Critical — Board-Level

Operational Risk Matrix

Helios Digital • Gold Issuance Facility

Scoring Methodology

Probability (P)

1 Rare • 2 Unlikely • 3 Possible • 4 Likely • 5 Frequent

Impact (I)

1 Low • 2 Moderate • 3 High • 4 Severe • 5 Existential

Severity = P × I — Owners are roles (not people) to keep this durable.

Response Standards

“Halt Issuance”

Stop new activations / mints immediately.

“Redemption Throttle”

Slow queue processing under published policy (no discretionary favoritism).

“Public Statement”

Short factual update, no promises, next update timestamp.

Legal & Regulatory

IDRiskPISevDetectionPrevent / MitigateResponseOwner
L-01Token marketed as "investment/returns" creating securities posture3515Marketing review, social monitoringStrict language rules, approvals, disclaimersFreeze marketing, counsel memo, update site copyCompliance & Legal
L-02Unlicensed money transmission exposure (fiat handling)3515Payment flow auditUse regulated on/off-ramps, avoid custodying customer fiatHalt fiat intake, reroute via licensed partnersCompliance & Legal
L-03Sanctions breach via onboarding or redemption2510Screening logs, alertsSanctions screening + geo-fencing + policyHalt redemption to impacted accounts, report if requiredCompliance & Legal
L-04Misleading redemption promises (speed/availability)3412Support tickets, SLA driftPolicy-defined windows + minimums + transparent SLAPublic update, throttle, prioritize per policy onlyTreasury & Risk
L-05Data privacy breach (KYC metadata leaks)2510Security monitoringStore minimal data, vendor DPAs, access controlIncident protocol, notifications, rotate secretsEngineering + Compliance

Custody & Asset Backing

IDRiskPISevDetectionPrevent / MitigateResponseOwner
C-01Fraudulent custody receipt or forged attestation2510Reconciliation mismatchSigned attestations, independent audit, dual confirmationsHalt issuance, forensic review, replace attestor keysCustody Ops + Treasury
C-02Vault partner insolvency / frozen operations2510News/legal noticeDiversify custody, contract protections, insuranceHalt issuance, redemption plan activation, counsel leadCustody Ops + Legal
C-03Gold is not allocated as claimed (pooling/rehypothecation)2510Audit / serial mismatchRequire allocated custody + audit rightsHalt issuance, publish facts, migrate custodyTreasury + Custody
C-04Insurance coverage insufficient or exclusions triggered3412Annual policy reviewCoverage review + riders + diversificationPause issuance, disclose limitations, renegotiateTreasury + Legal

Treasury & Liquidity

IDRiskPISevDetectionPrevent / MitigateResponseOwner
T-01Stablecoin depeg (USDC/USDT) disrupts conversion3412Price feed + exchange spreadsMulti-stable strategy + circuit breakersHalt conversions, reroute, publish statusTreasury
T-02Redemption wave (bank run dynamics)3515Queue growth, LP imbalanceBuffers, throttle policy, clear commsRedemption throttle, halt issuance, crisis commsTreasury + Ops Lead
T-03DEX liquidity drained (LP exploit or MEV attack)3412Pool health monitorsPhased liquidity, lockups, safeguardsPause liquidity adds, notify, assess arbitrageExchange & Liquidity
T-04Gold spot price gap vs token price (peg stress)4312Premium/discount monitorRedemption arbitrage path + transparencyPublish PoR + redemption schedule, no panic languageTreasury
T-05Treasury mis-execution (wrong pricing window / dealer issue)248ReconciliationExecution policy + dual approvalCorrect, disclose if material, improve controlsTreasury

Smart Contract & Technical

IDRiskPISevDetectionPrevent / MitigateResponseOwner
S-01Smart contract mint bug (over-mint)2510Supply invariant monitorsFormal invariants + audits + testsHalt issuance, snapshot, migration planEngineering
S-02Signature replay / attestation replay3412Nonce monitoringEIP-712 domain + nonces + expiryHalt deposits, rotate keys, patchEngineering
S-03Merkle root corruption (bad snapshot)3412Proof failuresDeterministic ordering + reproducible buildsPublish correction, append-only, investigateEngineering
S-04Oracle manipulation (if used)3412Price anomaliesUse multiple sources, bounded updatesFreeze pricing actions, publish statusTreasury + Eng
S-05Chain halt / severe congestion (XRPL/Stellar/EVM)339Chain statusMulti-rail fallback strategyTemporarily pause anchors, queue opsEngineering + Ops

Governance & Key Management

IDRiskPISevDetectionPrevent / MitigateResponseOwner
G-01Multisig/MPC key compromise2510Key alertsMPC + geo separation + allowlistsEmergency rotate, halt issuance, notify partnersOps Lead + Eng
G-02Insider misuse of pause/freeze/clawback2510Admin logsRole separation + timelocks + policyGovernance incident, publish action logOps Lead + Legal
G-03Governance capture (protocol token)248Voting anomaliesQuorums, timelocks, emergency veto policyPause governance execution, reviewOps Lead

Exchange & Market

IDRiskPISevDetectionPrevent / MitigateResponseOwner
X-01CEX listing rejected due to compliance gaps339Exchange feedbackReadiness pack, audits, legal opinionsIterate docs, focus DEX + complianceExchange Lead
X-02Delisting / trading halt on CEX248Exchange noticeMaintain PoR + response SLAsComms, redemption stability, fix root causeExchange Lead
X-03Market manipulation / short attack3412Price + volume anomaliesTransparent redemption + PoRPublish facts, stabilize ops, avoid promisesTreasury + Exchange
X-04Regulatory pressure requiring freeze capability3412Exchange/legal inboundDecision tree + published policyIf enabled, use only per policy + logsLegal + Ops

Reputational & Operational

IDRiskPISevDetectionPrevent / MitigateResponseOwner
R-01Media claims "scam" despite proofs3412MonitoringSingle source of truth pageFast factual response + proof linksOps Lead
R-02Social panic causes redemption spike4416Sentiment + queueComms cadence + transparencyThrottle per policy, publish updatesOps Lead + Treasury
O-01Understaffed support operations4312Ticket backlogStaffing plan + playbooksTemporarily cap activations, improve supportOps Lead
O-02Vendor failure (KYC provider, database outage)339Uptime monitorsRedundancy + DRFailover, temporary pause onboardingEngineering
O-03Accounting / reconciliation errors3412Audit mismatchDual control + daily checksCorrect, publish corrected snapshot, reviewTreasury
O-04Cross-chain anchor mismatch (XRPL vs Stellar)339Anchor verifierDeterministic anchor payloadPause anchor publishing, investigateEngineering
O-05Legal docs drift from actual operations3412Internal auditChange control + counsel reviewFreeze changes, align docs & opsLegal + Ops
O-06Redemption logistics failure (shipping/customs)339SLA missesRegional partners + policyOffer alternative redemption methodCustody Ops
O-07Price feed mismatch causes mispricing339MonitoringBounded updatesHalt pricing actions, manual reviewTreasury
O-08Dependency vulnerability exploited3412SCA alertsPatch cadenceIncident protocol, rotate keysEngineering
O-09Insider fraud (treasury)2510Audit trailsDual approvals + limitsHalt treasury actions, investigateOps Lead + Treasury
O-10Audit failure (third party cannot verify)248Audit reportsImprove evidence, deterministic proofsPause expansion, fix evidence pipelineEngineering + Treasury