Xcelus Decision Lab™ — Compliance Tabletop Exercises
Ninety Minutes Inside the Decisions Your Leadership Team Has Not Yet Had to Make
The Xcelus Decision Lab™ is a facilitated executive session that walks a leadership team through a developing organizational crisis in real time. It is not training. It is not a security tabletop. It is not a compliance audit. It is a structured executive discussion designed to surface a category of risk that typically does not get C-suite attention until an incident forces it — and to produce written commitments that the leadership team takes forward.
Quick Answer
What is an Xcelus Decision Lab, and how is it different from a compliance training course or an IT tabletop exercise?
An Xcelus Decision Lab is a 90-minute scenario-based discussion built specifically for compliance leadership — CCOs, General Counsel, Chief Risk Officers, and executive teams. Unlike IT tabletop exercises that simulate external threats, Decision Labs surface internal authority gaps and structural risk categories that only become visible when an incident forces them into view. Unlike standard compliance training that teaches the rules, Decision Labs puts leaders in the chair and asks: What would your team actually do in the next ninety minutes if this happened?
Each Lab is licensed to your organization, run by your internal facilitator, and produces written executive commitments that carry forward into board engagement, audit committee briefings, and 30-day follow-up.
Designed For
Chief Compliance Officers · General Counsel · Chief Risk Officers · Internal Audit Leaders · Compliance Committees · Executive Leadership Teams · Board Committees
A Different Kind of Executive Session
This Is
A facilitated case discussion — ninety minutes inside a developing organizational crisis with senior leadership in the chair.
A leadership-level conversation about authority, contracts, regulatory thresholds, and the structural risk categories that surface only when an incident forces them.
A commitment-producing session — leaders leave with written next steps, named owners, and a 30-day check-in already scheduled.
This Is Not
Security awareness training. Your phishing tabletops cover external threats. This is internal.
Compliance training. Participants are not being taught the rules — they are being asked what they would do under pressure.
A security incident simulation. The format is a structured case discussion. No keyboards, no live systems, no red teams.
Built for the Conversation Before the Incident
Compliance failures at the leadership level are rarely caused by ignorance of the rules. They are caused by decisions made under pressure — by leaders who knew the rules in the abstract but did not recognize the moment they were in.
Every Decision Lab is built around a structural risk category that does not currently get leadership attention — vendor-side misappropriation, business authority versus regulatory authority, the boundary between a deferrable program risk and a 72-hour notification clock. The Lab is for the conversations that need to happen before the incident, not after.
The Seventeen Decision Labs Available Now
Each Lab addresses a distinct category of leadership risk. Designed to be run independently or in sequence over a quarter.
For Public Company Leadership
The Invisible Insider →
When a routine vendor session becomes a securities investigation.
A vendor employee’s 43-minute window between viewing FDA approval data on a client system and his sister’s stock purchase triggers a federal investigation. The Lab places the CCO, General Counsel, CISO, and CEO in the same room to work through disclosure timing, vendor relationship review, and the regulatory engagement decisions that follow when the dots are connected internally before the SEC connects them externally.
Category: Vendor MNPI · Misappropriation Theory · SEC engagement
For Vendor and Service Provider Leadership
The MSA You Didn’t Read →
When an eighteen-page contract becomes a federal securities investigation.
The 2:30 PM call comes in from a publicly traded client’s General Counsel — and the leadership team learns that the standard NDA clause in the standard MSA quietly committed the entire workforce to federal securities law obligations no one had read carefully. The Lab is the companion to The Invisible Insider, viewed from the vendor side. The CEO, COO, General Counsel, and HR lead work through the audit, training gap, and disclosure decisions that determine whether an employee’s act becomes a one-off incident or a company-defining one.
Category: Vendor MSA exposure · Training gap audit · Client cooperation
For Data Privacy and Regulated Industry Leadership
The Authorization Email →
When a risk acceptance decision crosses a regulatory line.
