Title
CharterReady Clear — the done-for-you Diocesan Safe Environment Compliance Completeness Desk.
A specialist-validated, AI-native operations service that keeps every parish, school, and diocesan entity's
child-protection compliance file audit-ready between annual external Charter audits — not a training platform,
not an accreditation body, not a law firm.
Final decision
FINAL DECISION: BLUEPRINT
This run clears the evidence threshold and all six rubric gates. A complete blueprint follows.
Executive summary
Every U.S. Catholic diocese and eparchy (196 nationally) operates under the USCCB Charter for the
Protection of Children and Young People and must submit to an annual, externally-conducted compliance
audit performed by Stonebridge Business Partners. In the most recently reported cycle, 194 of 196
dioceses/eparchies participated, 2,320,143 background checks were logged on clergy, employees, and volunteers,
and more than 5.1 million adults and children were trained to recognize abuse warning signs — yet the audit
still produced a formal noncompliance finding (Diocese of Houma-Thibodaux, Diocesan Review Board not convened
since October 2023) and, in a prior cycle, required follow-up visits at 14% of dioceses/eparchies because of
inadequate minor-protection findings. The underlying reason is structural: a diocese's central Safe Environment
office is typically a handful of staff responsible for reconciling training completions (usually tracked in
VIRTUS Online), background-check renewals (tracked by a separate vendor), and signed code-of-conduct
acknowledgments and Review Board minutes (often tracked only on paper at the parish level) across dozens to
several hundred individual parishes, schools, and diocesan agencies — each with its own bookkeeper or volunteer
coordinator doing this part-time and inconsistently.
CharterReady Clear sells dioceses and eparchies a done-for-you, specialist-validated Parish-Level
Safe Environment Completeness Report: an AI engine ingests the diocese's own VIRTUS/training export,
background-check vendor export, and parish self-attestation records; cross-references every parish/school/entity
against the diocese's own written Charter-compliance checklist; and produces a ranked Gap List (Complete /
At-Risk / Noncompliant) with parish-ready remediation letters. Every At-Risk or Noncompliant flag is validated
by a human compliance specialist — typically a former diocesan Safe Environment Coordinator — before release.
The service never assesses individual abuse risk, never investigates allegations, never stores raw
background-check report content, and never substitutes for the diocese's own Victim Assistance Coordinator,
Review Board, legal counsel, or the official Stonebridge/USCCB audit. It sits in the gap between VIRTUS (a
software tool the diocese must operate itself), Praesidium (comprehensive, higher-touch accreditation
consulting), and Stonebridge (the once-a-year external auditor) — an ongoing, ready-before-the-audit,
parish-level completeness layer that none of the three currently provide.
First revenue path: a free "Charter Readiness Gap Scan" sample (up to 10 parishes) as a lead magnet, a
one-time Diocese-Wide Pre-Audit Gap Scan priced by entity count ($2,500–$9,000), and a recurring Quarterly
Safe Environment Monitoring Desk retainer ($45–$85 per parish/entity per quarter). This is a narrow,
modest-but-real niche (an estimated $2.6M–$5.3M core annual TAM across the 196-diocese Catholic wedge alone,
Inferred/range — see Economic Sizing) with a credible expansion path into religious-institute provinces and
other-faith judicatories facing structurally similar compliance-tracking burdens.
Thesis
Regulatory-adjacent, audit-driven compliance obligations that require reconciling many small, inconsistent
records across many distributed sub-units (parishes) are exactly the shape of problem AI-native document
extraction and exception-flagging solves well — and exactly the shape of problem a two-to-three-person central
office cannot solve by hand at scale. The Catholic Church's Charter compliance framework is unusual among
nonprofit/religious-sector obligations in that it is externally audited on a fixed annual cycle by a named
third party (Stonebridge), publicly reported on (USCCB annual report), and has a known, sizeable, well-defined
buyer population (196 dioceses/eparchies) with proven willingness to pay for adjacent tooling (VIRTUS,
background-check vendors, Praesidium, MinistrySafe). No existing vendor offers the specific wedge of an
ongoing, done-for-you, parish-level completeness audit that closes gaps before the annual audit rather
than only measuring compliance at the audit or training staff in general.
Discovery rationale
This run performed 20+ targeted web searches across dental credentialing/insurance-verification outsourcing,
veterinary pet-insurance claims, child-care licensing, self-storage lien-sale compliance, funeral-home preneed
trust compliance, HOA reserve-study/special-assessment compliance, K-12 special-education (IEP) compliance,
assisted-living/RCFE survey readiness, medical-spa compliance, amusement-ride inspection compliance, and
finally faith-based/nonprofit youth-serving organization child-protection compliance. Before generating any
candidate into a full blueprint, the freshly-cloned manifest.json (618 prior runs) was checked by
keyword and semantic search for each candidate's market/buyer/workflow/outcome. Several strong-looking
candidates were confirmed as duplicates of prior runs (IEP/K-12 special-education compliance is already
IEPClear; self-storage lien-sale compliance is already covered by LienGate Clear and related
runs, and has an active AI-native commercial competitor, "Ai Lean," found during research; pet-insurance claims
assistance is already ClaimTail; medical-spa compliance is already ProtocolClear) and were
rejected under Section 28's duplicate-detection rule before any further work was invested in them. The
faith-based/nonprofit child-protection compliance space returned zero manifest hits on every tested keyword
("church," "clergy," "youth ministry," "safe sanctuary," "diocese" was not separately tested but the broader
terms return nothing), confirming this is genuinely unexplored terrain per Section 28's steering guidance
toward underexplored categories.
