Pre-IPO TerminalUK Listing Rules & IPO Intelligence
← The full diagnostic

Worked example

The diagnostic, worked through

Everything below was produced by the product, not written for this page. The answers are invented; the machinery that turns them into an order of work is the one a paying reader gets, including the PDF and the Excel workbook.

This is a fictional issuer. No part of it describes a real company.

The answers were authored to exercise the diagnostic — in particular the dependency graph, by denying the one criterion several others declare they depend on. They are not a redacted client, an anonymised deal or a composite of either. Nothing about any company we have worked with is inferable from this page, because nothing on it came from one.

What it was told

All 73 criteria answered: 66 claimed, 5 denied, 2 unsure. A perimeter of 6 entities, group policies not adopted at all of them, and 9 months to target admission.

Answered no

  • 1.2 Group risk register
  • 2.3 ICFR framework gate
  • 2.8 Internal audit
  • 5.2 Environmental policy
  • 8.6 MAR and inside information gate

Answered unsure

  • 6.2 Accounting and tax on complex deals
  • 9.3 Segregation of duties

Every other criterion was answered yes. That is the point of the example rather than a flattering shortcut: a company claiming almost everything still comes out with a page of work, because the claims collide with the handful of denials.

Executive summary

Written to be pasted into the letter. 73 of 73 criteria answered.

26 of the 73 FPPP criteria are open. 5 of them are gates.

The sponsor cannot give the FPPP confirmation under UKLR 24.3.2R(5) while these remain open: 2.3 ICFR framework; 4.1 Monthly management accounts; 8.1 IFRS accounting policies; 1.9 Directors' FPPP risk assessment; 8.6 MAR and inside information. Everything else in this report is secondary to them.

14 findings need operating history, a system change or a third party, so they set the timeline rather than the budget and cannot be compressed by spending more: 2.3 ICFR framework; 4.1 Monthly management accounts; 8.1 IFRS accounting policies; 2.4 Delegation of authority; 2.6 Whistleblowing policy; and others. These are the items to start this month.

4 of the open findings are foundations that other criteria stand on, so sequencing is not a preference: 1.2 Group risk register alone has 7 criteria that cannot be satisfied until it is in place. Closing dependent items first means doing them twice.

9 of the findings are consequences of other open items rather than separate problems — they resolve when their root does. The number of workstreams here is 17, not 26.

8 findings need an external specialist — reporting accountant, listing counsel, tax or model review — so they carry a procurement lead time before any work starts.

13 findings must hold at every one of the 6 declared perimeter entities. Group readiness on those is the weakest entity, not the average, so partial adoption does not partially close them.

Criteria met

47 of 73 criteria met · 24 open, 2 unsure · 5 of the 7 gate items open

met 47unsure 2open 24

This counts how much of the work is done. It is not a verdict on whether you can list — that is the line above, and one open gate item settles it however high this figure goes.

Every one of the 73 FPPP criteria was put to you.

19 criteria count as open despite being answered yes: each was claimed while something it is impossible without was answered no. One of the two answers is wrong, and until you know which, the claim cannot be counted.

13 of the criteria counted here must hold at every one of the 6 entities you declared, not at the holding company alone. This scan asks each question once, at group level, so a "met" records the answer you gave for the group. Group coverage on those is the weakest entity rather than the average, so the figure above can only be lower once it is asked per entity — never higher.

Where it sits, by area and by function

By FPPP area

  • 1. Directors' risk assessment of FPP 2 of 9 met · 7 open · the gate item is open
  • 2. High-level reporting environment 6 of 12 met · 6 open · 1 of the 2 gate items open
  • 3. Forecasting and budgeting 8 of 8 met · the gate item is met
  • 4. Management reporting framework 4 of 6 met · 2 open · the gate item is open
  • 5. ESG, climate and sustainability reporting 4 of 9 met · 5 open
  • 6. Significant transaction complexity 4 of 6 met · 1 open, 1 unsure
  • 7. Strategic projects and initiatives 8 of 8 met
  • 8. Financial accounting and reporting 5 of 7 met · 2 open · all 2 gate items open
  • 9. IT environment 6 of 8 met · 1 open, 1 unsure

By owning function

The default owner of each criterion, most outstanding first. It is where the work lands, not who is to blame for it.

