Master Cheatsheet: BA Work Breakdown Structure đến mức task/subtask
Mục đích: biến vòng đời dự án thành danh sách công việc có thể giao, làm, kiểm tra và truy vết. Đây không phải danh sách “tên tài liệu”; mỗi dòng là một task hoặc subtask tạo ra evidence cụ thể.
Quy ước
- Pack: nhóm output theo workstream.
- Artifact: tài liệu/sơ đồ/file có version và owner.
- Task: công việc có thể giao cho một người.
- Evidence of Done: bằng chứng để xác nhận task hoàn thành.
R= Required cho hầu hết dự án;C= Conditional, chỉ làm khi bối cảnh/rủi ro yêu cầu.
Không làm mọi artifact cho mọi dự án. Chọn theo risk, số actor, độ phức tạp quy trình, dữ liệu, tích hợp, compliance và mô hình vendor.
S0. Framing — tiếp nhận và định hình sáng kiến
S0.1 Opportunity intake pack
- [ ]
RThu yêu cầu gốc, email/ticket/tờ trình và xác định người yêu cầu. - [ ]
RViết problem statement: actor, hành vi hiện tại, trở ngại, tác động, outcome mong muốn. - [ ]
RTách fact, assumption, constraint và solution idea thành bốn danh sách riêng. - [ ]
RGhi scope khám phá ban đầu: process, đơn vị, user group, system, geography, thời gian. - [ ]
RTạo open-question log; mỗi câu có owner trả lời và due date. - [ ]
RTạo decision log; ghi quyết định, options, rationale, authority, ngày hiệu lực. - [ ]
CTạo RFA/tờ trình xin chủ trương khám phá.
Evidence of Done: opportunity brief có owner, scope khám phá, assumption và quyết định tiếp tục/dừng.
S0.2 Stakeholder & governance pack
- [ ] Liệt kê stakeholder theo vai trò, không chỉ tên cá nhân.
- [ ] Gán Business Owner, Process Owner, Product Owner, Data Owner, Technical Owner, QA/UAT Owner, Operations và specialist owner.
- [ ] Xác định quyền
decide / approve / advise / execute / informedcho từng nhóm quyết định. - [ ] Lập stakeholder matrix power–interest và engagement cadence.
- [ ] Lập escalation path cho scope, rule, architecture, security, data, legal/finance và release.
- [ ] Xác nhận kênh giao tiếp, repository chính thức và quy ước version/baseline.
S0.3 Business-case pack
- [ ]
CThu baseline cost, volume, cycle time, defect/loss hoặc revenue hiện tại. - [ ]
CXác định benefit hữu hình/vô hình và owner đo benefit. - [ ]
CƯớc tính CAPEX, OPEX, recurring license, implementation, migration, training, support và exit cost. - [ ]
CTính ROI/payback/NPV theo phương pháp tổ chức đang dùng. - [ ]
CLập sensitivity table cho volume, adoption, cost và timeline. - [ ]
CGhi assumptions và confidence; không trình point estimate như fact. - [ ]
CChuẩn bị RFA xin ngân sách/nguồn lực.
S1. Discovery — thu evidence và hiểu trạng thái hiện tại
S1.1 Research execution pack
- [ ] Viết research objective và decision cần được hỗ trợ.
- [ ] Chọn participant theo role, segment, permission và exception experience.
- [ ] Soạn interview/observation guide; tránh câu hỏi dẫn dắt.
- [ ] Lên lịch, consent và quy tắc xử lý dữ liệu nhạy cảm.
- [ ] Thực hiện interview/observation; lưu note và source reference.
- [ ] Mã hóa pain, behavior, workaround, need, constraint và quote evidence.
- [ ] Nhóm pattern; tách insight phổ biến khỏi trường hợp đơn lẻ.
- [ ] Ghi contradiction và evidence còn thiếu.
- [ ] Viết research findings và confidence/limitation.
