When an internal audit, regulatory review, or RCSA identifies an ineffective control or an unmitigated risk exposure, the organization must issue a formal Corrective Action Plan (CAP) to track the gap through to resolution.
[Identified Control Gap] ---> [Binding CAP Record Formed] ---> [Independent Audit Closure Sign-off]
A compliant CAP file must document four core elements:
- Root Cause Finding: A clear description of the control failure or process vulnerability identified during the assessment.
- Remediation Milestones: A step-by-step plan detailing the specific process modifications, system updates, or policy revisions required to address the gap.
- Individual Accountability Assignment: A single named individual who owns the remediation project and is accountable for meeting delivery goals.
- Target Completion Date (TCD): A binding deadline determined by the severity of the exposure (e.g., 30 days for high-risk findings, 90 days for moderate gaps).
Once the remediation milestones are complete, the independent internal audit function must review the implemented changes to verify their operating effectiveness before the CAP can be formally closed in the governance register.