  • Compliance & Risk 2 of 12 met · 10 open · the gate item is open
  • CFO / Finance 20 of 26 met · 5 open, 1 unsure · 2 of the 3 gate items open
  • ESG 3 of 6 met · 3 open
  • IT 6 of 8 met · 1 open, 1 unsure
  • Board / Company Secretary 5 of 7 met · 2 open · 1 of the 2 gate items open
  • Legal 2 of 4 met · 2 open · the gate item is open
  • Internal Audit 0 of 1 met · 1 open
  • Strategy 7 of 7 met
  • Investor Relations 2 of 2 met

5

Blocking

11

High

9

Medium

1

Low

Priority against effort

Two axes, held apart deliberately. Priority is what a sponsor needs before admission; effort is how much calendar time it takes. Collapsed into one score they trade against each other, and they should not: anything in the High-effort column starts this month whatever its priority, because that effort is time no budget buys back. Read down the column for the schedule, across the row for the sponsor.

Priority \ EffortLowMediumHigh
Blocking
  • 1.9 Directors' FPPP risk assessment
  • 8.6 MAR and inside information
  • 2.3 ICFR framework
  • 4.1 Monthly management accounts
  • 8.1 IFRS accounting policies
High
  • 1.2 Group risk register
  • 4.4 Out-of-cycle escalation
  • 6.2 Accounting and tax on complex deals
  • 2.4 Delegation of authority
  • 2.6 Whistleblowing policy
  • 2.10 Accounting records
  • 5.3 Health and safety policy
  • 5.4 Business ethics and anti-corruption
  • 6.5 Related-party transactions
  • 9.2 Logical access controls
  • 9.3 Segregation of duties
Medium
  • 1.3 Risk categories covered
  • 1.5 Risk owners
  • 1.8 FPP-relevant risk factors
  • 2.7 Control deficiency remediation
  • 5.5 Climate risk in the risk matrix
  • 1.6 Mitigation actions
  • 5.8 Corporate governance statement
  • 1.7 Board and committee challenge
  • 5.2 Environmental policy
Low
  • 2.8 Internal audit
Low
Write down and approve what already happens — days to a fortnight.
Medium
Build a process and run it enough to evidence it — one to three months.
High
Needs operating history, a system change or a third party — three months+, and more money does not make it faster.

Start these this month

14 findings need operating history, a system change or a third party. They set the admission date rather than the budget, and adding money or people does not make them finish sooner.

  • 2.3 ICFR framework External advisor
  • 4.1 Monthly management accounts Company
  • 8.1 IFRS accounting policies External advisor
  • 2.4 Delegation of authority Company
  • 2.6 Whistleblowing policy Company
  • 2.10 Accounting records Company
  • 5.3 Health and safety policy Company
  • 5.4 Business ethics and anti-corruption Company
  • 6.5 Related-party transactions External advisor
  • 9.2 Logical access controls Company
  • 9.3 Segregation of duties External advisor
  • 1.7 Board and committee challenge Company
  • 5.2 Environmental policy Company
  • 2.8 Internal audit External advisor

Findings

26 open, carrying the same fields a phase-1 FPPP red-flag report sets out in columns. The PDF keeps the columns; on screen the two prose fields get their own line, because a 230-character observation in a 190px column is not a column. 9 are marked via — they collapse when their root closes and are not separate workstreams. Counting them as independent findings is how a gap list becomes a scarier number than the company actually has.

#AreaTopicPriorityEffortWhoPhase
2.32. High-level reporting environmentICFR frameworkFoundation ×2BlockingHighExternal advisorPre-IPO
Observation

Not in place.

Recommendation

Identifies the key financial reporting controls, names a control owner for each, and states how design and operating effectiveness are assessed and on what cycle.

4.14. Management reporting frameworkMonthly management accountsFoundation ×3BlockingHighCompanyPre-IPO
Observation

Answered yes — this has to hold at every one of the 6 entities in your IPO perimeter, and you told us group policies are not adopted at all of them. Group readiness is the weakest entity, not the average — so this reads as not done.

Recommendation

A monthly pack containing all six elements, with divisional reporting for every entity in the IPO perimeter.

