What a Software Risk Assessment tells you
Sample report executive summary · Example Disc Golf Retailer · Pro Shop Portal · Release 24.3
This is section 1 of a full readout. The complete report runs to nineteen sections.
We examined one value stream — the Pro Shop Portal team, Release 24.3, five features — across a twelve-week release cycle representing 4,300 hours of funded development capacity.
890 hours — 20.7% of that capacity — went to unplanned rework and to work that was built but never shipped. That is the figure our guarantee attaches to, and it clears the 20% bar we committed to in writing before looking at a single ticket.
We show it in layers, never as one number: 18.4% measured from your own delivery record, plus 2.3% client-stated by your team and not independently verified.
A further 4.9% — 210 hours — is inferred: work visible in your record whose cause we could not attribute. It sits beside the figure, never inside it. Read together the picture is 25.6%, but 20.7% is the number we stand behind.
A third group sits outside the bar altogether. Unplanned sustaining work — patching, environment drift and unscheduled upgrades — took a further 185 hours, 4.3%. That figure is measured, not inferred, and it is real cost. But it is not rework, so it does not count toward the bar. Section 7 shows all three groups, and no hour appears in more than one.
Separately, and not added to that figure, the release shipped seven of eleven committed features. The date held and the cost held. What moved was scope — which is why nothing in your current reporting shows a problem.
20.7%
Guarantee figure
890 of 4,300 hrs
7 of 11
Committed features delivered
18%
Flow efficiency touch vs elapsed time
31%
Of completed story points were defects & rework
2.5x
Spread in hours per unit of delivered function
What is Working
Start here, because it matters for everything that follows. This team has a real process and follows it. Velocity held within 10% every sprint. 94% of defects are caught before customers see them. A definition of done and a test plan exist and are used. And your people read their own delivery record accurately — closer to the data than leadership on four of five questions. That is the hardest thing to build, and you already have it. The findings below are about what the process counts and when it catches things, not about whether the team is disciplined.
Six Takeaways
- Your release shipped on time, on budget, and four features short. Nothing in a date-and-cost report shows that. Scope absorbed the churn.
- Defects are found late. Requirements problems are being discovered in test, at roughly five times the cost of catching them when written.
- Velocity never varied by more than 10% all quarter — while 31% of the points completed were defect and rework items, pointed and counted exactly like features.
- Two features have been displaced across three consecutive releases. Neither appears on any escalation list.
- Your leaders and your team do not see the same organization. On every one of six safety questions, leaders scored more than a point higher than doers — and on “I would report a defect late in a release,” 4.4 against 2.1. That gap makes every defect figure in this report a floor.
- You are not measuring most of this. Every figure had to be reconstructed from your own delivery record, and 4.9% of the capacity we found could only be inferred — which is why we report it separately rather than inside the figure we stand behind.
Read the full sample report
This executive summary is section 1. The other eighteen sections carry the evidence behind every figure in it — how the capacity was measured, where the defects came from, and what the team would look like two maturity levels up.
What’s in the full report
1. Executive summary
2. What we examined
3. The process we followed
4. How to read this report
5. What your people told us
6. Process maturity
7. Where the capacity went
8. It’s leaking
9. It’s waiting
10. Velocity is fine, throughput isn’t
11. Ranked by opinion
12. Productivity
13. Where this could go — your measures at CMMI-3
14. What you are not measuring
15. Strengths to build on
16. Complete findings register
17. Findings mapped to Key Program Views
18. Next steps
19. Appendix — function point detail
We’ll ask for a business email. We will not call you. You’ll get the report — that’s it.