Candidate comparison
| # | Candidate | Verdict | Reason |
| 1 | Diocesan Safe Environment Compliance Completeness Desk (WINNER) |
Selected | Zero manifest overlap; externally-audited framework with named auditor
(Stonebridge) and public annual reporting; clear 196-entity buyer population; proven adjacent vendor spend
(VIRTUS, Praesidium, MinistrySafe, background-check vendors, insurer safety libraries); low licensing/UPL risk
(operational documentation completeness, not legal/clinical advice); clean narrow MVP wedge. |
| 2 | K-12 special-education (IEP) procedural-compliance & due-process risk desk |
Rejected — duplicate | Already built as IEPClear (run 2026-07-19-1412), same
buyer/workflow/outcome shape. |
| 3 | Self-storage lien-sale statutory-compliance desk | Rejected — duplicate +
active competitor | Already covered by LienGate Clear and related prior runs; research also
surfaced an active AI-native commercial competitor ("Ai Lean") already publishing state-by-state lien-law
guides and wrongful-sale-liability content in this exact space, eroding whitespace further. |
| 4 | Dental practice insurance credentialing/verification outsourcing |
Rejected — commoditized | 10+ direct existing vendors found in a single search
(Caplinedental, Verimedix, Helpware, Assured, Credex, Staffingly, DayDream, Needletail) offering nearly
identical generic BPO; fails the anti-duplication requirement's "generic outsourcing" disqualifier and has
weak differentiation potential. |
| 5 | Veterinary-clinic pet-insurance claims assistance | Rejected — duplicate +
weak economics | Already covered by ClaimTail; additionally, most U.S. pet insurance is
owner-reimbursement (not clinic-filed direct-pay), weakening the clinic-side buyer economics versus the
existing owner-facing product. |
| 6 | Assisted-living/RCFE state-survey readiness consulting | Rejected — saturated
+ pattern overlap | Dense existing competitor field (HealthBridge Consulting, ReadyForSurvey, Health
Dimensions Group) already selling mock-survey/readiness consulting; also close in shape to the manifest's
existing PoCReady Clear (SNF CMS-2567 plan-of-correction) nursing-facility-compliance pattern. |
| 7 | Amusement/FEC ride-inspection certificate completeness desk | Rejected —
weak evidence + smaller TAM | Zero manifest overlap (genuinely open), but buyer population is far
smaller (low hundreds of permanent parks/FECs plus traveling carnivals), evidence of a specific documentation
pain point (versus general safety-regulation awareness) was thin, and the underlying activity leans more
physical-asset/inspection-labor than the target profile prefers. |
CODE validation
Consumer/buyer trend
Since the 2018 wave of grand-jury reports and continuing through 2023–2026, U.S. dioceses face sustained
scrutiny: mandatory annual external Charter audits with published national reports, rising insurer requirements
for documented child-protection programs, and continued diocesan bankruptcy/settlement pressure that keeps
Safe Environment compliance a standing board-level (not just audit-week) priority.
Opportunity
The specific underserved gap: dioceses already buy training software (VIRTUS), background-check services,
and — for some — comprehensive accreditation consulting (Praesidium), but nothing sits between those tools and
the once-a-year external audit to continuously reconcile parish-level completeness and proactively flag gaps
before Stonebridge finds them. The reconciliation problem — matching names and dates across a training
platform, a background-check vendor, and paper/self-attested parish records, for anywhere from 20 to 300+
entities per diocese — is a textbook multi-source extraction-and-exception-flagging task.
Demand
Real, cited audit evidence: 14% of dioceses/eparchies required follow-up visits in a prior cycle due to
inadequate minor-protection findings (BackgroundChecks.com, summarizing a USCCB-commissioned audit); a formal
noncompliance finding was issued in the most recent reported cycle (Diocese of Houma-Thibodaux); priest
background-check completion was found at 99.3% — meaning roughly 0.7% of priests nationally, plus an unknown
and likely larger share of lay employees/volunteers, lacked a completed, on-file check at the time of that
audit. Existing paid-vendor ecosystem (VIRTUS, Praesidium, MinistrySafe, insurer safety-resource libraries)
confirms dioceses already allocate budget to this exact problem category.
Economic sizing
196 U.S. dioceses/eparchies (Verified, USCCB) × an estimated 20–300 parishes/schools/entities per diocese
(wide range; large archdioceses like Chicago or Los Angeles have 200–300+, small dioceses have well under 50) ×
an estimated $150–$300/entity/year willingness to pay for ongoing completeness monitoring (Inferred from
adjacent per-seat/per-parish vendor pricing patterns, not directly quoted) implies a core annual TAM in the
rough range of $2.6M–$5.3M for the Catholic-diocese wedge alone (Inferred, wide range, modest
by design — this is a narrow niche service business, not a venture-scale market). Expansion paths — Catholic
religious-institute provinces subject to Praesidium-style accreditation, and Protestant/other-faith judicatories
(dioceses, conferences, presbyteries, associations) with structurally similar but less centrally-audited
compliance burdens — plausibly double or triple the addressable market over a multi-year horizon, but those
figures are Unverified/Inferred and are treated as expansion, not baseline.
Rubric scorecard
| Gate | Score (1-5) | Rationale |
| Gate 1 — Low Trust Burden | 4 | Dioceses already outsource adjacent pieces (VIRTUS
training platform, background-check vendors, Praesidium consulting) to third parties; a documentation-review
vendor operating behind the scenes with the diocese's own Safe Environment Coordinator as the customer-facing
interface is a familiar, low-novelty trust ask. |
| Gate 2 — Low Task-Level Judgment | 4 | Core task decomposes into discrete, mostly
mechanical checks (is there a background check on file within the renewal window? is there a training
completion record? is there a signed acknowledgment?); judgment is concentrated in a bounded set of reviewable
exceptions (ambiguous name matches, leave-of-absence clergy, dual assignments). |
| Gate 3 — High Intelligence Threshold | 4 | Requires synthesizing three inconsistent source
systems (VIRTUS export, background-check vendor export, parish self-attestation) against each diocese's own
written policy (renewal intervals and categories vary by diocese) — a real multi-document, multi-rule synthesis
problem, not a single-form lookup. |
| Gate 4 — Regulation as Moat | 3 | Not government regulation, but a quasi-regulatory,
externally-audited, publicly-reported governance framework (the Charter) reinforced by insurer requirements —
a real moat against casual entrants, though softer than a statutory licensing regime. |
| Gate 5 — No Physical Labor | 5 | Entirely document/data-based; fully deliverable
remotely with no on-site physical work. |
| Gate 6 — Sam Altman Test | 4 | As frontier models improve at multi-document extraction,
entity resolution, and inconsistent-format reconciliation, the core engine gets faster, cheaper, and more
accurate — directly compounding this business's unit economics without requiring new headcount. |
Anti-commoditization check: if a future general-purpose model lets any diocese self-serve
this exact reconciliation with a consumer chatbot, the durable moat is not the extraction step itself but (a)
the specialist human validation layer that a diocese's own overloaded 1–3-person office cannot replicate without
hiring, (b) the accumulated diocese-specific policy rule-base (renewal intervals, entity lists, exception
history) built over successive quarters, and (c) the trust relationship as the vendor that never gets a diocese
a bad audit finding. Pure extraction commoditizes; the validated, accountable completeness report does not.
Target buyer
Primary buyer/ICP: Diocesan or eparchial Safe Environment Coordinator (sometimes titled
Director of Safe Environment, Office of Child and Youth Protection) at a U.S. Catholic diocese or eparchy with
roughly 20–300 parishes, schools, and diocesan agencies. Economic decision-maker: typically the
Chancellor or Vicar General who owns the compliance budget and carries Charter-audit risk on behalf of the
Bishop/Ordinary; for larger archdioceses, a dedicated Office of Child and Youth Protection director. Beachhead
targets: dioceses that recently received a follow-up-visit requirement or noncompliance finding, dioceses with
a newly appointed Safe Environment Coordinator (highest urgency + least institutional tribal knowledge), and
mid-size dioceses (60–150 parishes) too small to justify a large internal compliance team but too large to track
manually with confidence.