8.18. Financial accounting and reportingIFRS accounting policiesFoundation ×4BlockingHighExternal advisorPre-IPO
Observation

Answered yes — this has to hold at every one of the 6 entities in your IPO perimeter, and you told us group policies are not adopted at all of them. Group readiness is the weakest entity, not the average — so this reads as not done.

Recommendation

A group IFRS accounting policy manual, board-approved, with evidence it is the manual each perimeter entity actually applies.

1.91. Directors' risk assessment of FPPDirectors' FPPP risk assessmentvia 1.2BlockingMediumUsPre-IPO
Observation

Answered yes — the directors' assessment rests on the identified risks, and no group risk register exists to draw them from — see criterion 1.2 (Group risk register), which you told us is not in place. Closing 1.2 resolves this; it is not a separate workstream.

Recommendation

A single directors' FPPP risk assessment addressing each of the seven areas by name, and stating for each the procedures relied upon.

8.68. Financial accounting and reportingMAR and inside informationBlockingMediumExternal advisorPre-IPO
Observation

Not in place.

Recommendation

A maintained insider list, plus documented procedures for PDMR notifications and for assessing, escalating and disclosing inside information — including when to issue a holding announcement.

2.42. High-level reporting environmentDelegation of authorityHighHighCompanyPre-IPO
Observation

Answered yes — this has to hold at every one of the 6 entities in your IPO perimeter, and you told us group policies are not adopted at all of them. Group readiness is the weakest entity, not the average — so this reads as not done.

Recommendation

Approval limits for procurement, payments and commitments, by role and value band, stating for each how the limit is applied — enforced in the system, or by a named compensating control where the system cannot carry it.

2.62. High-level reporting environmentWhistleblowing policyHighHighCompanyPre-IPO
Observation

Answered yes — this has to hold at every one of the 6 entities in your IPO perimeter, and you told us group policies are not adopted at all of them. Group readiness is the weakest entity, not the average — so this reads as not done.

Recommendation

Names the reporting channel, protects the reporter from retaliation, and states how reports are escalated, investigated and tracked to conclusion.

2.102. High-level reporting environmentAccounting recordsHighHighCompanyPre-IPO
Observation

Answered yes — this has to hold at every one of the 6 entities in your IPO perimeter, and you told us group policies are not adopted at all of them. Group readiness is the weakest entity, not the average — so this reads as not done.

Recommendation

Records support production of management information within the stated close timetable.

5.35. ESG, climate and sustainability reportingHealth and safety policyHighHighCompanyPre-IPO
Observation

Answered yes — this has to hold at every one of the 6 entities in your IPO perimeter, and you told us group policies are not adopted at all of them. Group readiness is the weakest entity, not the average — so this reads as not done.

Recommendation

Sustainability and health-and-safety policies or procedures, where applicable to the operations, with evidence of implementation across the material ones.

5.45. ESG, climate and sustainability reportingBusiness ethics and anti-corruptionHighHighCompanyPre-IPO
Observation

Answered yes — this has to hold at every one of the 6 entities in your IPO perimeter, and you told us group policies are not adopted at all of them. Group readiness is the weakest entity, not the average — so this reads as not done.

Recommendation

A code of ethics, anti-corruption policies and whistleblowing procedures, each formally approved at every entity in the IPO perimeter.

6.56. Significant transaction complexityRelated-party transactionsHighHighExternal advisorPre-IPO
Observation

Answered yes — this has to hold at every one of the 6 entities in your IPO perimeter, and you told us group policies are not adopted at all of them. Group readiness is the weakest entity, not the average — so this reads as not done.

Recommendation

A maintained related-party register plus the documented procedure covering identification, assessment against the threshold, approval, and disclosure.

9.29. IT environmentLogical access controlsHighHighCompanyPre-IPO
Observation

Answered yes — this has to hold at every one of the 6 entities in your IPO perimeter, and you told us group policies are not adopted at all of them. Group readiness is the weakest entity, not the average — so this reads as not done.

Recommendation

A current user access list for each key financial application, showing access restricted to authorised users, with joiners and leavers reflected.

9.39. IT environmentSegregation of dutiesHighHighExternal advisorPre-IPO
Observation

Not known to be in place. For a sponsor, not knowing is the same answer as no.

