Michael Wollin yahoo@mercurysw.com [SCRUMDEVELOPMENT]
2015-12-07 19:04:50 UTC
In the conversations Iâve been having with my clientâs internal SOX compliance people, we have reached agreement that SOX can be handled partly in the acceptance criteria of the stories and partly with the Definition of Done. But we have hit a snag.
In their world, the User Acceptance Testing requirement can be met by the Product Owner, coming from the business, accepts the story as done. Alas, there may be a need to have a proxy product owner in some cases who is from the Information Management department and not the business. Not our first choice, but If this should be necessary, the SOX people donât feel the Proxy PO can do UAT and be compliant.
Looking for wisdom and for references to authoritative and/or insightful articles too.
Michael
In their world, the User Acceptance Testing requirement can be met by the Product Owner, coming from the business, accepts the story as done. Alas, there may be a need to have a proxy product owner in some cases who is from the Information Management department and not the business. Not our first choice, but If this should be necessary, the SOX people donât feel the Proxy PO can do UAT and be compliant.
Looking for wisdom and for references to authoritative and/or insightful articles too.
Michael