00

How to use this toolkit

The approach uses a gate first, then shared scoring, then a roadmap. No single framework covers all of this.

PhaseDaysFocusTemplates
Discover0–30Inventory systems and projects; separate out mandatory work1 Compliance gate · 2 TIME model · 3 Project inventory
Prioritise30–60Score discretionary work jointly with stakeholders; frame new ideas4 WSJF scoring · 5 Opportunity Solution Tree
Plan60–90Build the roadmap and the capacity / team case6 Now / Next / Later

Flow of work through the templates

  1. Everything found (systems, projects, ideas) goes through the Compliance gate first.
  2. Systems are also classified with TIME. “Invest” and “Migrate” systems generate candidate work items.
  3. Mandatory items go straight into the roadmap’s Now column and take capacity first.
  4. Discretionary items are scored with WSJF. Low-confidence items become discovery work, not delivery.
  5. New ideas go through the Opportunity Solution Tree before they are scored.
  6. The ranked list becomes the Now / Next / Later roadmap. “Next” is explicitly dependent on funding delivery capacity.
01

Compliance gate

Separate work the function must do from work it could do, before any scoring. This stops a compliance deadline being argued against a nice-to-have.

When Days 0–30, and again for every new item that arrives.

Rule of thumb

An item is mandatory only if at least one gate question is “Yes” and there is evidence (legislation, audit finding, regulator letter, contractual term). “A stakeholder says it’s urgent” does not count.

Gate questions

#QuestionYes / NoEvidence
G1Is there a legislative or regulatory deadline (e.g. new reporting requirement, policy change, mandated system change)?
G2Is there an open audit, regulator or internal-control finding that this addresses?
G3Would not doing it put reporting accuracy or timeliness at risk (penalties, fines, reputational harm)?
G4Is a system this depends on out of support, or dependent on one person?

Triage log

IDItemSource (system / project / idea)Gate triggered (G1–G4)EvidenceHard deadlineOutcome
C-01Mandatory / Discretionary
C-02Mandatory / Discretionary
C-03Mandatory / Discretionary

Next step: mandatory items go to the roadmap’s Now column with their deadline. Discretionary items go to WSJF scoring (Template 4). G4 items also flag the system for review in the TIME model (Template 2).

02

System landscape (TIME model)

Turn a messy system inventory into decisions. Each system is rated on business value and technical health, and that places it in one of four quadrants.

When Days 0–30. Revisit quarterly.

The quadrants

Low technical healthHigh technical health
High business valueMigrateValuable but fragile; replace or re-platformInvestStrategic; extend and improve
Low business valueEliminateRetire or consolidateTolerateKeep running, minimal spend

Scoring guide (1–5)

  • Business value: 1 = rarely used, easily replaced · 3 = supports a regular process · 5 = critical to compliance or reporting
  • Technical health: 1 = unsupported, undocumented, single owner · 3 = works but manual or brittle · 5 = supported, documented, integrated
  • Scores of 3 or more count as “high”.

What to look for in an area with no tech support

Spreadsheets and macros acting as systems, desktop tools, shared-drive workflows, vendor tools nobody owns, manual re-keying between systems, and key-person dependencies. These count as systems. Include them.

Inventory

IDSystem / toolType (vendor / in-house / spreadsheet / manual)Process supportedBusiness ownerUsersIntegrations / data flowsSupport statusKey-person risk (Y/N)Value (1–5)Health (1–5)TIMENotes
S-01
S-02
S-03

Next step: Invest and Migrate systems generate candidate work items for WSJF. Eliminate systems generate decommissioning items, which are often quick wins. Add a simple data-flow sketch of how the systems connect once the inventory is stable.

03

Project and initiative inventory

One list of every ongoing project and initiative, formal or informal, with its real status. Informal “someone is building a spreadsheet” work counts too.

When Days 0–30, built from stakeholder interviews.

Interview prompts for each stakeholder

  • What are you working on, or waiting for, that involves systems or data?
  • What problem does it solve, and what happens if it stops?
  • Who is funding or resourcing it today?
  • What’s blocking it?
  • What would you do next if you had a dev team?

Inventory

IDProject / initiativeSponsorFormal or informalProblem it solvesSystems affected (S-IDs)Status (idea / in progress / stalled / done)Resourcing todayBlockersData quality (H / M / L)Gate outcome (T1)
P-01
P-02
P-03

Look for: overlapping projects solving the same problem, stalled work that only needs a decision, and projects that depend on a Migrate or Eliminate system.

04

WSJF / Cost of Delay scoring

Rank discretionary work by what it costs to wait, divided by effort. It moves the stakeholder debate from “whose item” to “why now”.

When Days 30–60, scored jointly in a workshop. Re-score quarterly.