A VP sends a written authorization to accept two IT security findings under deadline pressure — not realizing one of them is a GDPR notification trigger; he does not have the authority to defer. The Lab places business leadership and the Data Protection Officer in the same room to work through what business authority can and cannot legally authorize, the 72-hour clock that begins when the email is sent, and the board-level question of how the organization governs the boundary between business and regulatory risk.
Category: Business authority vs regulatory authority · GDPR 72-hour clock · DPO escalation
For Engineering and Export Compliance Leadership
Grant Access Now, Classify Later →
When a VP’s directive authorizes a deemed export for which the company isn’t licensed.
Three weeks from design review and behind on export sign-off, a VP of Engineering directs the team to grant a foreign-national engineer access to the controlled technical library now and true up the classifications later. The release completes the instant the file opens — there is no shipping manifest to intercept. The Lab places the VP of Engineering, the Empowered Official, the General Counsel, and the CHRO in the same room to work through voluntary self-disclosure, the export-versus-anti-discrimination double bind, and the boundary between business and regulatory authority.
Category: Deemed export · Empowered Official authority · BIS voluntary self-disclosure
For Sales and Finance Leadership
Paper It Clean →
When a side letter becomes a restatement, and the executives who certified the financials never saw the email.
In the last week of the quarter, a VP of Sales closes the make-or-break deal with verbal promises — extended terms, a cancellation right, future credits — that never reach the order form, telling the deal desk to “paper it clean.” Seven months later, the customer forwards the email, and a CRM migration surfaces two more deals just like it. The Lab places the CFO, Controller, General Counsel, CCO, and CHRO in the same room to work through SAB 99 materiality, restatement, SEC self-reporting, and the no-fault Rule 10D-1 clawback that can reach executives who did nothing wrong.
Category: Revenue recognition · SOX 302/906 certification · Rule 10D-1 clawback
For Security, HR, Compliance, and Legal Leadership
The Seam →
When four leaders each do their job right, the gaps between them become the breach.
At a healthcare technology company, an employee exfiltrates patient records, and a colleague quietly flags it. Security contains the breach, HR moves to discipline, Legal pulls everything under privilege, and Compliance waits for clean facts — each doing their job correctly, none recognizing it as one shared incident until a reporter, a regulator, and a retaliation complaint arrive at once. The Lab places the CISO, CHRO, CCO, General Counsel, and CEO in the same room to work through the notification clock that started before compliance was told, to protect the reporter, and to explain why the most defensible individual decision can produce the worst collective outcome.
Category: Cross-functional coordination · HIPAA breach notification · Reporter protection
For Sales, Finance & Compliance Leadership
The Consulting Fee →
When a star performer’s “consulting fees” become the subject of a bribery investigation, the whistleblower’s clock is running.
An anonymous report alleges that Marrenford’s top regional sales director routed “consulting fees” to a firm owned by the brother-in-law of the official who awarded the company’s largest contract — and the reporter gives leadership 48 hours before going to regulators and the press. The Lab places the CEO, CFO, CCO, General Counsel, VP of Sales, CHRO, and Communications in the same room to work through crisis command, freezing payments and stopping work, protecting the whistleblower, and deciding whether to self-disclose before the internal investigation is finished.
Category: FCPA / anti-bribery · Third-party intermediary · Voluntary self-disclosure
For Operations, Security & Executive Leadership
The Open Chair →
When the people who normally make the decision can’t be reached, does someone sit in the chair — or does it stay empty?
A payments platform goes down on payday while the CEO and two senior leaders are legitimately unreachable. The executives left in the room must run a crisis no one has formally put them in charge of — and decide who acts when authority isn’t present. Runs with a human or an autonomous AI agent as the root cause; the AI tracks whether your business continuity plan still holds when the actor can’t be interviewed.
Category: Crisis leadership & incident command · Business continuity · AI governance
For Multinational and Cross-Border Privacy Leadership
The Context Notes →
When a well-meant HR courtesy becomes a transatlantic privacy crisis.
A routine HR practice — managers recording “return-to-work context notes” to support employees — quietly moves special-category data from the EU onto a shared US HR platform, and a data subject access request brings it all to the surface. The Lab runs as two simultaneous tables, EU and US, with forced cross-Atlantic sync points: leadership must work a GDPR erasure obligation that collides head-on with a US litigation hold, a 72-hour clock, and the question of which side actually has the authority to decide. A single-room fallback is included.
