Create your own
Lesson illustration

Phase 0 Screening: Classifying Ideas for Commitment, Continuation, or Stop

Hello, and welcome to the first lesson in the Product Factory process.

This module establishes the discipline that makes the rest of the factory credible: before interviewing customers, estimating a market, or building a prototype, determine whether an idea may be investigated at all, whether it carries a prior commitment, and whether its risks require the most rigorous lane. Phase 0 is deliberately short—two hours for a Lane M run—but it can prevent expensive work on an inadmissible or improperly framed idea.

By the end of this lesson, you will be able to run the Phase 0 screen and classify an idea as STOP, COMMITTED, or eligible to continue. You will also know when an idea must be routed to Lane L because of regulatory, data, safety, or harm-related risk.


Phase 0 is a screen, not a miniature discovery project

A common mistake is to treat every incoming idea as a question of customer demand: Will people buy it? Phase 0 asks more basic questions first:

  1. Is there a legal or regulatory condition that changes how this idea must be handled?
  2. Who could be worse off if the idea works exactly as intended?
  3. Has anyone already committed the organisation to deliver it?
  4. Have the accountable people been named?

This is not yet a detailed compliance assessment, a full safety case, or a data-protection impact assessment. It is an intake decision. The goal is to identify material constraints before the team becomes attached to a solution.

A useful distinction is:

TermMeaning at Phase 0What it does not mean
Regulatory triggerA feature of the idea that requires heightened attention or a more rigorous processThat the idea is automatically illegal
Lane L routingThe idea must use the programme-level path, including a risk registerThat it has passed legal review
STOPThe run cannot continue in its current formThat the underlying problem can never be revisited
COMMITTEDA customer, contract, or internal promise has already created an obligationThat validation and quality gates may be ignored
Eligible to continueThe idea may move to Phase 1 investigationThat it is desirable, feasible, or worth building

Phase 0 therefore produces a decision about admissibility and handling, not a verdict on the business opportunity.


The legal and regulatory screen: identify triggers early

Start with a plain description of what the proposed product would actually do. Avoid solution detail, but be concrete enough to reveal exposure:

  • Who would use it?
  • Whose information would it process?
  • What decisions, recommendations, or actions would it influence?
  • Could it affect access to employment, credit, housing, healthcare, education, insurance, public services, or other meaningful opportunities?
  • Would it handle health, financial, biometric, genetic, criminal-offence, or children’s data?
  • Would it monitor people, infer behaviour, combine datasets, or make automated decisions?
  • Which jurisdictions, licences, contracts, and sector rules apply?

The Product Factory rule is intentionally conservative: an idea touching regulated data, safety-critical decisions, or a licence the organisation does not hold is routed to Lane L before further work. That routing is not a bureaucratic penalty. It recognises that the decision has a different failure profile and cannot responsibly be treated as a small feature experiment.

For ideas operating under UK data-protection law, the UK Information Commissioner’s Office provides an instructive example. A data protection impact assessment (DPIA) is required before processing likely to create a high risk to people. Its triggers include significant automated decision-making, large-scale special-category data, systematic monitoring, children’s data, biometric data, location tracking, and combining datasets. Those are precisely the kinds of facts Phase 0 should surface.

Data protection impact assessments | ICO

Read the UK Information Commissioner’s Office guidance to see why a privacy and regulatory screen belongs at the beginning of an idea lifecycle rather than after a product design is underway.

In the section “When do we need a DPIA?”, begin with the rationale for screening before processing begins. Notice the distinction between identifying indicators of high risk and assessing the final level of risk. Then move to “DPIA screening checklist.” Read the screening factors. Treat this as a set of intake prompts, not as a substitute for legal advice or the DPIA itself. The ICO guidance is UK-specific; equivalent obligations may differ in other jurisdictions.

At this stage, record the trigger and its source, rather than pretending the uncertainty has been resolved. For example:

The proposed tool ranks job applicants using CV and assessment data. It may influence access to employment and involves automated scoring. [assumption]
Applicable employment, data-protection, and automated-decision requirements have not yet been assessed. [assumption]
Classification: Lane L required.

This record is more useful than saying “the product is compliant” without evidence. The latter is an unsupported conclusion; the former accurately states what is known and what must be examined.

A regulatory trigger produces one of two outcomes:

  • Lane L when the idea may be investigated but requires heightened governance and risk work.
  • STOP when the intended activity is impermissible in the proposed form, cannot meet a necessary condition, or cannot plausibly proceed within the organisation’s constraints.

Do not convert a legal question into a product preference. “We will deal with compliance later” is not a neutral choice; it is a decision to let implementation outrun the conditions under which it may be used.