Recommendation

A documented segregation-of-duties matrix, and a periodic access review that has actually been performed — with its outcome recorded, whether or not it raised anything.

1.21. Directors' risk assessment of FPPGroup risk registerFoundation ×7HighMediumCompanyPre-IPO
Observation

Not in place.

Recommendation

A current group risk register giving, for each risk, likelihood, financial impact, owner and mitigation.

4.44. Management reporting frameworkOut-of-cycle escalationHighMediumCompanyPre-IPO
Observation

Answered yes — this has to hold at every one of the 6 entities in your IPO perimeter, and you told us group policies are not adopted at all of them. Group readiness is the weakest entity, not the average — so this reads as not done.

Recommendation

States the materiality threshold, the escalation route to the board, and the timescale — with the link to the inside-information assessment made explicit.

6.26. Significant transaction complexityAccounting and tax on complex dealsHighMediumExternal advisorPre-IPO
Observation

Not known to be in place. For a sponsor, not knowing is the same answer as no.

Recommendation

States who assesses accounting and tax implications, at what point in the transaction, and how the assessment reaches the board before commitment.

1.71. Directors' risk assessment of FPPBoard and committee challengevia 1.2MediumHighCompanyPre-IPO
Observation

Answered yes — the board and committee review the register, and there is no register to review — see criterion 1.2 (Group risk register), which you told us is not in place. Closing 1.2 resolves this; it is not a separate workstream.

Recommendation

Minutes record the committee reviewing the risk register and challenging management on it — not merely receiving it.

5.25. ESG, climate and sustainability reportingEnvironmental policyMediumHighCompanyPre-IPO
Observation

Not in place.

Recommendation

An environmental policy carrying board approval, with evidence of its implementation at each entity across the group.

1.61. Directors' risk assessment of FPPMitigation actionsvia 1.2MediumMediumCompanyPre-IPO
Observation

Answered yes — mitigating actions are tracked per risk on the register, and there is no register to track them against — see criterion 1.2 (Group risk register), which you told us is not in place. Closing 1.2 resolves this; it is not a separate workstream.

Recommendation

Each risk carries mitigating actions with a status and a review date.

5.85. ESG, climate and sustainability reportingCorporate governance statementvia 2.3MediumMediumExternal advisorPre-IPO
Observation

Answered yes — the corporate governance statement must describe the internal control system for financial reporting, and no ICFR framework has been documented to describe — see criterion 2.3 (ICFR framework), which you told us is not in place. Closing 2.3 resolves this; it is not a separate workstream.

Recommendation

A draft corporate governance statement in which each applicable DTR and UK Corporate Governance Code requirement is addressed, and readable against them.

1.31. Directors' risk assessment of FPPRisk categories coveredvia 1.2MediumLowCompanyPre-IPO
Observation

Answered yes — risk categories are recorded on the risk register, so there is nothing for the identification process to populate — see criterion 1.2 (Group risk register), which you told us is not in place. Closing 1.2 resolves this; it is not a separate workstream.

Recommendation

Each of the five categories is represented by at least one identified risk, and the register shows which category each risk belongs to.

1.51. Directors' risk assessment of FPPRisk ownersvia 1.2MediumLowCompanyPre-IPO
Observation

Answered yes — risk owners are assigned against entries on a register, and there is no register to assign them on — see criterion 1.2 (Group risk register), which you told us is not in place. Closing 1.2 resolves this; it is not a separate workstream.

Recommendation

Every risk names an accountable individual.

1.81. Directors' risk assessment of FPPFPP-relevant risk factorsvia 1.2MediumLowCompanyPre-IPO
Observation

Answered yes — FPP-relevant risks are flagged on the register, and there is no register to flag them on — see criterion 1.2 (Group risk register), which you told us is not in place. Closing 1.2 resolves this; it is not a separate workstream.

Recommendation

Risks bearing on financial position and prospects are marked as such and each maps to the named procedure that addresses it.

2.72. High-level reporting environmentControl deficiency remediationvia 2.3MediumLowUsPre-IPO
Observation

Answered yes — an internal control deficiency is a departure from a defined control framework, and no ICFR framework has been documented — see criterion 2.3 (ICFR framework), which you told us is not in place. Closing 2.3 resolves this; it is not a separate workstream.