Category: Cross-border transfer · GDPR erasure vs US litigation hold · 72-hour clock · Two-table format
For Field Services and Frontline Workforce Leadership
The Account →
When the harasser is your biggest customer.
A field technician is harassed by a senior manager at the company’s single largest customer — and reports it. The Lab puts the Chief Revenue Officer, COO, CHRO, General Counsel, CFO, and CEO in one room, where protecting the worker is obvious in principle but collides with the revenue, the relationship, and the question of who actually has the authority to fire a customer. A rising three-inject arc ends in a public lawsuit naming both companies, turning the room’s earlier hesitation into exposure.
Category: Third-party / customer harassment · Employer duty · Values vs incentives · Authority to fire a customer
For Oilfield Services and International Operations Leadership
The Connected Rig →
When a fast field fix sends your crown-jewel data across a border.
To beat a $150K-per-day penalty, a field team force-onboards an unvetted vendor and proprietary rig data crosses a border — then a host-nation regulator accuses the company of unlawfully exporting it. The Lab puts the VP of International Operations, CIO/CISO, CCO/General Counsel, CFO, and CEO in one room, where containing the breach means shutting down a live rig and millions in penalties, and not containing it deepens a sovereign violation that the regulator is already watching. A rising three-inject arc ends in the realization that the centralized “everything-to-Houston” data model was the exposure all along.
Category: Data sovereignty · M&A integration blindspot · Third-party vendor access · Authority to shut down a live operation
For Biopharma and Regulated High-Growth Leadership
The Fast-Track Protocol →
Training on the tool didn’t change what people do under a deadline.
To hit an investor-facing milestone, an executive signs a trial-site contract through an outside e-signature link — bypassing the company’s new contract system — and is hailed as the hero. Months later, a serious adverse event sends Legal to pull the contract, and it isn’t in the system. The Lab puts Clinical Operations, the CMO/Head of R&D, CCO/General Counsel, CFO, and CEO in one room to confront stripped indemnification, a buried IP clause that threatens a licensing deal, and a compliance dashboard that read 100% adoption while the shortcut went unseen.
Category: Tool-based vs behavioral compliance · Shadow contracts · E-signature authority · The dashboard delusion
For Risk, Security, and Insurance Leadership
The Sanctioned Key →
When the only decryption key leads to a sanctioned wallet.
Ransomware halts a logistics giant at $2.2M per day, and the attackers’ wallet is tied to a group on the U.S. sanctions list — making payment a potential federal violation under strict liability. The Lab puts the CEO, CFO, CISO, General Counsel, and a surprise Board Observer in one room to work on operational survival against a legal double bind: pay and risk a federal crime, or stay dark for weeks. A rising three-inject arc ends when the room realizes it may not be allowed to pay at all.
Category: Ransomware response · OFAC strict liability · Material operational disruption · Who can authorize a payment
For Technology and Product Leadership
The Optimization Hack →
When a productivity shortcut quietly destroys your crown-jewel IP.
To beat a release deadline, a star engineer pastes the company’s unreleased core codebase into a public AI tool to “optimize” it — and may have just stripped the asset of its trade-secret protection. The Lab puts the CTO, Chief Product Officer, General Counsel, CISO, and CCO in one room to confront a loss with no breach to report, an insurance policy that may not respond, and no undo button. A rising three-inject arc ends in the irreversibility that no security tool ever flagged.
Category: Shadow AI · Trade-secret destruction · Public-LLM exposure · The insurance gap
For Supply Chain and Operations Leadership
The Tier-3 Ghost →
When a component three tiers down freezes $40M at the border.
Customs seizes $40M of core product because a tier-3 supplier used raw material from a restricted region flagged for forced labor — and the law presumes the goods guilty until the importer proves otherwise. The Lab puts the Chief Supply Chain Officer/COO, VP of Procurement, General Counsel, CFO, and Chief Sustainability/Compliance Officer in one room as a worthless tier-1 certificate, a failed indemnity, and a closing peak season collide. A rising three-inject arc ends when the burden of proof inverts onto the company.
