Months | Quality records that must transfer with the product, usually held in the parent's product lifecycle system. Custody, completeness and retrievability all need proving — an inspector will ask for a specific record and watch you retrieve it. |
| Postmarket surveillance and CVD | Day 1 | Published disclosure policy, security contact, key material and coordination arrangements under the new entity's name. Researchers report to whoever the website says; if the website still says the parent, your intake path is broken on Day 1. |
Programme plans assume that cloning the enterprise resource planning and manufacturing execution systems is an IT migration. It is not — it is a regulatory event. Every quality-critical system lands in the new environment in an unvalidated state, and until requalification is complete you cannot release product against it. This is the dependency that most often forces a separation date to move, and it is visible eighteen months out if anyone maps validation state onto the migration plan. Do that mapping in the first quarter of the programme.
Global registrations — the schedule risk nobody owns
A change of legal manufacturer is a regulatory event in every market. Some transfers are administrative; several take longer than the transition period allows and are directly revenue-blocking. Sequence by revenue at risk multiplied by lead time, and start the long ones before you start anything else.
| Market | Typical lead | Risk | What is actually involved |
|---|---|---|---|
| European Union | 12–18 months | High | Notified body certificates do not transfer freely; the body must accept the new legal manufacturer and re-issue. Registration in the EU database requires the new entity's own actor registration. Basic device identifiers change with the manufacturer, which cascades into labelling and packaging. A qualified person responsible for regulatory compliance must be appointed and evidenced. Notified body capacity is the binding constraint — book slots eighteen months out. |
| China | 12–24 months | Highest | Registration certificates are issued to a named registrant. Transfer is generally treated as a new registration rather than an amendment, with testing and technical review. Frequently exceeds the transition window. If a major product family sells into China, this needs a decision at board level about whether the transition period is long enough or whether a distribution arrangement bridges the gap. |
| Japan | 9–18 months | High | Marketing authorisation holder change plus a compliant quality management arrangement under the new holder, including the required domestic responsible roles. Not administrative. Start with Japan and China together — they set the critical path for the entire regulatory workstream. |
| Multi-market quality audit programme | 6–12 months | Medium | The single-audit programme certificate covers several regulators at once, which makes it efficient and also makes it a single point of failure. Re-certification under the new entity needs an auditing organisation slot; losing it cascades into every market that relied on it. |
| United Kingdom | 6–12 months | Medium | Registration under the new manufacturer, with a UK responsible person where the entity is not UK-established. Interacts with EU work — sequence them together to avoid two labelling changes. |
| Canada | 4–8 months | Medium | Licences are held by the manufacturer and require amendment or reissue, supported by the quality certification above. |
| Brazil | 9–18 months | Medium | Registration holder change with a local representative. Slow and document-heavy. |
| Australia | 3–6 months | Lower | Sponsor and manufacturer details updated on the register; relatively tractable if the underlying conformity evidence is in place. |
| Korea, India, Gulf, ASEAN | 3–12 months | Varies | Individually manageable, collectively enormous. Volume is the problem: dozens of markets, each with its own dossier. Resource this as a programme, not as a task. |
Inside a corporate group, cross-border personal data transfers typically run under binding corporate rules or an intra-group agreement. On Day 1 the new entity leaves the group and every one of those transfers becomes a transfer to a third country outside the covered structure. You need standard contractual clauses and transfer impact assessments in place at separation, plus your own record of processing activities and your own data protection officer where required. This is a Day 1 obligation with a months-long lead time and it is almost always found late, because it is invisible until someone asks which mechanism covers the flow.
Build one matrix: market by product family, with lead time, revenue at risk, owner and current status. Take it to the Quality & Regulatory Compliance Committee monthly. The purpose is not tracking — it is forcing an early, explicit board decision about which markets will not be ready, and what commercial arrangement bridges them. That decision made twelve months out is a strategy; made three months out it is a crisis.
Manufacturing and operational technology
An orthopaedics business is a machining, forming, additive and sterilisation business. Its plants run CNC estates, coordinate measuring machines, additive systems, cleanrooms, environmental monitoring, sterilisation and traceability infrastructure — most of it long-lived, much of it validated, and a meaningful share of it dependent on the parent's global network for services the plant floor never thinks about.
The network cut is the single largest production risk
Plant networks in a large group are rarely as isolated as the architecture diagram claims. Time synchronisation, name resolution, certificate services, licence servers, identity, print and label services, historians and remote vendor support paths all commonly traverse the parent's core. Cutting the network without mapping those dependencies stops production.
Do this, in order
- Passive traffic capture at each plant boundary for at least one full production cycle including a month-end and a maintenance window. Not a survey — a capture. Nobody can tell you what their machines talk to.
- Map every flow to a service, an owner and a disposition: stays local, replaced by new entity service, or transition-provided.
- Rebuild time synchronisation, name resolution and certificate services locally first. These three cause the most damage and are the cheapest to fix early.
- Inventory every licence server and every vendor remote-support path. Vendor connections into machine controllers are the most common unmanaged remote access in a plant.
- Rehearse the cut at the smallest site during a planned shutdown before attempting it anywhere else.
Two of the most commonly reported cutover failures across large separations are expired certificates and mis-sequenced domain and mail changes. Both are entirely preventable and both take out production or customer communications for days. Build a certificate inventory with expiry dates as a named workstream deliverable, and treat domain and mail cutover as a rehearsed, reversible change with a defined rollback.
Validated systems set the schedule
- Manufacturing execution and quality systems — every instance that moves, gets cloned or gets re-hosted requires requalification in the new environment. Map validation state onto the migration plan in the first quarter; it is the earliest reliable signal of whether the separation date is achievable.
- Audit trail continuity — migrated records must retain their audit trail. Confirm this in the migration design, not in validation testing, because by then the design is fixed.
- Sterilisation and environmental monitoring — parametric release and monitoring systems are quality-critical and often supplier-hosted. Supplier contracts, data ownership and record retrievability all need re-establishing.
- Traceability — lot and serial traceability from raw material to implanted device must survive the system split intact. A broken trace is a recall you cannot execute, and the regulator will treat it accordingly.
Supplier and contract manufacturer novation
Device suppliers touch product, which makes supplier separation a quality event as well as a commercial one.
- Quality agreements name the parent. Every one needs novation or replacement, with vigilance and change-notification flow-downs re-established. A supplier who does not know to notify you of a process change is a recall in waiting.
