Company · Leadership
Accountability is a structure, not a photograph
Enterprise buyers do not need a wall of headshots. They need to know which function owns which decision, who can stop the line, and what happens at 4pm on a Friday when a manifest does not reconcile.
How we are organised
Six functions, each with the authority to stop something
WesternTechSystems is privately held and independently operated, led by CEO Jamil Ashour, who founded the company in 2009.
Below that, the organisation is deliberately built so that the functions which protect your data and your evidence do not report to the functions measured on throughput. Compliance and physical security both sit outside the production line. That separation is unremarkable in a bank and surprisingly rare in this industry.
Ownership map
Who owns what
Operations
The floor, the workflow gates, throughput and turnaround
Owns the five-stage gated process end to end and holds the authority to stop it. Supervisors hold final sign-off on advancing a device between stages, and that authority does not sit with a sales team or a client account manager. If a gate criterion is not met, the device does not move.
Compliance
R2v3 and RIOS conformance, OSHA, audit readiness
Owns certification scope, corrective action, downstream vendor qualification and audit response. This is a standing role, not a responsibility someone picks up before an audit — which is the difference between a facility that is audit-ready and one that prepares for audits.
Physical security & loss prevention
Access control, camera coverage, secure receiving, legal hold
Owns the controls that make a chain of custody physically true: single-entry access, auto-locking doors, the secure receiving cage, and segregated legal-hold storage. Reports independently of production, because a security function that reports to throughput is not a security function.
IT infrastructure & security
The segregated data environment, integrations, certificate systems
Owns the segregated network, MFA and least-privilege access, encryption at rest and in transit, and the systems that generate and store per-device erasure certificates. Also owns the API, EDI and webhook integrations that push evidence into your systems.
Logistics
Inbound consolidation, carrier management, outbound manifests
Owns collection scheduling across distributed sites, carrier relationships, and manifest reconciliation on both ends. Most custody breaks happen in transit or at a receiving dock, so this function is where a lot of the real risk lives.
Commercial & program management
Scoping, SLAs, reporting cadence, escalation
Owns the commercial relationship and the reporting your team actually reads. A named program contact who knows your estate is worth more than a support queue, particularly during a facility exit or a compressed refresh window.
Escalation
What happens when something goes wrong
Agreed at scoping, written into the program, and tested before you need it.
- Day-to-day
- Your named program contact, with an agreed reporting cadence and a shared view of open items.
- Operational exception
- Routed to the accountable function directly — a quarantined device, a manifest discrepancy or a missed pickup goes to operations or logistics, not into a general queue.
- Compliance or security event
- Escalated to the compliance and security owners in parallel, and to you. We do not investigate first and inform afterwards.
- Executive
- The CEO. We are a privately held company of a size where that is a real escalation path and not a formality.
FAQ
Questions about accountability
Who is accountable if something goes wrong with our program?
Do you have a dedicated compliance owner, or is it a side responsibility?
Will we have a named contact?
Is the security function independent of operations?
Can we speak to the people who will actually run our program before we sign?
Who owns the company?
Meet the people who would run your program.
Operations and compliance join scoping calls. It tells you more than a capability deck does.