Skip to main content

Remediation backlog standard

STOP produces findings from four directions — debt, security, coverage, cost. They all land in one prioritised backlog, scored one way, so they compete on the same terms rather than four teams each claiming urgency.

The rules

  • One backlog. Tech-debt, security-debt, test-debt and cost findings all enter here, each linked to its evidence in the source register.
  • One scoring modelWSJF (urgency × risk-reduction ÷ effort). Security gaps and slow builds are scored the same way, so triage is honest.
  • Consciously-deferred items exit only via a risk-acceptance record — signed, time-boxed, with compensating controls and an expiry. Nothing just quietly drops off.

The output that matters

A prioritised remediation backlog plus the savings (FinOps review) to fund the AI tooling — the stable base everything next is built on. The backlog is the bridge from STOP's four audits to the sequenced work that clears the STOP exit gate.

Standards referenced: WSJF, ISO 31000.