An issue management framework is implemented in five sequential stages where the issue is identified, rated, assigned, remediated and validated. Each process ends in a documented decision that leaves behind the evidence a supervisor later tests.
This article covers the scope of the framework, the five stages and their owners, how severity is rated, the register fields and supervisory evidence that make an issue examinable, and how platform tooling supports this work.

What an Issue Management Framework Covers
The issues management framework governs findings that have already happened. Within the scope a broader issues management programme you will find:
- Internal audit findings
- Examination findings and matters requiring attention
- Control failures found in testing
- Gaps from a risk assessment
- Incident follow-ups
Other issues outside of this scope include:
- Open risks that have not yet materialised
- Public relations
The Five Stages of the Issue Management Process
Five stages carry an issue from discovery to closure and each ends with a named person deciding.
1. Identify
The issue is recorded within a defined window of discovery, with its source, the control or regulation affected, and a factual description of what failed.
2. Rate
The issue owner assigns severity against a published rubric. The severity sets the escalation level, remediation window and validation depth.
3. Assign
Each issue should have one accountable owner, an action plan with discrete steps, and one target date.
4. Remediate
The owner executes the corrective action plan and evidences each step.
5. Validate
An independent party tests whether the control now works and documents the test.
Rating Issue Severity
Institutions most often leave the rating rubric undocumented, and it is the part an examiner asks to see first. Four dimensions carry most of the weight:
- Whether the failure is reversible
- The customer or financial harm it caused
- Whether it has recurred
- Whether the root cause is known
The illustrative issue severity rating below shows what each tier triggers.
| Severity tier | Escalation level | Remediation window | Validation depth |
|---|---|---|---|
| High | Board risk committee | 90 days | Independent retest by internal audit |
| Moderate | Executive risk committee | 180 days | Second line review of evidence |
| Low | Business unit management | 365 days | Self-assessment with evidence retained |
What the Issue Register Has to Record
A register is examinable when each record answers an examiner’s questions without anyone reconstructing the file. Ten fields are important here:
- Source
- Description
- Control or regulation affected
- Root cause
- Severity
- Accountable owner
- Original due date
- Any revised due date with its reason and approver
- Current status
- Validation evidence behind closure
The count of open issues past their due date, and the aging distribution of the open population reach the board from this register, both of which issue tracking software derives automatically.
Evidence Supervisors Ask For
Per Federal Reserve supervisory letter SR 13-13, matters requiring immediate attention are of significant importance and urgency and must be addressed immediately, while matters requiring attention are expected to be addressed over a reasonable period.
The same guidance requires a written response setting out corrective actions and timeframes, interim progress targets where remediation runs past one examination cycle, and Reserve Bank follow-up until examiners confirm resolution.
The OCC and the FDIC narrowed that standard in a final rule published on 1 September 2026 and effective 2 November 2026. An MRA may be issued where a practice is imprudent and could reasonably be expected to materially harm the institution’s financial condition or present material risk to the Deposit Insurance Fund, or has already caused such harm, or where it is an actual violation of law.
Examiners test the framework by sampling the population of open issues at a chosen date, the aging and past-due counts, the documented root cause for a material issue, the workpaper behind a closed issue, the trail of due-date extensions and their approvals.
Supporting the Framework with Issue Management Software
Predict360 provides Issues Management, Internal Audit and Findings Management, and Regulatory Examination and Findings Management modules on one platform.
Findings and remediation tasks are assigned to accountable business owners, who develop action plans, update progress and document completion against expected completion dates. Request a demo below to learn more.
Frequently Asked Questions
What is the difference between a risk and an issue?
A risk is exposure that may occur, assessed by likelihood and impact. An issue is a control failure or requirement breach that has already occurred, assessed by severity and remediated to closure. They belong in separate registers because they are measured differently: risks against appetite, issues against due dates.
Does every issue need a root cause analysis?
Root cause analysis scales with severity. A high severity issue cannot close without a documented root cause, because a fix applied to a symptom leaves the failure able to recur. Low severity issues can close on the corrective action alone, provided the register records why formal root cause analysis was skipped.
What evidence do examiners expect for issue management?
Examiners typically request the population of open issues at a given date, the aging and past-due distribution, documented root cause for material issues, the validation workpaper behind a sample of closed issues, and the history of due-date extensions with approvals.
The Predict360 Enterprise Risk Management Software ensures managers have complete visibility of enterprise risk on a single dashboard.
Request Demo- Cloud-Based
- Risk Repository
- Assess Risks
- Real-time Monitoring