- Supplier audits are the parent's work product. You may not be entitled to the reports. Budget for re-auditing critical suppliers, and prioritise by product contact rather than spend.
- Master agreements fragment. Group-level pricing and, more importantly, group-level security and data protection terms do not automatically follow. Re-negotiating security schedules across hundreds of suppliers is a multi-year programme; triage it hard.
- Single-source and sterilisation partners first. These carry the highest continuity risk and the longest requalification lead times.
Shadow technology during separation
Separation deadlines are absolute, so business teams buy their own tools rather than wait for a review process that has no staff yet. Most of the technical debt you will spend three years cleaning up gets created in this eighteen-month window. Two responses work:
- Make the paved path faster than the workaround. A pre-approved catalogue with a same-week intake for anything on it, and a genuine 48-hour triage for anything not. Speed is the control.
- Put security embeds into the business units. Product, manufacturing, quality and R&D each have different regulatory exposure and none of them will call a central function. An embedded layer is the only thing that keeps discovery ahead of accumulation.
Track discovery rate monthly and report it as a culture indicator rather than a compliance failure. If discovery is rising and time-to-onboard is falling, the programme is working. If discovery is flat, your detection is broken — flat is never the true number during a separation.
The estate that has to separate
Every system falls into one of five separation patterns. Getting the pattern wrong is expensive: cloning something that should have been rebuilt imports the parent's mess, and rebuilding something that should have been cloned burns a year.
Clone and requalify — copy the instance, revalidate in the new environment. Carve out — split shared data and configuration into a new tenant. Net new — build fresh; the parent's version is unusable. Transition then replace — J&J operates it, you cut over later. Novate — contractual reassignment, little technical work.
HR and workforce
| System | Pattern | Evidence it produces | Trap |
|---|---|---|---|
| Core HR / HCM | Carve out | Authoritative worker population, joiner-mover-leaver events, role and org data | Access controls have no authoritative population until HR lands. Sequence HR before identity, not after. |
| Payroll | Carve out | Segregation of duties over payment, ICFR-relevant approvals | Often outsourced per country, so it is dozens of vendor relationships, not one system. |
| Learning management | Net new | Training records — simultaneously ICFR control environment evidence and quality system evidence | Training records are quality records. Losing history breaks both the ITGC test and the inspection response. |
| Badge and physical access | Clone / requalify | Site access populations, cleanroom and controlled-area entry logs | Shared campuses. Where DePuy and J&J occupy the same site, physical separation is a negotiation, not a project. |
| Recruiting and onboarding | Net new | Background check and onboarding control evidence | Hiring accelerates during separation while the control is being rebuilt. Highest-risk window for unvetted access. |
Programme plans put HR in the "people workstream" and identity in the "IT workstream", and the two never meet. But the HR system is the source of truth for every access control DePuy will assert, so if identity goes live before HR, your first access review has a population you cannot defend. Fix the sequence at the plan level, in the first quarter.
Cloud, identity and collaboration
| System | Pattern | Evidence it produces | Trap |
|---|---|---|---|
| Hyperscaler tenancy and organisation accounts | Carve out | Configuration baselines, privileged access, logging coverage | Shared landing zones, shared network transit and shared guardrails. Account migration moves the workload but not the controls around it. |
| Enterprise agreements and committed spend | Novate | Contractual security terms, data residency commitments | Losing the parent's committed-spend discount is visible; losing the negotiated security addendum is not. |
| Directory and identity provider | Net new | Access reviews, privileged access, authentication logs — the core ITGC set | Cloning inherits orphans, service accounts and stale privileged groups as DePuy's findings. Migrate selectively. |
| Email, collaboration and file storage | Clone / requalify | Retention, legal hold, data loss prevention | Mail and domain cutover is one of the two most commonly reported separation failures. Rehearse with a tested rollback. |
| ITSM and change management | Net new | Change approvals, emergency change population, incident records | The change record is a primary ITGC artefact. Starting a new instance at Day 1 leaves the transition period unevidenced unless you export first. |
| PKI and certificate management | Net new | Certificate inventory, expiry tracking, issuance approvals | Certificates issued from J&J's authority expire on J&J's schedule and often with no owner on DePuy's side. |
Connected product — robotic surgery, navigation, digital surgery
Most of an orthopaedics portfolio is implants and instruments, which carry no cybersecurity obligation. The robotic, navigation and digital surgery platforms carry all of it — and they sit inside hospital networks, touch patient data, and have field service organisations with remote access paths.
| Element | Pattern | Evidence it produces | Trap |
|---|---|---|---|
| Robotic surgical platform | Clone / requalify | Threat model, software bill of materials, premarket security documentation, postmarket vulnerability posture | Postmarket support commitments made in the submission become DePuy's obligations. Read them before Day 1, not after a disclosure. |
| Navigation and instrument tracking | Clone / requalify | Configuration baselines, hospital deployment inventory | Installed base inventory is usually incomplete. You cannot notify customers of a vulnerability in devices you cannot locate. |
| Cloud analytics and case data | Carve out | Access logs, data flow records, processing records and transfer mechanisms | Case data may be identifiable. Leaving the parent's group means new transfer mechanisms and, in some markets, new consent positions. |
| Device telemetry and remote support | Net new | Remote session logs, authentication to deployed devices | Service engineers reach devices inside hospital networks through paths that were never inventoried as remote access. |
| Field service and installed base management | Carve out | Service records, software version tracking, patch deployment status | Version tracking is what makes a vulnerability advisory actionable. Without it, disclosure is theoretical. |
| Product security disclosure endpoint | Net new | Intake records, coordination timelines, published advisories | Researchers report to whatever the website says. A J&J contact on Day 1 is a broken intake path. |
Hospitals will ask, in writing, whether their deployed robotic systems are still covered by the same security commitments after separation. That question arrives in the first month. Have a signed answer ready, agreed with regulatory and legal, before anyone asks.
