Most "risk-based testing" means doing the business's priority list in
order. A real risk position needs three lenses, a pre-mortem, and
questions phrased in words the room actually owns.
Why
Standard practice starts from ISO quality attributes: performance,
maintainability, suitability. Stakeholders do not think in those
words, so the prioritisation happens in a language foreign to the
people whose priorities it claims to encode. And on any project of
meaningful size, no single person can hold everything that should
shape test scope. Prioritisation has to be collaborative or it is
fiction.
How
Set the frame. What is this system for, who does
it serve. Then adopt prospective hindsight, the pre-mortem: assume
it has failed publicly, and work backwards.
Split into three groups. Technical focus,
business focus, customer advocates. Each group brainstorms every
way the system could put the organisation on the front page of the
newspaper, prompted by structured thought provokers. Duplicates are
kept: they carry signal about weight.
Group, then name each group as a question testing can
answer. Not "performance" but whatever this room means:
"is response time okay?", "has the data migrated?", "can it be
audited?".
Prioritise on likelihood (the chance the answer
is "no" if we do not test it) and impact to business outcomes or
customer experience. Add "priorities for assurance": items rated
lower but where key stakeholders still want visibility.
Allocate effort on a doubling scheme. Very high
gets twice the rigour of high, high twice medium, medium twice low.
The doubling makes scope tradeable: swap one medium for two lows,
trade a very-high to add two highs. And rigour scales with the
tier, rather than sequence alone: the top tier earns design
workshops, static testing, and formal test design techniques; the
bottom tier may earn exploratory testing only, or nothing.
The thought provoker grid: candidate questions per lens, used to
drive the brainstorm. The room picks, renames, and reweights them
in its own words.
Rigour by tier: the risk assessment decides which activities each
priority tier earns, from the full set at very high down to
scenario tests only, or nothing, at low.
What
The language step is where the value keeps proving itself. In one
workshop, "does it perform?" produced pushback: "performance, what
have appraisals got to do with this?" The word meant employee reviews
to half the room. The question that meant the same thing to everyone
was "is response time okay?". At a different customer, that exact
question fell flat, because there "response time" meant how quickly
staff responded to customer queries. Same framework, different words,
each time chosen by the room.
The workshop and the
Quality Integration Map
work in either order: bring an existing map in as the thought
provoker, or run the workshop first and build the map from what it
surfaces. The questions then flow into the
Sankey scope review
and the why-how-what plan summaries. One collaborative hour of
eliciting the right questions is worth more than any amount of
template reuse.