Skip to main content

Remediation backlog standard

STOP produces findings from five directions — debt, security, coverage, cost and ways-of-working friction. They all land in one prioritised backlog, scored one way, so they compete on the same terms rather than each source claiming urgency separately.

The rules

  • One backlog. Tech-debt, security-debt, test-debt, cost and ways-of-working findings all enter here, each linked to its evidence in the source register.
  • One scoring modelWSJF (Cost of Delay ÷ job size). Security gaps and slow builds are scored the same way, so triage is honest.
  • Consciously-deferred items exit only via a risk-acceptance record — signed, time-boxed, with compensating controls and an expiry. Nothing just quietly drops off.

The output that matters

A prioritised remediation backlog plus the savings (FinOps review) to fund the AI tooling — the stable base everything next is built on. The backlog is the bridge from STOP's audits to the sequenced work that clears the STOP exit gate.

Standards referenced: WSJF, ISO 31000.