Telephony, contact centre and commercial systems
| System | Pattern | Evidence it produces | Trap |
|---|---|---|---|
| Contact centre and complaint intake | Transition then replace | Call records, timestamp of awareness, complaint handoff records | The adverse event clock runs from awareness. During transition, awareness sits with a J&J-operated centre. Define the timestamp of record contractually and test it with seeded complaints. |
| Telephony, numbers and call recording | Clone / requalify | Recording retention, consent handling, access to recordings | Published customer numbers appear on labelling, IFUs and hospital contracts. Changing them is a labelling change, not a telecoms change. |
| CRM and customer master | Carve out | Customer contact records used for field notifications and recalls | If the customer master is incomplete, you cannot execute a field action. This is a recall capability question, not a sales question. |
| Field inventory and consignment | Carve out | Lot and serial location, consignment reconciliation | Orthopaedic consignment inventory sits in hospitals and reps' vehicles. Traceability across the split is a recall dependency. |
| Customer portals and e-commerce | Net new | Authentication, entitlement, order records | Hospital IT will re-run security reviews on any new customer-facing endpoint. Budget for the questionnaires. |
Telephony is treated as facilities plumbing and assigned to whoever handles the office move. But in a device company the complaint line is a regulated intake channel with a statutory clock attached, and the number itself is printed on product labelling. Move it into the regulatory workstream.
Quality, regulatory and manufacturing systems
| System | Pattern | Evidence it produces | Trap |
|---|---|---|---|
| Electronic quality management system | Clone / requalify | Document control, CAPA, complaint records, training linkage | Arrives in the new environment unvalidated. Requalification, not migration. |
| PLM and design history files | Clone / requalify | Design records that must transfer with the product | Custody, completeness and retrievability all need proving. An inspector will ask for one specific record and watch you retrieve it. |
| ERP | Clone / requalify | The bulk of the ITGC and financially significant control set | The single longest pole. Validation state and ICFR scope land on the same system at the same time. |
| MES, historian and shop floor | Clone / requalify | Device history records, batch and lot traceability | Often site-specific with one administrator and no backup. Identify that person early. |
| Regulatory information management and submissions gateway | Net new | Registration inventory, submission records, electronic reporting | The gateway account blocks electronic adverse event reporting until it is live and tested. |
| Labelling, print and traceability | Clone / requalify | Device identifier records, label version control | A change of legal manufacturer cascades into device identifier records and, in some cases, relabelled product. |
| Sterilisation and contract manufacturer systems | Novate | Parametric release records, supplier quality data | Supplier-hosted. Data ownership and retrievability need re-establishing contractually. |
Security and data tooling
| System | Pattern | Evidence it produces | Trap |
|---|---|---|---|
| SIEM and log management | Transition then replace | Detection coverage, incident timelines, retention | J&J detects during transition but DePuy owes the disclosure. Agree the maximum notification interval in writing. |
| Endpoint and server protection | Net new | Coverage percentage, policy compliance | Coverage gaps appear at the seams — OT endpoints, engineering workstations, field service laptops. |
| Vulnerability management | Net new | Scan coverage, time to remediate against policy | Time-to-remediate is a published commitment for connected product. The tool must cover product, not just IT. |
| SBOM and AIBOM tooling | Net new | Component inventory per product release, disclosure support | Required for premarket submissions and increasingly for customer contracts. Not optional for the robotic platform. |
| Secrets and privileged access | Net new | Privileged session records, credential rotation | Shared service credentials embedded in plant systems are the hardest to find and the last to be rotated. |
| Data warehouse, BI and AI platforms | Carve out | Data lineage, access records, AI use case inventory | Separation-era productivity pressure is exactly when unreviewed AI tooling enters clinical and manufacturing workflows. |
Security tooling is usually last in the queue because it produces no revenue and blocks no shipment. The counter-argument that works with a CFO: six of these systems produce the evidence the external auditor will test, and three of them produce the evidence a regulator will ask for. They are not overhead — they are the instruments that generate your assertions.
One control set, six regimes
DePuy will be assessed against SOX ITGC, FDA device requirements, CMMC Level 2 where defence work exists, the EU Cyber Resilience Act, GDPR and HIPAA — plus SOC 2 and ISO 27001 for customers. Running six programmes is unaffordable for a newly separated entity and produces six sets of contradictory evidence.
The rule: a control operates once, produces one artefact, and satisfies many regimes. What differs is not the control but the evidence standard applied to it — and that difference is where most programmes fail, because they collect evidence adequate for one regime and offer it to another.
The evidence standards are not the same
| Regime | Evidence standard | What that means in practice |
|---|---|---|
| SOX ITGC | Complete and accurate, with a defensible population | The population must be provably whole. An access review over an incomplete extract fails even if every line in it was reviewed correctly. |
| CMMC Level 2 | Adequate and sufficient, per assessment objective | Adequacy is whether the artefact addresses the objective; sufficiency is whether there is enough of it. Both are judged per objective, not per control. |
| FDA / QMSR | Attributable, legible, contemporaneous, original, accurate | Timing and attribution matter as much as content. A record reconstructed after the fact is not contemporaneous, however accurate. |
| 21 CFR Part 11 | Audit trail integrity and signature binding | The record must show who did what and when, with the trail intact through any migration. |
| GDPR | Demonstrable accountability | You must be able to show the decision and its reasoning, not merely the outcome. |
| EU CRA | Documented across the product lifecycle | Vulnerability handling and component inventory must be evidenced per product release, not at an organisational level. |
An organisation fluent in all six can design one artefact that clears the highest bar and reuse it everywhere. An organisation fluent in one designs for that one and re-collects for the rest. In a device separation you need ITGC, Part 11 and quality system evidence out of the same systems simultaneously — so the multi-regime view is the only view that works.
Domain to regime crosswalk
| Domain | SOX ITGC | FDA / QMSR | CMMC L2 | EU CRA | GDPR | HIPAA |
|---|---|---|---|---|---|---|
| GOV | Control environment | Management review | Policy evidence, all domains | Art.13 processes | Art.24, Art.5(2) | §164.308(a)(1) |
| ORG | Competence, COSO 4 | Training records | AT family | — | Art.39 training | §164.308(a)(5) |
| AST | Scoping completeness | DMR/DHF linkage | CM.L2-3.4.1 | Annex I(2) SBOM | Art.30 records | §164.310(d) |
| IAM | Logical access — most tested | Part 11 §11.10(d),(g) | AC, IA, AU families | Annex I(1)(d) | Art.32(1)(b) | §164.312(a),(d) |
| INF | Computer operations | Infrastructure qualification | SC, MA families | Annex I(1)(e) | Art.32 | §164.312(e) |
| APP | Program development and change | Design control, CSV | CM, SA practices | Art.13 secure development | Art.25 by design | §164.308(a)(8) |
| DAT | IPE completeness/accuracy | Part 11 record integrity | MP, SC families | Annex I(1)(c) | Art.5, 32, 44–49 | §164.312(a)(2)(iv) |
| SUP | Service organisation reliance | Supplier qualification | External service providers | Art.13(5) due diligence | Art.28 processors | §164.308(b) BAAs |
| OPS | Job scheduling, monitoring | Production controls | AU, SI families | Annex I(2)(6) logging | Art.32(1)(d) | §164.308(a)(1)(ii)(D) |
| VUL | Patch within change | 524B postmarket | RA, SI families | Art.13(8), Art.14 | Art.32(1)(d) | §164.308(a)(1)(ii)(B) |
| IRB | Deficiency escalation | Complaint and MDR interface | IR family | Art.14 reporting | Art.33, 34 | §164.308(a)(6), Breach Rule |
| AUD | Management assessment | Internal audit, QMSR | CA family, POA&M | Conformity assessment | Art.32(1)(d) | §164.308(a)(8) |
Indicative mapping for programme design. Confirm each cell against the current text of the regime and your assessed scope before relying on it — CRA obligations in particular phase in on a staged timetable.
