What Happens to the No? The Not-So-Silent Veto
·1722 words·9 mins
Most organizations have a risk acceptance process on paper. What they actually have is hallway conversations and comment threads that vanish when projects close. When something breaks, everyone reconstructs who knew what from memory, under pressure, with lawyers involved. Aviation solved this problem decades ago with the MEL. The framework forces explicit conditions, named owners, and real expiry dates. Security work has similar machinery. We just let it collect dust while risks drift between teams unowned.