S1.2 As-Is process pack
- [ ] Xác định start/end event và trigger.
- [ ] Liệt kê actor/swimlane và handoff.
- [ ] Ghi từng activity, input, output, system/tool và business rule.
- [ ] Vẽ gateway/decision criteria; tránh nhãn “xử lý” mơ hồ.
- [ ] Vẽ happy path, alternative path, exception, retry và escalation.
- [ ] Gắn cycle time, wait time, volume, rework hoặc pain evidence nếu có.
- [ ] Đánh dấu manual step, duplicate entry và control point.
- [ ] Playback với Process Owner và người thực hiện.
- [ ] Sửa flow, lưu source BPMN/Mermaid và export SVG/PDF.
S1.3 User experience pack
- [ ] Xác định persona/proto-persona hoặc behavioral segment cần phân biệt.
- [ ] Lập journey stages và mục tiêu người dùng tại mỗi stage.
- [ ] Ghi touchpoint, action, question, pain, emotion và opportunity.
- [ ] Chọn một user goal và vẽ task/user flow hiện tại.
- [ ] Ghi entry point, precondition, screen/action, decision, error, exit và completion state.
- [ ] Kiểm tra permission khác nhau có tạo flow khác không.
- [ ] Kiểm tra cross-channel/handoff sang người hoặc hệ thống khác.
- [ ] Xác nhận journey/user flow bằng research evidence.
S1.4 Current data & system inventory
- [ ] Liệt kê system, owner, purpose, environment và lifecycle status.
- [ ] Liệt kê interface hiện tại: source, destination, protocol, frequency, volume, owner.
- [ ] Liệt kê report/file/manual spreadsheet đang được dùng.
- [ ] Thu sample dữ liệu đã ẩn thông tin nhạy cảm.
- [ ] Xác định source of truth theo business object.
- [ ] Ghi data quality issue: missing, duplicate, invalid, stale, inconsistent.
- [ ] Ghi access, retention, privacy và compliance constraint.
S1.5 Market/vendor scan
- [ ]
CChọn competitor/vendor và tiêu chí benchmark trước khi xem kết quả. - [ ]
CThu evidence feature, UX flow, pricing/model, integration và limitation. - [ ]
CLập feature/capability matrix và note “unknown/not verified”. - [ ]
CViết Make-vs-Buy options: build, buy, configure, outsource. - [ ]
CSo sánh TCO, time-to-value, fit, lock-in, security, integration, operations và exit. - [ ]
CSoạn/phát hành RFI và tổng hợp response.
S2. Definition — scope, requirement và acceptance
S2.1 Scope & outcome pack
- [ ] Chốt outcome metric, baseline, target, data source, cadence và owner.
- [ ] Liệt kê scope in, scope out, dependency và deferred item.
- [ ] Vẽ product/process boundary và system boundary.
- [ ] Lập capability map hoặc feature map.
- [ ] Tạo MVP/phase boundary; ghi rationale và consequence nếu hoãn.
- [ ] Lập prioritization matrix và lưu authority quyết định.
S2.2 Requirement pack
- [ ] Tạo requirement ID và source/evidence link.
- [ ] Viết business requirement gắn outcome.
- [ ] Viết stakeholder/user requirement gắn actor và goal.
- [ ] Viết functional requirement gắn trigger, input, rule, behavior, output.
- [ ] Viết non-functional requirement có metric, condition và measurement method.
- [ ] Ghi assumption, dependency, constraint và out-of-scope gần requirement liên quan.
- [ ] Review ambiguity, conflict, feasibility và testability.
- [ ] Baseline/version requirement set sau approval.
S2.3 Story & acceptance pack
- [ ] Tạo story map: activity → task → story.
- [ ] Chia release slice theo end-to-end value, không theo technical layer.
- [ ] Viết user story hoặc use case theo bối cảnh dự án.
