Beyond Quality

An open-source community for deeper enquiry.

Podcast

Governance of quality

What this research does

Testing strategy, QA process, security work and product work usually run as separate management conversations, each negotiating its own budget, with no shared frame connecting any of them to what the organization is trying to achieve.

This research describes the level above them: governance, the company-wide human system of direction, oversight and accountability, through which an organization decides what quality is worth to it, how much uncertainty it accepts in pursuit of that value, and who answers for the outcome.

The purpose of this research is to provide a tool (a framework) that allows organizations to gain and maintain clarity on the economics of their quality-related decisions. With that clarity, the right people can make these decisions on time and on economic grounds, and monitor their outcomes.

It does three things:

  1. Defines quality governance and its interface with management, using the vocabulary of ISO 37000, ISO/IEC 38500 and ISO/IEC 38507: what flows down (purpose, value objectives, risk appetite, delegation limits) and what flows up (bet checks, risk sizes, accepted risks, breaches and warnings, proposals).
  2. Positions two existing researches: Economics of Testing is the how for risk management in QA, and this research uses it as the resource for management; QA in the Age of AI-Accelerated Development diagnoses the problem agents introduce, researches it and suggests one possible solution.
  3. Advances its own thesis: AI-accelerated development does not merely add risks for this system to process; it erodes the human capacities the system runs on unless deliberate countermeasures are taken. The countermeasures are partly formulated in the ai-era-testing research already, and this work will feed updates back into it; governance is the level where they get mandated.

1. Problem statement

This section makes four observations and states their shared root.

The four observations are one information deficiency (no model of value or loss), one decision deficiency (no common measure for time and quality, no owner of the whole), one structural deficiency (no interface where the sum could be owned), and the same decision deficiency repeated at the adoption scale, under an external dynamic that erodes the knowledge any fix would run on. The root: quality is treated as a set of management practices with nothing above them. The governing body’s instruments (purpose, value objectives, risk appetite, policy, delegation) are never explicitly connected to the quality work done below. The disconnect is self-reinforcing: organizational structure, incentive schemes, and the way processes and responsibilities are defined all shape one another, and together they produce the silos and the Goodhart’s-law effects (a measure that becomes a target stops being a good measure) that keep each function optimizing its own numbers. This is why Deming’s company-wide quality efforts only work when top management takes on leadership for the change, and why the governance standards make the same demand: governance starts from the very top, otherwise nothing works.

Repairing the four deficiencies buys four capabilities, one per deficiency, stated as capabilities rather than outcome promises: what becomes possible and decidable, not what improves by how much.

The capabilities land differently per role, and no single reader can implement them alone; the practice page will carry the per-role version: what each role gains next to what each must do.

2. Definitions

The vocabulary this research operates, taken from the standards and explained in simple words: governance, the governing body, management, accountability, risk appetite, compliance (including why governance is not compliance), quality as a degree (which is what makes it governable at all), and the working definition the research builds on. Page: definitions.md.

3. Value first, risk second

The ordering thesis, definitional rather than good practice: risk is the effect of uncertainty on objectives, so the value work sets objectives before risks can be derived. The value model (the degrees to target and what reaching and holding them is worth to the company) lives on the same page. Page: value.md.

4. The governance-management interface for quality

What flows down (purpose, value objectives, quality targets, risk appetite, delegation limits; written down together as the statement, they are the governance policy), what flows up (five kinds of reports: bet checks, the current size of each risk, accepted risks with sign-offs, breaches and warnings, proposals; the evidence itself stays below) and why, and the never-ending loop the interface runs as; why the parameters are set at the top and nowhere else is argued on value.md. Page: interface.md.

5. The management-layer implementations

The two linked researches set against this governance system. Economics of Testing is the how for risk management in QA: its four-step loop runs inside the parameters the statement publishes and produces most of what flows up, which serves risk governance, oversight and performance. QA in the Age of AI-Accelerated Development diagnoses the problem agents introduce, researches it and suggests one possible solution; its two debts and four conditions are read against the governance tasks and the AI clauses. Page: implementations.md.

6. The erosion thesis

The research’s own claim: AI-accelerated development erodes the capacity to run the machinery above unless countermeasures are mandated and funded, and this is where the purpose statement’s “maintain” is defended. Page: erosion.md.

7. Putting it to work

The practice layer, per role: what each role gains next to what each must do; the parameters governing bodies set, what QA and engineering leadership supply upward, possibly a short diagnostic. Page: practice.md.

8. Scope and non-goals

9. Reading order

  1. This hub.
  2. The section pages in order: definitions.md, value.md, interface.md, implementations.md, erosion.md, practice.md.
  3. Economics of Testing: the risk-governance and oversight machinery. Its AI-era addendum is planned.
  4. QA in the Age of AI-Accelerated Development: the two debts, the generative ratification loop, the four conditions, and the Direction 3 proposal.

References

Designations follow each standard’s own: 37000, 31000 and 9000 are ISO standards with no IEC involvement; 38500, 38507 and 25010 are joint ISO/IEC standards from JTC 1. The mixed prefixes are deliberate. Standards are paraphrased with clause references only; no licensed text is reproduced beyond fair use.