Secondary/expansion ICP: Catholic religious-institute provinces and dioceses subject to
Praesidium-style accreditation standards; Protestant and other-faith judicatories (dioceses, conferences,
presbyteries, districts, associations) overseeing many congregations with insurer-driven child-protection
documentation requirements.
Jobs-to-be-Done
- "When the annual Charter audit cycle approaches, help me know — before Stonebridge does — exactly which of
my parishes have an expired background check, a missing training record, or no signed code-of-conduct on
file, so I can fix it instead of explaining it."
- "When a new pastor, DRE, or volunteer coordinator starts at a parish, help me make sure their safe-environment
paperwork gets picked up by someone at the diocese, not lost in a filing cabinet."
- "When I inherit this role from a predecessor, help me get an honest, complete picture of where every parish
actually stands, without a six-month manual audit of spreadsheets."
- "When the Bishop or insurer asks 'are we compliant,' help me answer with evidence, not a guess."
Painful problem
A diocese's central Safe Environment office is small (commonly 1–3 FTE) and responsible for tracking
compliance across every parish, school, and diocesan agency — often 50–300+ discrete entities, each employing
and relying on volunteers who rotate frequently. Three separate systems of record must be reconciled by hand:
(1) VIRTUS Online or an equivalent platform tracking training completions, (2) a background-check vendor's
records of completed/renewed checks, and (3) parish-level self-attestation of code-of-conduct acknowledgment
and, in many dioceses, Review Board or safe-environment-committee meeting minutes. These three systems rarely
use consistent parish names, employee/volunteer identifiers, or renewal-interval logic, and the reconciliation
work is almost always done manually in spreadsheets by an overstretched office once or twice a year — typically
right before the external audit, when it is too late to meaningfully close gaps. The consequence, evidenced
directly in USCCB's own published audit findings, is real: follow-up visits required at 14% of dioceses in one
past cycle, and a formal noncompliance finding in the most recent cycle. Beyond the audit itself, an incomplete
file is a real legal, insurance, and reputational exposure if it is ever discovered after an incident — the
exact scenario diocesan risk managers and insurers are trying hardest to prevent.
The outcome we sell
Not software the diocese must learn and operate. CharterReady Clear sells a specialist-validated,
ranked Parish-Level Safe Environment Completeness Report, delivered quarterly (or as a one-time
pre-audit scan): every parish/school/entity is classified Complete / At-Risk / Noncompliant against the
diocese's own written Charter-compliance checklist, with a plain-language explanation of each gap and a
ready-to-send remediation letter drafted for the diocese to review and forward. The diocese receives an
answer, not a dashboard to interpret.
First one-feature MVP wedge
| Element | Definition |
| ICP | A single mid-size Catholic diocese (roughly 50–150 parishes/schools) in the continental
U.S. |
| Trigger event | An upcoming annual Charter audit cycle, a recent follow-up-visit requirement, or
a newly appointed Safe Environment Coordinator. |
| Pain | Manual, spreadsheet-based reconciliation across VIRTUS, the background-check vendor, and
parish self-attestation, chronically incomplete across too many parishes for a 1–3 person office. |
| One-feature MVP | A single "Charter Readiness Gap Scan": one-time, retrospective completeness
check of every parish file against the diocese's own written checklist. |
| Input | Diocese's existing VIRTUS training-completion export, background-check vendor export, and
a parish roster/self-attestation spreadsheet, transferred under a signed data-handling agreement. |
| Output | A ranked Gap List (Complete / At-Risk / Noncompliant) per parish/entity, with
draft remediation letters. |
| Human chokepoint | A compliance specialist (former diocesan Safe Environment Coordinator or
equivalent) reviews and approves every At-Risk/Noncompliant flag before release, to avoid false positives that
would needlessly alarm a pastor or volunteer coordinator. |
| Success metric | Percentage of flagged gaps closed by the diocese before its next Charter audit;
avoidance of a new follow-up-visit requirement or noncompliance finding. |
| What they'll ask for next | An ongoing quarterly monitoring subscription, automated push
reminders to parish office staff ahead of expirations, and a diocese-wide rollup view for board/insurer
reporting. |
Evidence summary
196
U.S. Catholic dioceses/eparchies
Verified — USCCB
194/196
Participated in FY2025 audit data collection
Verified — USCCB 2025 report
2.32M
Background checks logged (clergy/employees/volunteers)
Verified — USCCB 2025 report
5.13M
Adults + children/youth trained (2.33M + 2.80M)
Verified — USCCB 2025 report
14%
Of dioceses required follow-up visits (prior cycle)
Verified — BackgroundChecks.com / USCCB audit
1
Formal noncompliance finding, FY2025 cycle
Verified — USCCB 2025 report
Claim table (Verified / Inferred / Unverified)
| Claim | Label | Notes |
| 196 US dioceses/eparchies; 194 participated in FY2025 audit data collection | Verified |
USCCB 2025 CYP Annual Report + USCCB news release |
| 2,320,143 background checks logged on clergy/employees/volunteers | Verified |
USCCB 2025 CYP Annual Report |
| 2,328,545 adults + 2,803,250 children/youth trained | Verified |
USCCB 2025 CYP Annual Report |
| 61 on-site audit visits (36 physical, 25 remote); 133 more dioceses provided data remotely |
Verified | USCCB 2025 CYP Annual Report |
| One noncompliance finding FY2025: Diocese of Houma-Thibodaux Review Board not convened since 10/17/2023 |
Verified | USCCB 2025 CYP Annual Report |
| Stonebridge Business Partners conducts the annual Charter compliance audit | Verified |
USCCB Offices of Child and Youth Protection, Audits page |
| Prior-cycle priest background-check completion 99.3%; 14% of dioceses required follow-up visits for
inadequate minor-protection findings | Verified |
BackgroundChecks.com summary of a USCCB-commissioned audit |
| VIRTUS Online is the dominant safe-environment training/tracking platform used by most US dioceses |
Verified | VIRTUS Online site; Diocese of Alexandria explainer |
| Praesidium offers abuse-prevention accreditation/consulting to Catholic religious institutes and other
organizations | Verified | Praesidium Inc. site |
| MinistrySafe offers training, background-check products, and a "Church & Ministry Compliance
Consulting" service | Verified | MinistrySafe site (cmcc, pricing pages) |
| Major church insurers (GuideOne, Church Mutual, Brotherhood Mutual) require or strongly encourage
documented child-protection policy, background checks, and training | Verified |
Insurer safety-resource pages |
| SBC's national Abuse Reform Implementation Task Force stepped back from building a centralized abuser
database (Feb 2025) citing legal/logistical hurdles | Verified |
Christianity Today; Religion News Service |
| Diocesan Safe Environment offices are typically 1–3 FTE relative to dozens–hundreds of parishes |
Inferred | Consistent with widely reported thin chancery-office staffing; no single
diocese-by-diocese staffing census was located |
| Background-check renewal cycles commonly run 3–5 years depending on diocesan policy |