- [ ] Ghi precondition, trigger, main flow, alternative, exception và postcondition.
- [ ] Viết acceptance criteria Given–When–Then.
- [ ] Thêm edge cases: empty, boundary, invalid, duplicate, concurrent, timeout, cancellation.
- [ ] Thêm permission/role case và audit requirement.
- [ ] Link story/use case tới rule, wireframe, API/data, NFR và test.
S2.4 Business-rule pack
- [ ] Tạo rule ID, rule statement, source, owner và effective date.
- [ ] Ghi condition, action/outcome, exception và priority khi rules conflict.
- [ ] Tạo decision table cho nhiều điều kiện.
- [ ] Tạo state-transition table/diagram cho object có lifecycle.
- [ ] Ghi formula, rounding, currency/timezone và sample calculation.
- [ ] Xác định rule cấu hình được hay hard-coded.
- [ ] Review rule với Business Owner và specialist owner.
S2.5 Procurement definition pack
- [ ]
CĐóng gói scope, process, rules, requirement, NFR và acceptance thành RFP. - [ ]
CĐịnh nghĩa mandatory, scored và informational criteria. - [ ]
CĐịnh nghĩa response format để so sánh vendor nhất quán. - [ ]
CTạo clarification log và quy tắc phát hành amendment.
S3. Solution design — UX, process, data, API và controls
S3.1 To-Be process pack
- [ ] Xác định trigger, target outcome và process owner.
- [ ] Vẽ future-state actor/swimlane, task, event và gateway.
- [ ] Ghi system/manual activity và handoff artifact.
- [ ] Thêm exception, retry, compensation, cancellation và escalation.
- [ ] Gắn business rule ID và control/evidence point.
- [ ] So sánh As-Is/To-Be và ghi impact tới role, SOP, data, system.
- [ ] Review feasibility với architecture, QA, Operations và owner.
S3.2 User flow & wireframe pack
- [ ] Chọn user goal/task cần thiết kế.
- [ ] Vẽ user flow: entry → action/screen → decision → completion/exit.
- [ ] Thêm alternative, back, cancel, timeout, permission denied và recovery.
- [ ] Tạo screen inventory và screen ID.
- [ ] Tạo wireframe cho từng màn hình/trạng thái trọng yếu.
- [ ] Gắn field, action, navigation, visibility và enable/disable rule.
- [ ] Thiết kế empty/loading/error/success/partial state.
- [ ] Ghi validation message, confirmation và destructive-action safeguard.
- [ ] Gắn accessibility note: keyboard, focus, label, contrast, error announcement.
- [ ] Tạo clickable prototype nếu cần kiểm chứng interaction.
- [ ] Playback prototype với user/Business Owner; ghi decision và change.
- [ ] Link screen/flow tới story, rule, API và analytics event.
S3.3 Data-model pack
- [ ] Liệt kê business objects và canonical term.
- [ ] Vẽ conceptual ERD: entity và relationship chính.
- [ ] Vẽ logical ERD: attribute, PK, candidate key, FK, cardinality, optionality.
- [ ] Ghi unique/check/reference constraint và lifecycle/state.
- [ ] Xác định master/reference/transaction/history/audit data.
- [ ] Tạo data dictionary: field, definition, type, length/precision, format, nullable, default.
- [ ] Ghi validation rule, error message, classification, owner, source of truth.
- [ ] Tạo CRUD matrix theo role/process/system.
- [ ] Tạo data lineage source → transform → destination/report.
- [ ] Review PII/sensitive data, masking, retention và deletion.
- [ ] Tạo sample records và boundary/invalid examples.
- [ ] Link entity/field tới requirement, API, report và test.
S3.4 Reporting & analytics pack
- [ ] Xác định user, decision và cadence của report/dashboard.
- [ ] Định nghĩa metric/formula, grain, dimension, filter và timezone.
- [ ] Xác định source, freshness, late-arriving data và reconciliation.
