BitSense · vCISO Advisory

DePuy Synthes — GRC Separation Blueprint

Designing the governance, risk and compliance function for the new entity: what to rebuild, what to harvest, which committees to stand up and when, and where the FDA, notified body, manufacturing and global registration dependencies bite. Built for a device separation completing mid-to-late 2027.
Companion to the Spin-Off Separation Tracker Day 1 target: H2 2027 Saved locally in your browser
0 of 0 done

The whole programme in order

Twenty-nine moves, top to bottom, from eighteen months out to a year past separation. Each one is tagged with what kind of work it is, what it depends on, and the trap or delay attached to it.

Read it as a sequence, not a schedule. Several moves run in parallel — what matters is that nothing starts before the thing it depends on.

The answer: rebuild what asserts, harvest what instructs, rebuild every register

Neither pure option is right. Rebuilding 400 documents from nothing burns the eighteen months you don't have. Cleaning the parent's library imports the parent's architecture — controls that assume global shared services, an enterprise SOC, a corporate legal function and a group risk appetite that the new entity will not have.

The dividing line is what the document does. A policy asserts — it is a commitment made by a named legal entity to a regulator, a customer, an auditor or a board, and an assertion inherited from a parent is a commitment to operate a control you may have no ability to operate. A work instruction instructs — how to qualify a CNC controller or run a sterility validation is good engineering that survives a change of ownership. A register records decisions — and every decision in the parent's risk, exception and vendor registers was made against the parent's appetite, capital base and insurance tower. Registers are always rebuilt.

Expected split across a device GRC library

DispositionShareWhat falls hereThe rule
Rebuild~25% Board and committee charters; the information security policy and every subordinate policy; risk appetite statement; delegation of authority; code of conduct; all registers (risk, control, exception, evidence, asset, vendor, processing activity); SoA; disclosure controls. Anything that names the entity, asserts to an outside party, or records a decision.
Harvest~55% Standards and procedures: access management, change control, vulnerability management, incident response runbooks, secure SDLC, CSV/CSA protocols, supplier quality procedures, complaint handling, CAPA, design control SOPs. Keep the technical content, replace every entity reference, system reference, role name and escalation path. Assume 30–50% rewrite by volume.
License then replace~15% Deeply technical, entity-neutral material: cryptographic standards, secure coding guidelines, hardening baselines, test method validations, engineering specifications. Use under the separation agreement's transitional IP licence, replace before it expires. Track the expiry date as a control.
Retire~5% Documents that exist only because of group structure: shared-service SLAs, intra-group transfer procedures, group-level reporting instructions, sector-alignment standards. Do not migrate. They describe a structure that ends on Day 1.
The QMS is a different animal

Everything above applies to the GRC library. Quality system documents live under change control and, once effective, carry validated state. You cannot quietly "clean" an SOP referenced by a device master record — each change is a controlled change with an impact assessment, a training record and, where it touches a validated system, revalidation. Budget three to four times the cycle time for QMS-adjacent documents and start them first. Under the harmonised quality management system regulation now in force, your QMS document architecture should be expressed in ISO 13485 structure, which is also the structure a notified body and an MDSAP auditor will expect.

Triage a specific document

Does the document assert something to an outside party — a regulator, notified body, customer, auditor or the board?
How much of it depends on the parent's structure — shared services, group functions, sector reporting lines, enterprise tooling?
Is it inside the quality system or referenced by a device master record, design history file or validated system?
Does it record decisions — accepted risks, approved exceptions, rated vendors, scoped assets?
Answer the four questions and the disposition appears here.
Sequencing rule

Do not start with policies. Start with the obligation register — every regulatory, contractual, certification and financial commitment the entity carries on Day 1 — and let it tell you which policies you actually need. A separated device company typically discovers it needs 25 to 35 policies, not the 120 it inherited. The parent's library grew by accretion over decades of acquisitions; you have the rare chance to not repeat that.

Document disposition register

Work this top to bottom. Set status on each line as you go. The rebuild set is small and non-negotiable; the harvest set is where the volume and the schedule risk sit.

Governance layer — rebuild, no exceptions

Charters, appetite, authority. These define the entity and cannot be inherited.
Audit Committee charter
Rebuild · Must name cyber risk oversight, ICFR responsibility and the disclosure decision path before the first board meeting
Quality & Regulatory Compliance Committee charter
Rebuild · Board-level; standard for a listed device company and expected by investors given recall exposure
Enterprise risk management framework and risk appetite statement
Rebuild · The parent's appetite reflected a diversified balance sheet the new entity does not have
Delegation of authority matrix
Rebuild · Drives every approval control in the ITGC set; get it before you design access controls
Information Security Steering Committee charter
Rebuild · The single most-cited artefact in a first-year SOC 2 and ISO 27001 audit
Disclosure Committee charter and cyber materiality procedure
Rebuild · Required for a newly listed entity; the materiality path must work while the parent still runs the SOC
Code of conduct and speak-up policy
Rebuild · Culture anchor; also an ICFR control environment element the external auditor will test

Policy layer — rebuild, sized to the obligation register

Target 25–35 policies. Each must trace to at least one external obligation.

Structure as one apex policy with subordinate policies beneath it. The apex is what you show a customer or an auditor first; the subordinates carry the detail. Every subordinate policy must name its owner, its review cadence, the committee that approves it, and the obligations it satisfies.

Apex

Information Security Policy
Approved by the board or Audit Committee, not by the CISO. This is what makes it an assertion.

Subordinate set — the minimum viable list

Access control · Acceptable use · Asset management · Cryptography and key management
Rebuild the policy statement; harvest the underlying standards
Change management · Configuration and hardening · Network and infrastructure security
Change management is a SOX ITGC pillar — write it with the external auditor in the room
Secure development · Product security · Software bill of materials and AI bill of materials
Scope carefully: implants are not cyber devices, but robotics, navigation and digital surgery platforms are
Vulnerability management · Coordinated vulnerability disclosure · Postmarket surveillance interface
The CVD policy is externally published and must carry the new entity's contact and PGP key on Day 1
Incident response · Business continuity · Disaster recovery · Crisis communications
Must work across the transition boundary while the parent operates detection
Third party risk · Supplier security · Contract manufacturer and sterilisation partner security
Device-specific: your suppliers touch product, not just data
Data classification · Privacy · Records retention · Data transfer
Retention must satisfy device record-retention rules, not just tax and employment
Computer system validation and electronic records / electronic signatures
The bridge document between IT security and the quality system
AI governance · Operational technology security · Physical and environmental security
OT policy is separate from IT policy or it will be ignored by manufacturing
Human resources security · Security awareness and culture · Exception management
Exception management is how you avoid re-accumulating the parent's exception backlog

Register layer — rebuild every one

A register is a record of decisions. Inherited decisions are void on Day 1.
Obligation register
Build this first. Everything else derives from it.
Control catalogue with severability attributes
See section 4
Risk register
Re-score every inherited risk against the new appetite; do not migrate scores
Exception register
Every parent-approved exception expires on Day 1 unless re-approved. Make this explicit in policy.
Evidence register — artefact, generating system, custody, retention
The highest-leverage register in a separation. See the evidence rule in section 4.
Asset inventory — IT, OT, medical device fleet, software, AI systems
OT and product assets are usually absent from the parent's IT inventory
Third party register with re-assessment status
Parent assessments are parent work product and may not transfer
Record of processing activities and transfer impact assessments
See the intra-group transfer trap in section 9
Statement of Applicability
Cannot be inherited — it is the certified scope of a management system that will not exist yet
Regulatory registration inventory — every registration, licence, certificate, per country, per site
Owned by regulatory affairs, but GRC must hold a copy because it drives the obligation register

How to run the harvest with an AI assistant

Where leverage is real and where it manufactures risk

Where it earns its keep

  • Obligation extraction. Feed contracts, filings and customer security schedules; extract every commitment into a structured register with a source citation on each row. This is the highest-value use and the one most people skip.
  • Reference sweep. Find every mention of the parent, its systems, its role titles and its escalation paths across the harvested library. Mechanical, exhaustive, and the thing humans miss most.
  • Cross-regime mapping. Generate the first-pass control-to-regime mapping, then have a human confirm. Mapping is a good machine task because it is recall-bound, not judgement-bound.
  • Gap analysis. Compare the harvested document against the obligation it is supposed to satisfy and list what is missing. Faster and more complete than a reviewer working from memory.
  • Consistency enforcement. Terminology, defined terms, numbering, cross-reference integrity across a 200-document set.
  • Draft-to-house-style conversion. Rewriting harvested procedures into the new entity's voice and template.

Where it must not be used unsupervised

  • Risk acceptance and appetite. These are governance decisions with named accountable humans. Generated risk scores are indefensible in an audit.
  • Anything inside the quality system. QMS documents carry validated state and change-control history. Generated content entering a controlled document without a controlled change is a finding waiting to be written.
  • Regulatory determinations. Whether a product is a cyber device, whether a change is a new submission, whether an event is reportable — these are regulatory affairs judgements with legal consequences.
  • Evidence. Never generate, summarise or reconstruct evidence. Evidence is produced by systems, not written.
Practical control

Add one field to every document record: ai_assisted with values none / drafting / review / extraction, plus the name of the human approver. Auditors are beginning to ask. Having the answer already recorded turns an awkward question into a two-minute demonstration of your change control.

Committee architecture

Four tiers. Board committees own oversight and cannot be delegated. Executive committees own decisions. Operating councils own execution. One cross-boundary body governs the relationship with the former parent and dissolves at transition exit.

Stand these up before Day 1, not on it. A committee whose first meeting is also its first crisis has no operating history, no minute trail and no demonstrated effectiveness — and minutes are the primary evidence that governance controls operated.

Audit Committee

Board tier · quarterly, plus a monthly separation session through transition exit
BoardRequiredStand up at T-12

Owns

  • Internal control over financial reporting, including the general IT control set
  • External auditor relationship and the scoping conversation for the first audit
  • Internal audit charter, plan and independence
  • Cybersecurity risk oversight and the disclosure determination path
  • Whistleblower and ethics escalation

Membership

Independent directors only, at least one financial expert. The CISO must have a standing agenda slot and an executive-session right — not a slot at the invitation of the CFO. In a device separation the committee should also see the head of quality at least twice a year, because quality failures and financial exposure are the same conversation.