Worked example — secure SDLC and CI/CD
The pipeline for the robotic and navigation software is where the most regimes converge on a single control chain. Design it once, correctly, and it clears all of them.
The control chain
| Control | Tooling | Artefact it produces | Regime it satisfies |
|---|---|---|---|
| APP-01 Authorisation to commit | GitHub Enterprise with SSO to the identity provider, SCIM provisioning, teams mapped to roles | Repository access population, joiner-mover-leaver events | SOX logical access; CMMC AC and IA; HIPAA §164.312(a) |
| APP-02 Peer review | Branch protection, required reviewers, CODEOWNERS, signed commits | Pull request record with reviewer identity and timestamp | SOX change management; QMSR design control; Part 11 attribution |
| APP-03 Segregation of duties | Deployment environments with required approvers distinct from committers | Deployment approval record | SOX SoD — the classic finding when developers can deploy |
| APP-04 Component inventory | SCA scanning in the pipeline, SBOM generation per build (SPDX or CycloneDX) | Per-release SBOM stored with the release artefact | FDA 524B; EU CRA Art.13(8) and Annex I(2)(1) |
| APP-05 Vulnerability gate | SCA and SAST thresholds, policy-as-code failing the build | Gate pass/fail record per build, with exceptions logged | CRA Art.13 secure development; CMMC RA and SI; FDA premarket |
| APP-06 Release authorisation | Release pipeline requiring quality sign-off for regulated builds | Signed release record linked to the design history file | QMSR design transfer; Part 11 signature binding; SOX change |
| APP-07 Postmarket vulnerability handling | PSIRT case tracker, VEX/CSAF advisory generation, KEV monitoring | Advisory with affected-version statement and remediation timeline | FDA postmarket; CRA Art.14; ISO/IEC 29147 and 30111 |
Teams build the pipeline for engineering velocity and then retrofit control evidence. But the SOX-testable artefact is the pull request record with reviewer identity, and the CRA-testable artefact is the per-release SBOM — both of which must be generated at the moment of the action and retained. Retrofitting means reconstructing, and a reconstructed record fails the contemporaneous test even where it passes the accuracy one.
Repository history, pull request records and build artefacts for the audit period live in J&J's tenancy. Export them into DePuy's evidence repository before the tenancy is cut, or the entire pre-separation development record becomes unavailable exactly when the first assessment asks for it.
Culture, training and the reporting cycle
Training records, phishing results, tabletop after-actions and board packs are usually treated as programme decoration. In a separated device company they are four different regimes' evidence, produced by the same activities.
Design them once. The alternative is an LMS that satisfies HR, a phishing platform that satisfies nobody, and a board pack whose numbers do not reconcile with the annual filing.
Training — four regimes, one record
A completion record is simultaneously a SOX control environment element, a CMMC assessment objective, a HIPAA requirement and a quality system record. That combination sets the design constraints, and they are stricter than any single regime implies.
Design constraints
- Role-based, not universal. Plant operators, field service engineers, developers, finance and clinical affairs each need different content. Universal training satisfies the tick-box and fails the assessment objective, which asks whether people were trained for their role.
- Records are quality records. They fall under document and record control, which means retention, retrievability and change control apply. Losing history at separation is a quality finding as well as an audit one.
- Completion is necessary but never sufficient. Report it because you must; steer on behaviour because completion tells you nothing.
- Language and shift patterns. A global manufacturing footprint means translated content and modules that fit a shift, not a desk day. This is the single most common reason plant completion rates lag.
Training history lives in J&J's learning system and does not come with the business. Arriving at Day 1 with zero completion evidence fails four regimes at once, and there is no way to reconstruct it afterwards. Extract or re-baseline before the tenancy is cut.
Phishing simulation — run it as a measurement, not a trap
The metric that matters is not click rate. It is report rate and time to first report, because those are the two things that actually shorten an incident. A population that clicks and reports beats one that neither clicks nor reports, and click-rate-only programmes optimise for the wrong outcome.
How to run it
- Start early enough to have a trend by Day 1 — a single cycle is a data point, not a measurement.
- Report click rate, report rate and time to first report together. Never publish click rate alone.
- Follow up with coaching, never with punishment. Punitive programmes drive reporting down, which is the opposite of the goal.
- Tailor the pretexts to separation reality — payroll changes, benefits enrolment, new supplier portals, IT migration notices. These are exactly what attackers will use, and exactly what employees are conditioned to expect.
- Consult works councils before deploying simulation and monitoring at EU sites. In some jurisdictions this is a legal precondition, not a courtesy.
The transition window is the highest-risk phishing period this organisation will ever have. Employees expect unfamiliar systems, new domains, unexpected login prompts and legitimate emails from names they do not recognise. Every signal people normally use to detect a phish is temporarily unreliable — plan the awareness campaign around that fact specifically.
Tabletop calendar
| Exercise | Audience | The question it answers |
|---|---|---|
| Cross-boundary incident | DePuy and J&J incident leads, legal, regulatory, comms | When an event touches both estates, who leads, who notifies, and on whose clock does the deadline run? |
| Product vulnerability | PSIRT, quality, regulatory, field service, comms | A researcher reports a flaw in a deployed robotic platform. Can you triage, coordinate, advise and notify inside your published timeline? |
| Materiality and disclosure | Audit committee, CFO, GC, CISO | Facts arrive incomplete. Who determines materiality, on what record, and can you file inside the required window? |
| Plant disruption | Site leadership, OT, quality, supply chain | A site loses its manufacturing systems. Can you fail over, can you still release product, and when does it become a supply notification? |
The exercise itself is not the evidence — the after-action report with dated, owned actions is. Run at least one before Day 1 and one within the first quarter after, because the exercise that finds a charter gap is worth more than the one that goes smoothly.