Category: Supply-chain provenance · Forced-labor import law · Tier-vendor indemnification failure · Rebuttable presumption
For Boards, Audit Committees, and PE/VC Investors
The Lead Investor Call →
When a whistleblower names the CEO forty-eight hours before close.
Two days before a company-defining buyout goes through, a credible, documented whistleblower report names the charismatic CEO. Investigate, and the deal dies; push it through and “investigate later” may be a fraud on the buyer. The Lab puts the Board Chair, General Counsel, CHRO, CFO, and Lead Independent Director in one room — intentionally without the CEO — to work on board fiduciary duty, material disclosure, pause-vs-kill mechanics, and emergency succession. A rising three-inject arc turns “deal with it after close” into the exposure.
Category: Board governance · Whistleblower escalation · Material transaction disclosure · Fiduciary liability
For Finance, Technology, and Executive Leadership
The Running Total →
When the AI bill you’re dividing is still climbing as you speak.
A company-wide push to “go use AI” switched on uncapped credits with no cap, no guidance, and no owner — and a six-figure overspend surfaced on one team’s experiment. The Lab puts the CEO, CFO, CIO/CTO, CISO, and the department heads whose teams use AI in one room to divide a bill that feels like a settled accounting problem. A rising three-inject arc ends when the room realizes the meter never stopped: the spend is still climbing as they meet, and no one can say what it is right now.
Category: AI spend governance · Guardrail ownership · Real-time cost visibility · Live gap vs settled bill
How a Lab Runs
Each Lab runs 90 minutes in seven scripted segments.
What Comes in the Kit
Every Decision Lab kit includes seven deliverables, licensed to your organization and run by your internal facilitator.
Facilitator Guide
Complete session script with phased narration, discussion prompts, expected responses, and debrief guidance.
Executive Slide Deck
A professionally designed presentation that guides participants through the exercise. Sequenced to match the facilitator guide.
Executive Role Cards
Printable, one per leadership role, with background information, primary concerns, and predictable blind spots for that seat.
Scenario Injection Cards
Time-stamped facts that land at scripted moments to introduce new developments and increase complexity.
After-Action Review
Structured discussion framework for capturing commitments live in the room — owners, deadlines, dependencies.
Executive Summary Template
A ready-to-use one-page memo for the board, audit committee, or ownership.
30-Day Follow-Up Template
A structured accountability tool to track commitments and progress between the session and the next leadership review.
When a Decision Lab Is the Right Tool
Five attributes consistently separate strong Lab scenarios from weak ones. If your situation matches these, this is the format.
The decisions belong to senior leadership.
Disclosure timing. Regulatory engagement. Contract review. Board communication. Organizational posture. The scenario must put real authority on the table — not “what should the employee have done.”
The risk category is structurally invisible until an incident occurs.
Vendor-side misappropriation. Business authority versus regulatory authority. The boundary between a deferrable program risk and a 72-hour notification clock. If your leadership team already discusses this category regularly, you do not need a Lab.
The pressure comes from inside the organization.
The leader who sent the email he should not have sent. The employee who saw something he should not have seen. The VP who accepted a risk he did not have the authority to accept. External-threat scenarios belong to the security tabletop format.
The decisions are genuinely contested.
Business instinct and legal instinct point in opposite directions. Reasonable executives disagree. The right answer is itself something the room must work through. If the facilitator can predict every response before the session begins, the scenario is too thin.
The consequences play out across quarters, not days.
The commitments captured in the room need a real organizational arc to live within — board engagement, audit committee briefings, 30-day check-ins, and ongoing remediation work over the following 12 to 18 months.
Pricing and How to Get a Kit
Each Lab is licensed to your organization with unlimited internal use. Single Lab and three-Lab bundle pricing available.
Pricing
Contact Xcelus for pricing.
Single Lab kits and three-Lab bundles available, each licensed to your organization with unlimited internal use. Light industry customization is included; deeper customization is available as a separate engagement.