Separation-specific duty

Approve the Day 1 minimum-viable-compliance position: which obligations are fully met at separation, which are met by transitional arrangements, and which carry a documented gap with an owner and a date. This approval is the thing that converts an undocumented weakness into a governed roadmap. Get it in the minutes.

First meeting agenda

  1. Charter adoption and independence confirmations
  2. External auditor scoping — control environment, in-scope systems, transition boundary treatment
  3. ICFR readiness assessment and the timing of management's first assessment
  4. Obligation register walkthrough and the Day 1 gap position
  5. Cyber disclosure procedure — who decides materiality while the parent operates detection
  6. Internal audit resourcing decision: build, co-source or outsource
Trap

A newly listed company is generally not required to include management's assessment of internal control in its first annual report, and the auditor attestation follows later still. Teams read this as a year of grace. It is not. The controls must be designed and operating from Day 1 because the financial statement audit itself relies on them, and because your first assessment will look back over a period that includes the transition. Treat the relief as a reporting deferral, never a design deferral.

Quality & Regulatory Compliance Committee

Board tier · quarterly
BoardDevice-specificStand up at T-12

Owns

  • Quality system effectiveness across all manufacturing sites
  • Regulatory inspection readiness and the status of every open observation, warning letter or consent decree exposure
  • Recall and field action oversight
  • Postmarket surveillance and vigilance performance, including reporting timeliness
  • Product security posture for connected devices, sitting alongside the Audit Committee's enterprise cyber oversight

Why it is separate from the Audit Committee

Because the failure modes are different and the expertise is different. A committee that has to choose between reviewing revenue recognition and reviewing a rising complaint trend will always choose revenue. In a device company, the quality committee is the one that catches the problem eighteen months before it becomes a financial one.

Separation-specific duty

Own the regulatory transfer plan — every registration, certificate and licence in every market, with a named owner, a lead time and a revenue-at-risk figure. This is the committee that must be told when a market registration will not transfer inside the transition window.

Interface with security

Two standing items: connected-product vulnerability posture with time-to-remediate against your published commitment, and the status of computer system validation for any quality-critical system being migrated or re-hosted. Both are places where a security decision becomes a regulatory one.

Information Security Steering Committee

Executive tier · monthly through transition, then every six weeks
ExecutiveAudit evidenceStand up at T-15

Owns

  • Approval of the control catalogue and every policy below the apex
  • Risk acceptance within delegated limits; escalation above them
  • Exception approval, renewal and expiry
  • Security investment prioritisation and the roadmap for the build-by-date control set
  • Transition exit readiness decisions — this committee decides whether a control has operated long enough to cut the parent dependency

Membership

Chaired by the CISO or the chief risk officer. Voting members: CIO, chief quality officer, head of regulatory affairs, general counsel, CFO delegate, head of manufacturing or supply chain, head of R&D or product. In a device company, quality and regulatory are voting members rather than guests — if they are guests, the committee cannot make a decision that touches a validated system, which is most decisions.

What it must produce as evidence

  • Minutes with named attendees, decisions and dissents — not a slide deck
  • A decision log with an identifier per decision, referenced from the risk and exception registers
  • A quarterly attestation pack that feeds the Audit Committee
Design note

Give this committee a hard rule: no exception is approved without an expiry date and a named owner, and no exception is renewed twice without escalation to the Audit Committee. Separations generate exceptions at a rate no steady-state program ever sees, and this single rule is what stops the transition-era backlog from becoming permanent.

Quality Management Review

Executive tier · at planned intervals, practically quarterly
ExecutiveRegulator expects itMandatory

Not optional and not something you design freely — the quality management system regulation and ISO 13485 both prescribe management review inputs and outputs, and an inspector will ask for the records. The new entity needs its own management review cycle running before Day 1, with its own top management named, because a review conducted by the parent's management is not a review of your quality system.

Security's inputs to it

  • Product security posture and open vulnerabilities in released product
  • Validation status of quality-critical computer systems
  • Data integrity incidents affecting quality records
  • Supplier security findings for suppliers that touch product
Trap

Teams treat management review as a quality-only ritual and keep security out of it. Then a data integrity observation lands and there is no record that security ever reported into the quality system. Get a standing security input on the agenda from the first cycle — it is cheap, and it is the evidence that your two systems are connected.

Transition Governance Board

Cross-boundary · fortnightly, dissolves at final exit
TemporaryHighest riskJoint with parent

Joint body with the former parent, governing every service the parent continues to provide. Treat the parent as your largest and most critical third party, because that is exactly what it now is.

Owns

  • Service performance against the agreed schedules
  • Evidence delivery — the artefacts the parent owes you for controls it operates on your behalf
  • Deficiency escalation: when a parent-operated control fails, whose deficiency is it and who reports it
  • Exit sequencing and the trigger conditions for cutting each service
  • Incidents that cross the boundary, including who notifies which regulator

The four questions its charter must answer

  1. When a control the parent operates fails, who records the deficiency and in whose register?
  2. When an incident touches both entities, who leads, who notifies, and on whose clock does the reporting deadline run?
  3. What evidence does the parent deliver, in what format, at what cadence, and what happens when it does not?
  4. Who can extend a service, at what cost, and with whose approval?
Trap

Audit rights are not evidence delivery. A clause granting you the right to audit the parent gets you the ability to ask; it does not get you the quarterly access review extract in a format your auditor can test, on the fifth working day, every quarter, for the full audit period. Negotiate delivery obligations with format, cadence and remedy — and negotiate them before signature, because you will not get them afterwards.

Operating councils

Working tier · cadence varies
Execution

Change Advisory Board · weekly

The most audit-visible control you will operate. Emergency change is where separations generate ITGC findings — everything is urgent, so everything becomes an emergency change, and the population of unapproved changes explodes. Cap emergency change as a percentage of total and report it monthly.

Data Governance Council · monthly

Owns classification, retention, privacy and the record of processing. In a device company it also owns quality record integrity, which is why it must include a quality representative.

Product Security Board · monthly

Scoped to connected product only — robotics, navigation, digital surgery, patient-facing applications. Owns threat modelling, the software bill of materials programme, disclosure decisions and premarket security content. Keep it separate from the enterprise steering committee; the audiences and the regulators are different.

AI Governance Council · monthly

Owns the AI inventory, use-case intake and risk classification. Needed on Day 1 rather than later, because separation-era productivity pressure is precisely when unreviewed AI tooling enters manufacturing and clinical workflows.

Site Security & OT Councils · monthly, per major site

One per significant manufacturing site, chaired by the site leader, not by IT. Plant managers do not attend committees run from headquarters, and OT security fails without them.

Third Party Risk Committee · monthly

Runs the novation queue during separation and the assessment queue afterwards. Prioritise by data sensitivity and product contact, not by contract value.

Sizing

Eleven bodies looks heavy until you count what they replace: in the parent, this work was absorbed by dozens of group functions. The discipline is that each body has a charter, decision rights, a quorum and minutes — and that any body which has not made a decision in two consecutive meetings gets merged into another. Review the whole architecture at transition exit and expect to retire two or three.

Relationships — the actual operating system of a separation

In a separation you have almost no authority. The control catalogue is yours, but the evidence sits with J&J, the validation state sits with quality, the plant dependencies sit with a controls engineer nobody has introduced you to, and the notified body slot sits with a scheduler who has never heard your name.

Map people by what you need from them, not by the org chart. Then work out who can introduce you. Cold approaches inside a separation get deprioritised by people who are already at capacity; a warm handoff from someone whose deadline they share does not.

How to find who to reach out to

Six methods that work when the org chart doesn't

The person you need is rarely the person the org chart points at. Six ways to find them:

Follow the evidence

For every control tagged J&J-extract, ask who generates the artefact today. Not who owns the system — who runs the query. That person is your real counterparty for the next two years, and they are usually three levels below the name on the service schedule.

Follow the certificate

Every certificate, registration and licence has a named signatory and a named scheme or account manager on the issuing side. Both are findable in the certificate itself. The account manager controls your audit slot.

Follow the ticket queue

Pull the top fifty tickets by volume for each plant and each function. The assignment groups tell you who actually operates the estate, and the recurring requesters tell you where the friction is. This finds shadow ownership faster than any interview.

Follow the invoice

Accounts payable knows every vendor, every renewal date and every contract owner. It is the most complete and least used inventory in the company, and it surfaces the systems nobody declared.

Ask the auditor

Internal audit and the external auditor have already spent years identifying who they go to for each control. Ask for their contact list. It is free, accurate and pre-vetted.

Ask who gets blamed

When something breaks in a given area, who gets called at two in the morning? That is the person who knows how it actually works, regardless of title.

Practical rule

Ask for a fifteen-minute call with one specific question, not a meeting to "discuss the separation". Specific asks get answered; open-ended ones get deferred until after Day 1, which is too late.

Inside DePuy — the coalition you cannot build without

Nine relationships, each with the ask and what breaks without it
WhoWhat you need from themWhat breaks without it
CFO and ControllerITGC scope, the external auditor relationship, and funding for the build-by-date control set.You design controls the auditor will not accept, and you find out in the first test cycle.
Chief Quality OfficerAccess to the quality change control process and a standing security input to management review.Every procedure change stalls, and security is invisible to the inspector.
Head of Regulatory AffairsThe registration inventory, submission status, and which products are in cybersecurity scope.You cannot build the obligation register, and connected-product commitments go unowned.
CIO and infrastructure leadsThe migration plan, application ownership, and control over sequencing.Identity, logging and evidence get built after the systems they are supposed to cover.
General CounselSeparation agreement terms, the documentation licence, disclosure path, and privacy transfer mechanisms.You miss the evidence-delivery window and the licence expiry, both irreversible.
CHROThe HR system as the joiner-mover-leaver source of truth, plus training records and works council navigation.Access controls have no authoritative population and EU changes stall on consultation.
Head of Manufacturing and site leadersShutdown windows, plant access, and sponsorship of the site security councils.Network cuts happen without rehearsal and OT security is ignored on the floor.
Head of R&D and digital surgeryProduct security scope, threat models, and the software bill of materials programme.Connected products ship with unowned postmarket obligations.
Internal AuditTheir existing contact map, control walkthroughs and independent testing capacity.You rebuild knowledge that already exists and lose your best early-warning channel.
Sequencing

Quality and regulatory first, finance second, IT third. Counterintuitive for a security leader, but in a device separation the quality and regulatory calendars are the ones you cannot move — and they are the relationships that take longest to earn, because you are asking for access to a system that treats outsiders as a compliance risk.