Inferred | Pattern observed across multiple diocesan policy pages reviewed; varies by
diocese, not standardized nationally |
| Protestant/other-faith judicatories face structurally similar compliance-tracking burdens |
Inferred | Reasonable extrapolation from the SBC case; not directly measured |
| Aggregate diocesan spend on Charter-compliance administration nationally |
Unverified | Not published by USCCB or any diocese located in this research |
| A specific diocese's willingness to pay CharterReady Clear's proposed price points |
Unverified | No pricing test conducted yet; proposed pricing is benchmarked against adjacent
vendor pricing patterns, not diocese-confirmed |
Source-claim matrix
| Claim | Source | Type | Date | Confidence | Used in |
| 196 dioceses/eparchies; 194 participated | USCCB news release |
Primary/institutional | 2026 | High | Economic sizing, Buyer, Evidence |
| 2.32M background checks; 5.13M trained | USCCB 2025 CYP Annual Report (PDF) |
Primary/institutional | 2025 | High | Evidence, CODE-Demand |
| Stonebridge conducts the annual audit | USCCB Audits page |
Primary/institutional | 2026 | High | Competitive landscape, Anti-duplication |
| Charter framework description | USCCB Charter page |
Primary/institutional | 2026 | High | Regulatory considerations |
| Prior-cycle 99.3% completion; 14% follow-up visits | BackgroundChecks.com |
Secondary/trade | 2025 | Medium-High | CODE-Demand, Painful problem |
| 196-diocese count cross-check | Catholic-Hierarchy.org |
Secondary/reference | 2026 | Medium-High | Economic sizing |
| VIRTUS platform description | VIRTUS Online |
Vendor/primary | 2026 | High | Competitive landscape |
| VIRTUS is mandatory/near-universal among dioceses | Diocese of Alexandria |
Primary/institutional | 2026 | Medium-High | Competitive landscape |
| Praesidium accreditation services | Praesidium Inc. |
Vendor/primary | 2026 | High | Competitive/budget validation |
| MinistrySafe compliance consulting + pricing | MinistrySafe CMCC,
MinistrySafe pricing |
Vendor/primary | 2026 | High | Pricing evidence, Competitive landscape |
| Insurer-required documented child-protection policy |
Brotherhood Mutual,
Church Mutual
(GuideOne is also a major church insurer with published child-protection guidance, but its specific
guidance pages returned a 404 during link verification and are omitted as citations pending a working URL) |
Vendor/primary (insurers) | 2026 | High | CODE-Demand, Budget validation |
| Specific documented safeguards required (screening, six-month rule, two-adult rule, training) |
Brotherhood Mutual |
Vendor/primary | 2026 | High | Painful problem, Regulatory |
| SBC abuser-database rollback | Christianity Today |
Secondary/trade press | 2025 | Medium | Expansion market (Inferred) |
| USCCB "historic milestone" report framing | Angelus News |
Secondary/Catholic press | 2026 | Medium | CODE-Trend |
| Annual audit process, general description | Diocese of Raleigh |
Primary/institutional | 2022 (process description, still current per USCCB Audits page) | Medium | Regulatory considerations |
Market and demand evidence
196 dioceses/eparchies form a closed, enumerable, high-quality prospect list (published by USCCB/Catholic
Hierarchy). Demand signals are direct and public: the annual national CYP report itself documents follow-up
visits and noncompliance findings; Catholic press (Angelus News) covers the report as major news each year;
and dioceses already budget for VIRTUS, background-check vendors, and, in some cases, Praesidium accreditation
— none of which is optional in any meaningful sense given insurer requirements and Charter obligations. The
market is not hypothetical: it is a mandatory annual compliance cycle with a named external auditor and a
public report card.
Active buyer conversations
Public demand signals located during research (Verified, general category-level, not diocese-specific private
conversations, which were not accessible): USCCB's own annual report and press coverage of that report each
year (Angelus News, BishopAccountability.org, The Good Newsroom aggregation) function as a public forum for
diocesan compliance performance; church-insurer safety-resource libraries (GuideOne, Church Mutual, Brotherhood
Mutual) actively publish guidance addressed directly to parish/diocesan staff on this exact documentation
burden, indicating sustained buyer-side questions; MinistrySafe's own marketing content addresses the "we know
you don't have the staff to track this" pain point directly. No private forum threads or RFP language specific
to diocesan Safe Environment offices were found in this run's searches — this is Noted as a gap to fill via
direct diocesan-conference outreach (see Warm GTM) rather than treated as absent demand.
Competitive landscape
| Player | What they do | Why CharterReady Clear is different |
| VIRTUS Online | Training-content delivery and completion-tracking software the diocese/parish
staff operate themselves. | A tool the diocese must run itself, not a done-for-you audit; CharterReady
Clear ingests VIRTUS exports as one input, it does not compete with VIRTUS's training-delivery function. |
| Stonebridge Business Partners | The official, USCCB-commissioned external Charter compliance
auditor, once per year. | Audits once annually and does not help a diocese find or fix gaps proactively
between audits; CharterReady Clear is explicitly not an audit and never claims to replace or represent the
Stonebridge process. |
| Praesidium | Comprehensive abuse-prevention accreditation and consulting, standards-and-culture
focused, higher-touch and higher-cost, serving Catholic religious institutes and other organizations. |
CharterReady Clear is a narrower, lower-cost, higher-frequency operational completeness layer — not
an accreditation body and not a substitute for Praesidium's broader organizational-culture work. |
| MinistrySafe | Training content, background-check products, and a compliance-consulting offering
(CMCC), largely training- and policy-document led. | MinistrySafe's compliance consulting is
project/engagement-based; CharterReady Clear is an ongoing, quarterly, parish-file-level completeness
monitoring service layered on top of whatever training/background-check vendor the diocese already uses. |
| Background-check vendors (various, CRA-compliant) | Conduct the actual criminal-history checks. |
CharterReady Clear does not conduct background checks and never stores raw report content — it verifies
that a completed check exists on file within the renewal window. |
Competitor and budget validation
Existing budget lines proven by this research: (1) VIRTUS licensing/usage fees paid by the large majority of
US dioceses; (2) background-check vendor fees paid per employee/volunteer, recurring on each diocese's renewal
cycle; (3) Praesidium accreditation and consulting fees paid by dioceses and religious institutes seeking
formal accreditation; (4) MinistrySafe training and compliance-consulting fees. This is not a market with "no
competitors" — it is a market with several adjacent, budgeted vendors and one mandatory external auditor, which
is a stronger signal than a greenfield market: real money already moves through this exact problem category.
CharterReady Clear does not compete for the same budget line as any of the four; it targets a currently
unclaimed ongoing-completeness-monitoring line item that a diocese would otherwise have to build in-house or
go without.
