Following the resolution of a material crisis, the risk function leads a comprehensive review to identify why internal controls failed and prevent a repeat of the incident.
Applying the 5 Whys Post-Crisis Process
The investigation team uses the 5 Whys Model to dig past immediate event triggers and identify systemic corporate weaknesses. The alphanumeric sequence works as follows:
Incident: A critical customer database was encrypted by a ransomware attack.
  |- Why 1: An employee clicked on a malicious phishing link in an email.
  |- Why 2: The automated corporate email security filter failed to flag the message.
  |- Why 3: The security software's threat definition logs were outdated.
  |- Why 4: The IT systems team had postponed a scheduled software update.
  |- Why 5: The firm lacked an automated, auditable system to enforce patch management rules.

By identifying the root cause (the missing system patch verification), compliance can implement a permanent structural fix rather than simply blaming individual staff members.

Â