Recommendation

States how deficiencies are logged, rated for severity, communicated, assigned and cleared, with timescales and an escalation threshold to the audit committee.

5.55. ESG, climate and sustainability reportingClimate risk in the risk matrixvia 1.2MediumLowCompanyPre-IPO
Observation

Answered yes — climate risks are integrated into the Group Risk Matrix, and no group risk register exists to integrate them into — see criterion 1.2 (Group risk register), which you told us is not in place. Closing 1.2 resolves this; it is not a separate workstream.

Recommendation

An ESG risk matrix in which physical and transition climate risks are each separately identified, with the supporting climate risk assessment referenced.

2.82. High-level reporting environmentInternal auditLowHighExternal advisorPre-IPO
Observation

Not in place.

Recommendation

An internal audit charter and annual plan approved by the audit committee — or, where there is no function, a board-approved explanation naming the compensating controls relied upon.

How the foundations get closed

6 of the open findings are either gates or criteria that at least two others are impossible without. The Recommendation column above is the acceptance condition — what has to be true when somebody looks. This is the other half: what closing it involves, in the order the work runs. Where calendar time is the binding input rather than money, the first step says so.

2.3ICFR frameworkBlockingHigh effort · External advisor · 2 criteria stand on it
  1. 1Start now, and for a reason that is not urgency: operating effectiveness testing needs a period of history behind it, so a late start cannot be bought back with people or money.
  2. 2Scope down from the financial statement line items that matter to the controls that produce them. A list assembled bottom-up from the controls that happen to exist documents the current state rather than the required one.
  3. 3Name an individual control owner for each key control. An owner that is a department cannot be asked what happened in March.
  4. 4Separate design from operating effectiveness in the document, and state who tests each and on what cycle. Design and implementation is the bar at the confirmation (FCA TN 708.4); the operating record is what phase 2 reads.
  5. 5Roll it out at every entity in the perimeter, not only the holding company. This criterion is scored at the weakest entity, so a framework adopted in four of seven places scores as four of seven, not as most of the way.
4.1Monthly management accountsBlockingHigh effort · Company · 3 criteria stand on it
  1. 1Produce the pack every month starting with this month, even in an imperfect form. The evidence here is a run of months and it is the one input no budget shortens.
  2. 2Publish a close calendar with an issue date for each month, then record the actual issue date against it. The calendar is the plan; the log of hits and misses is the evidence.
  3. 3Extend divisional reporting to every entity in the perimeter, dormant ones included. A perimeter entity absent from the pack is a hole in the consolidation and it is found at conversion.
  4. 4Add the missing elements — P&L, cash flow, balance sheet, working capital, KPIs — as identifiable items rather than one composite page, so completeness can be checked at a glance.
  5. 5Take the pack to the board monthly and keep the minute. A pack produced and never read evidences a process at the wrong level.
8.1IFRS accounting policiesBlockingHigh effort · External advisor · 4 criteria stand on it
  1. 1Board-approve one group manual, then test whether each perimeter entity actually applies it. The second half is the half that fails.
  2. 2List the entities reporting under local GAAP with the conversion path for each. The conversion has to run off this manual rather than off a separate working practice built in the finance team.
  3. 3Write down the key judgements and estimates with the reasoning, not only the policy. They are what a reporting accountant reads first.
  4. 4Do this before the historical financial information is prepared. Without it the numbers in the prospectus have no stated basis, and inconsistency between entities surfaces at conversion — late, and in public.
1.9Directors' FPPP risk assessmentBlockingMedium effort · Us
  1. 1Put one named owner on the document itself, not one per area. Seven part-owners produce seven annexes and no assessment.
  2. 2Use the seven areas the criterion names as the section headings, so a reader can check coverage without reading the prose.
  3. 3In each section write the risk first and the procedure relied on second, and name the artefact that evidences the procedure. A procedure with no named artefact is a claim, and phase 1 asks for the artefact.
  4. 4Where a procedure is not yet in place, say so and attach the plan with a date. FCA TN 708.4 contemplates gaps identified and undertaken to be addressed at the confirmation, not gaps closed already — but it does not contemplate gaps unstated.
  5. 5Route the draft through the audit committee before the board, and keep both minutes. The bar at the confirmation is designed, documented, approved and communicated; the minutes are the last two words.
8.6MAR and inside informationBlockingMedium effort · External advisor
  1. 1Open the insider list now. UK MAR binds an issuer from the request for admission, not from the first day of dealings, and the IPO is itself the largest inside-information event the company has had.
  2. 2Name an owner for the list inside the company. Article 18 is not transferred by asking an adviser to keep it.
  3. 3Write the assessment route down: who decides whether something is inside information, within what time, and who can call a holding announcement.
  4. 4Stand up the PDMR notification process and tell the PDMRs it exists. The obligation lands on individuals who have not had it before.
  5. 5Run the procedure once over a real event from the last quarter. A procedure nobody has used is a document.
1.2Group risk registerHighMedium effort · Company · 7 criteria stand on it
  1. 1Do this before the criteria that stand on it. Each of them draws its content from the register, so closing them first means closing them twice.
  2. 2Give every risk a named individual owner and a dated mitigation action. A departmental owner cannot be chased and does not satisfy a reviewer.
  3. 3Put climate risk, physical and transition, in the group register rather than in a separate ESG document. One artefact then answers both the risk criterion and the ESG one.
  4. 4Set a review cycle of six months or shorter and keep the revision history. A register last touched eighteen months ago reads worse than a thin one updated last quarter, because the dates are what a reviewer reads first.
  5. 5Take it to the audit and risk committee for challenge, and check the minutes record challenge rather than receipt.

