Valeo · security governance / February 2026

Status and risk do not belong in the same column

A task can be almost finished and still carry high risk, or remain open while representing little business exposure. Those two dimensions had to be modeled separately.

2 min read
Valeo · security governance
riskreportingprioritizationgovernance

Situation

Traditional project statuses easily imply that work close to completion is automatically less risky. Audit preparation does not behave that way. A control that is 90% complete may still be missing exactly the evidence an auditor needs, while a fully open administrative item may have very little material impact.

Approach

I separated execution status from risk classification in the reporting model. Risk was not inferred by reversing a completion percentage; it was evaluated from impact, evidence quality, deadline and dependency. That sometimes produced a priority order that looked very different from the project-task list.

Outcome

The team started addressing items that represented genuine audit risk earlier, even when they looked small on paper. Management discussions became clearer because one colour no longer had to describe both progress and exposure at the same time.