Pricing evidence and proposed pricing
Direct diocese-specific pricing for a completeness-monitoring service was not publicly available (dioceses
do not publish vendor contracts), so proposed pricing is benchmarked against adjacent per-seat/per-entity vendor
pricing patterns observed in this sector (Inferred, not diocese-confirmed) and against the manifest's established
convention of per-unit, never-hourly pricing for completeness-desk businesses.
| Offer | Price | Notes |
| Charter Readiness Gap Scan (sample, up to 10 parishes) | Free | Lead magnet |
| Diocese-Wide Pre-Audit Gap Scan (one-time) | $2,500–$9,000 | Scaled by entity count
(≈$35–$45/entity, with a diocese-size floor and ceiling) |
| Quarterly Safe Environment Monitoring Desk | $45–$85 per parish/entity per quarter |
Minimum diocese retainer $1,500/quarter; billed quarterly to the diocese, never hourly |
| Remediation Sprint (large gap backlog) | $150–$400 per parish requiring active remediation
support | Fixed fee, scoped per engagement |
No contingency, success-fee, or recovered-dollar pricing is used anywhere in this model — appropriately,
since Charter compliance is not a monetary-recovery event and any pricing tied to audit outcomes would create a
perverse incentive to under-report gaps, which this business must never do.
Regulatory and compliance considerations
The USCCB Charter is not a government statute but a binding internal-governance framework adopted by the
US Conference of Catholic Bishops, reinforced by insurer contractual requirements and, in most states, by
mandatory-reporter statutes governing anyone who works with minors (which apply to diocesan/parish personnel
directly, not to this service). Background-check results themselves are regulated data in most states (subject
to FCRA-like handling rules when a CRA is used) — CharterReady Clear must never store or transmit raw
criminal-history report content, only completion-status metadata supplied by the diocese's own vendor. Data
covering minors and volunteers is sensitive; a signed data-handling/confidentiality agreement with each diocese,
scoped narrowly to completion metadata (not case files, not allegation records, not personally identifying
details beyond what is needed for name-matching), is required before any engagement begins.
Licensing boundary
What AI can draft/extract/classify/calculate/monitor/prepare: extract dates and completion
status from training and background-check export files; classify each parish/entity as Complete / At-Risk /
Noncompliant against the diocese's own written policy checklist; calculate days-until-expiration; monitor for
missing documentation categories; prepare draft parish remediation-notice letters and a ranked summary report.
What trained (non-licensed) compliance specialists review and approve: every AI-flagged
At-Risk/Noncompliant file before release; that the applied checklist matches the diocese's current written
policy (these vary and change by diocese); ambiguous name-matching/entity-resolution cases; final wording of
remediation letters.
What must be escalated immediately, untouched, to the diocese's own personnel: any case
involving an actual abuse allegation, a credible-accusation status, or a personnel/ministerial-suitability
question goes directly to the diocese's own Victim Assistance Coordinator, Review Board, and legal counsel.
CharterReady Clear never receives, stores, or processes allegation case files or victim-identifying information
— those are explicitly out of scope by contract.
What the company must never claim: never claim to assess or predict an individual's abuse
risk; never claim to conduct or substitute for the official Stonebridge/USCCB Charter audit; never claim legal
compliance certification (this is not a law firm and not an accreditation body); never store raw
background-check report content, only vendor-confirmed completion-status metadata. Every deliverable carries a
standing disclaimer to this effect, and every access/flag decision is logged for the diocese's own audit trail.
AI-native advantage
This is AI-native beyond "uses ChatGPT" in three concrete ways: (1) multi-source entity
resolution — matching inconsistent parish names, clergy assignment histories, and volunteer identities
across three independently-formatted export files is precisely the kind of fuzzy, context-dependent matching
LLMs handle far better and cheaper than rule-based scripts alone; (2) policy-aware classification
— each diocese's written checklist differs slightly (renewal intervals, entity categories, exception rules), so
the engine must reason over a diocese-specific policy document rather than apply one universal rule set; (3)
compounding accuracy — every quarter's human-validated corrections (false positives, edge
cases like clergy on leave or dual-parish assignments) become training signal that improves the next quarter's
automated draft, so cost-per-parish-reviewed falls over time even as the diocese roster grows.
Internal AI engine architecture
| Layer | Function |
| 1. Intake | Secure upload portal for VIRTUS export, background-check vendor export, and parish
self-attestation spreadsheet, under a signed data-handling agreement. |
| 2. Normalization | Entity resolution across parish names, clergy assignment history, and
volunteer identities; standardization of inconsistent date formats. |
| 3. Retrieval/knowledge | Diocese's own written Safe Environment policy, relevant Charter articles,
and (where applicable) state mandatory-reporter reference notes, indexed for lookup. |
| 4. AI workbench | LLM extraction of training-completion dates, background-check dates,
code-of-conduct signature status, and Review Board minutes metadata; anomaly/staleness detection. |
| 5. Deterministic rules | Renewal-interval gates per the diocese's own policy (e.g., background
check every 3–5 years, training every N years); hard date-math, no LLM judgment involved. |
| 6. Human chokepoint | Compliance specialist validates every At-Risk/Noncompliant flag; resolves
ambiguous matches; never makes a personnel/ministerial-suitability determination. |
| 7. QA | Second-reviewer spot-check of a sample of Complete classifications plus 100% check of
Noncompliant classifications; citation-completeness check on every remediation letter. |
| 8. Delivery | Ranked Gap List, parish-ready remediation letters, and a diocese-level rollup
summary delivered as a static report (PDF/portal), not a login-required SaaS tool the diocese must learn. |
| 9. Learning loop | Each cycle's specialist corrections (false positives/negatives, new exception
types) feed back into prompt and rule-base refinement for that diocese and, in generalized form, across the
client base. |
| 10. Model-portability | Engine built model-agnostic (prompt/rule layer separated from any single
vendor's API) so frontier-model upgrades improve accuracy without a rebuild. |
AI-vs-human operations pipeline
Intake & data-handling agreement (human, one-time setup)
Extraction & normalization (AI)
Deterministic renewal-interval gating (rules engine)
Risk scoring & draft classification (AI)
Specialist validation of every At-Risk/Noncompliant flag (human)
Remediation-letter drafting (AI)
QA spot-check + citation check (human)
Delivery + audit-log entry (automated)
Failure risks and mitigations: false-positive flags (mitigated by mandatory human validation before release);
missed edge cases like clergy on medical leave or newly-merged parishes (mitigated by an explicit exception
queue reviewed each cycle); stale diocese policy documents (mitigated by an annual policy-refresh check with
the Safe Environment Coordinator). What must never be fully automated: any communication implying an
individual's suitability for ministry, any handling of an actual allegation, and the diocese's own final
sign-off before any remediation letter is sent to a parish.