At J&J — counterparties, not colleagues

The relationship changes character on announcement day

The people across the boundary were colleagues and will become a critical third party. The window in which they will still help you informally is short, and it closes when their own retained-organisation roles are confirmed. Extract what you need early.

  • J&J service owners — the named operator of each retained service. Get the person who runs the query, not the person who owns the platform. Ask them what evidence they can realistically produce and in what format, before the schedules are drafted.
  • J&J security operations — detection, triage and the notification interval you will depend on for disclosure. Agree the maximum interval in writing and rehearse it.
  • Separation Management Office — controls the schedules, the timeline and the escalation route. Your reconciliation finding goes here.
  • J&J privacy and legal — the intra-group transfer mechanisms you fall out of on Day 1, and the scope of the documentation licence.
  • J&J procurement — which supplier agreements can be novated, which cannot, and where the volume pricing and security terms actually live.
  • J&J internal audit and quality — historical findings, open observations and supplier audit reports. Ask now; entitlement to these becomes contested later.
Trap

Treating the J&J relationship as goodwill rather than contract. Goodwill evaporates when their retained organisation is announced and people start protecting their own headcount. Every dependency that matters must survive the day the people you know are reassigned.

Outside — the ones with calendars you don't control

Book relationships, not just slots
  • External auditor — engage on control environment scoping twelve to eighteen months out. Their view of in-scope systems will change your plan, and hearing it early is free.
  • Notified body scheme manager — the individual who allocates audit capacity. A relationship here is worth more than a formal application.
  • Auditing organisation for the multi-market programme — same logic, different scheme.
  • Local regulatory representatives — in every market where DePuy is not established. These appointments have legal weight and lead time.
  • Cloud provider account team — tenancy separation, enterprise agreement novation, and technical support for the carve-out. They have done this before; ask for their separation playbook.
  • Insurance broker — cyber, product liability and D&O for a standalone entity, priced without the parent's tower. Start early; underwriters will ask control questions you need answers to.
  • Outside counsel — separation agreement, privacy transfers, disclosure obligations.
  • Peer security leaders in medtech — the people who have run a device separation. Two conversations here save six months of discovery.

Bottom-up — the people who actually know

Where the real dependency map lives

Executive relationships get you permission. These relationships get you accuracy.

  • Plant controls and automation engineers — they know what the machines talk to, which no diagram records.
  • QA document control — knows every procedure, every reference and every change queue. Nothing in the harvest happens without them.
  • The historian or MES administrator — usually one person per site, often with no backup. Identify them early; they are a single point of failure as well as a source.
  • Field service engineers for robotic and navigation platforms — they know how systems connect inside hospitals, what remote support paths exist, and what customers actually asked about security.
  • Service desk and contact centre supervisors — they see complaint intake, shadow tooling and where users work around process.
  • The person who renews the certificates — often unnamed, sometimes nobody. Finding out it is nobody is itself the finding.
Design move

Convert these into a standing structure rather than a series of favours. The BISO layer and the site security councils exist precisely so that plant and product knowledge reaches you continuously, without you having to remember to ask.

Control catalogue and the severability model

Build your own numbered catalogue anchored to a recognised functional spine, and treat every external framework as a mapping rather than a spine. Certificates get rescoped, customers add commitments, regulations move — mappings absorb that without re-plumbing controls. And at transition exit nothing needs renumbering, because no parent identifier ever entered the catalogue.

Twelve domains, 90 to 130 controls

GOV governance and compliance management · ORG roles, workforce and security culture · AST asset, data and product inventory · IAM identity and access · INF infrastructure and network · APP secure development and product security · DAT data protection and privacy · SUP third party and supply chain · OPS operations, logging and monitoring · VUL vulnerability, threat and postmarket disclosure · IRB incident response and resilience · AUD assurance, evidence and internal audit

If a domain exceeds fifteen controls you are writing procedures, not controls. A separated entity cannot operate three hundred controls in year one, and a catalogue nobody can operate is worse than a smaller one everybody can.

The four severability attributes

AttributeValuesWhat it drives
Operator classDePuy · Parent-operated · Shared · VendorWho performs the activity today. Derived bottom-up from controls, this list will not match the transition service schedule negotiated by corporate development — and that delta is your first finding.
Severance stateNative-D1 · Transition-dependent · Build-by-dateWhether Day 1 is the end state. The build-by-date set is your board-approved gap plan.
Evidence custodyDePuy-system · Parent-extract · Vendor-attestWhether you can still produce evidence after the parent dependency ends. Parent-extract controls need a delivery obligation, not an audit right.
Exit triggerFree text conditionConverts a contractual end date into a testable control condition.

Three rules that follow

Rule one — assertion never transfers with operation

A control can be parent-operated and still asserted by the new entity. The parent performs, you monitor, receive evidence and sign. This is the normal and correct arrangement; what breaks programs is leaving the assertion ambiguous, so that when the control fails nobody knows whose deficiency it is.

Rule two — the evidence repository is Native-D1 for every control, without exception

This is the single highest-leverage move in a separation. The parent may operate a control through the entire transition, but the artefact lands in your repository, in your custody, on your retention clock, from Day 1. Otherwise your first audit arrives with a testable population that lives in a system you no longer have access to. Separate the evidence layer before you separate the control layer. It is cheap, it is unglamorous, and it is the difference between a clean first opinion and a scope limitation.

Rule three — exit triggers are control tests, not dates

A transition-dependent control becomes native only when the replacement has operated with evidence for a defined period: typically two consecutive cycles for periodic controls, ninety days for continuous ones. Exiting on the contractual date with zero operating history is how separations manufacture material weaknesses, and it happens because the exit date sits in a commercial schedule that nobody mapped to a control.

Control record shape

Shaped to merge with the separation tracker's JSON export. The workstream_ref back-link is what turns a separation checklist into the front end of a permanent programme: tasks close at cutover, controls persist, and the link shows an auditor which separation activity established each control.

FieldExample
id / domainIAM-04 · Identity and access
titlePeriodic review of privileged access to financially significant and quality-critical systems
obligations[]ITGC access scope · service criteria for logical access · quality system record control · privacy access limitation
mappings{}SOX ITGC · SOC 2 common criteria · ISO 27001 Annex A · HIPAA administrative safeguards · electronic records access limitation
operatorParent-operated
severanceTransition-dependent
evidence_custodyParent-extract
evidence{}Quarterly review export with complete population · parent identity platform to DePuy evidence repository · quarterly · retained per device record rules
exit_triggerDePuy directory operating two consecutive quarterly reviews with complete, reconciled populations and no unresolved orphan accounts
owner / workstream_refNamed accountable individual · link to the separation tracker workstream
ai_assistednone / drafting / review / extraction plus approver

Metrics for the first twenty-four months

FDA and US regulatory dependencies

These are the items that block product from shipping or reports from filing. They are owned by regulatory affairs, but GRC has to hold the map because each one generates obligations, controls and evidence. Confirm every item against the separation agreement and the Form 10 — treat the detail below as the checklist, not as the record.

DependencyLead timeWhat actually has to happen
Establishment registration and listingAnnual cycle, act earlyEvery manufacturing, contract-sterilisation and specification-developer site registers under the new owner. New owner operator account, new user accounts, device listings reassigned. Miss the annual cycle and the site is unregistered, which is a shipment stop.
510(k) and PMA ownership transferWeeks to monthsOwnership transfer notification per clearance. Volume is the issue, not difficulty — an orthopaedics portfolio can carry many hundreds of clearances across hips, knees, trauma, spine, extremities and sports medicine. Build the inventory first and reconcile it against the product catalogue, because the two will not match.
Electronic Submissions Gateway accountWeeks, and it blocksThe new entity needs its own gateway account with its own credentials and a completed connectivity and test-submission cycle before it can file electronic adverse event reports. Frequently discovered late. Until it works, the new entity cannot meet a reporting deadline on its own systems.
Adverse event reporting continuityDay 1 hard stopComplaints arriving at parent-operated call centres about the new entity's devices must reach the new entity's complaint system inside the reporting clock. Define the handoff, the timestamp of record and the escalation. The clock runs from awareness, and awareness now sits with a third party.
Unique device identification recordsMonthsDevice identifier records are keyed to the labeller's organisation identifier. A change of legal manufacturer means every record needs updating and, where the identifier itself changes, new identifiers and relabelled product. This is the dependency most likely to be underestimated, and getting it wrong degrades recall traceability.
Quality system regulation alignmentContinuousThe harmonised quality management system regulation is now in force, so the new entity's QMS documentation should be built in ISO 13485 structure from the start rather than converted later. Advantage of a spin-off: you are not migrating a legacy structure.
Electronic records and signaturesPer systemEvery migrated or cloned quality-critical system must preserve audit trail continuity, retain record integrity and re-establish signature binding under the new entity. A lift-and-shift that flattens history breaks the audit trail requirement.
Computer system validation stateLong poleA cloned instance in a new environment under a new entity is a new system. Validation does not transfer automatically. At minimum: installation and operational requalification in the new environment, with performance qualification for anything quality-critical. This drives more of the separation timeline than anything else in IT.
Premarket cybersecurity for connected productPer submissionImplants are not cyber devices; robotics, navigation, digital surgery and patient-facing applications are. Any submission in flight at separation needs its security documentation re-issued under the new entity, and the postmarket support commitments in those submissions become the new entity's obligations.
Design history and device master recordsMonthsQuality records that must transfer with the product, usually held in the parent's product lifecycle system. Custody, completeness and retrievability all need proving — an inspector will ask for a specific record and watch you retrieve it.
Postmarket surveillance and CVDDay 1Published disclosure policy, security contact, key material and coordination arrangements under the new entity's name. Researchers report to whoever the website says; if the website still says the parent, your intake path is broken on Day 1.
The validation trap, stated plainly

Programme plans assume that cloning the enterprise resource planning and manufacturing execution systems is an IT migration. It is not — it is a regulatory event. Every quality-critical system lands in the new environment in an unvalidated state, and until requalification is complete you cannot release product against it. This is the dependency that most often forces a separation date to move, and it is visible eighteen months out if anyone maps validation state onto the migration plan. Do that mapping in the first quarter of the programme.

