Where a transaction is decided
Control points
Every important event contains a choice about what happens next.
A revised certificate, a release request, a delayed payment or a custody hand-off is not only an event that a counterparty reacts to.
It is a control point: a moment at which the transaction has to decide whose evidence counts, who may act, what becomes blocked or permitted, who must be told, and what changes next.
Most of those choices already exist. They sit in contracts, mandates, facility conditions, operating procedures and habits. Some were made deliberately. Others arrived by default.
An event is unavoidable. The way the transaction responds is a design choice.
This is written for the people who carry the consequence: operations and trade finance in a trading house, credit and risk at a lender, and whoever has to sign the control arrangement at a warehouse or collateral manager.
The event is the same. The response is decided.
A firm that treats the left column as its reality is reacting. A firm that has settled the right column is operating a design.
Three events, and the choice inside each
| What happens | What the parties have to have decided |
|---|---|
| A certificate is revised | What the revised certificate supersedes, who must receive it, and whether it changes finance or release. |
| A seller requests release | Whose approval is required, what evidence must be current, and what happens to security after the goods leave. |
| A payment is late | When the position becomes exceptional, who may cure it, and what activity has to pause meanwhile. |
None of the three questions is difficult. What makes them expensive is answering them for the first time while the cargo is on the quay.
Sixty-five control points, across twelve moments and eight parties.
Twenty-nine are points where a party sets or executes part of the response. Thirty-six are points where a party does not control the response and its position changes because of the choice made there.
Both are decisions. The second kind is decided by whoever holds the first.
The sixty-five, by moment
| Moment | Sets the response | Position changes |
|---|---|---|
| Contract | Seller, Buyer | Bank, Insurer |
| Approval | Buyer, Collateral manager, Bank, Insurer | Seller, Warehouse |
| Nomination | Seller, Buyer, Carrier | Warehouse, Insurer |
| Intake | Warehouse, Collateral manager | Seller, Bank, Insurer |
| Inspection | Inspector | Seller, Buyer, Warehouse, Collateral manager, Bank, Insurer |
| Valuation | Collateral manager, Bank | Seller, Insurer |
| Drawdown | Seller, Bank | Collateral manager, Insurer |
| Release | Seller, Warehouse, Collateral manager, Bank, Carrier | Buyer, Insurer |
| Change or exception | Inspector | Seller, Buyer, Warehouse, Collateral manager, Bank, Insurer, Carrier |
| Delivery | Buyer, Carrier | Seller, Bank, Insurer |
| Settlement | Seller, Buyer, Inspector | Collateral manager, Bank, Insurer |
| Claim or close | Seller, Buyer | Bank, Insurer |
This is an illustrative model of a financed cargo under a collateral management agreement. Your matrix is not assumed to match it. The differences are evidence of your transaction’s actual design, and they are usually where the useful work begins.
Each of these is a choice somebody already made.
Not in the abstract. These three come up in almost every conversation about a financed physical transaction.
The three, and what is usually inherited
| The moment | The design most firms inherited | What could be decided instead |
|---|---|---|
| A certificate is revised | The revised certificate is circulated by email. Existing valuation and release permissions stay in place until somebody notices. | It supersedes the earlier version immediately; or it changes the record and pauses action only above an agreed materiality threshold; or it requires renewed approval before release or further drawdown. |
| A release is requested | The seller instructs the warehouse. The collateral manager and the bank find out at the next reconciliation. | The collateral manager validates against the controlled schedule first; or the bank and collateral manager approve jointly above a threshold; or release is blocked while any required evidence is out of date. |
| A new warehouse or counterparty joins | The commercial relationship is agreed, and the custody and evidence conditions are worked out afterwards, in operation. | The mandate, eligible assets, instruction framework and reporting duties are settled at approval, so intake and release run under one agreed framework from the first cargo. |
Every one of these was decided by somebody. In most firms it was decided once, by whoever set the arrangement up first, and has not been revisited since.
Three ways to authorise a release, and each one costs something.
The warehouse executes or refuses the physical release. It is the point at which an incorrect documentary decision stops being reversible, because the goods have gone.
Three designs are in common use. None is best in the abstract.
Three designs, and what each costs
| The design | What it improves | What it requires |
|---|---|---|
| Seller instruction alone | Speed, and the fewest parties in the path of a routine movement. | High confidence in the seller’s own controls, and acceptance that its instruction can override an arrangement it previously agreed. |
| Collateral manager validates | Controlled stock is protected, because release is checked against the schedule finance relies on. | A current custody record and an explicit mandate, not an assumed one. |
| Bank and collateral manager approve | The strongest lender protection, and the clearest record afterwards. | More coordination, and a tolerance for delay on releases that would otherwise be routine. |
The work is comparing these before the live transaction depends on one of them, and not after a release has already gone the wrong way.
Not every choice is available.
Contracts, law, lenders, insurers and counterparties set real limits. A borrower does not redesign a facility condition because a model suggests a better one, and a seller does not decide what an inspector will certify.
The work is not to pretend you control everybody else. It is to find where you can improve your own position, where a better shared rule is worth negotiating, and which dependency you are prepared to accept deliberately instead of by default.
A dependency you have decided to accept is a different thing from one you have not noticed. The second is what costs money.
A control point that has been decided can be measured.
An exception resolved by phone leaves nothing behind. The same exception, arriving at a point with an agreed rule and a named owner, leaves a record: the event, the choice made, the response, any override, and the outcome.
Over a few months that shows which control points repeatedly create waiting time, disputes, rework, trapped cash or senior intervention. It does not make the transaction intelligent. It gives the business a stable record from which the next design decision is made on evidence instead of recollection.
That is the difference between a firm that believes releases are slow and a firm that can say which release condition is responsible, on which flow, with which counterparty.
The output is your own control-point register.
The set above is an illustrative base model. In an engagement it becomes your register: for each material point, the party that sets the response and the parties affected, the condition and evidence required, the current rule and the credible alternatives, the downstream consequence of each, the owner and the obstacle to change, and the measure that would show whether the change worked.
Three or four points are usually live in a business at any one time. The rest were settled years ago and still hold. Finding out which is which is most of stage one.
It is a list of changes your transaction can take, and it is yours whether or not anything is ever built.
And it is something you can put in front of somebody else.
A register of this kind is written to be read by people who were not in the room: a credit committee, a risk function, an internal auditor, a procurement reviewer deciding whether the work was worth commissioning.
Each point names what is decided, who decides it, what evidence it rests on and what the alternative would cost. That is the form an argument has to be in before somebody can defend it internally.
The same control design has been built four times, on four different ledgers, to find out which parts of it a system can carry and which parts stay with people and contracts. All four run, and the first is open source.