Consulting innovation · Risk-based prioritisation

Three-lens risk workshop

Most "risk-based testing" means doing the business's priority list in order. A real risk position needs three lenses, a pre-mortem, and questions phrased in words the room actually owns.

Why

Standard practice starts from ISO quality attributes: performance, maintainability, suitability. Stakeholders do not think in those words, so the prioritisation happens in a language foreign to the people whose priorities it claims to encode. And on any project of meaningful size, no single person can hold everything that should shape test scope. Prioritisation has to be collaborative or it is fiction.

How

  1. Set the frame. What is this system for, who does it serve. Then adopt prospective hindsight, the pre-mortem: assume it has failed publicly, and work backwards.
  2. Split into three groups. Technical focus, business focus, customer advocates. Each group brainstorms every way the system could put the organisation on the front page of the newspaper, prompted by structured thought provokers. Duplicates are kept: they carry signal about weight.
  3. Group, then name each group as a question testing can answer. Not "performance" but whatever this room means: "is response time okay?", "has the data migrated?", "can it be audited?".
  4. Prioritise on likelihood (the chance the answer is "no" if we do not test it) and impact to business outcomes or customer experience. Add "priorities for assurance": items rated lower but where key stakeholders still want visibility.
  5. Allocate effort on a doubling scheme. Very high gets twice the rigour of high, high twice medium, medium twice low. The doubling makes scope tradeable: swap one medium for two lows, trade a very-high to add two highs. And rigour scales with the tier, rather than sequence alone: the top tier earns design workshops, static testing, and formal test design techniques; the bottom tier may earn exploratory testing only, or nothing.
Thought provoker grid: candidate test objective questions from the business, technology, and customer perspectives
The thought provoker grid: candidate questions per lens, used to drive the brainstorm. The room picks, renames, and reweights them in its own words.
Rigour by priority tier: higher risk tiers earn more test activities, from design workshops and static testing down to scenario tests only
Rigour by tier: the risk assessment decides which activities each priority tier earns, from the full set at very high down to scenario tests only, or nothing, at low.

What

The language step is where the value keeps proving itself. In one workshop, "does it perform?" produced pushback: "performance, what have appraisals got to do with this?" The word meant employee reviews to half the room. The question that meant the same thing to everyone was "is response time okay?". At a different customer, that exact question fell flat, because there "response time" meant how quickly staff responded to customer queries. Same framework, different words, each time chosen by the room.

The workshop and the Quality Integration Map work in either order: bring an existing map in as the thought provoker, or run the workshop first and build the map from what it surfaces. The questions then flow into the Sankey scope review and the why-how-what plan summaries. One collaborative hour of eliciting the right questions is worth more than any amount of template reuse.

← One-page executive reporting Next: Improvement opportunities map →