Skip to content

M1-01 Requirements Validation & Sign-off

Milestone: M1 — Detailed Planning and Team Onboarding SOW Reference: SOW §1.4, Appendix 1; Deliverable D1 Requirement Clarity: ⚠️ Blocking — several open items below must be answered before this task can close Dev Status: ⚪ Not a build item — documentation/sign-off task

Overview

Produce the Requirements Validation Output (D1): a reviewed, internally-consistent version of the SOW's Appendix 1 Requirements Specification, with all clarifications and delivery assumptions recorded in writing. This is the formal gate before design work starts on M2/M3.

Tasks

  • Walk through SOW Appendix 1 (FR1–FR8, NFR1–NFR6, OR1–OR3, INT1–INT8) line by line with Curo
  • Resolve and record answers to the open items list (see below)
  • Produce the marked-up requirements document + approval note (Word/PDF, per Appendix 2 Deliverable format)
  • Get Curo's Technical and Acceptance Lead (Annie Andrews per Appendix 4) to review and approve

Open items to resolve as part of this task

  1. Reclaim Protocol (FR4) scope & pricing — new requirement vs. the original v3 doc; confirm client sign-off status (see ../M7/M7-01-reclaim-protocol-scope-confirmation.md).
  2. FR2 disclosure-policy configuration depth — full config vs. default-only for MVP (see ../M5/M5-02-disclosure-policy-configuration.md).
  3. Credits/vouchers mechanism (NFR5) — the original credit-pool/treasury/voucher mechanism isn't respecified in the SOW (see ../M5/M5-11-credits-vouchers-mechanism.md).
  4. General payment/invoicing capability (NFR5) — distinct from item 3; confirm whether manual invoicing is acceptable for MVP or in-platform payment processing is expected now (see ../M5/M5-14-general-payment-invoicing-capability.md).
  5. M10 go-live vs. Final Acceptance definition (see ../M10/M10-01-production-deployment-go-live-readiness.md).
  6. AWS hosting target for the deploy pipeline (see ../M4/M4-01-v01-beta-release-package-deployment.md).
  7. Minor dropped specifics — passkey support, SMS gateway, Zendesk-specific help tooling, backup retention/geo-distribution detail, standalone DDoS status: confirm each is deliberately descoped or still required.
  8. KYB MVP-vs-Beta phasing — SOW text implies the in-platform KYB web form may only be required by "full Beta release," not MVP (see ../M2/M2-01-organisation-kyb-onboarding-flow.md).
  9. Regulatory compliance scope — UKDIATF, CCPA, SOC2, and UK staffing data-retention rules are each named once in NFR3 with no further specification of expected activity (see ../M9/M9-13-regulatory-industry-compliance.md).
  10. SAML 2.0 requirement — listed as a supported standard in Appendix 6 but not otherwise referenced; confirm it's actually needed for MVP (see ../M9/M9-12-saml2-tls13-protocol-support.md).
  11. D5e (M9) release packaging — unlike M4/M6/M8, M9 has no defined beta version number for its own deployment package; confirm whether it ships inside M10 or needs its own release step.
  12. SOW-internal D7/D8 numbering inconsistency — Appendix 3 references a "D8" deliverable that Appendix 2's Deliverables table never defines (see ../M10/M10-04-source-code-repository-handover.md).

Dependencies

  • Curo/Annie Andrews availability for review (Appendix 4 — Technical and Acceptance Lead).
  • Appendix 5 assumptions A1–A12 being reasonably stable at sign-off time.

Acceptance Criteria

  • Requirements clarified, agreed and internally consistent (per Appendix 3 "D1" row)
  • Marked-up requirements + approval note delivered
  • All 12 open items above have a written answer, not just verbal agreement

Existing Reference Material

Blockers & Risks

  • Risk: if this task is rushed or treated as a formality, the ambiguities carry silently into M5/M7/M10 where they cost far more to unwind.