Physical Design · All levels
Risk Review and Executive Signoff — Mechanism
Mechanism for Risk Review and Executive Signoff (Signoff and Tapeout).
Physical and tool mechanism
Executive signoff requires concise risk narratives backed by quantitative severity, likelihood, customer impact, and mitigation plans.
Mechanism to narrate
Separate technical certainty from business tolerance explicitly.
Express residual risks in scenario form with impact windows.
Capture final go/no-go rationale with accountable signers.
Reference workflow
1. Identify where Risk Review and Executive Signoff sits in the PD flow
2. Name inputs consumed and outputs produced
3. State the metric that proves success or failure
4. Link to the next downstream stage that depends on this stepKey takeaways
Narrate Risk Review and Executive Signoff using metrics, not tool commands alone.
10+ year engineer lens
A senior engineer does not describe Risk Review and Executive Signoff as a tool step. They explain what physical assumption changed, which report becomes trustworthy after that change, and which downstream owner can now make a decision.
Boundary conditions to state
Which stage of the database is valid: pre-CTS, post-CTS, post-route, post-fill, or final signoff.
Which approximation is still present: estimated RC, ideal clock, abstracted macro, vectorless power, or waived PV rule.
Which downstream result depends on this mechanism: Launch quality and accountability..
What top-company reviewers expect
You can point to Signoff and Tapeout closure dashboard before proposing a fix.
You can separate a local symptom from a systematic methodology issue.
You can explain why the fix is reversible, bounded, and cheaper than the alternatives.
Deep dive: how this shows up in real closure
Tapeout is an auditable decision backed by tagged artifacts.
Reports and artifacts to inspect
closure dashboard: timing, power, PV, DFT, package, and open waivers
revision manifest: RTL, netlist, SDC, GDS/OASIS, library, rule deck
waiver register: rule, count, owner, approver, expiration
foundry handoff package checklist
Mini case study
Timing and power are green, but the GDS tag differs from the STA database tag. The design is not ready. Reconcile the manifest and rerun signoff on the exact export database.
Debug branches
If a metric is yellow, name the owner, date, and mitigation before signoff review.
If the tag is mismatched, stop export; traceability is a hard gate.
If post-mask ECO is requested, confirm allowed metal layers before promising a fix.
Senior review question
Ask yourself: what single report line would prove this page's concept is either passing or failing?
What changes at 10+ years
You are expected to predict what your fix can break before running it.
You should recognize when the issue is methodology, not one block's implementation.
You should communicate risk in tapeout language: owner, evidence, impact, mitigation, and decision date.
Principal-level review bar
Deep subpage pages in this course should be read like real closure review material. For a 10+ year PD engineer, the bar is not remembering terminology; it is making a release-quality decision under ambiguity.
What excellent looks like
Names the failing metric, corner/mode, database tag, and analysis switches before proposing a fix.
Separates data, constraint, physical, tool, and methodology root causes instead of treating all failures as optimization problems.
Chooses experiments by information gain and reversibility, not by habit.
States regression blast radius across timing, route, power, PV, DFT, package, and tapeout manifest.
Turns recurring failures into methodology guardrails, dashboards, or checklist items.
Closure note template
STAFF / PRINCIPAL CLOSURE NOTE
Context:
stage: <pre-CTS | post-CTS | post-route | post-fill | signoff>
tag: <database / netlist / SDC / library stack>
failing metric: <exact report line>
affected scope: <block / hierarchy / path group / power domain / region>
Hypotheses:
H1: <most likely physical or constraint mechanism>
H2: <competing explanation>
H3: <methodology or input-data issue>
Decision:
next experiment: <cheap check that can falsify H1>
fix candidate: <minimal reversible change>
rollback trigger: <metric that says the fix is wrong>
regression set: <timing / route / power / PV / DFT / package>
escalation owner: <team or reviewer>Tradeoffs a senior engineer must discuss
Technical tradeoff
Tapeout is an auditable decision backed by tagged artifacts. Explain not only the preferred fix, but what margin or schedule you are spending to get it.
Cross-team tradeoff
What must RTL, synthesis, CAD, STA, DFT, package, IP, or foundry agree to before this decision is final?
Which artifact becomes the source of truth after the decision: report, waiver, manifest, ECO script, or methodology deck?
What is the cost of being wrong: one rerun, ECO churn, mask risk, performance loss, or silicon escape?
Leadership communication
"The current blocker is <metric> in <corner/mode/stage>. The leading cause is <mechanism>. I recommend <fix> because it is bounded and reversible. The regression surface is <domains>. If it fails, we escalate to <owner> with <evidence>."Key takeaways
Always connect the concept back to a measurable signoff artifact.
A fix is not complete until you can name the regression checks.
Common pitfalls
Optimizing by habit instead of reading the current report.
Forgetting that a local fix can regress timing, routing, power, or PV elsewhere.