- [ ] Tạo report wireframe và drill-down/export behavior.
- [ ] Định nghĩa access/row-level security.
- [ ] Tạo sample calculation và expected output.
- [ ] Định nghĩa analytics events: name, trigger, properties, identity, consent.
S3.5 Integration inventory pack
- [ ] Tạo interface ID và owner.
- [ ] Ghi source, destination, direction, protocol, sync/async, trigger/frequency.
- [ ] Ghi data classification, volume, peak, latency và availability dependency.
- [ ] Ghi authentication/authorization, certificate/key rotation owner.
- [ ] Ghi retry, timeout, idempotency, duplicate handling và dead-letter/replay.
- [ ] Ghi monitoring, alert, support owner và SLA/OLA.
- [ ] Vẽ system context, component/integration và sequence diagram.
S3.6 API contract & documentation pack
- [ ] Xác định API consumer/provider và business capability.
- [ ] Chọn endpoint, method, path và versioning convention.
- [ ] Ghi base URL/environment và authentication scheme.
- [ ] Ghi headers, path/query parameters và validation.
- [ ] Định nghĩa request/response schema, required/optional, enum, format và example.
- [ ] Định nghĩa success status code và error status/code/message/details/correlation ID.
- [ ] Ghi pagination, sorting, filtering và limit.
- [ ] Ghi idempotency behavior, timeout, retry và rate limit.
- [ ] Ghi concurrency/version control nếu update dữ liệu.
- [ ] Tạo OpenAPI/Swagger file.
- [ ] Tạo Postman/Bruno collection và environment variables không chứa secret thật.
- [ ] Tạo API field-mapping matrix source → transform/default → destination.
- [ ] Tạo API error matrix: condition → HTTP/business code → consumer action → owner.
- [ ] Tạo sequence diagram cho happy path, auth failure, validation failure và timeout/retry.
- [ ] Review contract với provider, consumer, security, QA và Operations.
S3.7 API test design & execution pack
- [ ] Chuẩn bị environment URL, test account/role, token/certificate và test data.
- [ ] Kiểm tra DNS/TLS/auth connectivity; không lưu secret trong collection/report.
- [ ] Test happy path với minimum và representative payload.
- [ ] Test required field missing, null, empty, invalid type/format/enum.
- [ ] Test min/max length, numeric/date boundary, timezone và encoding.
- [ ] Test unknown field/additional property theo contract.
- [ ] Test authentication: missing, invalid, expired/revoked credential.
- [ ] Test authorization theo role/tenant/object ownership.
- [ ] Test object not found, conflict và invalid state transition.
- [ ] Test duplicate request và idempotency key.
- [ ] Test pagination, filter, sort, default/max page size.
- [ ] Test rate limit và consumer behavior khi nhận
429. - [ ] Test timeout, retry/backoff, circuit behavior và late response.
- [ ] Test concurrent update/version conflict nếu áp dụng.
- [ ] Test schema/contract bằng OpenAPI validator.
- [ ] Verify database/event/downstream side effect; kiểm tra không ghi dữ liệu khi request fail.
- [ ] Verify audit log, correlation ID, tracing và masking dữ liệu nhạy cảm.
- [ ] Verify error response không lộ stack trace/secret/internal topology.
- [ ] Lưu request/response đã mask, timestamp, environment, build/version và result.
- [ ] Tạo defect với reproduction, expected/actual, evidence, severity và affected requirement.
- [ ] Retest fix và chạy regression collection.
- [ ] Cập nhật API docs, RTM và test summary sau thay đổi contract.
S3.8 Event/webhook/batch pack
- [ ] Định nghĩa event name, producer, consumer, trigger và schema/version.
- [ ] Ghi ordering, duplication, delivery guarantee và replay policy.
- [ ] Ghi correlation/business key và PII classification.
- [ ] Test duplicate, out-of-order, missing, poison message và consumer downtime.