These steps are our considered account of how the work runs, not a requirement of the standard and not the sponsor’s or the reporting accountant’s instruction. Nothing here says what the outcome of doing them is, because nobody can.

The order of work

This is the order the work is worth doing in, on the answers given. It is not a project plan signed off by anybody, not a requirement of the standard, and not the sponsor's or the reporting accountant's instruction.

26 open items in 7 waves at 4 in flight at once. At 2 it is 13 waves; at 8 it is 4. The effort bands did not move between those three figures — how many things you can run at once is what changes the shape of the programme, and it is the one input here that is yours rather than ours.

2 at once

13 waves

3 at once

9 waves

4 at once

7 waves

6 at once

5 waves

8 at once

4 waves

16 of the 26 open items your own team can close. 8 need an external specialist — a reporting accountant, listing counsel, tax or a model review — and that is a procurement lead time before any work starts on them. 2 are work this product does.

3 items cannot start until another function delivers something first. Those are the ones to watch: an item late inside one lane is that lane's problem, and an item late across two is nobody's until it is everybody's.

9 of the 14 heaviest-band items could start now and cannot, because the first wave holds 4. The findings above say every one of them wants to start immediately, since the binding input on them is calendar time; this says how many of them your capacity actually admits. Both are true, and the distance between them is what the plan turns on — it is why this page asks how many you can run rather than adding up how long each takes. A further 2 are waiting on another open item, which capacity does not move.

Your target admission puts you at T-9 on the conventional phasing, and no item here is first expected earlier than that.

Function \ Wave1234567
Compliance & Risk
  • 2.3 ICFR framework
  • 1.2 Group risk register
  • 1.7 Board and committee challenge
  • 2.6 Whistleblowing policy
  • 5.4 Business ethics and anti-corruption
  • 1.6 Mitigation actions
  • 1.3 Risk categories covered
  • 1.5 Risk owners
  • 1.8 FPP-relevant risk factors
  • 2.7 Control deficiency remediation
Board / Company Secretary
  • 1.9 Directors' FPPP risk assessment
  • 5.8 Corporate governance statement
CFO / Finance
  • 8.1 IFRS accounting policies
  • 4.1 Monthly management accounts
  • 2.4 Delegation of authority
  • 2.10 Accounting records
  • 4.4 Out-of-cycle escalation
  • 6.2 Accounting and tax on complex deals
Internal Audit
  • 2.8 Internal audit
ESG
  • 5.2 Environmental policy
  • 5.3 Health and safety policy
  • 5.5 Climate risk in the risk matrix
Legal
  • 8.6 MAR and inside information
  • 6.5 Related-party transactions
IT
  • 9.2 Logical access controls
  • 9.3 Segregation of duties

A wave is an ordering, not a length of time. The effort bands describe single items and say nothing about how many can run at once, so nothing here is added up and nothing here is a date. What sets the shape is the number of items in flight, which is yours to set.