Global registrations — the schedule risk nobody owns

A change of legal manufacturer is a regulatory event in every market. Some transfers are administrative; several take longer than the transition period allows and are directly revenue-blocking. Sequence by revenue at risk multiplied by lead time, and start the long ones before you start anything else.

MarketTypical leadRiskWhat is actually involved
European Union12–18 monthsHighNotified body certificates do not transfer freely; the body must accept the new legal manufacturer and re-issue. Registration in the EU database requires the new entity's own actor registration. Basic device identifiers change with the manufacturer, which cascades into labelling and packaging. A qualified person responsible for regulatory compliance must be appointed and evidenced. Notified body capacity is the binding constraint — book slots eighteen months out.
China12–24 monthsHighestRegistration certificates are issued to a named registrant. Transfer is generally treated as a new registration rather than an amendment, with testing and technical review. Frequently exceeds the transition window. If a major product family sells into China, this needs a decision at board level about whether the transition period is long enough or whether a distribution arrangement bridges the gap.
Japan9–18 monthsHighMarketing authorisation holder change plus a compliant quality management arrangement under the new holder, including the required domestic responsible roles. Not administrative. Start with Japan and China together — they set the critical path for the entire regulatory workstream.
Multi-market quality audit programme6–12 monthsMediumThe single-audit programme certificate covers several regulators at once, which makes it efficient and also makes it a single point of failure. Re-certification under the new entity needs an auditing organisation slot; losing it cascades into every market that relied on it.
United Kingdom6–12 monthsMediumRegistration under the new manufacturer, with a UK responsible person where the entity is not UK-established. Interacts with EU work — sequence them together to avoid two labelling changes.
Canada4–8 monthsMediumLicences are held by the manufacturer and require amendment or reissue, supported by the quality certification above.
Brazil9–18 monthsMediumRegistration holder change with a local representative. Slow and document-heavy.
Australia3–6 monthsLowerSponsor and manufacturer details updated on the register; relatively tractable if the underlying conformity evidence is in place.
Korea, India, Gulf, ASEAN3–12 monthsVariesIndividually manageable, collectively enormous. Volume is the problem: dozens of markets, each with its own dossier. Resource this as a programme, not as a task.
Privacy: the intra-group transfer cliff

Inside a corporate group, cross-border personal data transfers typically run under binding corporate rules or an intra-group agreement. On Day 1 the new entity leaves the group and every one of those transfers becomes a transfer to a third country outside the covered structure. You need standard contractual clauses and transfer impact assessments in place at separation, plus your own record of processing activities and your own data protection officer where required. This is a Day 1 obligation with a months-long lead time and it is almost always found late, because it is invisible until someone asks which mechanism covers the flow.

Sequencing advice

Build one matrix: market by product family, with lead time, revenue at risk, owner and current status. Take it to the Quality & Regulatory Compliance Committee monthly. The purpose is not tracking — it is forcing an early, explicit board decision about which markets will not be ready, and what commercial arrangement bridges them. That decision made twelve months out is a strategy; made three months out it is a crisis.

Manufacturing and operational technology

An orthopaedics business is a machining, forming, additive and sterilisation business. Its plants run CNC estates, coordinate measuring machines, additive systems, cleanrooms, environmental monitoring, sterilisation and traceability infrastructure — most of it long-lived, much of it validated, and a meaningful share of it dependent on the parent's global network for services the plant floor never thinks about.

The network cut is the single largest production risk

Plant networks in a large group are rarely as isolated as the architecture diagram claims. Time synchronisation, name resolution, certificate services, licence servers, identity, print and label services, historians and remote vendor support paths all commonly traverse the parent's core. Cutting the network without mapping those dependencies stops production.

Do this, in order

  1. Passive traffic capture at each plant boundary for at least one full production cycle including a month-end and a maintenance window. Not a survey — a capture. Nobody can tell you what their machines talk to.
  2. Map every flow to a service, an owner and a disposition: stays local, replaced by new entity service, or transition-provided.
  3. Rebuild time synchronisation, name resolution and certificate services locally first. These three cause the most damage and are the cheapest to fix early.
  4. Inventory every licence server and every vendor remote-support path. Vendor connections into machine controllers are the most common unmanaged remote access in a plant.
  5. Rehearse the cut at the smallest site during a planned shutdown before attempting it anywhere else.
Certificate and name-service expiry

Two of the most commonly reported cutover failures across large separations are expired certificates and mis-sequenced domain and mail changes. Both are entirely preventable and both take out production or customer communications for days. Build a certificate inventory with expiry dates as a named workstream deliverable, and treat domain and mail cutover as a rehearsed, reversible change with a defined rollback.

Validated systems set the schedule

  • Manufacturing execution and quality systems — every instance that moves, gets cloned or gets re-hosted requires requalification in the new environment. Map validation state onto the migration plan in the first quarter; it is the earliest reliable signal of whether the separation date is achievable.
  • Audit trail continuity — migrated records must retain their audit trail. Confirm this in the migration design, not in validation testing, because by then the design is fixed.
  • Sterilisation and environmental monitoring — parametric release and monitoring systems are quality-critical and often supplier-hosted. Supplier contracts, data ownership and record retrievability all need re-establishing.
  • Traceability — lot and serial traceability from raw material to implanted device must survive the system split intact. A broken trace is a recall you cannot execute, and the regulator will treat it accordingly.

Supplier and contract manufacturer novation

Device suppliers touch product, which makes supplier separation a quality event as well as a commercial one.

  • Quality agreements name the parent. Every one needs novation or replacement, with vigilance and change-notification flow-downs re-established. A supplier who does not know to notify you of a process change is a recall in waiting.
  • Supplier audits are the parent's work product. You may not be entitled to the reports. Budget for re-auditing critical suppliers, and prioritise by product contact rather than spend.
  • Master agreements fragment. Group-level pricing and, more importantly, group-level security and data protection terms do not automatically follow. Re-negotiating security schedules across hundreds of suppliers is a multi-year programme; triage it hard.
  • Single-source and sterilisation partners first. These carry the highest continuity risk and the longest requalification lead times.

Shadow technology during separation

Separation deadlines are absolute, so business teams buy their own tools rather than wait for a review process that has no staff yet. Most of the technical debt you will spend three years cleaning up gets created in this eighteen-month window. Two responses work:

  • Make the paved path faster than the workaround. A pre-approved catalogue with a same-week intake for anything on it, and a genuine 48-hour triage for anything not. Speed is the control.
  • Put security embeds into the business units. Product, manufacturing, quality and R&D each have different regulatory exposure and none of them will call a central function. An embedded layer is the only thing that keeps discovery ahead of accumulation.
Measure it

Track discovery rate monthly and report it as a culture indicator rather than a compliance failure. If discovery is rising and time-to-onboard is falling, the programme is working. If discovery is flat, your detection is broken — flat is never the true number during a separation.

The estate that has to separate

Every system falls into one of five separation patterns. Getting the pattern wrong is expensive: cloning something that should have been rebuilt imports the parent's mess, and rebuilding something that should have been cloned burns a year.

Clone and requalify — copy the instance, revalidate in the new environment. Carve out — split shared data and configuration into a new tenant. Net new — build fresh; the parent's version is unusable. Transition then replace — J&J operates it, you cut over later. Novate — contractual reassignment, little technical work.

HR and workforce

The most underestimated dependency in the whole estate
SystemPatternEvidence it producesTrap
Core HR / HCMCarve outAuthoritative worker population, joiner-mover-leaver events, role and org dataAccess controls have no authoritative population until HR lands. Sequence HR before identity, not after.
PayrollCarve outSegregation of duties over payment, ICFR-relevant approvalsOften outsourced per country, so it is dozens of vendor relationships, not one system.
Learning managementNet newTraining records — simultaneously ICFR control environment evidence and quality system evidenceTraining records are quality records. Losing history breaks both the ITGC test and the inspection response.
Badge and physical accessClone / requalifySite access populations, cleanroom and controlled-area entry logsShared campuses. Where DePuy and J&J occupy the same site, physical separation is a negotiation, not a project.
Recruiting and onboardingNet newBackground check and onboarding control evidenceHiring accelerates during separation while the control is being rebuilt. Highest-risk window for unvetted access.
The sequencing trap

Programme plans put HR in the "people workstream" and identity in the "IT workstream", and the two never meet. But the HR system is the source of truth for every access control DePuy will assert, so if identity goes live before HR, your first access review has a population you cannot defend. Fix the sequence at the plan level, in the first quarter.

Cloud, identity and collaboration

The foundation everything else depends on
SystemPatternEvidence it producesTrap
Hyperscaler tenancy and organisation accountsCarve outConfiguration baselines, privileged access, logging coverageShared landing zones, shared network transit and shared guardrails. Account migration moves the workload but not the controls around it.
Enterprise agreements and committed spendNovateContractual security terms, data residency commitmentsLosing the parent's committed-spend discount is visible; losing the negotiated security addendum is not.
Directory and identity providerNet newAccess reviews, privileged access, authentication logs — the core ITGC setCloning inherits orphans, service accounts and stale privileged groups as DePuy's findings. Migrate selectively.
Email, collaboration and file storageClone / requalifyRetention, legal hold, data loss preventionMail and domain cutover is one of the two most commonly reported separation failures. Rehearse with a tested rollback.
ITSM and change managementNet newChange approvals, emergency change population, incident recordsThe change record is a primary ITGC artefact. Starting a new instance at Day 1 leaves the transition period unevidenced unless you export first.
PKI and certificate managementNet newCertificate inventory, expiry tracking, issuance approvalsCertificates issued from J&J's authority expire on J&J's schedule and often with no owner on DePuy's side.