- [ ] Với webhook: signature validation, replay protection, retry schedule và endpoint ownership.
- [ ] Với batch/file: naming, encoding, delimiter, header/trailer, control total, schedule và rerun.
- [ ] Tạo reconciliation report source count/value → accepted → rejected → target.
S3.9 Security, access & audit pack
- [ ] Tạo actor/role-permission matrix theo action và data scope.
- [ ] Kiểm tra least privilege và segregation of duties.
- [ ] Định nghĩa approval/delegation và emergency/break-glass access.
- [ ] Ghi session, MFA, password/token/certificate requirement.
- [ ] Ghi encryption in transit/at rest và key owner.
- [ ] Định nghĩa audit event, actor, timestamp, before/after, correlation và retention.
- [ ] Threat/abuse-case review cho high-risk flow/API.
- [ ] Link security requirement tới test và specialist sign-off.
S3.10 NFR & operability pack
- [ ] Performance: response time percentile, throughput, dataset/load condition.
- [ ] Availability: service window, SLO/SLA, maintenance và dependency.
- [ ] Resilience: timeout, retry, failover, degraded mode, recovery evidence.
- [ ] RTO/RPO và backup/restore test requirement.
- [ ] Scalability/capacity assumption và alert threshold.
- [ ] Observability: log, metric, trace, dashboard, alert, owner/runbook.
- [ ] Accessibility/usability/localization/browser-device compatibility.
- [ ] Privacy/retention/deletion/export requirement.
- [ ] Support model, incident priority và escalation.
S3.11 Vendor solution pack
- [ ] Phát hành RFQ và thu báo giá bóc tách.
- [ ] Chấm business, technical, security, delivery, cost và reference evidence.
- [ ] Thực hiện scripted demo/use-case, không chỉ vendor-led demo.
- [ ] Ghi gap: standard fit, configure, customize, workaround, out-of-scope.
- [ ] Kiểm tra license metric, environment, support, upgrade và exit/data extract.
- [ ] Soạn SOW: deliverable, milestone, acceptance, dependency, assumption, change control.
- [ ] Soạn SLA annex và service-credit/escalation nếu áp dụng.
- [ ] Chuẩn bị recommendation/RFA chọn vendor và exception/risk acceptance.
S4. Delivery readiness — chuẩn bị backlog, test và môi trường
S4.1 Backlog refinement pack
- [ ] Chia epic/feature thành story end-to-end có thể demo/test.
- [ ] Gắn priority, value, estimate, dependency và target release.
- [ ] Kiểm tra story có actor, behavior, rule, AC và edge case.
- [ ] Gắn wireframe/user flow, API/data, NFR và analytics.
- [ ] Tạo spike cho unknown kỹ thuật có output/decision rõ.
- [ ] Kiểm tra DoR và ghi lý do nếu exception.
S4.2 Traceability pack
- [ ] Link objective/outcome → business requirement.
- [ ] Link requirement → process/use case/story/rule.
- [ ] Link story → UX/API/data/NFR artifact.
- [ ] Link requirement/story → test case/UAT scenario.
- [ ] Link defect/change → affected requirement/test/release.
- [ ] Kiểm tra orphan requirement và untraced test.
S4.3 Test-readiness pack
- [ ] Chốt test scope, level, responsibility và entry/exit criteria.
- [ ] Chuẩn bị test case matrix cho UI, rule, data, API, integration, permission và NFR.
- [ ] Chuẩn bị synthetic/masked test data và cleanup/reset procedure.
- [ ] Xác nhận environment, build/version, endpoint, stub/mock và dependency availability.
- [ ] Xác nhận logging/access để thu evidence và debug.
- [ ] Định nghĩa defect severity, priority, workflow và disposition authority.
S4.4 Enablement & change pack
- [ ] Lập impacted-role/process/system matrix.