Compliance & Riskwaves 1–7

10 open. 8 of the 10 your own team can close; 1 needs an external specialist, so it carries a procurement lead time before any work starts, and 1 is work this product does.

Framework document ×1

Register ×5

Committee minutes ×1

Policy ×2

Documented procedure ×1

Board / Company Secretarywaves 2–5

2 open. None of them can be closed inside the company; 1 needs an external specialist, so it carries a procurement lead time before any work starts, and 1 is work this product does. This lane cannot finish on its own: it waits on Compliance & Risk.

Framework document ×1

Documented procedure ×1

CFO / Financewaves 1–6

6 open. 4 of the 6 your own team can close; 2 need an external specialist, so they carry a procurement lead time before any work starts.

Policy ×1

Management accounts ×2

Matrix ×1

Documented procedure ×2

Internal Auditwave 3

1 open. It cannot be closed inside the company; 1 needs an external specialist, so it carries a procurement lead time before any work starts.

Terms of reference ×1

ESGwaves 4–7

3 open. All 3 your own team can close; none needs an outside specialist. This lane cannot finish on its own: it waits on Compliance & Risk.

Policy ×2

Register ×1

Legalwaves 2–4

2 open. None of them can be closed inside the company; 2 need an external specialist, so they carry a procurement lead time before any work starts.

Register ×2

ITwaves 2–5

2 open. 1 of the 2 your own team can close; 1 needs an external specialist, so it carries a procurement lead time before any work starts.

System configuration record ×2

Every item, in the order it is worth doing

The line under each row is the reason it sits where it does. It is our derivation and you are meant to be able to argue with it — which you cannot do with a plan that only shows you the bars.

WaveRefItemFunctionArtefactEffortWhoFirst seen at
12.3ICFR frameworkCompliance & RiskFramework documentHighExternal advisorT-9

Nothing blocks it, so it starts in the first wave. It is a gate: the confirmation cannot be given without it.

11.2Group risk registerCompliance & RiskRegisterMediumCompanyT-6

Nothing blocks it, so it starts in the first wave. 1.9 is a gate that cannot be satisfied until this is, so it is scheduled with the gates rather than on its own merits.

18.1IFRS accounting policiesCFO / FinancePolicyHighExternal advisorT-9

Nothing blocks it, so it starts in the first wave. It is a gate: the confirmation cannot be given without it.

14.1Monthly management accountsCFO / FinanceManagement accountsHighCompanyT-9

Nothing blocks it, so it starts in the first wave. It is a gate: the confirmation cannot be given without it.

21.9Directors' FPPP risk assessmentHandoffBoard / Company SecretaryFramework documentMediumUsT-9

Cannot start before 1.2, which is also open. It is a gate: the confirmation cannot be given without it.

28.6MAR and inside informationLegalRegisterMediumExternal advisorT-9

Nothing blocks it — it is in wave 2 only because the earlier waves were full at 4 in flight. It is a gate: the confirmation cannot be given without it.

29.2Logical access controlsITSystem configuration recordHighCompanyT-6

Nothing blocks it — it is in wave 2 only because the earlier waves were full at 4 in flight. Open work is stacked behind it one level deep, so closing it first is what stops the rest being done twice.

21.7Board and committee challengeCompliance & RiskCommittee minutesHighCompanyT-6

Cannot start before 1.2, which is also open. The binding input is calendar time, which is the one thing nothing else buys back.

32.4Delegation of authorityCFO / FinanceMatrixHighCompanyT-9

Nothing blocks it — it is in wave 3 only because the earlier waves were full at 4 in flight. The binding input is calendar time, which is the one thing nothing else buys back.

32.6Whistleblowing policyCompliance & RiskPolicyHighCompanyT-9

Nothing blocks it — it is in wave 3 only because the earlier waves were full at 4 in flight. The binding input is calendar time, which is the one thing nothing else buys back.