Connected product — robotic surgery, navigation, digital surgery

The narrow but high-consequence product security scope

Most of an orthopaedics portfolio is implants and instruments, which carry no cybersecurity obligation. The robotic, navigation and digital surgery platforms carry all of it — and they sit inside hospital networks, touch patient data, and have field service organisations with remote access paths.

ElementPatternEvidence it producesTrap
Robotic surgical platformClone / requalifyThreat model, software bill of materials, premarket security documentation, postmarket vulnerability posturePostmarket support commitments made in the submission become DePuy's obligations. Read them before Day 1, not after a disclosure.
Navigation and instrument trackingClone / requalifyConfiguration baselines, hospital deployment inventoryInstalled base inventory is usually incomplete. You cannot notify customers of a vulnerability in devices you cannot locate.
Cloud analytics and case dataCarve outAccess logs, data flow records, processing records and transfer mechanismsCase data may be identifiable. Leaving the parent's group means new transfer mechanisms and, in some markets, new consent positions.
Device telemetry and remote supportNet newRemote session logs, authentication to deployed devicesService engineers reach devices inside hospital networks through paths that were never inventoried as remote access.
Field service and installed base managementCarve outService records, software version tracking, patch deployment statusVersion tracking is what makes a vulnerability advisory actionable. Without it, disclosure is theoretical.
Product security disclosure endpointNet newIntake records, coordination timelines, published advisoriesResearchers report to whatever the website says. A J&J contact on Day 1 is a broken intake path.
Customer-facing consequence

Hospitals will ask, in writing, whether their deployed robotic systems are still covered by the same security commitments after separation. That question arrives in the first month. Have a signed answer ready, agreed with regulatory and legal, before anyone asks.

Telephony, contact centre and commercial systems

Where a phone line becomes a regulatory clock
SystemPatternEvidence it producesTrap
Contact centre and complaint intakeTransition then replaceCall records, timestamp of awareness, complaint handoff recordsThe adverse event clock runs from awareness. During transition, awareness sits with a J&J-operated centre. Define the timestamp of record contractually and test it with seeded complaints.
Telephony, numbers and call recordingClone / requalifyRecording retention, consent handling, access to recordingsPublished customer numbers appear on labelling, IFUs and hospital contracts. Changing them is a labelling change, not a telecoms change.
CRM and customer masterCarve outCustomer contact records used for field notifications and recallsIf the customer master is incomplete, you cannot execute a field action. This is a recall capability question, not a sales question.
Field inventory and consignmentCarve outLot and serial location, consignment reconciliationOrthopaedic consignment inventory sits in hospitals and reps' vehicles. Traceability across the split is a recall dependency.
Customer portals and e-commerceNet newAuthentication, entitlement, order recordsHospital IT will re-run security reviews on any new customer-facing endpoint. Budget for the questionnaires.
Trap

Telephony is treated as facilities plumbing and assigned to whoever handles the office move. But in a device company the complaint line is a regulated intake channel with a statutory clock attached, and the number itself is printed on product labelling. Move it into the regulatory workstream.

Quality, regulatory and manufacturing systems

Where validation state sets the schedule
SystemPatternEvidence it producesTrap
Electronic quality management systemClone / requalifyDocument control, CAPA, complaint records, training linkageArrives in the new environment unvalidated. Requalification, not migration.
PLM and design history filesClone / requalifyDesign records that must transfer with the productCustody, completeness and retrievability all need proving. An inspector will ask for one specific record and watch you retrieve it.
ERPClone / requalifyThe bulk of the ITGC and financially significant control setThe single longest pole. Validation state and ICFR scope land on the same system at the same time.
MES, historian and shop floorClone / requalifyDevice history records, batch and lot traceabilityOften site-specific with one administrator and no backup. Identify that person early.
Regulatory information management and submissions gatewayNet newRegistration inventory, submission records, electronic reportingThe gateway account blocks electronic adverse event reporting until it is live and tested.
Labelling, print and traceabilityClone / requalifyDevice identifier records, label version controlA change of legal manufacturer cascades into device identifier records and, in some cases, relabelled product.
Sterilisation and contract manufacturer systemsNovateParametric release records, supplier quality dataSupplier-hosted. Data ownership and retrievability need re-establishing contractually.

Security and data tooling

Mostly net new, and mostly the last thing funded
SystemPatternEvidence it producesTrap
SIEM and log managementTransition then replaceDetection coverage, incident timelines, retentionJ&J detects during transition but DePuy owes the disclosure. Agree the maximum notification interval in writing.
Endpoint and server protectionNet newCoverage percentage, policy complianceCoverage gaps appear at the seams — OT endpoints, engineering workstations, field service laptops.
Vulnerability managementNet newScan coverage, time to remediate against policyTime-to-remediate is a published commitment for connected product. The tool must cover product, not just IT.
SBOM and AIBOM toolingNet newComponent inventory per product release, disclosure supportRequired for premarket submissions and increasingly for customer contracts. Not optional for the robotic platform.
Secrets and privileged accessNet newPrivileged session records, credential rotationShared service credentials embedded in plant systems are the hardest to find and the last to be rotated.
Data warehouse, BI and AI platformsCarve outData lineage, access records, AI use case inventorySeparation-era productivity pressure is exactly when unreviewed AI tooling enters clinical and manufacturing workflows.
Funding argument

Security tooling is usually last in the queue because it produces no revenue and blocks no shipment. The counter-argument that works with a CFO: six of these systems produce the evidence the external auditor will test, and three of them produce the evidence a regulator will ask for. They are not overhead — they are the instruments that generate your assertions.

One control set, six regimes

DePuy will be assessed against SOX ITGC, FDA device requirements, CMMC Level 2 where defence work exists, the EU Cyber Resilience Act, GDPR and HIPAA — plus SOC 2 and ISO 27001 for customers. Running six programmes is unaffordable for a newly separated entity and produces six sets of contradictory evidence.

The rule: a control operates once, produces one artefact, and satisfies many regimes. What differs is not the control but the evidence standard applied to it — and that difference is where most programmes fail, because they collect evidence adequate for one regime and offer it to another.

The evidence standards are not the same

Same artefact, six different tests of whether it is good enough
RegimeEvidence standardWhat that means in practice
SOX ITGCComplete and accurate, with a defensible populationThe population must be provably whole. An access review over an incomplete extract fails even if every line in it was reviewed correctly.
CMMC Level 2Adequate and sufficient, per assessment objectiveAdequacy is whether the artefact addresses the objective; sufficiency is whether there is enough of it. Both are judged per objective, not per control.
FDA / QMSRAttributable, legible, contemporaneous, original, accurateTiming and attribution matter as much as content. A record reconstructed after the fact is not contemporaneous, however accurate.
21 CFR Part 11Audit trail integrity and signature bindingThe record must show who did what and when, with the trail intact through any migration.
GDPRDemonstrable accountabilityYou must be able to show the decision and its reasoning, not merely the outcome.
EU CRADocumented across the product lifecycleVulnerability handling and component inventory must be evidenced per product release, not at an organisational level.
Why this is a differentiator, not a burden

An organisation fluent in all six can design one artefact that clears the highest bar and reuse it everywhere. An organisation fluent in one designs for that one and re-collects for the rest. In a device separation you need ITGC, Part 11 and quality system evidence out of the same systems simultaneously — so the multi-regime view is the only view that works.

Domain to regime crosswalk

Where each of the twelve domains lands
DomainSOX ITGCFDA / QMSRCMMC L2EU CRAGDPRHIPAA
GOVControl environmentManagement reviewPolicy evidence, all domainsArt.13 processesArt.24, Art.5(2)§164.308(a)(1)
ORGCompetence, COSO 4Training recordsAT familyArt.39 training§164.308(a)(5)
ASTScoping completenessDMR/DHF linkageCM.L2-3.4.1Annex I(2) SBOMArt.30 records§164.310(d)
IAMLogical access — most testedPart 11 §11.10(d),(g)AC, IA, AU familiesAnnex I(1)(d)Art.32(1)(b)§164.312(a),(d)
INFComputer operationsInfrastructure qualificationSC, MA familiesAnnex I(1)(e)Art.32§164.312(e)
APPProgram development and changeDesign control, CSVCM, SA practicesArt.13 secure developmentArt.25 by design§164.308(a)(8)
DATIPE completeness/accuracyPart 11 record integrityMP, SC familiesAnnex I(1)(c)Art.5, 32, 44–49§164.312(a)(2)(iv)
SUPService organisation relianceSupplier qualificationExternal service providersArt.13(5) due diligenceArt.28 processors§164.308(b) BAAs
OPSJob scheduling, monitoringProduction controlsAU, SI familiesAnnex I(2)(6) loggingArt.32(1)(d)§164.308(a)(1)(ii)(D)
VULPatch within change524B postmarketRA, SI familiesArt.13(8), Art.14Art.32(1)(d)§164.308(a)(1)(ii)(B)
IRBDeficiency escalationComplaint and MDR interfaceIR familyArt.14 reportingArt.33, 34§164.308(a)(6), Breach Rule
AUDManagement assessmentInternal audit, QMSRCA family, POA&MConformity assessmentArt.32(1)(d)§164.308(a)(8)

Indicative mapping for programme design. Confirm each cell against the current text of the regime and your assessed scope before relying on it — CRA obligations in particular phase in on a staged timetable.

Worked example — secure SDLC and CI/CD

One control chain, six regimes, one evidence set

The pipeline for the robotic and navigation software is where the most regimes converge on a single control chain. Design it once, correctly, and it clears all of them.