Quarterly board pack and the disclosure chain
One metric set, three destinations: the audit committee quarterly, the annual governance disclosure, and the sustainability statement. Define each metric once with documented lineage, or the three will disagree and the filing is the one made under oath.
The standing pack
- Separation health — native coverage percentage, exit triggers met against services remaining, evidence completeness for the transition period.
- Control operation — emergency change ratio, access review completion with population reconciliation, open deficiencies by severity.
- Threat and vulnerability — time to remediate against published commitments, connected-product posture, open advisories.
- Behaviour — exception volume and renewal rate, phishing report rate and time to first report, shadow discovery rate, self-reported incidents.
- Regulatory — market transfer status, open observations, upcoming assessments.
- One narrative page — what changed, what worries you, what you need. The metrics inform; this page is what the committee actually discusses.
Feeding the disclosures
- Governance disclosure — board oversight structure, management's role, and the risk management processes. The described process must match what the minutes show actually happened.
- Sustainability statement — governance and business-conduct datapoints draw on the same governance structures, whistleblowing channels and training figures. Where a European sustainability reporting obligation applies, these become assured data, not marketing.
- Reconciliation — before filing, check the narrative against the minutes. A filing describing quarterly board oversight against minutes showing two meetings is a finding, and an avoidable one.
Building the board pack, the governance disclosure and the sustainability inputs as three separate exercises with three owners. They diverge within two cycles, and the divergence is visible to anyone who reads both documents.
Metrics design for the DePuy CISO organisation
Six measurement domains — connected product, enterprise IT, manufacturing and OT, regulatory and compliance, supplier security, and people — plus a temporary separation set that retires at transition exit.
Supplier security belongs in this list and is usually the weakest one. In a device company suppliers touch product, not just data: a contract manufacturer, a sterilisation partner or a component supplier whose change-notification flow-down is broken is a recall in waiting. That is a security metric with a quality consequence, and it has no natural owner unless the CISO organisation claims it.
Design rules
- A decision changes when it moves. If no one would do anything differently at 82 percent versus 74 percent, it is a status update, not a metric. Delete it.
- Defined once, with documented lineage. The same number feeds the audit committee, the annual governance disclosure and, where it applies, the sustainability statement. Three separate definitions produce three different numbers and the filing is the one made under oath.
- Coverage before outcome. Every domain needs a denominator you can defend before any percentage means anything. "94 percent of assets patched" is meaningless if the asset inventory is 60 percent complete — and worse than meaningless, because it reads as reassurance.
- Paired metrics, never singles. Report volume with age, completion with population reconciliation, click rate with report rate. Single metrics get gamed, and usually not deliberately — people optimise what is measured.
- Named owner, or it does not get reported. Every metric has one accountable human who can explain the movement. An unexplained number wastes a board's time and costs you credibility for the ones that matter.
Each metric carries: the question it answers, the owner, the source system, the calculation, the population and how completeness is established, the target and the escalation threshold, the direction of good, the review cadence, and which external disclosure it feeds. Hold this in the same register as the controls, not in a slide deck.
Connected product security
| Metric | Family | Why it earns its place |
|---|---|---|
| Products in scope with a current threat model | Coverage | The denominator for everything else in this domain. Anything not modelled is not being managed. |
| Installed base version visibility | Coverage | Percentage of deployed units whose software version is known. This is the metric that makes an advisory actionable — without it, disclosure is theoretical and field remediation cannot be planned. |
| Releases shipped with a current SBOM | Coverage | Directly evidences premarket expectations and CRA component-inventory obligations. Measure per release, not per product. |
| Known exploited vulnerabilities in released product — count and maximum age | Outcome | The single most defensible product security number. Pair count with age; a count of two, both 400 days old, is worse than a count of nine all under 30 days. |
| Time to remediate against your published commitment, by severity | Timeliness | You committed to this in submissions and customer contracts. It is measured against your promise, not an industry benchmark. |
| Advisory cycle time — report received to advisory published | Timeliness | Researchers and agencies judge you on this. It is also the number that determines whether coordination holds or a researcher goes public. |
| Field remediation completion at 30, 90 and 180 days | Outcome | Publishing a fix is not deploying one. In a hospital estate the gap between the two is measured in quarters. |
| Premarket security content accepted without rework | Operation | Rework on security sections delays clearances. A leading indicator of whether the security and regulatory functions are actually integrated. |
Enterprise IT
| Metric | Family | Why it earns its place |
|---|---|---|
| Access review completion with population reconciliation | Operation | Never report completion alone. A completed review over an incomplete population fails the SOX test entirely, and that is the most common ITGC finding there is. |
| Privileged accounts without a named owner | Coverage | The cleanest single indicator of directory hygiene, and the number that exposes a cloned directory immediately. |
| Emergency change as a share of total change | Operation | The leading indicator of ITGC trouble. During separation everything feels urgent, so this rises silently until the auditor finds it. |
| Change failure rate and rollback frequency | Outcome | Pairs with the above. High emergency change with low failure means process theatre; high both means genuine instability. |
| Vulnerability remediation within policy, by severity | Timeliness | Report against your own policy SLA, and report the aged tail separately from the average — the average always looks fine. |
| Logging coverage across in-scope systems | Coverage | Detection and audit trail both depend on it. This is also the metric that reveals which systems the separation quietly left behind. |
| Multi-factor coverage on financially significant and quality-critical systems | Coverage | Scoped deliberately — universal MFA percentages hide the systems that matter. |
| Backup restore test success rate | Operation | Backup success is not restore success. Only the restore test is evidence. |
| Mean time to detect and contain | Outcome | Only meaningful once detection is native. Until then, report the notification interval J&J actually achieved against the contractual maximum. |
Manufacturing and OT
| Metric | Family | Why it earns its place |
|---|---|---|
| OT asset inventory confidence by site | Coverage | Percentage of plant assets with a named owner and a criticality rating. Everything else in this domain is unreliable until this is high. |
| Unmanaged vendor remote access paths open into plant networks | Coverage | Almost always non-zero and almost never inventoried. Trend it to zero and keep reporting it after it gets there. |
| Sites independent of J&J for time, name and certificate services | Coverage | The most direct separation readiness signal for manufacturing, and a plant leader understands it immediately. |
| Quality-critical systems with current validated state | Operation | Sits at the security and quality boundary. A system out of validated state cannot support product release. |
| Production-impacting security or availability events | Outcome | The number the business cares about. Report it alongside minutes of production lost, not as a count alone. |
| Segmentation conformance against the target zone model | Operation | Measures whether the network cut actually delivered isolation or just moved the boundary. |
Regulatory and compliance
| Metric | Family | Why it earns its place |
|---|---|---|
| Obligation coverage | Coverage | Percentage of registered obligations with a mapped control that is actually operating. Report orphans in both directions — obligations with no control, controls with no obligation. |
| Evidence completeness for the current audit period | Coverage | Not overall completeness, which will look fine and hide the transition-period gap that matters. |
| Assessment objectives with adequate and sufficient evidence | Coverage | The CMMC framing, but useful across every regime. It forces the question of whether an artefact actually answers the objective. |
| Open deficiencies and observations by severity and age | Outcome | Age is the signal. A stable count with rising age is a programme quietly failing. |
| Registration transfers landed against revenue at risk | Timeliness | Report revenue exposed, not registration count. A board acts on the first and ignores the second. |
| Regulatory notification timeliness | Timeliness | Adverse event, breach and vulnerability reporting against each statutory clock. One miss is a finding regardless of the rate. |
Supplier security
Enterprise supplier programmes tier by data sensitivity and spend. That is the wrong model for a device company, where a supplier who touches product carries recall exposure even if they never see a byte of personal data. Tier on both axes and report them separately.
