Remediation backlog standard
STOP produces findings from four directions — debt, security, coverage, cost. They all land in one prioritised backlog, scored one way, so they compete on the same terms rather than four teams each claiming urgency.
The rules
- One backlog. Tech-debt, security-debt, test-debt and cost findings all enter here, each linked to its evidence in the source register.
- One scoring model — WSJF (urgency × risk-reduction ÷ effort). Security gaps and slow builds are scored the same way, so triage is honest.
- Consciously-deferred items exit only via a risk-acceptance record — signed, time-boxed, with compensating controls and an expiry. Nothing just quietly drops off.
The output that matters
A prioritised remediation backlog plus the savings (FinOps review) to fund the AI tooling — the stable base everything next is built on. The backlog is the bridge from STOP's four audits to the sequenced work that clears the STOP exit gate.
Standards referenced: WSJF, ISO 31000.