32.8Internal auditInternal AuditTerms of referenceHighExternal advisorT-6

Nothing blocks it — it is in wave 3 only because the earlier waves were full at 4 in flight. The binding input is calendar time, which is the one thing nothing else buys back.

32.10Accounting recordsCFO / FinanceManagement accountsHighCompanyT-9

Nothing blocks it — it is in wave 3 only because the earlier waves were full at 4 in flight. The binding input is calendar time, which is the one thing nothing else buys back.

45.2Environmental policyESGPolicyHighCompanyT-6

Nothing blocks it — it is in wave 4 only because the earlier waves were full at 4 in flight. The binding input is calendar time, which is the one thing nothing else buys back.

45.3Health and safety policyESGPolicyHighCompanyT-6

Nothing blocks it — it is in wave 4 only because the earlier waves were full at 4 in flight. The binding input is calendar time, which is the one thing nothing else buys back.

45.4Business ethics and anti-corruptionCompliance & RiskPolicyHighCompanyT-6

Nothing blocks it — it is in wave 4 only because the earlier waves were full at 4 in flight. The binding input is calendar time, which is the one thing nothing else buys back.

46.5Related-party transactionsLegalRegisterHighExternal advisorT-6

Nothing blocks it — it is in wave 4 only because the earlier waves were full at 4 in flight. The binding input is calendar time, which is the one thing nothing else buys back.

59.3Segregation of dutiesITSystem configuration recordHighExternal advisorT-9

Cannot start before 9.2, which is also open. The binding input is calendar time, which is the one thing nothing else buys back.

54.4Out-of-cycle escalationCFO / FinanceDocumented procedureMediumCompanyT-6

Nothing blocks it — it is in wave 5 only because the earlier waves were full at 4 in flight.

51.6Mitigation actionsCompliance & RiskRegisterMediumCompanyT-9

Cannot start before 1.2, which is also open.

55.8Corporate governance statementHandoffBoard / Company SecretaryDocumented procedureMediumExternal advisorT-6

Cannot start before 2.3, which is also open.

66.2Accounting and tax on complex dealsCFO / FinanceDocumented procedureMediumExternal advisorT-6

Nothing blocks it — it is in wave 6 only because the earlier waves were full at 4 in flight.

61.3Risk categories coveredCompliance & RiskRegisterLowCompanyT-6

Cannot start before 1.2, which is also open.

61.5Risk ownersCompliance & RiskRegisterLowCompanyT-6

Cannot start before 1.2, which is also open.

61.8FPP-relevant risk factorsCompliance & RiskRegisterLowCompanyT-6

Cannot start before 1.2, which is also open.

72.7Control deficiency remediationCompliance & RiskDocumented procedureLowUsT-6

Cannot start before 2.3, which is also open.

75.5Climate risk in the risk matrixHandoffESGRegisterLowCompanyT-6

Cannot start before 1.2, which is also open.

Company
Company — internal. The knowledge is in the building; the work is not done.
External advisor
External advisor — a specialist you do not have in-house, so it carries a procurement lead time.
Us
Us — work this product does. Kept deliberately narrow.

First seen at is the point on the published phasing at which the reporting accountant expects to see something, derived from the criterion’s own properties by the same rule the timetable prints. A row in amber is one the phasing wants earlier than the target you gave.

By FPPP area

Each area takes its worst finding, not its average. A group policy three subsidiaries never adopted is not 60% done.

01Directors' risk assessment of FPP7 open / 9BlockingHigh effort
02High-level reporting environment6 open / 12BlockingHigh effort
03Forecasting and budgeting0 open / 8Clear
04Management reporting framework2 open / 6BlockingHigh effort
05ESG, climate and sustainability reporting5 open / 9HighHigh effort
06Significant transaction complexity2 open / 6HighHigh effort
07Strategic projects and initiatives0 open / 8Clear
08Financial accounting and reporting2 open / 7BlockingHigh effort
09IT environment2 open / 8HighHigh effort
A4 landscape, built in this tab. Nothing is uploaded.

What this example leaves out

The three register checks are missing, and they cannot be faked here: each one is a lookup against a public register, and its result means nothing without the names it was given and the date the register was read. They are free and public in their own right, so run them on real names rather than reading invented ones.