The harm screen: ask who loses if success occurs

The harm check is not limited to product defects, malicious use, or data breaches. Its deliberately uncomfortable question is:

Who is worse off if this works exactly as intended?

The phrase exactly as intended matters. It prevents the team from escaping into “we would never misuse it” or “we will fix bugs.” A product can function perfectly and still transfer risk, opportunity, cost, dignity, or power onto someone else.

For an AI-assisted product, harms can affect individuals, groups, communities, organisations, society, and the environment. They may arise through exclusion, biased outcomes, surveillance, inaccurate recommendations, loss of autonomy, financial loss, unsafe action, or a burden shifted to people with less ability to object.

Artificial Intelligence Risk Management Framework (AI RMF 1.0)

Read the relevant parts of NIST’s AI Risk Management Framework for a disciplined way to think about harm: as consequences experienced by real stakeholders, not merely as technical failure.

In Section 1.1, read the scope of harms. Focus on the range of affected parties; the question is not only whether the buyer benefits. Then turn to the MAP function on page 25. Read the context requirement. Notice that intended purpose, deployment setting, laws, users, assumptions, and impacts must be understood together.

A one-sentence harm statement should name:

  1. the affected party;
  2. the mechanism by which the product affects them; and
  3. the material consequence.

For example:

If this automated candidate-ranking product succeeds as intended, applicants may be denied interviews because an opaque scoring model systematically ranks particular backgrounds lower.

That sentence does not automatically require STOP. It reveals a harm pathway that must be treated as a serious design and governance issue. But if the team cannot write the sentence honestly, or would not say it aloud to the affected person, Phase 0 requires STOP. The product’s benefits do not excuse concealing a foreseeable burden.

The ICO risk matrix below illustrates a complementary discipline: risk depends on both the severity of harm and its likelihood. Severe harm can deserve urgent attention even when it is not the most probable outcome; a low-severity outcome may be tolerable even if more likely. In Phase 0, use this matrix to sharpen discussion, not to manufacture false precision.

The ICO’s matrix classifies risk by combining likelihood of harm—from remote to more likely than not—with severity of impact—from minimal impact to serious harm. It helps distinguish a small inconvenience from a plausible, serious consequence requiring heightened handling.

A concise intake note might read:

Harm-screen fieldExample entry
Affected partyJob applicants
Intended product actionRank applicants for recruiter review
Possible harmQualified applicants receive fewer opportunities because of systematic ranking error or embedded bias
SeverityPotentially serious: employment access is affected
LikelihoodUnknown at intake
Phase 0 resultRoute to Lane L; make the uncertainty explicit

Notice the final row. “Unknown” is an acceptable early fact. Pretending that unknown risk is low is not.


The commitment screen: distinguish an obligation from an opportunity

An idea can arrive already promised. Perhaps a contract has been signed, a customer request has been accepted, or an executive has made a delivery commitment. In that case, the organisation may no longer be free to use customer validation as a simple go/no-go decision.

Mark the Idea Record COMMITTED when there is a real commitment, and record its evidence:

  • contract, statement of work, order form, or written acceptance;
  • documented customer request that the organisation agreed to fulfil;
  • internal commitment with a named accountable sponsor;
  • delivery date, scope, and any stated constraints.

A vague hope—“sales would like this”—is not a commitment. Nor should someone be able to label an idea committed merely to bypass the possibility of STOP. The record should identify who committed what, to whom, and where the commitment is documented.

The committed path changes the purpose of later evidence:

  • Phase 3 becomes a scoping exercise: evidence determines what to build and for whom, rather than whether to build anything.
  • Phases 0, 8, and 11 still operate normally. Legal constraints, unacceptable harm, unmanageable scope, and product-quality failures still matter.
  • The run is excluded from kill-rate statistics. A product that had to ship because of a prior promise does not show that the factory’s gates selected a good opportunity.

This protects the integrity of Phase 17 calibration. If committed projects are counted as ordinary successful launches, the factory will appear better at filtering ideas than it really is.


Make the classification explicit

At the end of the two-hour screen, classify the idea in a short, reviewable record. The decision must be clear enough that another person can understand why the run took its route.

ClassificationUse whenRequired recordConsequence
STOPA screen condition fails: the activity is impermissible in its proposed form, a necessary constraint cannot be met, the harm cannot be honestly stated, or the required intake conditions are absentSpecific failing condition, evidence or assumption tags, and decision rationaleClose and log the run; revisit only as a new run if something materially changes
COMMITTEDA real prior promise or obligation existsCommitment source, scope, accountable person, and relevant risk triggersFollow the committed path; do not count it in ordinary kill-rate statistics
Eligible to continueNo prior commitment exists, the screen is complete, foreseeable harms can be openly stated, and no inadmissible blocker is foundLegal/regulatory triggers, harm statement, commitment result, and initial routeContinue to Phase 1; assign Lane L if the trigger requires it

These labels are not mutually exclusive in every respect. For example, an idea can be both COMMITTED and Lane L. “Committed” says something about delivery obligation; “Lane L” says something about risk and process intensity.