| Metric | Family | Why it earns its place |
|---|---|---|
| Supplier tiering completeness on both axes | Coverage | Data sensitivity and product contact. A sterilisation partner is low on one and critical on the other, and a single-axis model misses it entirely. |
| Critical suppliers with a current security assessment | Coverage | Post-separation this drops sharply, because J&J's assessments are J&J's work product and may not transfer. Expect a visible cliff and plan the re-assessment queue against it. |
| Critical suppliers with executed security and data protection terms under the DePuy entity | Coverage | Novation moves the contract; it does not always move the security schedule. This metric finds the gap. |
| Product-contact suppliers with vigilance and change-notification flow-down in place | Coverage | The device-specific one, and the one that becomes a recall. A supplier who does not know to notify you of a process change is an unmanaged product risk. |
| Supplier-notified incidents within the contractual window | Timeliness | Measures whether the terms you negotiated actually function. Most organisations never check. |
| Time to revoke supplier access after offboarding | Timeliness | Directly testable, frequently poor, and a standard audit sample. |
| Single-source and sole-sterilisation concentration | Coverage | Resilience rather than security in the narrow sense, but it belongs in the same conversation and no other function reports it. |
| Fourth-party visibility for critical suppliers | Coverage | Where your critical supplier's critical supplier is known. Low is expected; unknown-and-unmeasured is the problem. |
Supplier assessment coverage will look excellent on Day 1 because the register was inherited, and then collapse when someone checks whether DePuy is actually entitled to those assessment reports. Baseline the metric on assessments DePuy holds and owns, not on assessments that exist somewhere.
Separation set — temporary, retires at exit
- Native coverage — share of controls with no J&J dependency. The single cleanest indicator of separation health.
- Exit triggers met against services remaining — if triggers lag the schedule, you are heading for a date-driven exit and a material weakness.
- Evidence completeness for the transition period specifically — the gap that overall completeness hides.
- J&J evidence delivery against the agreed cadence — measures whether the delivery obligations you negotiated are working, while there is still time to escalate.
- Inherited exceptions re-decided against expired by default — tells you whether governance is actually operating or just recording.
- Licensed documents remaining against the licence countdown — one number, one date, unambiguous.
- Sites cut against sites rehearsed — if cuts are running ahead of rehearsals, stop.
These metrics should disappear at transition exit, and their removal should be a minuted decision. Separation metrics that survive into steady state become noise that crowds out the ones that matter.
People and culture
- Phishing report rate and time to first report — the two that actually shorten an incident. Report click rate alongside, never alone.
- Exception volume, renewal rate and aged exceptions — the clearest measure of whether the paved path is faster than the workaround.
- Shadow technology discovery rate — rising discovery with falling onboarding time means the programme works. Flat is never the true number.
- Self-reported incidents as a share of total — a rising share is good news reported as bad news. Say so explicitly or the board will misread it.
- Time to onboard a tool through the approved path — the friction metric. It predicts the shadow discovery rate one quarter out.
- Training completion by role — reported because four regimes require it, never used to steer.
What goes to which audience
| Audience | Cadence | Metrics | What they see and what it decides |
|---|---|---|---|
| Board / Audit Committee | Quarterly | 8–12 | Native coverage, evidence completeness, open deficiencies by age, obligation coverage, time to remediate against commitment for released product, known exploited vulnerabilities and their age, critical supplier assessment and flow-down coverage, emergency change ratio, registration transfer revenue at risk, one behaviour composite — plus one narrative page. Decides funding, risk acceptance and the Day 1 gap position. |
| Quality & Regulatory Compliance Committee | Quarterly | 10–14 | The product security set in full, validated state, regulatory notification timeliness, supplier flow-down, field remediation completion, installed base visibility. Decides recall and field action posture and inspection readiness. |
| Security Steering Committee | Monthly | 25–35 | Every domain at working depth, plus the separation set. Decides exceptions, prioritisation and transition exit readiness. |
| Transition Governance Board | Fortnightly | 7 | The separation set only, with J&J present. Decides service extensions, exit sequencing and escalations. |
| Site and BISO councils | Monthly | Local slice | Their own OT inventory, remote access, segmentation and behaviour numbers. Decides local remediation priority. |
| Operational dashboards | Continuous | All | Everything, unaggregated, for the people doing the work. |
The board pack feeds the annual governance disclosure and, where a European sustainability reporting obligation applies, the governance and business-conduct datapoints in the sustainability statement. Before filing, reconcile the narrative against the minutes. A filing describing quarterly board oversight against minutes showing two meetings is a finding, and an entirely avoidable one.
Anti-metrics and the maturity ramp
Do not report these
- Attacks blocked, alerts generated, emails filtered. Activity volume that no decision depends on. It also invites the question of what got through, which you then answer badly.
- Training completion alone. Necessary as evidence, useless as a signal.