The control chain

ControlToolingArtefact it producesRegime it satisfies
APP-01 Authorisation to commitGitHub Enterprise with SSO to the identity provider, SCIM provisioning, teams mapped to rolesRepository access population, joiner-mover-leaver eventsSOX logical access; CMMC AC and IA; HIPAA §164.312(a)
APP-02 Peer reviewBranch protection, required reviewers, CODEOWNERS, signed commitsPull request record with reviewer identity and timestampSOX change management; QMSR design control; Part 11 attribution
APP-03 Segregation of dutiesDeployment environments with required approvers distinct from committersDeployment approval recordSOX SoD — the classic finding when developers can deploy
APP-04 Component inventorySCA scanning in the pipeline, SBOM generation per build (SPDX or CycloneDX)Per-release SBOM stored with the release artefactFDA 524B; EU CRA Art.13(8) and Annex I(2)(1)
APP-05 Vulnerability gateSCA and SAST thresholds, policy-as-code failing the buildGate pass/fail record per build, with exceptions loggedCRA Art.13 secure development; CMMC RA and SI; FDA premarket
APP-06 Release authorisationRelease pipeline requiring quality sign-off for regulated buildsSigned release record linked to the design history fileQMSR design transfer; Part 11 signature binding; SOX change
APP-07 Postmarket vulnerability handlingPSIRT case tracker, VEX/CSAF advisory generation, KEV monitoringAdvisory with affected-version statement and remediation timelineFDA postmarket; CRA Art.14; ISO/IEC 29147 and 30111
The trap in this chain

Teams build the pipeline for engineering velocity and then retrofit control evidence. But the SOX-testable artefact is the pull request record with reviewer identity, and the CRA-testable artefact is the per-release SBOM — both of which must be generated at the moment of the action and retained. Retrofitting means reconstructing, and a reconstructed record fails the contemporaneous test even where it passes the accuracy one.

Separation-specific move

Repository history, pull request records and build artefacts for the audit period live in J&J's tenancy. Export them into DePuy's evidence repository before the tenancy is cut, or the entire pre-separation development record becomes unavailable exactly when the first assessment asks for it.

Culture, training and the reporting cycle

Training records, phishing results, tabletop after-actions and board packs are usually treated as programme decoration. In a separated device company they are four different regimes' evidence, produced by the same activities.

Design them once. The alternative is an LMS that satisfies HR, a phishing platform that satisfies nobody, and a board pack whose numbers do not reconcile with the annual filing.

Training — four regimes, one record

A completion record is simultaneously a SOX control environment element, a CMMC assessment objective, a HIPAA requirement and a quality system record. That combination sets the design constraints, and they are stricter than any single regime implies.

Design constraints

  • Role-based, not universal. Plant operators, field service engineers, developers, finance and clinical affairs each need different content. Universal training satisfies the tick-box and fails the assessment objective, which asks whether people were trained for their role.
  • Records are quality records. They fall under document and record control, which means retention, retrievability and change control apply. Losing history at separation is a quality finding as well as an audit one.
  • Completion is necessary but never sufficient. Report it because you must; steer on behaviour because completion tells you nothing.
  • Language and shift patterns. A global manufacturing footprint means translated content and modules that fit a shift, not a desk day. This is the single most common reason plant completion rates lag.
Separation trap

Training history lives in J&J's learning system and does not come with the business. Arriving at Day 1 with zero completion evidence fails four regimes at once, and there is no way to reconstruct it afterwards. Extract or re-baseline before the tenancy is cut.

Phishing simulation — run it as a measurement, not a trap

The metric that matters is not click rate. It is report rate and time to first report, because those are the two things that actually shorten an incident. A population that clicks and reports beats one that neither clicks nor reports, and click-rate-only programmes optimise for the wrong outcome.

How to run it

  • Start early enough to have a trend by Day 1 — a single cycle is a data point, not a measurement.
  • Report click rate, report rate and time to first report together. Never publish click rate alone.
  • Follow up with coaching, never with punishment. Punitive programmes drive reporting down, which is the opposite of the goal.
  • Tailor the pretexts to separation reality — payroll changes, benefits enrolment, new supplier portals, IT migration notices. These are exactly what attackers will use, and exactly what employees are conditioned to expect.
  • Consult works councils before deploying simulation and monitoring at EU sites. In some jurisdictions this is a legal precondition, not a courtesy.
Separation-specific risk

The transition window is the highest-risk phishing period this organisation will ever have. Employees expect unfamiliar systems, new domains, unexpected login prompts and legitimate emails from names they do not recognise. Every signal people normally use to detect a phish is temporarily unreliable — plan the awareness campaign around that fact specifically.

Tabletop calendar

Four exercises a year, each answering a different question
ExerciseAudienceThe question it answers
Cross-boundary incidentDePuy and J&J incident leads, legal, regulatory, commsWhen an event touches both estates, who leads, who notifies, and on whose clock does the deadline run?
Product vulnerabilityPSIRT, quality, regulatory, field service, commsA researcher reports a flaw in a deployed robotic platform. Can you triage, coordinate, advise and notify inside your published timeline?
Materiality and disclosureAudit committee, CFO, GC, CISOFacts arrive incomplete. Who determines materiality, on what record, and can you file inside the required window?
Plant disruptionSite leadership, OT, quality, supply chainA site loses its manufacturing systems. Can you fail over, can you still release product, and when does it become a supply notification?
Make the after-action the deliverable

The exercise itself is not the evidence — the after-action report with dated, owned actions is. Run at least one before Day 1 and one within the first quarter after, because the exercise that finds a charter gap is worth more than the one that goes smoothly.

Quarterly board pack and the disclosure chain

One metric set, three destinations: the audit committee quarterly, the annual governance disclosure, and the sustainability statement. Define each metric once with documented lineage, or the three will disagree and the filing is the one made under oath.

The standing pack

  • Separation health — native coverage percentage, exit triggers met against services remaining, evidence completeness for the transition period.
  • Control operation — emergency change ratio, access review completion with population reconciliation, open deficiencies by severity.
  • Threat and vulnerability — time to remediate against published commitments, connected-product posture, open advisories.
  • Behaviour — exception volume and renewal rate, phishing report rate and time to first report, shadow discovery rate, self-reported incidents.
  • Regulatory — market transfer status, open observations, upcoming assessments.
  • One narrative page — what changed, what worries you, what you need. The metrics inform; this page is what the committee actually discusses.

Feeding the disclosures

  • Governance disclosure — board oversight structure, management's role, and the risk management processes. The described process must match what the minutes show actually happened.
  • Sustainability statement — governance and business-conduct datapoints draw on the same governance structures, whistleblowing channels and training figures. Where a European sustainability reporting obligation applies, these become assured data, not marketing.
  • Reconciliation — before filing, check the narrative against the minutes. A filing describing quarterly board oversight against minutes showing two meetings is a finding, and an avoidable one.
Trap

Building the board pack, the governance disclosure and the sustainability inputs as three separate exercises with three owners. They diverge within two cycles, and the divergence is visible to anyone who reads both documents.

Metrics design for the DePuy CISO organisation

Six measurement domains — connected product, enterprise IT, manufacturing and OT, regulatory and compliance, supplier security, and people — plus a temporary separation set that retires at transition exit.

Supplier security belongs in this list and is usually the weakest one. In a device company suppliers touch product, not just data: a contract manufacturer, a sterilisation partner or a component supplier whose change-notification flow-down is broken is a recall in waiting. That is a security metric with a quality consequence, and it has no natural owner unless the CISO organisation claims it.

Design rules

Five tests before a metric enters the set
  1. A decision changes when it moves. If no one would do anything differently at 82 percent versus 74 percent, it is a status update, not a metric. Delete it.
  2. Defined once, with documented lineage. The same number feeds the audit committee, the annual governance disclosure and, where it applies, the sustainability statement. Three separate definitions produce three different numbers and the filing is the one made under oath.
  3. Coverage before outcome. Every domain needs a denominator you can defend before any percentage means anything. "94 percent of assets patched" is meaningless if the asset inventory is 60 percent complete — and worse than meaningless, because it reads as reassurance.
  4. Paired metrics, never singles. Report volume with age, completion with population reconciliation, click rate with report rate. Single metrics get gamed, and usually not deliberately — people optimise what is measured.
  5. Named owner, or it does not get reported. Every metric has one accountable human who can explain the movement. An unexplained number wastes a board's time and costs you credibility for the ones that matter.
Metric definition standard

Each metric carries: the question it answers, the owner, the source system, the calculation, the population and how completeness is established, the target and the escalation threshold, the direction of good, the review cadence, and which external disclosure it feeds. Hold this in the same register as the controls, not in a slide deck.

Connected product security

Robotics, navigation, digital surgery — narrow scope, highest consequence
MetricFamilyWhy it earns its place
Products in scope with a current threat modelCoverageThe denominator for everything else in this domain. Anything not modelled is not being managed.
Installed base version visibilityCoveragePercentage of deployed units whose software version is known. This is the metric that makes an advisory actionable — without it, disclosure is theoretical and field remediation cannot be planned.
Releases shipped with a current SBOMCoverageDirectly evidences premarket expectations and CRA component-inventory obligations. Measure per release, not per product.
Known exploited vulnerabilities in released product — count and maximum ageOutcomeThe single most defensible product security number. Pair count with age; a count of two, both 400 days old, is worse than a count of nine all under 30 days.
Time to remediate against your published commitment, by severityTimelinessYou committed to this in submissions and customer contracts. It is measured against your promise, not an industry benchmark.
Advisory cycle time — report received to advisory publishedTimelinessResearchers and agencies judge you on this. It is also the number that determines whether coordination holds or a researcher goes public.
Field remediation completion at 30, 90 and 180 daysOutcomePublishing a fix is not deploying one. In a hospital estate the gap between the two is measured in quarters.
Premarket security content accepted without reworkOperationRework on security sections delays clearances. A leading indicator of whether the security and regulatory functions are actually integrated.

Enterprise IT

Where the auditor looks first
MetricFamilyWhy it earns its place
Access review completion with population reconciliationOperationNever report completion alone. A completed review over an incomplete population fails the SOX test entirely, and that is the most common ITGC finding there is.
Privileged accounts without a named ownerCoverageThe cleanest single indicator of directory hygiene, and the number that exposes a cloned directory immediately.
Emergency change as a share of total changeOperationThe leading indicator of ITGC trouble. During separation everything feels urgent, so this rises silently until the auditor finds it.
Change failure rate and rollback frequencyOutcomePairs with the above. High emergency change with low failure means process theatre; high both means genuine instability.
Vulnerability remediation within policy, by severityTimelinessReport against your own policy SLA, and report the aged tail separately from the average — the average always looks fine.
Logging coverage across in-scope systemsCoverageDetection and audit trail both depend on it. This is also the metric that reveals which systems the separation quietly left behind.
Multi-factor coverage on financially significant and quality-critical systemsCoverageScoped deliberately — universal MFA percentages hide the systems that matter.
Backup restore test success rateOperationBackup success is not restore success. Only the restore test is evidence.
Mean time to detect and containOutcomeOnly meaningful once detection is native. Until then, report the notification interval J&J actually achieved against the contractual maximum.