The essential rule is that Lane L is not a loophole around STOP. Escalation is appropriate when the idea can still be responsibly assessed and governed. It is not appropriate when the work itself is unacceptable or impossible under the stated constraints.


A worked Phase 0 example

Consider this raw idea:

“Build an AI assistant that recommends which employees should be selected for a leadership-development programme.”

A rushed team might immediately begin prototype work or interview managers about desired features. The Phase 0 approach begins with the screen.

1. Legal and regulatory check

The product would process employee information and make recommendations that could influence access to career opportunity. Depending on its data, jurisdiction, and use, it may raise employment-law, data-protection, and automated-decision concerns.

Record: “Uses employee data and may influence career opportunities; applicable requirements are not yet assessed. [assumption]

Result: Route to Lane L.

2. Harm check

A plausible harm statement is:

“If the assistant succeeds as intended, employees may be excluded from development opportunities because its recommendations reproduce historical patterns of unequal advancement.”

This is a statement the team should be prepared to discuss openly with employees. The harm is material, but articulable. It creates a mandatory risk to investigate, rather than automatically producing STOP.

Result: Continue the screen, with the harm explicitly recorded.

3. Commitment check

Suppose the HR director has said, “It would be useful to have this next quarter,” but no agreement, budget approval, or delivery promise exists.

Record: “No contract, approved commitment, or documented promise identified. [assumption]

Result: Not committed.

4. Classification

The correct Phase 0 output is:

Eligible to continue in Lane L.
Reason: the idea is not screened out, but it involves employee data and a potentially consequential recommendation. Its regulatory context and harm pathway require programme-level governance before normal opportunity work proceeds.

Contrast that with a different outcome: if the intended product were designed to automatically deny employees eligibility without a credible lawful and ethical path, and the team could not defend the resulting exclusion openly, the proper classification would be STOP in its current form.


A practical two-hour intake structure

Keep the screen bounded. Phase 0 should uncover decisive constraints, not become unbounded research.

TimeActivityOutput
20 minutesDescribe intended users, affected parties, data, decisions, and deployment settingScope note
30 minutesIdentify legal, regulatory, licence, data, and safety triggersTrigger list with provenance tags
30 minutesWrite the harm statement and estimate severity and likelihood qualitativelyHarm note
20 minutesVerify whether a real commitment existsCommitment evidence or absence
20 minutesRecord classification, route, unresolved assumptions, and decision rationaleIdea Record and Decision Log entry

When you lack evidence, write [assumption]; do not turn a guess into a reassuring conclusion. For Phase 0, this is especially important because the most dangerous sentence is often: “There are no regulatory issues,” written before anyone has determined what the product actually does.

A minimal Phase 0 record can fit on one page:

Idea:
Intended use and setting:

Legal/regulatory triggers:
- [tag] ...

Harm statement:
- If this succeeds as intended, [affected party] may be worse off because [mechanism and consequence].

Commitment status:
- COMMITTED / NOT COMMITTED
- Evidence: [tag] ...

Classification:
- STOP / COMMITTED / ELIGIBLE TO CONTINUE
- Lane routing: S / M / L
- Rationale:

Owner:
Challenger:
Decision date:

The final three fields prepare the ground for the next lessons. The Owner and Challenger are not decorative names: a later gate is only meaningful if someone other than the originator can make the case to stop.


Phase 0 is successful when it makes the next decision safer and faster—not when it produces a lengthy risk document. Its key disciplines are to surface regulatory triggers early, state harms in terms of real people and consequences, distinguish a promise from an opportunity, and write an unambiguous classification.

The central takeaways are:

  • A regulatory trigger usually changes the required lane; it is not, by itself, proof of illegality or clearance.
  • The harm question asks who loses even when the product works as designed.
  • A real commitment changes later gates from pure go/no-go decisions into scope and risk controls, but it does not waive legal, harm, scope, or quality discipline.
  • STOP, COMMITTED, and eligible to continue must be recorded with reasons and provenance, rather than left as informal impressions.

Next, you will assign the idea to Lane S, M, or L and set the time and money caps that prevent a small opportunity from absorbing a programme-sized investment.

Can't find a good explanation? Sign up and we'll make it for you

Sign up