- Raw vulnerability counts without age or exploitability. The count is a function of scanner coverage, so improving coverage looks like getting worse.
- Maturity scores presented as progress. A self-assessed score moving from 2.6 to 2.9 is not evidence of anything, and boards have learned to discount it.
- Percentages with an undefended denominator. The most common way a security report misleads without anyone intending to.
What you can honestly measure, and when
| Period | Measurable | What to say about the rest |
|---|---|---|
| Day 1 | Coverage and completion | Denominators and control operation. Do not promise outcome metrics — you have no baseline and no history, and claiming otherwise is the fastest way to lose a board's trust. |
| +6 months | Timeliness | Enough operating history for SLA adherence and cycle times to mean something. |
| +12 months | Outcome | Detection and containment times, remediation completion, incident trends — once detection is native and a full period exists. |
| +24 months | Leading indicators | Friction predicting shadow discovery, exception aging predicting deficiencies, supplier concentration predicting disruption. |
Name what you can and cannot measure yet, and when each becomes available. A CISO who says "we can report coverage now and outcomes from month twelve, here is why" is more credible than one who produces a full dashboard on Day 1 that nobody can trace to a source system.
Eighteen months to Day 1, then twenty-four to steady state
Anchored to a separation completing in the second half of 2027. Lanes: GOV governance DOC documents CTL controls REG regulatory MFG manufacturing SOX financial controls.
Build the obligation register and find the long poles
- DOC Obligation register from contracts, filings, customer security schedules and every registration in every market. Read exercise, not design exercise.
- REG Registration inventory with lead times. Start China, Japan and the notified body conversation immediately — they set the critical path.
- MFG Validation-state mapping onto the system migration plan. This is the earliest honest answer to whether the date holds.
- GOV Stand up the Information Security Steering Committee in provisional form so it has a minute trail before Day 1.
- CTL Draft the twelve-domain catalogue against the obligation register only. Import nothing.
- SOX Engage the prospective external auditor on control environment scoping. Their view of in-scope systems changes your plan.
Tag severability and shape the transition schedules
- CTL Tag every control with operator, severance state, evidence custody and exit trigger. The parent-operated set is now your transition scope, derived bottom-up.
- GOV Reconcile that set against the commercially negotiated service schedule. The delta is a finding — escalate it.
- DOC Negotiate evidence delivery obligations for every parent-extract control. Before signature.
- MFG Passive traffic capture at every plant boundary.
- REG Notified body slot booked; multi-market audit programme slot booked.
- GOV Board committee charters drafted: Audit, Quality & Regulatory Compliance.
Evidence repository live, policy rebuild starts
- CTL Evidence repository stood up and receiving. Parent-operated controls start depositing artefacts now, not at Day 1. This is the rule that saves the first audit.
- DOC Apex policy and the rebuild set drafted. QMS-adjacent documents start first — they carry the longest change-control cycle.
- GOV Board committees formally constituted; Transition Governance Board charter agreed with the parent.
- SOX ITGC design walkthroughs on the target system landscape.
- MFG Local time, name and certificate services rebuilt at the pilot site.
Build and rehearse
- CTL Identity and logging foundation native. Everything downstream depends on the entity owning its own directory, its own logs and its own joiner-mover-leaver process.
- MFG Rehearse the network cut at the smallest site during a planned shutdown.
- REG Establishment registrations, clearance transfers and gateway account in progress; device identifier record updates underway.
- DOC Harvest set rewritten; reference sweep complete; transitional licence expiry dates logged as controls.
- GOV Every inherited exception re-decided or scheduled to expire.
- SOX First internal test cycle on native controls to establish operating history.
Freeze, prove, and agree the Day 1 gap position
- GOV Audit Committee approves the minimum-viable-compliance position with the documented gap plan, owners and dates. Get it in the minutes.
- CTL Cross-boundary incident simulation. The most likely early failure is an incident touching both entities where nobody knows who notifies whom.
- REG Disclosure policy, security contact and key material published under the new entity, staged for Day 1 activation.
- MFG Site cuts sequenced, rollback plans tested, certificate expiry inventory clean.
- DOC Policy library approved and published. Training assigned.
The entity asserts for itself
- Policy library live under the new name. Registers populated. Committees already meeting with a minute history.
- Evidence repository holding artefacts for the pre-separation period — the thing that makes your first audit testable.
- Documented gaps with owners and dates, board-approved. Undocumented gaps become findings; documented gaps become a roadmap.
Exit by control, not by calendar
- CTL Work the exit trigger queue. Report native coverage monthly to the Audit Committee.
- SOX First full test cycle; management's assessment prepared on the deferred schedule but with controls operating from Day 1.
- DOC Replace every licensed document before the transitional licence expires.
- REG Long-lead market transfers land. Escalate any that will not.
- GOV First independent assurance engagement — an observation window has to start somewhere.
Steady state and honest retrospection
- Management system certification achieved; independent assurance report issued over a full period.
- Transition Governance Board dissolved; committee architecture reviewed and two or three bodies retired.
- Separation-era technical debt register worked down deliberately, with the shadow technology discovered in the cutover window either adopted or removed.
- Obligation register re-run against the control catalogue. In a newly separated entity, obligations move faster than controls for the first three years.
Twenty traps
Ordered by how often they are found late. Set status as you confirm each one is handled.
1 · Cleaning the parent's policies imports the parent's architecture
The policy reads fine after a find-and-replace, but it still assumes an enterprise security operations centre, a global privacy office, a group legal function and a corporate insurance tower. You end up asserting controls you have no ability to operate — which is worse than having no policy, because now it is a documented commitment you are failing.
Rebuild every document that asserts. Harvest only documents that instruct. Test each harvested document with one question: can the new entity actually perform everything this document commits it to, on Day 1, with the people and systems it will have?
2 · Evidence for the audit period lives in systems you are about to lose
Your first audit covers a period that includes the transition. The evidence sits in the parent's identity platform, ticketing system and log store. When access ends, so does your ability to produce it — and the auditor will still ask.
The evidence repository is native on Day 1 for every control, regardless of who operates the control. Negotiate delivery obligations with format, cadence and remedy before the transition agreement is signed.
3 · Cloned validated systems arrive unvalidated
A copy of the enterprise system in a new environment under a new legal entity is a new system. Validation does not travel with the data. Until requalification is complete you cannot release product against it.
