If the LocalPolicy didnt disable it, iBoot verifies the root signature hash for the signed system volume (SSV) If paired recoveryOS boot fails, booting into fallback recoveryOS is attempted. iBoot loads the. macOS-paired firmware, the trust cache, the device tree, and the Boot. Collection of. third-party kexts is loaded if the. LocalPolicy allows it to. load the Auxiliary Kernel Collection (AuxKC)”]
Source: https://support.apple.com/guide/security/boot-modes-sec10869885b/1/web/1