Formula

Cost of Delay (CoD) = Business value + Time criticality + Risk reduction

WSJF = CoD ÷ Effort

Scoring scales (1–5)

Factor135
Business valueMinor convenience for a few usersNoticeable time or cost saving for one teamMajor saving, accuracy gain or capability across the function
Time criticalityNo deadline; value holds if delayedValue drops over a quarter or twoTied to an annual cycle, legislative date or reporting deadline
Risk reductionNo change to riskReduces manual error or reworkRemoves a compliance, audit or key-person risk
Effort (job size)Days; config or small changeWeeks; one teamMonths; new build or multiple systems

Confidence rating (for mixed data)

  • High: backed by data (volumes, hours, error rates)
  • Medium: consistent stakeholder evidence, some data
  • Low: opinion or assumption only

Confidence is not multiplied into the score, because that hides uncertainty. Instead it decides what kind of work the item becomes:

High / Medium confidenceLow confidence
High WSJFDelivery candidateDiscovery spikeValidate first, then re-score
Low WSJFBacklogPark

Scoring sheet

IDItemLink (C / S / P / O-ID)ValueTime crit.Risk red.CoDEffortWSJFConfidenceEvidence / assumptionsRank
W-01
W-02
W-03

Worked example (illustrative)

ItemValueTime crit.Risk red.CoDEffortWSJFConfidence
Automate data extract feeding the annual report4541334.3Medium
Replace a macro-based reconciliation workbook3251025.0High
Self-service dashboard for the business311541.3Low

The reconciliation workbook ranks first despite lower value, because it’s cheap and removes a key risk. The dashboard is low-WSJF and low-confidence, so it gets parked.

05

Opportunity Solution Tree

Explore new ideas without jumping to solutions. Ideas are mapped to the outcome they serve and the problem (opportunity) behind them. Then problems are compared before solutions are.

When Days 30–60, alongside interviews. Keep it separate from the existing project list until ideas are ready to score.

Structure

OUTCOME (one measurable goal for the function)
├── Opportunity A (a user problem or need, in their words)
│   ├── Solution idea A1
│   │   └── Test / experiment
│   └── Solution idea A2
└── Opportunity B
    └── Solution idea B1
        └── Test / experiment

Example outcomes

  • Reduce manual effort in the reporting cycle
  • Improve accuracy and auditability of data
  • Shorten the time to answer business queries

Opportunity log

IDOutcomeOpportunity (problem, in stakeholder’s words)Who raised itEvidenceSolution ideasCheapest testReady for WSJF?
O-01Y / N
O-02Y / N
O-03Y / N

Rules

Frame opportunities as problems, not features (“we re-key data from X to Y every month”, not “we need an integration”). Aim for two or three solution ideas per opportunity. An idea moves to WSJF scoring once its opportunity has evidence.

06

Now / Next / Later roadmap

Show direction and sequence without committing to dates you can’t yet support. It suits a function with no dev team yet.

When Days 60–90. Review monthly; re-plan quarterly.

Column rules

  • Now (0–3 months): mandatory items from the Compliance gate, plus top-ranked, high-confidence WSJF items that fit current capacity (vendors, central IT, config changes).
  • Next (3–6 months): top-ranked items that depend on the proposed dev team, plus discovery spikes that have validated. Mark each one with its dependency.
  • Later (6+ months): strategic Invest and Migrate work, larger ideas from the Opportunity Solution Tree, and anything still low-confidence.

Roadmap

Theme / outcomeNowNextLater
Compliance and risk
Efficiency and automation
Data and reporting
System landscape (TIME actions)

For each roadmap item, record: ID · outcome · owner · dependency (e.g. “needs dev team”, “needs vendor”) · confidence · mandatory (Y/N).

Capacity note for the dev-team case

Total the effort of everything in Next that says “needs dev team”. That total, plus the risk of the items waiting, is the core of the business case.

07

Stakeholder scoring workshop

Score WSJF jointly, so competing stakeholders own the ranking rather than contest yours.

Before (1 week out)

  • Share the scoring scales and the pre-filled item list (Templates 3–5).
  • Ask each sponsor to bring evidence for their items: volumes, hours, error rates, deadlines.
  • Agree on a decision owner for tie-breaks, such as the head of the function.

Agenda (about 2 hours)

BlockWhat happens
Context 10 minThe 90-day goal and confirmation that mandatory items are already out of scope for debate.
Calibrate 15 minScore two reference items together so everyone reads the scales the same way.
Score one factor at a time 60 minScore all items on Value, then all on Time criticality, and so on. Scoring across rows, not down columns, reduces bias toward favourite items. Use silent scoring, then discuss big gaps.
Confidence check 15 minTag each item High / Medium / Low.
Review ranking 15 minSanity-check the top 10. Challenge surprises with evidence, not seniority.
Close 5 minConfirm next steps and when the ranking will be re-scored.

Pitfalls to avoid

MoSCoW on its ownEvery stakeholder marks their item a Must.
RICE“Reach” is weak for an internal function, and it needs data you don’t have yet.
Treating scores as preciseWSJF gives a sequence, not a truth. A 4.3 vs a 4.1 is a tie.
Scoring before the gateMandatory work skews the ranking if it’s left in.
One-off prioritisationRe-score quarterly and whenever a new regulatory change lands.