Map validation state onto the migration plan in the first quarter of the programme, and give the requalification schedule its own owner reporting to the Quality & Regulatory Compliance Committee.
4 · The electronic submissions account blocks adverse event reporting
The new entity needs its own gateway account, credentials and completed test-submission cycle before it can file electronically. Weeks of lead time, discovered late, and it sits directly in front of a statutory clock.
Open it twelve months out and run a live test submission. Keep a documented manual fallback for the first ninety days.
5 · Intra-group data transfers lose their legal basis on Day 1
Transfers that ran under group-level binding rules or an intra-group agreement become third-country transfers the moment the entity leaves the group. Invisible until someone asks which mechanism covers the flow.
Standard contractual clauses and transfer impact assessments executed before Day 1, your own record of processing activities, and a data protection officer appointed where required.
6 · Market registrations that will not transfer inside the transition window
Several major markets treat a manufacturer change as a new registration with full technical review. Lead times can exceed the entire transition period, and the consequence is a revenue stop in a market you cannot serve.
Build the market-by-product matrix in month one. Force the board decision about bridging arrangements twelve months out, while it is still a strategy rather than a crisis.
7 · Notified body capacity, not notified body approval
The certificate transfer is achievable. Getting an audit slot is the constraint. Bodies remain heavily booked, and a missed slot cascades into every market that relies on the certificate.
Book eighteen months out and treat the slot as a fixed programme milestone that other work plans around.
8 · The transition schedule and the control dependency map disagree
Corporate development negotiates services top-down from a functional view. Your control catalogue produces a bottom-up dependency list. They will not match, and the controls whose dependency was never negotiated simply stop working at separation.
Reconcile the two lists before signature and escalate the delta as a formal finding to the Transition Governance Board.
9 · Exiting a service on the contractual date with no operating history
The service ends because the contract says so, the replacement control has never operated, and the first audit finds a testable population of zero. This is the most common route to a material weakness in a separation.
Exit triggers are control tests, not dates. No cut without two operated cycles or ninety days of continuous evidence.
10 · The cloned directory inherits the parent's mess
A copied identity estate brings orphaned accounts, parent service accounts, stale privileged groups and nested entitlements nobody can explain. All of it becomes your access review population and your findings.
Migrate identities selectively against an approved population rather than cloning. It costs more up front and it is the single best predictor of a clean first ITGC opinion.
11 · Emergency change becomes the normal change path
Everything during separation is urgent, so everything becomes an emergency change with retrospective approval. The unapproved-change population explodes and the change control test fails.
Cap emergency change as a percentage of total, report it monthly to the steering committee, and require post-implementation review inside five working days with no exceptions.
12 · The plant network cut stops production
Time synchronisation, name resolution, certificate services, licence servers and vendor support paths traverse the parent's core in ways no diagram shows. Cutting without a capture-based map halts lines.
Passive capture at every plant boundary over a full production cycle. Rebuild time, name and certificate services locally first. Rehearse at the smallest site during a planned shutdown.
13 · Certificate expiry and mail cutover
Two of the most frequently reported cutover failures across large separations. Both preventable, both capable of taking out production or customer communications for days.
Certificate inventory with expiry dates as a named deliverable. Domain and mail cutover treated as a rehearsed, reversible change with a tested rollback.
14 · Complaint intake breaks the reporting clock
Complaints about your devices arrive at parent-operated call centres during transition. The statutory clock runs from awareness, and awareness now sits with a third party you do not control.
Define the handoff, the timestamp of record and the escalation path in the transition agreement. Test it with seeded complaints before Day 1.
15 · Device identifier records tied to the parent's organisation identifier
Identifier records key off the labeller's organisation identifier. A change of legal manufacturer cascades into record updates and, in some cases, new identifiers and relabelled product. Getting it wrong degrades recall traceability.
Scope this in the first quarter with labelling and packaging in the room. It is a supply chain project, not a data project.
16 · Supplier quality agreements name the parent
Vigilance and change-notification flow-downs run to the parent. A supplier who does not know to notify you of a process change is a recall in waiting, and supplier audit reports are the parent's work product you may not be entitled to.
Novate critical supplier and sterilisation agreements first, prioritised by product contact. Budget for re-auditing rather than assuming report transfer.
17 · Reading the first-year reporting relief as a design deferral
A newly listed company gets relief on when it must report on internal control. Teams hear a year of grace. But the financial statement audit relies on those controls from Day 1, and the first assessment looks back over a period that includes the transition.
Design and operate from Day 1. Use the relief for reporting timing only, and say so explicitly in the Audit Committee minutes so nobody plans against the wrong reading.
18 · Cyber disclosure while the parent operates detection
A newly listed entity owes timely disclosure of material incidents. During transition, detection, triage and often the first assessment of scope sit with the parent — but the disclosure obligation is yours, on your clock.
Write the materiality determination path into the Disclosure Committee charter and the transition agreement together, with a maximum notification interval from the parent. Rehearse it in the cross-boundary incident simulation.
19 · Transitional document licence expires with the library half-replaced
Separation agreements typically grant a limited, time-boxed licence to use the parent's documentation. The date passes, the replacement programme slipped, and the entity is operating on documents it no longer has the right to use — with the parent's name still in the footer.
Log the licence expiry as a control with an owner and a countdown. Report replacement progress against it monthly to the steering committee.
20 · Two cultures form in the first six months
One group wants the parent's rigour without the parent's funding. The other reads separation as permission — smaller company, fewer rules. Both are reacting to the same absence of a stated position, and whichever wins becomes permanent.
Name the non-negotiables early and few — four or five, stated plainly, enforced without exception. Everything else is a paved path where speed is the control. Then measure behaviour rather than training completion: exception volume, time-to-remediate, shadow technology discovery rate, self-reported incidents. Every organisation has a car going around the barrier. How routine that has become is your real security culture score.
Working notes
Saved in this browser. Use Export JSON to take status and notes with you.
Open questions to resolve against the source documents
- Spin, sale or dual track — the governance architecture differs materially. A listed spin needs the full board committee structure and disclosure machinery; a sale to a strategic buyer inherits the buyer's.
- Which entity holds each manufacturing site's registration at separation, and does any site serve both entities?
- Transition service duration by function — and specifically whether it exceeds the longest market registration lead time.
- Which connected products fall in scope for premarket security requirements, and which submissions are in flight at separation.
- Scope of the transitional documentation licence and its expiry.
- Whether the parent's independent assurance reports cover any service the new entity will consume, and for how long.