Governance and control
Speed, made safer

Governance should make speed safer. Not make slowness respectable.

Canopus is being designed so that ownership, risk appetite, control evidence and regulatory boundaries are visible before they are tested by growth.

A high-security vault and a waiting line, illustrating the need to combine security with usability.
Governance by design

Six questions every operating decision should answer.

The aim is not to make risk disappear. It is to make responsibility difficult to lose.

Who decides?

Reserved matters, delegated authority and committee mandates should make the decision-maker explicit.

Who owns the risk?

Business ownership and independent oversight should remain distinguishable even when delivery is shared.

What evidence exists?

Controls should leave a usable record of review, challenge, approval, exception and remediation.

Which dependency matters?

Third parties, technology, data and people dependencies should be visible in the process and the risk view.

What happens when it fails?

Incident, continuity, recovery and exit arrangements should be designed before the first serious disruption.

Who is affected?

Customer, regulatory, shareholder, colleague and community consequences belong in the decision—not after it.

The control environment

Policies describe the institution. Evidence proves it exists.

  • Board and committee mandates aligned to decision rights and regulatory accountability.
  • Risk appetite translated into limits, escalation thresholds and management information.
  • Three-lines responsibilities across business ownership, independent risk and compliance, and internal assurance.
  • Conflicts and related-party transactions identified, disclosed, approved and monitored.
  • Model, data, technology and outsourcing risks governed as part of the operating model.
  • Incident, loss-event, business-continuity and recovery evidence available for learning and supervision.
A lighthouse representing clarity, continuity and accountable direction.
Regulatory boundaries

The name on the door does not create the permission.

Banking and virtual-asset activities in Seychelles sit within distinct legal and supervisory frameworks.

CBS

Banking

Banking business is subject to authorisation and supervision by the Central Bank of Seychelles under the applicable financial institutions framework.

Central Bank of Seychelles
FSA

Virtual assets

Any future virtual-asset service would require the relevant authorisation from the Seychelles Financial Services Authority and compliance with the VASP framework.

FSA legal framework
IC

Personal data

Website and future operational processing must respect the Seychelles Data Protection Act 2023 and oversight of the Information Commission.

Information Commission
Outsourcing without abdication

A bank may buy a service. It cannot buy relief from responsibility.

The partner model is therefore designed around audit rights, regulatory access, data control, resilience testing, concentration awareness and credible exit.

OwnThe decision, policy, risk appetite and accountable outcome.
OverseePerformance, incidents, change, control evidence and remediation.
AssureIndependent testing and challenge proportionate to risk.
ExitData, service and knowledge remain portable when the relationship ends.
The governance question

Can the institution explain itself under pressure?

That is the standard against which policies, systems, partners and people should be designed.

Discuss governance