And right after posting my reply I found
which suggests that tornado does not use the OS level trusted roots?! This is annoying I’d still try and dig into why/how to persuade tornado to use the OS level CA bundle and only resort to having to customise the code after exhausting that option.