skip to content

As the owner of a risk register, how do you defend a deliberate decision to leave an area unverified?

level: principalimportance: should knowfreq 40%

answer

  1. Chosen, not merely left out
  2. Name the failure, not the area
  3. Same scale as what you tested
  4. Containment is cheaper than coverage
  5. The consequence-owner accepts, with an expiry

basics

~20 s

Make it a decision, not an omission: name the failure being accepted, score it on the same scale as what you did verify, offer a cheaper containment, and have the consequence-owner accept it with a review date.

solid answer

~50 s

An unverified area is indefensible when it is silent and routine when it is explicit. Four things make it explicit. **Name it**: the area, the specific failure mode accepted, and the assumption keeping likelihood low. **Score it on the same scale** as the areas that did get depth, so the comparison is visible and the choice can be argued with rather than merely trusted. **Offer containment instead of coverage**: a staged rollout, a reversible switch, an audit or reconciliation check, a limited audience — these lower what a failure costs without buying verification you cannot afford. **Route acceptance to the consequence-owner**: the business owner accepts residual risk, not the test lead, because acceptance means agreeing to bear a cost. Then date it and attach a trigger that brings it back: usage above a threshold, a change in the area, a related defect. State it all in consequence terms, never coverage percentages.

go deeper

for a junior

Know that shipping with some risk remaining is normal, and that an untested area should be written down rather than left unmentioned. Be able to say that the decision belongs to someone above the test role.

for a middle

Be ready to state an untested area as a consequence rather than a gap in coverage, and to name one containment measure — a staged rollout, a reversible switch, a monitoring check — that lowers the cost of a failure you did not verify.

for a senior

Show the full package: the named failure mode, its score against areas that did get depth, the containment offered, and who agreed. Interviewers listen for whether you route acceptance to the person who bears the cost.

for a principal

Own the mechanism, not the individual item: what qualifies for escalation, how acceptance expires, and how you keep the practice from degrading into signature collection. Be ready to say where an accepted risk exceeds the accepter's authority and must go further.

## Residual risk, precisely Residual risk is what remains after the mitigations you actually performed. Every release ships with some, so the question is never whether residual risk exists but whether anyone **chose** it. An area left unverified because it was ranked low and the budget ran out is a legitimate outcome of risk-based selection. The same area left unverified because nobody noticed is an incident waiting to be explained badly. ## What a defensible decision contains **A named failure mode, not a named area.** "We did not test the archive path" invites the answer "so test it". "We accepted that an archived record may be restored with a stale status, affecting records older than the retention window" invites a decision, because the reader can now weigh it. The assumption that keeps likelihood low should be stated too — it is the thing that will later turn out to be wrong, and writing it down is what makes the failure diagnosable. **The same scoring as everything else.** The comparison is the argument. If the accepted area sits below eleven areas that did receive depth, the decision defends itself; if it sits above three of them, you have found a real problem in the plan and the conversation is different. Scoring accepted items on a separate, softer scale is how registers become unfalsifiable. **A cheaper alternative to depth.** Verification is not the only lever, and a senior owner is expected to reach for the other one. Impact-side mitigations cost a fraction of full coverage: a staged rollout to a small audience, a switch that reverts the behaviour in seconds, an independent reconciliation or audit check that flags a bad state the day it appears, a constrained input range that removes the dangerous state entirely, or a documented manual fallback for the operators. Offering "we will not verify this, and here is how we would notice and undo it" is a materially different proposition from "we will not verify this". **Acceptance by the person who bears the consequence.** This is the part most often got wrong. A test lead can measure risk, describe it and recommend; accepting it means agreeing to absorb the cost if it happens, and that authority belongs with product, the business, or whoever owns the outcome. A quality function that accepts risk on the business's behalf has quietly taken accountability for decisions it cannot fund. **A date and a trigger.** Acceptance decays. What was fine at a thousand users a day is not fine at forty thousand, and it is not fine after the area is rewritten. Attach the condition that brings the item back: usage crossing a threshold, any change to the component, a defect found nearby, a regulatory change, a partner going live on it. **Consequence language.** "Coverage in this module is 34 percent" tells a business reader nothing they can act on. "If this fails, an estimated few hundred customers see a wrong balance for up to a day, and correcting it is a manual repair costing about two operator-days" is a decision. Ranges and stated assumptions beat false precision; if the estimate is soft, say it is soft. ## The organisational failure modes - **Sign-off theatre.** A name collected on a document nobody read is worse than no sign-off, because it manufactures a defence while removing the conversation. If the accepter cannot restate the risk in their own words, they have not accepted it. - **Acceptance by silence.** Circulating a residual-risk list with no response deadline and treating the silence as agreement. Ask for an explicit yes on the top items only — which means the list must be short enough to read. - **Blame insurance.** Writing residual risk primarily to be able to point at it later. The test is uncomfortable but clarifying: if you would not be comfortable with the item being read aloud after an incident, it is not a decision, it is cover, and the item probably needs escalating rather than filing. - **Escalating everything.** A list of forty accepted risks is not transparency; it is an unreadable document that guarantees the two that mattered were skimmed. Escalate the few, absorb the rest at the level that can absorb them, and say which is which. - **The register that only grows.** Accepted items with no expiry accumulate until nobody reads any of them. Every accepted item needs either a closure or a review date. ## Where the boundary sits Defending a deliberate gap is a judgement about **exposure**, not about process compliance. It survives scrutiny when the reasoning is visible, the comparison is honest, the alternative was offered, and the person who would pay the price said yes knowing what they were saying yes to. When those four are true, an area left unverified is a professional decision — and the ability to make it, rather than the ability to test everything, is what the ranking exercise existed to produce.

  • The person you need to accept a residual risk keeps deferring the decision. What do you do?
    Make deferral itself a visible choice with a cost. Give a short written statement of the exposure, a date after which the release proceeds with the risk unaccepted, and a note that the item will be recorded as unaccepted rather than accepted. Most deferral is a signal the item is unreadable or the wrong person was asked, so shorten it and check who actually owns the consequence before escalating a level, which is the last step rather than the first.
  • How do you keep a list of accepted risks from becoming an unread document over time?
    Cap it and expire it. Only items above a stated band go on the escalated list; everything else is absorbed at the level that can absorb it and recorded, not escalated. Every accepted item carries a review date or a trigger condition, and an item that reaches its date without review is closed or re-escalated rather than quietly renewed. A list short enough to read at every release boundary is the only kind that changes a decision.
  • Is there a case where you should refuse to accept the decision and escalate instead?
    Yes, where the consequence lands outside the accepting party's authority: safety, legal or regulatory exposure, or harm to people who are not the accepter's customers. A product owner can accept a commercial loss their own budget bears; they cannot accept a duty owed by the organisation to a regulator or to third parties. Say plainly which of those categories the item falls into, because that classification, not seniority, decides where the decision has to go.

A structural surveyor does not open every wall. The report says which walls were not opened, why the risk was judged acceptable, and what would change that judgement — and the buyer, not the surveyor, decides to proceed.

saying these in an interview costs you the question

  • Lets the test lead accept business risk
  • Reports coverage percentages instead of consequences
  • Collects a signature without a restatement
  • Treats silence on a circulated list as agreement
  • Escalates every accepted item equally
  • Records acceptance with no expiry or trigger

context