Manufacturing and OT

Where a security metric becomes a supply metric
MetricFamilyWhy it earns its place
OT asset inventory confidence by siteCoveragePercentage of plant assets with a named owner and a criticality rating. Everything else in this domain is unreliable until this is high.
Unmanaged vendor remote access paths open into plant networksCoverageAlmost always non-zero and almost never inventoried. Trend it to zero and keep reporting it after it gets there.
Sites independent of J&J for time, name and certificate servicesCoverageThe most direct separation readiness signal for manufacturing, and a plant leader understands it immediately.
Quality-critical systems with current validated stateOperationSits at the security and quality boundary. A system out of validated state cannot support product release.
Production-impacting security or availability eventsOutcomeThe number the business cares about. Report it alongside minutes of production lost, not as a count alone.
Segmentation conformance against the target zone modelOperationMeasures whether the network cut actually delivered isolation or just moved the boundary.

Regulatory and compliance

The obligation-to-evidence chain
MetricFamilyWhy it earns its place
Obligation coverageCoveragePercentage of registered obligations with a mapped control that is actually operating. Report orphans in both directions — obligations with no control, controls with no obligation.
Evidence completeness for the current audit periodCoverageNot overall completeness, which will look fine and hide the transition-period gap that matters.
Assessment objectives with adequate and sufficient evidenceCoverageThe CMMC framing, but useful across every regime. It forces the question of whether an artefact actually answers the objective.
Open deficiencies and observations by severity and ageOutcomeAge is the signal. A stable count with rising age is a programme quietly failing.
Registration transfers landed against revenue at riskTimelinessReport revenue exposed, not registration count. A board acts on the first and ignores the second.
Regulatory notification timelinessTimelinessAdverse event, breach and vulnerability reporting against each statutory clock. One miss is a finding regardless of the rate.

Supplier security

Yes, it belongs here — and in a device company it is a product metric

Enterprise supplier programmes tier by data sensitivity and spend. That is the wrong model for a device company, where a supplier who touches product carries recall exposure even if they never see a byte of personal data. Tier on both axes and report them separately.

MetricFamilyWhy it earns its place
Supplier tiering completeness on both axesCoverageData sensitivity and product contact. A sterilisation partner is low on one and critical on the other, and a single-axis model misses it entirely.
Critical suppliers with a current security assessmentCoveragePost-separation this drops sharply, because J&J's assessments are J&J's work product and may not transfer. Expect a visible cliff and plan the re-assessment queue against it.
Critical suppliers with executed security and data protection terms under the DePuy entityCoverageNovation moves the contract; it does not always move the security schedule. This metric finds the gap.
Product-contact suppliers with vigilance and change-notification flow-down in placeCoverageThe device-specific one, and the one that becomes a recall. A supplier who does not know to notify you of a process change is an unmanaged product risk.
Supplier-notified incidents within the contractual windowTimelinessMeasures whether the terms you negotiated actually function. Most organisations never check.
Time to revoke supplier access after offboardingTimelinessDirectly testable, frequently poor, and a standard audit sample.
Single-source and sole-sterilisation concentrationCoverageResilience rather than security in the narrow sense, but it belongs in the same conversation and no other function reports it.
Fourth-party visibility for critical suppliersCoverageWhere your critical supplier's critical supplier is known. Low is expected; unknown-and-unmeasured is the problem.
Separation trap

Supplier assessment coverage will look excellent on Day 1 because the register was inherited, and then collapse when someone checks whether DePuy is actually entitled to those assessment reports. Baseline the metric on assessments DePuy holds and owns, not on assessments that exist somewhere.

Separation set — temporary, retires at exit

Report these monthly, then delete them deliberately
  • Native coverage — share of controls with no J&J dependency. The single cleanest indicator of separation health.
  • Exit triggers met against services remaining — if triggers lag the schedule, you are heading for a date-driven exit and a material weakness.
  • Evidence completeness for the transition period specifically — the gap that overall completeness hides.
  • J&J evidence delivery against the agreed cadence — measures whether the delivery obligations you negotiated are working, while there is still time to escalate.
  • Inherited exceptions re-decided against expired by default — tells you whether governance is actually operating or just recording.
  • Licensed documents remaining against the licence countdown — one number, one date, unambiguous.
  • Sites cut against sites rehearsed — if cuts are running ahead of rehearsals, stop.
Retire them on purpose

These metrics should disappear at transition exit, and their removal should be a minuted decision. Separation metrics that survive into steady state become noise that crowds out the ones that matter.

People and culture

Behaviour, not completion
  • Phishing report rate and time to first report — the two that actually shorten an incident. Report click rate alongside, never alone.
  • Exception volume, renewal rate and aged exceptions — the clearest measure of whether the paved path is faster than the workaround.
  • Shadow technology discovery rate — rising discovery with falling onboarding time means the programme works. Flat is never the true number.
  • Self-reported incidents as a share of total — a rising share is good news reported as bad news. Say so explicitly or the board will misread it.
  • Time to onboard a tool through the approved path — the friction metric. It predicts the shadow discovery rate one quarter out.
  • Training completion by role — reported because four regimes require it, never used to steer.

What goes to which audience

The same data, four different altitudes
AudienceCadenceMetricsWhat they see and what it decides
Board / Audit CommitteeQuarterly8–12Native coverage, evidence completeness, open deficiencies by age, obligation coverage, time to remediate against commitment for released product, known exploited vulnerabilities and their age, critical supplier assessment and flow-down coverage, emergency change ratio, registration transfer revenue at risk, one behaviour composite — plus one narrative page. Decides funding, risk acceptance and the Day 1 gap position.
Quality & Regulatory Compliance CommitteeQuarterly10–14The product security set in full, validated state, regulatory notification timeliness, supplier flow-down, field remediation completion, installed base visibility. Decides recall and field action posture and inspection readiness.
Security Steering CommitteeMonthly25–35Every domain at working depth, plus the separation set. Decides exceptions, prioritisation and transition exit readiness.
Transition Governance BoardFortnightly7The separation set only, with J&J present. Decides service extensions, exit sequencing and escalations.
Site and BISO councilsMonthlyLocal sliceTheir own OT inventory, remote access, segmentation and behaviour numbers. Decides local remediation priority.
Operational dashboardsContinuousAllEverything, unaggregated, for the people doing the work.
The disclosure chain

The board pack feeds the annual governance disclosure and, where a European sustainability reporting obligation applies, the governance and business-conduct datapoints in the sustainability statement. Before filing, reconcile the narrative against the minutes. A filing describing quarterly board oversight against minutes showing two meetings is a finding, and an entirely avoidable one.

Anti-metrics and the maturity ramp

Do not report these

  • Attacks blocked, alerts generated, emails filtered. Activity volume that no decision depends on. It also invites the question of what got through, which you then answer badly.
  • Training completion alone. Necessary as evidence, useless as a signal.
  • Raw vulnerability counts without age or exploitability. The count is a function of scanner coverage, so improving coverage looks like getting worse.
  • Maturity scores presented as progress. A self-assessed score moving from 2.6 to 2.9 is not evidence of anything, and boards have learned to discount it.
  • Percentages with an undefended denominator. The most common way a security report misleads without anyone intending to.

What you can honestly measure, and when

PeriodMeasurableWhat to say about the rest
Day 1Coverage and completionDenominators and control operation. Do not promise outcome metrics — you have no baseline and no history, and claiming otherwise is the fastest way to lose a board's trust.
+6 monthsTimelinessEnough operating history for SLA adherence and cycle times to mean something.
+12 monthsOutcomeDetection and containment times, remediation completion, incident trends — once detection is native and a full period exists.
+24 monthsLeading indicatorsFriction predicting shadow discovery, exception aging predicting deficiencies, supplier concentration predicting disruption.
Say this to the board at the first meeting

Name what you can and cannot measure yet, and when each becomes available. A CISO who says "we can report coverage now and outcomes from month twelve, here is why" is more credible than one who produces a full dashboard on Day 1 that nobody can trace to a source system.

Eighteen months to Day 1, then twenty-four to steady state

Anchored to a separation completing in the second half of 2027. Lanes: GOV governance DOC documents CTL controls REG regulatory MFG manufacturing SOX financial controls.

T-18 to T-15Now → Q4 2026

Build the obligation register and find the long poles

  • DOC Obligation register from contracts, filings, customer security schedules and every registration in every market. Read exercise, not design exercise.
  • REG Registration inventory with lead times. Start China, Japan and the notified body conversation immediately — they set the critical path.
  • MFG Validation-state mapping onto the system migration plan. This is the earliest honest answer to whether the date holds.
  • GOV Stand up the Information Security Steering Committee in provisional form so it has a minute trail before Day 1.
  • CTL Draft the twelve-domain catalogue against the obligation register only. Import nothing.
  • SOX Engage the prospective external auditor on control environment scoping. Their view of in-scope systems changes your plan.
T-15 to T-12Q4 2026 → Q1 2027

Tag severability and shape the transition schedules

  • CTL Tag every control with operator, severance state, evidence custody and exit trigger. The parent-operated set is now your transition scope, derived bottom-up.
  • GOV Reconcile that set against the commercially negotiated service schedule. The delta is a finding — escalate it.
  • DOC Negotiate evidence delivery obligations for every parent-extract control. Before signature.
  • MFG Passive traffic capture at every plant boundary.
  • REG Notified body slot booked; multi-market audit programme slot booked.
  • GOV Board committee charters drafted: Audit, Quality & Regulatory Compliance.
T-12 to T-9Q1 → Q2 2027

Evidence repository live, policy rebuild starts

  • CTL Evidence repository stood up and receiving. Parent-operated controls start depositing artefacts now, not at Day 1. This is the rule that saves the first audit.
  • DOC Apex policy and the rebuild set drafted. QMS-adjacent documents start first — they carry the longest change-control cycle.
  • GOV Board committees formally constituted; Transition Governance Board charter agreed with the parent.
  • SOX ITGC design walkthroughs on the target system landscape.
  • MFG Local time, name and certificate services rebuilt at the pilot site.
T-9 to T-6Q2 → Q3 2027