- [ ] Xác định training need, trainer, audience, format và completion evidence.
- [ ] Lập communication plan: message, audience, sender, channel, timing.
- [ ] Xác định SOP/runbook owner và deadline.
- [ ] Lập adoption/support readiness checklist.
S5. Build & Verify — hỗ trợ delivery và chứng minh đáp ứng
S5.1 Build support
- [ ] Trả lời clarification và ghi câu trả lời vào artifact chính thức.
- [ ] Phân tích impact khi dev phát hiện constraint/gap.
- [ ] Cập nhật rule/AC/wireframe/API/data spec có version.
- [ ] Ghi decision và người có thẩm quyền; tránh quyết định chỉ nằm trong chat.
- [ ] Thực hiện story playback/demo và ghi discrepancy.
S5.2 Functional verification
- [ ] Test happy path theo acceptance criteria.
- [ ] Test alternative/exception/permission/boundary.
- [ ] Test business rule/decision table/state transition.
- [ ] Test wireframe behavior, validation, navigation và UI states.
- [ ] Test report calculation/filter/export/access.
- [ ] Test data persistence, relationship, audit và downstream effect.
- [ ] Thực hiện API/integration test pack ở S3.7.
- [ ] Ghi evidence theo build/environment/test data.
S5.3 Defect & change control
- [ ] Reproduce và phân loại defect vs requirement gap vs CR/out-of-scope.
- [ ] Ghi severity, business impact, evidence, owner và target fix.
- [ ] Triage disposition: fix, defer với risk acceptance, reject, duplicate.
- [ ] Retest và cập nhật result/build.
- [ ] Xác định regression scope và chạy/ghi evidence.
- [ ] Với CR: mô tả change, reason, impact scope/time/cost/risk và approval.
- [ ] Cập nhật baseline, RTM, backlog và release plan sau CR được duyệt.
S5.4 UAT pack
- [ ] Xác định UAT objective, scope, participant và UAT Owner.
- [ ] Chọn scenario theo business process, role, risk và exception.
- [ ] Chuẩn bị account/permission, data, environment và build.
- [ ] Viết script/scenario với precondition, steps, expected và evidence.
- [ ] Brief user, support channel và escalation.
- [ ] Theo dõi execution, blocker, defect và retest.
- [ ] Tổng hợp coverage, pass/fail, open defect và accepted risk.
- [ ] Lấy sign-off hoặc documented no-go có authority.
S6. Release & Transition — migration, cutover và vận hành
S6.1 Data migration pack
- [ ] Inventory source table/file/report và owner.
- [ ] Lập source-to-target field mapping.
- [ ] Ghi transform, lookup, default, cleansing và rejection rule.
- [ ] Xác định extraction/freeze/delta strategy.
- [ ] Chuẩn bị migration test data và rehearsal.
- [ ] Chạy trial migration; ghi duration, error, reject và performance.
- [ ] Reconcile record count, control total, sample và critical balance.
- [ ] Ghi exception owner và remediation.
- [ ] Lấy Data/Business Owner sign-off.
S6.2 Cutover & rollback pack
- [ ] Lập timeline task-by-task với start/end, owner, dependency và evidence.
- [ ] Xác định communication, command centre và contact/escalation.
- [ ] Xác định data freeze, deployment, migration, configuration và access task.
- [ ] Viết sanity/smoke test sau triển khai.
- [ ] Định nghĩa go/no-go criteria và decision authority.
- [ ] Định nghĩa rollback trigger, deadline, owner và steps.
- [ ] Kiểm tra backup/restore và business continuity workaround.
- [ ] Rehearse cutover/rollback cho high-risk release.
S6.3 Operational handover pack
- [ ] Viết SOP/user guide theo role và business scenario.
- [ ] Viết runbook cho monitoring, incident, manual recovery và escalation.
- [ ] Ghi known issue, workaround, limitation và open risk.