Dynasty translation layer
| Layer | Translation |
| Buyer | Diocesan Safe Environment Coordinator; urgent problem is the annual audit and ongoing
legal/insurance exposure; desired outcome is a clean audit and a defensible paper trail. |
| Service | Done-for-you completeness report; automated extraction/classification, human-validated
before delivery. |
| Workflow | Intake → normalization → classification → specialist review → remediation-letter
delivery → follow-up check → next-quarter renewal. |
| Tooling | Secure upload portal, spreadsheet/PDF report delivery, standard email for remediation
letters — no custom software required before first revenue. |
| Sales | A one-page offer: "know your Charter-audit gaps before Stonebridge does" with a free
sample scan as the entry point. |
| Delivery | Minimum viable delivery is a specialist manually running the extraction/classification
prompts and compiling the report by hand for the first 3 dioceses; automation of the intake portal and
report templating comes after that proof. |
| Expansion | Evolves into a standard diocesan onboarding playbook, then a template library covering
religious-institute provinces and Protestant/other-faith judicatories. |
Anti-duplication analysis
This is not a generic compliance dashboard, not a customer-operated co-pilot, and not a clone of VIRTUS,
Praesidium, or MinistrySafe (see Competitive landscape for the specific differentiation from each). It is not a
directory or lead-gen site. The narrow wedge — ongoing, parish-file-level completeness monitoring delivered as a
done-for-you report between annual external audits — is not currently offered by any vendor found in this
research. The underserved buyer segment is specifically mid-size dioceses (60–150 parishes) too small for a
dedicated in-house compliance analytics team but too large to track manually with confidence.
Anti-commoditization analysis
If a future general-purpose model makes the raw extraction step trivially self-serve, the durable moat shifts
entirely to (1) the specialist human validation layer, which a diocese's own thin office cannot replicate
without hiring a dedicated analyst, (2) the accumulated diocese-specific policy and exception history built up
over successive quarters, and (3) the accountable, liability-aware trust relationship — a diocese will not want
to self-serve its own audit-readiness check using a consumer AI tool with no human sign-off standing behind it.
Service delivery workflow
- Signed data-handling/confidentiality agreement executed with the diocese.
- Diocese uploads VIRTUS export, background-check vendor export, and parish roster/self-attestation
spreadsheet via a secure portal.
- AI engine normalizes and cross-references all three sources against the diocese's own written checklist.
- Specialist reviewer validates every At-Risk/Noncompliant flag; resolves ambiguous matches.
- QA spot-check and citation-completeness check.
- Ranked Gap List and remediation letters delivered to the Safe Environment Coordinator.
- Diocese reviews, approves, and forwards remediation letters to parishes (diocese retains final say on any
parish-facing communication).
- Follow-up check at the next cycle confirms which gaps closed; unresolved items escalate for a targeted
Remediation Sprint if needed.
Operations as product
SOPs: a structured intake checklist per diocese (what fields, what formats, what cadence); a required
evidence list per parish/entity category (clergy, staff, volunteer with regular minor contact, volunteer with
occasional contact); an automated completeness check that flags missing source files before classification
even begins; an exception queue for ambiguous matches, reviewed weekly during active engagements; reviewer
assignment logic (specialists are assigned by diocese for continuity); confidence scoring on every AI-drafted
classification; a full audit trail of every access, extraction, and human decision; version control on each
diocese's policy checklist; gold-standard example files used to calibrate new specialist reviewers; red-team
checks run quarterly against a held-out set of known-gap test files; customer-ready output templates; a
root-cause review after any missed gap is later discovered by the diocese or by Stonebridge, feeding the
learning loop.
No-holes quality engine
Every Noncompliant classification receives 100% human review before release (no sampling). Every Complete
classification receives spot-check review on a rotating 10% sample per cycle. Any parish with a prior-cycle
gap is automatically re-verified at 100% the following cycle regardless of its new classification, to guard
against a missed recurrence. A "second pair of eyes" sign-off is required before any diocese-wide rollup report
goes out. Any specialist-identified false positive or false negative is logged, root-caused, and used to update
the diocese's rule base within the same cycle, not deferred to "someday."
What the human expert actually does
| Task | License required | Min/unit @ launch | Min/unit @ day 90 |
Automation path | Quality risk | Cannot be automated | Documentation/audit trail |
| Validate At-Risk/Noncompliant flag | None (trained compliance specialist) | 6–10 min |
3–5 min | AI pre-drafts rationale; specialist confirms/edits | False positive alarms a parish
unnecessarily | Yes — final judgment call always human | Reviewer ID + timestamp + rationale logged |
| Resolve ambiguous name/entity match | None | 4–8 min | 2–4 min | AI suggests
top matches; specialist confirms | Wrong match misattributes a gap to the wrong parish |
Yes | Match decision logged |
| Approve remediation-letter wording | None | 3–5 min | 2–3 min | AI drafts;
specialist edits tone/specificity | Overly alarming or vague letter reduces diocese trust |
Yes | Final letter version archived |
| Escalate a suspected allegation/suitability issue | None (immediate handoff, no independent
action) | <2 min to escalate | <2 min | Not automatable, by design |
Highest — must never be delayed or handled internally | Always human, always immediate |
Escalation timestamp + recipient logged, no case detail retained |
Minimum viable offer
The Charter Readiness Gap Scan: a one-time, retrospective completeness check delivered as a ranked Gap List
plus draft remediation letters, for a flat fee scaled by parish count. No portal login required for the MVP —
delivery is a PDF/spreadsheet report plus a 30-minute walkthrough call with the Safe Environment Coordinator.
Fulfillment process
First 3 customers fulfilled semi-manually: the founder/specialist runs the extraction and classification
prompts by hand against each diocese's uploaded files, reviews every flag personally, and compiles the report
in a standard template. Tools needed day one: a secure file-transfer method (encrypted email or a simple
upload form), a spreadsheet/document environment, and an LLM workbench for extraction and drafting. What is
automated later: the intake portal, the entity-resolution matching, and report templating, once the process has
been proven manually across the first cohort. What should not be automated at first: any parish-facing
communication, which the diocese always reviews and sends itself in the earliest engagements.
Human-in-the-loop quality control
100% human validation of every At-Risk/Noncompliant flag before release; rotating 10% sample review of
Complete classifications; automatic 100% re-verification of any parish with a prior-cycle gap; a second-reviewer
sign-off on every diocese-wide rollup; a standing rule that any ambiguity defaults to human escalation rather
than an automated guess.