Build and rehearse

  • CTL Identity and logging foundation native. Everything downstream depends on the entity owning its own directory, its own logs and its own joiner-mover-leaver process.
  • MFG Rehearse the network cut at the smallest site during a planned shutdown.
  • REG Establishment registrations, clearance transfers and gateway account in progress; device identifier record updates underway.
  • DOC Harvest set rewritten; reference sweep complete; transitional licence expiry dates logged as controls.
  • GOV Every inherited exception re-decided or scheduled to expire.
  • SOX First internal test cycle on native controls to establish operating history.
T-6 to T-1Q3 → Q4 2027

Freeze, prove, and agree the Day 1 gap position

  • GOV Audit Committee approves the minimum-viable-compliance position with the documented gap plan, owners and dates. Get it in the minutes.
  • CTL Cross-boundary incident simulation. The most likely early failure is an incident touching both entities where nobody knows who notifies whom.
  • REG Disclosure policy, security contact and key material published under the new entity, staged for Day 1 activation.
  • MFG Site cuts sequenced, rollback plans tested, certificate expiry inventory clean.
  • DOC Policy library approved and published. Training assigned.
Day 1H2 2027

The entity asserts for itself

  • Policy library live under the new name. Registers populated. Committees already meeting with a minute history.
  • Evidence repository holding artefacts for the pre-separation period — the thing that makes your first audit testable.
  • Documented gaps with owners and dates, board-approved. Undocumented gaps become findings; documented gaps become a roadmap.
Day 1 to +122028

Exit by control, not by calendar

  • CTL Work the exit trigger queue. Report native coverage monthly to the Audit Committee.
  • SOX First full test cycle; management's assessment prepared on the deferred schedule but with controls operating from Day 1.
  • DOC Replace every licensed document before the transitional licence expires.
  • REG Long-lead market transfers land. Escalate any that will not.
  • GOV First independent assurance engagement — an observation window has to start somewhere.
+12 to +242029

Steady state and honest retrospection

  • Management system certification achieved; independent assurance report issued over a full period.
  • Transition Governance Board dissolved; committee architecture reviewed and two or three bodies retired.
  • Separation-era technical debt register worked down deliberately, with the shadow technology discovered in the cutover window either adopted or removed.
  • Obligation register re-run against the control catalogue. In a newly separated entity, obligations move faster than controls for the first three years.

Twenty traps

Ordered by how often they are found late. Set status as you confirm each one is handled.

1 · Cleaning the parent's policies imports the parent's architecture

The policy reads fine after a find-and-replace, but it still assumes an enterprise security operations centre, a global privacy office, a group legal function and a corporate insurance tower. You end up asserting controls you have no ability to operate — which is worse than having no policy, because now it is a documented commitment you are failing.

Fix

Rebuild every document that asserts. Harvest only documents that instruct. Test each harvested document with one question: can the new entity actually perform everything this document commits it to, on Day 1, with the people and systems it will have?

2 · Evidence for the audit period lives in systems you are about to lose

Your first audit covers a period that includes the transition. The evidence sits in the parent's identity platform, ticketing system and log store. When access ends, so does your ability to produce it — and the auditor will still ask.

Fix

The evidence repository is native on Day 1 for every control, regardless of who operates the control. Negotiate delivery obligations with format, cadence and remedy before the transition agreement is signed.

3 · Cloned validated systems arrive unvalidated

A copy of the enterprise system in a new environment under a new legal entity is a new system. Validation does not travel with the data. Until requalification is complete you cannot release product against it.

Fix

Map validation state onto the migration plan in the first quarter of the programme, and give the requalification schedule its own owner reporting to the Quality & Regulatory Compliance Committee.

4 · The electronic submissions account blocks adverse event reporting

The new entity needs its own gateway account, credentials and completed test-submission cycle before it can file electronically. Weeks of lead time, discovered late, and it sits directly in front of a statutory clock.

Fix

Open it twelve months out and run a live test submission. Keep a documented manual fallback for the first ninety days.

5 · Intra-group data transfers lose their legal basis on Day 1

Transfers that ran under group-level binding rules or an intra-group agreement become third-country transfers the moment the entity leaves the group. Invisible until someone asks which mechanism covers the flow.

Fix

Standard contractual clauses and transfer impact assessments executed before Day 1, your own record of processing activities, and a data protection officer appointed where required.

6 · Market registrations that will not transfer inside the transition window

Several major markets treat a manufacturer change as a new registration with full technical review. Lead times can exceed the entire transition period, and the consequence is a revenue stop in a market you cannot serve.

Fix

Build the market-by-product matrix in month one. Force the board decision about bridging arrangements twelve months out, while it is still a strategy rather than a crisis.

7 · Notified body capacity, not notified body approval

The certificate transfer is achievable. Getting an audit slot is the constraint. Bodies remain heavily booked, and a missed slot cascades into every market that relies on the certificate.

Fix

Book eighteen months out and treat the slot as a fixed programme milestone that other work plans around.

8 · The transition schedule and the control dependency map disagree

Corporate development negotiates services top-down from a functional view. Your control catalogue produces a bottom-up dependency list. They will not match, and the controls whose dependency was never negotiated simply stop working at separation.

Fix

Reconcile the two lists before signature and escalate the delta as a formal finding to the Transition Governance Board.

9 · Exiting a service on the contractual date with no operating history

The service ends because the contract says so, the replacement control has never operated, and the first audit finds a testable population of zero. This is the most common route to a material weakness in a separation.

Fix

Exit triggers are control tests, not dates. No cut without two operated cycles or ninety days of continuous evidence.

10 · The cloned directory inherits the parent's mess

A copied identity estate brings orphaned accounts, parent service accounts, stale privileged groups and nested entitlements nobody can explain. All of it becomes your access review population and your findings.

Fix

Migrate identities selectively against an approved population rather than cloning. It costs more up front and it is the single best predictor of a clean first ITGC opinion.

11 · Emergency change becomes the normal change path

Everything during separation is urgent, so everything becomes an emergency change with retrospective approval. The unapproved-change population explodes and the change control test fails.

Fix

Cap emergency change as a percentage of total, report it monthly to the steering committee, and require post-implementation review inside five working days with no exceptions.

12 · The plant network cut stops production

Time synchronisation, name resolution, certificate services, licence servers and vendor support paths traverse the parent's core in ways no diagram shows. Cutting without a capture-based map halts lines.

Fix

Passive capture at every plant boundary over a full production cycle. Rebuild time, name and certificate services locally first. Rehearse at the smallest site during a planned shutdown.

13 · Certificate expiry and mail cutover

Two of the most frequently reported cutover failures across large separations. Both preventable, both capable of taking out production or customer communications for days.

Fix

Certificate inventory with expiry dates as a named deliverable. Domain and mail cutover treated as a rehearsed, reversible change with a tested rollback.

14 · Complaint intake breaks the reporting clock

Complaints about your devices arrive at parent-operated call centres during transition. The statutory clock runs from awareness, and awareness now sits with a third party you do not control.

Fix

Define the handoff, the timestamp of record and the escalation path in the transition agreement. Test it with seeded complaints before Day 1.

15 · Device identifier records tied to the parent's organisation identifier

Identifier records key off the labeller's organisation identifier. A change of legal manufacturer cascades into record updates and, in some cases, new identifiers and relabelled product. Getting it wrong degrades recall traceability.

Fix

Scope this in the first quarter with labelling and packaging in the room. It is a supply chain project, not a data project.

16 · Supplier quality agreements name the parent

Vigilance and change-notification flow-downs run to the parent. A supplier who does not know to notify you of a process change is a recall in waiting, and supplier audit reports are the parent's work product you may not be entitled to.

Fix

Novate critical supplier and sterilisation agreements first, prioritised by product contact. Budget for re-auditing rather than assuming report transfer.

17 · Reading the first-year reporting relief as a design deferral

A newly listed company gets relief on when it must report on internal control. Teams hear a year of grace. But the financial statement audit relies on those controls from Day 1, and the first assessment looks back over a period that includes the transition.

Fix

Design and operate from Day 1. Use the relief for reporting timing only, and say so explicitly in the Audit Committee minutes so nobody plans against the wrong reading.

18 · Cyber disclosure while the parent operates detection

A newly listed entity owes timely disclosure of material incidents. During transition, detection, triage and often the first assessment of scope sit with the parent — but the disclosure obligation is yours, on your clock.

Fix

Write the materiality determination path into the Disclosure Committee charter and the transition agreement together, with a maximum notification interval from the parent. Rehearse it in the cross-boundary incident simulation.

19 · Transitional document licence expires with the library half-replaced

Separation agreements typically grant a limited, time-boxed licence to use the parent's documentation. The date passes, the replacement programme slipped, and the entity is operating on documents it no longer has the right to use — with the parent's name still in the footer.

Fix

Log the licence expiry as a control with an owner and a countdown. Report replacement progress against it monthly to the steering committee.

20 · Two cultures form in the first six months

One group wants the parent's rigour without the parent's funding. The other reads separation as permission — smaller company, fewer rules. Both are reacting to the same absence of a stated position, and whichever wins becomes permanent.

Fix

Name the non-negotiables early and few — four or five, stated plainly, enforced without exception. Everything else is a paved path where speed is the control. Then measure behaviour rather than training completion: exception volume, time-to-remediate, shadow technology discovery rate, self-reported incidents. Every organisation has a car going around the barrier. How routine that has become is your real security culture score.

Working notes

Saved in this browser. Use Export JSON to take status and notes with you.

Open questions to resolve against the source documents

  • Spin, sale or dual track — the governance architecture differs materially. A listed spin needs the full board committee structure and disclosure machinery; a sale to a strategic buyer inherits the buyer's.
  • Which entity holds each manufacturing site's registration at separation, and does any site serve both entities?
  • Transition service duration by function — and specifically whether it exceeds the longest market registration lead time.
  • Which connected products fall in scope for premarket security requirements, and which submissions are in flight at separation.
  • Scope of the transitional documentation licence and its expiry.
  • Whether the parent's independent assurance reports cover any service the new entity will consume, and for how long.

Notes