Remediation backlog standard
STOP produces findings from five directions — debt, security, coverage, cost and ways-of-working friction. They all land in one prioritised backlog, scored one way, so they compete on the same terms rather than each source claiming urgency separately.
The rules
- One backlog. Tech-debt, security-debt, test-debt, cost and ways-of-working findings all enter here, each linked to its evidence in the source register.
- One scoring model — WSJF (Cost of Delay ÷ job size). Security gaps and slow builds are scored the same way, so triage is honest.
- Consciously-deferred items exit only via a risk-acceptance record — signed, time-boxed, with compensating controls and an expiry. Nothing just quietly drops off.
The output that matters
A prioritised remediation backlog plus the savings (FinOps review) to fund the AI tooling — the stable base everything next is built on. The backlog is the bridge from STOP's audits to the sequenced work that clears the STOP exit gate.
Standards referenced: WSJF, ISO 31000.