Testing should be stopped based on risk assessment for the system being tested, not simply because all tests are done, time is up, or faults are fixed. Risk-based testing considers the cost of remaining defects versus the cost of additional testing. Even with all planned tests run, high-risk areas may need more testing.