14. Risk and How We Define Done on Paper

The gate review package marked every action closed.

Two critical failure modes were still open in the lab log — verification and reliability tracking both, with no accepted closure evidence. It was Thursday, gate prep underway.

The paper package says done, but the program state is not. The gap is not a communication failure — it is a structural one. The action tracker and the failure-mode log are not the same artifact, and no gate-packet requirement connected closure of one to the other. Fixing it requires a single rule: closure evidence must cite the failure-mode investigation disposition, not just the action ID. That single rule is the spine of this chapter.

That gap is where late cost, schedule slips, and credibility damage enter through integration and executive review.

This is the gate-closure logic: the chamber evidence became a controlled requirement revision, and that revision had to be in the record before the gate could close.


"Done on paper" must match decision reality

Artifacts are useful only when a named owner uses them to change a specific decision and downstream behavior.

A credible "done" statement is a decision object that must:

  1. state explicit criteria (gate chair's pass condition),
  2. cite evidence references (gate chair's confidence source),
  3. include owner sign-off,
  4. declare residual risk (gate chair's accept-or-escalate input),
  5. confirm downstream updates are complete.

If any element is missing, "done" is only a status label and fails as a decision condition at gate.

Minimum credible artifact standard

For each risk or verification artifact, require this minimum metadata:

  • name artifact owner,
  • record revision and date,
  • link requirement or risk ID,
  • state decision linkage (what choice this supports),
  • report current confidence and known gaps.

If the artifact has no linkage, the gate chair cannot use it for a decision.

Artifact evolution across builds

Risk artifacts should evolve with new evidence across builds, not reset at each phase boundary.

Each artifact revision should show four deltas:

  • state what changed,
  • record what remains uncertain,
  • retire concerns with evidence and rationale,
  • declare what new risk emerged.

Resetting artifacts to "clean" each phase destroys institutional memory that gate and program leaders need.

Busywork vs decision work

The filter is simple: does this artifact change a decision, or was it produced to show the artifact exists? Format-only completion, generic failure text, no owner, no closure date — any of those signals the artifact served the tracker, not the program.

What keeps: honest uncertainty on the table, a clear link to an active decision, and tradeoff framing that each tier can read without a follow-up meeting.

You know the difference after the first gate debrief where someone produced a risk summary that nobody had read. That is not a documentation gap — that is what busywork looks like when it reaches the table.


A gate package at a large industrial program marked all thermal actions closed. Two critical failure modes — thermal runaway propagation and connector derating under field humidity — were still under active investigation in the test lab. The disconnect: the action tracker was PM-owned and tracked action-item status by ID. The failure-mode log was engineering-owned and tracked investigation state by failure mode. No artifact required a closure entry to cite a failure-mode log entry rather than just an action ID. One internal audit caught the gap three days before the gate review. The auditor had not been looking for it specifically — she was tracing an action item listed as closed with no linked evidence, and the failure-mode log was the first place she checked. If the gate had proceeded, the program would have released a build configuration while two unresolved failure modes were still in active investigation — a six-to-eight-week integration cost if either materialized in production. The fix was one line in the gate-packet template: closure evidence must cite the failure-mode log entry and its investigation disposition, not just the action ID. The organization had been closing gates the old way for two cycles and had shipped at least twice with failure modes still open. Three days of one auditor's scrutiny was all that separated this gate from the same outcome.


Tie-ins to gates and one-page truth

You need risk artifacts to feed the records that gate decisions depend on. When they stay in a technical silo, leadership walks into the gate review with paper confidence that nobody in the lab would recognize.

They must feed the decision records the gate depends on — the gate decision itself, the risk register, the one-page narrative, and escalation to named owners when a failure mode stays open. If this propagation is weak, paper confidence drifts from the real program state and misleads leadership decisions.

What matters is that one record exists, everyone knows it is where failure modes and their investigation status live, and it is the record that gets pulled for the one-page summary and the gate package — not a status assembled fresh for the occasion.

Practical "done" review in 15 minutes

For each high-impact closure item, ask:

  1. What was the done criterion?
  2. What evidence satisfies it?
  3. What risk remains despite closure?
  4. Which dependent decisions changed because of this closure?

If questions 3 and 4 are blank, closure is cosmetic — do not treat as done; return the item to the evidence owner before the gate proceeds.


Done means the failure mode is dispositioned, not the action item is closed.

Field test: find one item your last gate called closed. Can you name the evidence that moved it to closure, the DRI who accepted residual risk, and the date that decision was recorded? If the closure record has none of those, it is closed on paper, not closed in fact.

Pull your last gate package, pick one action marked closed, and follow it to the failure-mode log. If the disposition is not there — and nothing required it to be — that is not a paperwork slip. It is the same seam that splits open every time work crosses to another tier.