Nonlinear scaling and unit economics
50-60%
Target gross margin by year 1
$40-60
Blended COGS per parish/entity per quarter cycle
30-40%
Automation share of task-minutes at launch
70%+
Automation share of task-minutes targeted by day 90
COGS breakdown per parish/entity per quarter cycle: model inference/extraction (~$3–6), specialist review
minutes at a loaded rate (~$15–25, 6–10 min at launch falling to 3–5 min by day 90), QA spot-check amortized
(~$3–5), hosting/software (~$2–4), support/escalation handling amortized (~$3–5), rework/false-positive
correction amortized (~$2–4). Throughput per specialist per day at launch: roughly 25–40 flagged files reviewed;
targeted to 60–90 by day 90 as prompts and rule bases mature. Cycle time: 2–3 weeks from intake to delivery at
launch, targeted to 1 week by day 90. Rework-rate target: under 8% of flags requiring specialist correction by
day 90. Quality-failure-rate target (a gap missed that surfaces later): under 1%. Escalation-rate target
(suspected allegation/suitability issue surfaced): tracked but not capacity-planned against, since these must
always be handled regardless of volume. Margin expansion path: as the rule base and entity-resolution accuracy
compound per diocese, specialist minutes per parish fall while price per parish holds, expanding margin without
headcount growth. CAC payback: targeted under 6 months given the free sample-scan lead magnet converts directly
into a paid one-time scan. Lead-magnet-to-pilot conversion assumption: 15–25% of sample-scan recipients proceed
to a paid Diocese-Wide Gap Scan (Inferred, unconfirmed). Pilot-to-paid-retainer conversion assumption: 50%+ of
one-time Gap Scan customers convert to the Quarterly Monitoring Desk within two cycles (Inferred). Retention
assumption: dioceses that adopt quarterly monitoring and avoid a subsequent audit finding renew at high rates,
similar to other completeness-desk businesses in this portfolio (Inferred from category pattern, not
diocese-confirmed).
Distribution proof table
| Channel | Why ICP is reachable | First angle | Conversion assumption |
Proof source | Measurement | Follow-up |
| Direct outreach to diocesan chancery offices | Public diocese directories list Safe Environment
Coordinator contact info | "Know your Charter-audit gaps before Stonebridge does" |
2–5% reply rate on cold outreach (Inferred) | Category pattern for B2B compliance outreach |
Reply rate, meeting-booked rate | Free sample scan offer on every reply |
| State/regional Catholic conference & risk-management association events | Diocesan risk
managers and Safe Environment Coordinators attend these regularly | Short talk/booth on audit-readiness
gaps found in prior engagements (anonymized) | Unverified — no event attended yet |
Category pattern for professional-association GTM | Leads collected per event |
Free sample scan follow-up within 48 hours |
| Church-insurer safety-resource referral partnerships | GuideOne/Church Mutual/Brotherhood Mutual
already publish content on this exact pain point | Co-branded or referred "audit-readiness checklist" |
Unverified — no partnership established | Insurer content already targets this exact buyer |
Referral volume | Dedicated referral-partner intake form |
| Search / answer-engine visibility | Safe Environment Coordinators search for "Charter audit
readiness," "VIRTUS compliance gap," etc. | Educational content answering these exact queries |
Unverified — content not yet published | Search terms observed in this run's own research |
Organic traffic to lead-magnet page | Email capture + free scan offer |
| Warm referral from religious-institute/accreditation consultants | Praesidium-adjacent consultants
may refer dioceses needing an ongoing layer they don't provide | Complementary-service positioning, not
competitive | Unverified — no relationship established | Category pattern for adjacent-vendor
referral | Referral volume | Revenue-share or reciprocal-referral agreement |
Sales and outreach plan
Primary motion: direct outreach to Safe Environment Coordinators at mid-size dioceses, leading with the free
sample scan (up to 10 parishes) rather than a generic demo request. Secondary motion: presence at
Catholic-conference risk-management and Safe Environment professional gatherings. Outreach message leads with
a diagnosis, not a pitch: "here is the kind of gap our sample scans typically surface — want to see what yours
looks like, at no cost, for 10 parishes?"
Founder-led content plan
Content teaches the exact pain: why the reconciliation problem exists structurally (three systems, no shared
identifiers), what a follow-up-visit finding actually costs a diocese in staff time, what "at-risk" looks like
in practice (a lapsed check nobody caught for 18 months), and how the annual audit cycle actually works from
the diocese's side. All content is written to be genuinely useful to a Safe Environment Coordinator whether or
not they ever become a customer.
First 30 days of content
- 10 educational posts: "What Stonebridge actually checks," "The three systems that never agree," "How long
should a background check stay valid," "What a follow-up-visit finding really means," "Where dioceses lose
track of volunteers," "VIRTUS export gotchas," "Review Board minutes: what auditors look for," "New Safe
Environment Coordinator's first 90 days," "Reading your own diocese's prior audit letter," "What insurers
actually require versus what the Charter requires."
- 3 diagnostic teardown formats: an anonymized sample Gap List walkthrough; a "spot the gap" annotated
example file; a before/after of a diocese's completeness rate across two quarters.
- 2 lead-magnet angles: the free 10-parish sample scan; a downloadable "Charter audit readiness self-check"
checklist.
- 1 webinar/live-review idea: "A live walkthrough of what a Gap List looks like," for Safe Environment
Coordinators considering the free scan.
- 1 outbound diagnosis template: a short note referencing the diocese's public prior-audit status (if any
follow-up visit was publicly noted) and offering the free sample scan.
Lead magnet and waitlist plan
Primary lead magnet: the free Charter Readiness Gap Scan on up to 10 parishes, delivered within 5 business
days of receiving sample files. This gives the diocese a real, specific artifact (not a generic checklist) that
demonstrates the value directly. Conversion path: sample scan → 30-minute review call → paid Diocese-Wide Gap
Scan → Quarterly Monitoring Desk retainer. A lead is sales-ready when the Safe Environment Coordinator has
reviewed the sample Gap List and asks about diocese-wide pricing.
Warm GTM plan
Warm GTM sources: any existing personal or professional network contacts at diocesan chanceries or Catholic
risk-management associations; a scoped free-scan offer extended to 2–3 relationship-based dioceses first, to
generate case-study material (anonymized, with permission) before broader outreach.
Targeted outbound plan
Perfect-fit prospects: mid-size dioceses (60–150 parishes) with a publicly noted follow-up-visit requirement
in a past audit cycle, or a recently posted Safe Environment Coordinator job opening (a strong turnover/urgency
signal). Outreach leads with a diagnosis — a short, specific note about the general pattern of gaps found in
similar-size dioceses — not a generic demo ask.
Answer-engine/search visibility plan
Educational content is structured to directly answer the exact questions a Safe Environment Coordinator or
new chancery staffer would type into a search engine or AI assistant ("how long is a VIRTUS background check
valid," "what does a Charter follow-up visit mean," "what do dioceses need before the annual audit"), with
clear, citable, non-promotional answers up front and the service offer positioned as a natural next step.
Pilot design and early-demand-trap mitigation
First pilot cohort: 3–5 dioceses, capped, selected for a mix of diocese sizes (small, mid, large) to
stress-test the entity-resolution logic. Early-access incentive: founding-cohort pricing locked for 12 months.
Feedback mechanism: a structured debrief call after each delivered Gap Scan, explicitly separating "this is a
product gap" (feeds the rule base/prompt library) from "this is one-off custom work for this diocese" (billed
separately if it recurs). Early-demand-trap mitigation: a free sample scan generating interest is not treated as
validated demand until it converts to a paid Diocese-Wide Gap Scan — waitlist signups and free-scan requests
alone do not count toward the pilot cap.
