Skip to main content

NFR & compliance catalogue

A reusable menu of non-functional and compliance requirements, selected per product at Definition and verified at Refinement. Turns domain constraints from tribal knowledge into testable requirements.

The menu

Select what applies; state the target; it becomes testable.

AreaOptions / targets
Quality (ISO/IEC 25010)performance efficiency, reliability, security, maintainability, portability — with concrete targets
AccessibilityWCAG 2.2 AA (see accessibility standard)
Data protectionUK GDPR, data residency (UK / India handling)
Financial conductFCA Consumer Duty; Lloyd's / market rules where relevant
AI featuresEU AI Act risk classification (see AI decision auditability)
Availabilityuptime SLO, RPO / RTO
Auditabilityaudit-trail completeness, retention
Multi-tenancytenant isolation guarantees

The rules

  • Selected at Definition — the applicable rows go into the PFD with concrete targets.
  • Verified at Refinement — each becomes a check in the Refinement Exit gate.
  • A requirement without a target isn't a requirement — "fast" is not a target; "p95 < 300ms" is.

Standards referenced: ISO/IEC 25010, WCAG 2.2, UK GDPR, FCA Consumer Duty, EU AI Act.