P4.14.2Binding ethics review to veto-capable gatesdesign

Assessment must bind to gates with veto power

Aliases: gate authority · advisory versus binding review · binding point of assessment

What it is

Ethics assessment exists in two forms: advisory — it produces opinions for reference, which decision-makers may heed or ignore; and binding — it attaches to a hard gate in the process, and the event cannot happen without passing. The difference lies not in assessment content but in the binding point: where the assessment hangs, and whether passing it blocks subsequent actions. An assessment attached at the wrong place (conclusions silently ignorable, multiple skippable steps between review and release) is advisory in substance no matter how professional its method, while the organization displays "we have ethics review" outward. An assessment's effective power equals the authority of its binding gate; the assessment's content only governs the quality of that power once exercised.

Why it happens

Binding force comes from the node's position in the flow, not from the review opinion itself. The nodes with real teeth are resource-class switches: merging into mainline, data-access authorization, the release train, the deployment flag flip — these actions are machine-enforced, and skipping them is operationally impossible. To gain binding force, an assessment must attach to one of these switches so that "assessment incomplete" blocks the action at the tooling layer. An assessment living only at the document layer (a wiki page, a weekly report) lacks this property: ignoring it costs nothing while schedule pressure is permanent, so ignoring becomes the rational default. A second mechanism is timing mismatch: if assessment binds after release (review to be filled in post-launch), the object of constraint no longer exists — the decision has taken effect, and review can only ratify it retrospectively. That is exactly why ratification-style review is popular: it satisfies the compliance appearance while leaving the organization fully free.

Where it stops holding

Veto power must not be overused: giving every assessment node one-strike veto gridlocks the process, reviewers end up endorsing every small change, and eventually the organization routes around the process entirely. Healthy binding is tiered veto — low-risk changes pass a fast lane with a record; high-risk ones (new data uses, new populations, harm-sensitive features) trigger strong veto; the tiering criteria themselves stay public and stable, else tiering becomes the new bypass. One real constraint: veto gates cost too much for small teams and early products — the honest move there is to shrink the form (one person, one checklist) while keeping the binding property, rather than keeping the form and hollowing out the binding.

Applying it

  • Inventory the process's genuinely machine-enforced points (merge, authorization, release switches), pick one as the ethics assessment's binding target so that "assessment failed" blocks the action at the toolchain level rather than relying on someone remembering to check the review conclusion.
  • Establish risk-tiered routing: changes route by population impact; low risk passes automatically with a record, high risk enters strong review; tiering criteria are public and versioned, and changing them is itself a high-risk change.
  • Forbid ratification mode: any "launch first, review later" path must go through explicit waiver, with named approval and automatic entry into the next quarterly re-review list.
  • Verify: track the gate's actual block rate and bypass rate — a permanently zero block rate means the assessment only ever says yes (bound but toothless judgment); a high bypass rate means the binding is loose (a skip channel exists); both call for re-siting the binding point.

Related

  • Same group: P4.14.1 Process's job is to surface questions, not to settle them · P4.14.3 Checklists degrade judgment into ticking
  • Adjacent: P4.07.2 Execution under metric pressure is no exemption · P4.14.4 Written traces of decision processes
  • Search terms: binding review · release gate · advisory versus binding

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/P4.14.2