How It Works
Contact Xcelus to confirm scope and pricing. Receive all seven deliverables digitally within 24 hours of agreement. Schedule the session for whenever your leadership team is available. Most organizations run their first Lab within 30 days.
Frequently Asked Questions
Who runs the session — your team or ours?
You do. The kit is licensed to your organization and designed to be facilitated by your CCO, General Counsel, or designated executive. Keeping facilitation internal keeps the conversation honest and the commitments accountable to the room. External facilitators tend to produce performative engagement; internal facilitators produce real decisions.
How is this different from a security tabletop?
Security tabletops cover external threats — phishing, ransomware, and social engineering. The Decision Lab covers internal authority gaps — the moments when leaders within the organization make decisions they did not realize they lacked the authority to make. Different category, different format, different audience. If you already run quarterly IT tabletops, the Decision Lab complements them rather than replacing them.
How is this different from a Case Study Review from LRN or Navex?
Case Study Reviews from larger compliance vendors are typically generic, drawn from enforcement actions, and require the CCO to provide the structure, the discussion prompts, and the facilitation logic from scratch. Decision Labs ship as complete facilitator kits with scenario-specific role cards, time-stamped injection cards, after-action capture templates, and a 30-day follow-up structure. The scenarios themselves are original — built around recognizable institutional pressure patterns rather than retold enforcement actions.
Can we customize the scenarios for our industry?
Each Lab is designed to be vertical-recognizable without being vertical-specific. The Invisible Insider works for any public company. The MSA You Didn’t Read works for any service provider with publicly traded clients. The Authorization Email works for any GDPR-regulated organization. Light customization is built into the kit; deeper customization is available as a separate engagement.
What size organization is this for?
Most appropriate for organizations with formal C-suite leadership teams — typically 200+ employees. Labs have been designed for both public and non-public companies. The MSA You Didn’t Read in particular was built for non-public service providers whose clients are publicly traded.
Do we get to keep the materials?
Yes. The license is perpetual within your organization. Run the Lab as many times as you need to — with new executives, with the board, with regional leadership teams, with the audit committee. The 30-Day Follow-Up template is designed for ongoing use across multiple sessions.
How much does a Decision Lab cost?
Pricing is scoped to your organization and the Lab or Labs selected. Contact Xcelus to discuss single-Lab and bundle pricing. Every kit is licensed with unlimited internal use, and light industry customization is included.
How often should we run a Lab?
Most organizations run one Lab per quarter in the first year, then transition to running each Lab annually as part of the executive risk calendar. Labs are available now to address different risk categories and can run in sequence without overlap. New Labs are always being added to the product line.
The Methodology Behind Every Lab
Every Xcelus product is built around the Decision Readiness Engine™ — our framework for the seven moments where situational pressure makes the wrong choice feel normal. The Executive Decision Lab is where that framework lands at the C-suite level.
Where standard compliance training answers the question “what is the rule?” the Decision Lab answers a different question: what would your leadership team actually do in the next ninety minutes if this happened?
Related Compliance Resources
Insider Trading & Tipping Scenarios →
The microlearning scenarios behind Labs 01 and 02 — Alex, Susan, Rachel, and Marcus appear here first in the four-angle vendor scenario that the Labs are built on.
Compliance Conversations Ep. 11: The Invisible Insider →
The audio companion to Lab 01 and Lab 02. Walks through the misappropriation theory, the plumber analogy, and the 43-minute gap that connects vendor access to a federal investigation.
Executive case studies for CCO and board reading. The written counterpart to the Decision Lab format — same scenarios, different delivery mode.
Have the Conversation Before the Incident Forces It
Your leadership team will have these conversations eventually. The only question is whether you have them now or after the incident forces them. Contact Xcelus to discuss which Lab fits your organization’s risk profile.
© 2005–2026 Xcelus LLC. All rights reserved. Executive Decision Lab™ is a trademark of Xcelus LLC.
© 2005–2026 Xcelus LLC. All rights reserved. This content is for training and discussion only and is not legal advice; consult qualified counsel about your organization’s specific obligations.