- [ ] Chuyển giao dashboard/alert/log access và support contact.
- [ ] Xác nhận support hours, SLA/OLA và vendor escalation.
- [ ] Tổ chức training; lưu attendance/completion/evidence.
- [ ] Chuẩn bị release note nội bộ/ngoài và FAQ.
- [ ] Lấy operational readiness/handover sign-off.
S6.4 Release approval pack
- [ ] Tổng hợp build, test, UAT, regression, security/NFR và migration evidence.
- [ ] Liệt kê open defect/risk, disposition, owner và expiry/review date.
- [ ] Xác nhận rollback, monitoring, support và communication ready.
- [ ] Ghi go/no-go decision, authority, condition và timestamp.
- [ ]
CChuẩn bị RFA nghiệm thu/chuyển giao/milestone payment.
S7. Operate & Learn — đo outcome, sửa hệ thống và đóng vòng đầu tư
S7.1 Post-launch monitoring
- [ ] Xác nhận dashboard/alert hoạt động và owner nhận cảnh báo.
- [ ] Theo dõi adoption, task completion, error, latency, support volume và business KPI.
- [ ] So sánh baseline/target và phân đoạn theo role/channel nếu cần.
- [ ] Thu feedback và link tới journey/task/requirement liên quan.
- [ ] Phân loại defect, usability issue, training gap, process gap và enhancement.
S7.2 Incident & problem analysis
- [ ] Ghi incident timeline, impact, affected user/data/process và mitigation.
- [ ] Thu log/trace/evidence; giữ correlation và version.
- [ ] Phân tích contributing factor/root cause, không dừng ở “human error”.
- [ ] Tạo corrective/preventive action với owner/due date.
- [ ] Cập nhật requirement, test, runbook, monitoring và training.
S7.3 PIR & benefit realization
- [ ] So sánh KPI/ROI/cost/timeline thực tế với business case.
- [ ] Giải thích variance bằng evidence và assumption sai/đúng.
- [ ] Đánh giá adoption, operation, vendor/SLA và risk còn lại.
- [ ] Ghi lesson learned và action có owner.
- [ ] Quyết định scale, iterate, hold, remediate, retire hoặc stop investment.
S7.4 Enhancement & retirement
- [ ] Tạo enhancement backlog gắn outcome/evidence.
- [ ] Re-prioritize và đưa item qua lifecycle phù hợp.
- [ ] Với retire: impact assessment, dependency/consumer inventory và data retention/export.
- [ ] Lập migration/communication/support/end-date và rollback/contingency.
- [ ] Thu hồi access/integration/secret, archive artifact và cập nhật system catalog.
X. Cross-cutting BA controls — duy trì suốt dự án
- [ ] RAID log: risk, assumption, issue, dependency; owner, due, status, impact.
- [ ] Decision log: options, criteria, decision, authority, consequence.
- [ ] Open-question/clarification log.
- [ ] Glossary và canonical term.
- [ ] Artifact register: ID, title, version, status, owner, approver, link.
- [ ] Change history và baseline register.
- [ ] Evidence/source register và confidence.
- [ ] Traceability matrix và orphan check.
- [ ] Approval/sign-off register.
- [ ] Meeting/action log chỉ giữ action/decision cần truy vết; không thay artifact chuẩn.
Definition of Done cho một BA task nhỏ
Một subtask chỉ được coi là done khi:
- [ ] Có output/evidence cụ thể và link được mở.
- [ ] Actor, scope, environment/build hoặc data context rõ.
- [ ] Fact/assumption/decision được phân biệt.
- [ ] Owner và reviewer/approver đúng thẩm quyền.
- [ ] Feedback đã resolve hoặc được ghi disposition.
- [ ] Artifact liên quan và RTM được cập nhật.
- [ ] Không chứa secret hoặc dữ liệu nhạy cảm chưa được xử lý.
- [ ] Version/status/ngày cập nhật rõ.