Most prioritisation frameworks treat every piece of work as a candidate for scoring. In a regulated organisation that is exactly where they break. A filing obligation with a legal date does not have a reach number, and a known security exposure does not become less urgent because someone estimated it at four person-months.
RICE+ keeps RICE for the work that genuinely competes for capacity, and puts three gates in front of it. Anything that trips a gate is scheduled rather than scored. What is left is a discretionary backlog you can rank honestly, because everything in it is genuinely optional.
There is a companion tool for the other half of the question. The AI use-case gate decides how much autonomy an AI use case has earned.
Your portfolio
No initiatives yet. Add one, or load the example portfolio to see how the gates behave.
Ranked output
How RICE+ works
The three gates
Every initiative is checked against three questions before it is allowed anywhere near a score. The gates are deliberately about obligation and risk, not about value, because value is what the scoring stage is for.
- Regulatory or legal
- Is this required by law, by a regulator, or by a contractual obligation? An obligation with a fixed date is mandatory. An obligation without one is committed, which means it needs a slot in the plan but not necessarily the next one.
- Security and data protection
- Is there a known exposure here? An uncontained risk is mandatory. A risk with a working control around it is committed, and the control is what buys you the scheduling room.
- Operational continuity
- What happens if this is not done? Service or reporting that fails outright is mandatory. Service that degrades is committed.
An initiative that trips no gate is discretionary, and only discretionary work is scored. This is the whole point of the model: it stops a genuine obligation from having to win an argument against a popular feature request, and it stops teams from quietly laundering pet projects through the word "compliance".
The score
Discretionary work uses standard RICE:
Score = Reach × Impact × Confidence ÷ Effort
- Reach
- How many people or processes this affects in a quarter. Count them, do not estimate a feeling.
- Impact
- How much it changes things for each of them, from minimal at 0.25 up to massive at 3.
- Confidence
- How much evidence sits behind the reach and impact numbers. 100 percent means measured, 80 percent means reasoned, 50 percent means someone is guessing and everybody knows it.
- Effort
- Total person-months across everyone involved, not elapsed calendar time.
Scores are still calculated for gated work and shown in grey, because the number is useful context in the room. It is not used to rank anything inside the mandatory or committed tiers, and the tool will not let it be.
What this deliberately does not do
It does not produce a plan. It produces a defensible starting position for the conversation where the plan gets made, and a record of what the inputs were when the decision was taken. That record is usually worth more six months later than the ranking itself.
It also does not know your capacity. A ranked list of nineteen initiatives is not a roadmap until someone draws a line across it and says where the quarter stops.
Also in the lab
AI use-case gate. The same idea applied to autonomy rather than order: seven questions and three gates that decide whether an AI use case should run unattended, assist a person, or be redesigned before anyone builds it. This tool decides what to do next; that one decides how much to trust it.