Early-access feedback flywheel
Corrections from each pilot diocese become SOPs (documented exception-handling rules), refined prompts,
updated retrieval sources (the diocese's own policy re-indexed after any revision), and new QA checks. What
must be fixed before expanding beyond the pilot cohort: entity-resolution accuracy above 90% on first pass
(pre-human-review) and a specialist review time under 8 minutes per flagged file on average.
Build-before-scale checkpoints
After 5 pilots: harden intake format requirements and the required-evidence checklist per entity category.
After 10 pilots: harden SOPs, the exception queue, and reviewer checklists into a documented playbook. After 20
pilots: pause new pilot onboarding until COGS, rework rate, escalation rate, and cycle time are formally
measured against target before continuing to scale. Manual workarounds acceptable temporarily: hand-compiling
reports in a shared template. Signals the model isn't scalable: specialist review time failing to drop with
volume, or entity-resolution accuracy plateauing below 85% despite rule-base refinement.
7-day / 30-day / 90-day launch plans
Day 1–7
- Finalize the data-handling agreement template and the free sample-scan offer page.
- Identify and reach out to 15–20 target dioceses (mid-size, public follow-up-visit history or recent Safe
Environment Coordinator turnover).
- Publish the first 3 educational content pieces.
Day 8–30
- Deliver the first free sample scans to responding dioceses.
- Convert at least 1 sample scan into a paid Diocese-Wide Gap Scan.
- Publish the remaining first-30-days content and the diagnostic teardown formats.
Day 31–90
- Complete the 3–5 diocese pilot cohort.
- Convert at least 2 pilot dioceses to the Quarterly Monitoring Desk retainer.
- Harden SOPs per the 5-pilot and 10-pilot checkpoints; measure COGS and rework rate.
Metrics and KPIs
- Sample scans delivered per month; sample-scan-to-paid-scan conversion rate.
- Paid Gap Scans delivered; Gap-Scan-to-retainer conversion rate.
- Specialist review minutes per flagged file (trending down).
- Entity-resolution first-pass accuracy (trending up).
- Rework rate, quality-failure rate, escalation rate.
- Gross margin per diocese engagement.
- Retainer renewal rate at cycle end.
Risks and mitigations
The most consequential risks are (1) mishandling a suspected-allegation escalation — mitigated by an
absolute, trained, no-exceptions escalation protocol and explicit contractual scope exclusion of allegation
handling; (2) a false-positive flag damaging trust with a parish or diocese — mitigated by mandatory 100% human
review of every At-Risk/Noncompliant flag before release; (3) a missed gap that later surfaces in an official
audit — mitigated by conservative classification defaults (ambiguous cases default to At-Risk, not Complete)
and the automatic 100% re-verification rule for any parish with prior-cycle history.
Exhaustive risk register
1. Data-handling breach involving sensitive volunteer/employee PII
Likelihood: Low. Impact: Severe. Mitigation: encrypted transfer/storage, minimal-necessary data scope
(completion metadata only, never raw background-check report content), signed data-handling agreement,
access logging.
2. Mishandled escalation of a suspected allegation
Likelihood: Low. Impact: Severe. Mitigation: absolute no-exceptions immediate-escalation protocol; contract
explicitly excludes allegation handling; specialist training includes this scenario explicitly.
3. False-positive flag alarms a parish unnecessarily
Likelihood: Medium. Impact: Moderate. Mitigation: 100% human validation before release; conservative
confidence thresholds.
4. Missed gap later surfaces in the official Stonebridge audit
Likelihood: Low-Medium. Impact: Severe (reputational). Mitigation: conservative default classification,
100% re-verification of prior-gap parishes, quarterly red-team testing against known-gap files.
5. Diocese policy checklist changes without notice
Likelihood: Medium. Impact: Moderate. Mitigation: annual policy-refresh check built into the SOP; version
control on each diocese's checklist.
6. Slow sales cycle due to institutional/hierarchical decision-making
Likelihood: High. Impact: Moderate. Mitigation: free sample scan lowers the barrier to a first "yes";
founding-cohort pricing creates urgency.
7. Small total addressable market limits growth ceiling
Likelihood: Certain (by design, narrow niche). Impact: Moderate. Mitigation: planned expansion into
religious-institute provinces and other-faith judicatories after the Catholic-diocese wedge is proven.
8. Reputational sensitivity of the subject matter (child protection, abuse history)
Likelihood: Medium. Impact: Moderate-Severe if mishandled. Mitigation: strict scope boundaries, no marketing
claims about preventing abuse, explicit "documentation completeness only" positioning throughout.
9. Key-person dependency on a small specialist reviewer pool
Likelihood: Medium. Impact: Moderate. Mitigation: documented SOPs and gold-standard training files enable
faster onboarding of additional specialists.
10. Diocese resistance to sharing sensitive personnel data with an outside vendor
Likelihood: Medium. Impact: Moderate. Mitigation: narrow data-scope agreement (metadata only), references
from pilot dioceses, transparent security practices documented up front.
11. Model/vendor cost increases erode margin
Likelihood: Low-Medium. Impact: Moderate. Mitigation: model-agnostic architecture allows switching
providers without a rebuild.
12. A diocese disputes a Noncompliant classification
Likelihood: Medium. Impact: Low-Moderate. Mitigation: every classification is fully cited against the
diocese's own policy document, with a specialist-authored rationale attached.
What could kill this
The two failure modes that would end this business: (1) a serious mishandling of a sensitive escalation
that damages trust irreparably with even one diocese, given how small and reputation-connected this buyer
community is; (2) failure to convert free sample scans into paid engagements at a sustainable rate, given the
slow, hierarchical nature of diocesan purchasing decisions. Both are named explicitly so they can be watched
for and addressed early rather than discovered late.
Go/no-go reasoning
Go. The evidence threshold is cleared: a clearly identified buyer (196 enumerable dioceses/eparchies with a
named decision-maker role), a painful and specific problem (documented in USCCB's own audit findings), evidence
of existing spend (VIRTUS, Praesidium, MinistrySafe, background-check vendors), a narrow MVP wedge (a one-time
sample scan), a practical fulfillment path without large custom software, a credible path to 50%+ gross margin,
and a believable distribution path (direct outreach plus Catholic risk-management professional channels). No
fatal disqualifier applies: this is not legal, tax, medical, insurance, or financial advice; it does not require
substantial physical labor; it is not a clone of any existing vendor found in this research.
Final recommendation
Proceed to build CharterReady Clear as a blueprint, starting with direct outreach to 15–20 mid-size dioceses
offering the free 10-parish Charter Readiness Gap Scan, with the explicit goal of converting at least one paid
Diocese-Wide Gap Scan within 30 days and building a 3–5 diocese pilot cohort within 90 days.