An issue management framework is implemented in five sequential stages where the issue is identified, rated, assigned, remediated and validated. Each process ends in a documented decision that leaves behind the evidence a supervisor later tests.

This article covers the scope of the framework, the five stages and their owners, how severity is rated, the register fields and supervisory evidence that make an issue examinable, and how platform tooling supports this work.

Teams are learning how to implement an issue management framework.

What an Issue Management Framework Covers

The issues management framework governs findings that have already happened. Within the scope a broader issues management programme you will find:

  • Internal audit findings
  • Examination findings and matters requiring attention
  • Control failures found in testing
  • Gaps from a risk assessment
  • Incident follow-ups

Other issues outside of this scope include:

  • Open risks that have not yet materialised
  • Public relations

The Five Stages of the Issue Management Process

Five stages carry an issue from discovery to closure and each ends with a named person deciding.

1. Identify

The issue is recorded within a defined window of discovery, with its source, the control or regulation affected, and a factual description of what failed.

2. Rate

The issue owner assigns severity against a published rubric. The severity sets the escalation level, remediation window and validation depth.

3. Assign

Each issue should have one accountable owner, an action plan with discrete steps, and one target date.

4. Remediate

The owner executes the corrective action plan and evidences each step.

5. Validate

An independent party tests whether the control now works and documents the test.

Rating Issue Severity

Institutions most often leave the rating rubric undocumented, and it is the part an examiner asks to see first. Four dimensions carry most of the weight:

  • Whether the failure is reversible
  • The customer or financial harm it caused
  • Whether it has recurred
  • Whether the root cause is known

The illustrative issue severity rating below shows what each tier triggers.

Severity tierEscalation levelRemediation windowValidation depth
HighBoard risk committee90 daysIndependent retest by internal audit
ModerateExecutive risk committee180 daysSecond line review of evidence
LowBusiness unit management365 daysSelf-assessment with evidence retained

What the Issue Register Has to Record

A register is examinable when each record answers an examiner’s questions without anyone reconstructing the file. Ten fields are important here:

  1. Source
  2. Description
  3. Control or regulation affected
  4. Root cause
  5. Severity
  6. Accountable owner
  7. Original due date
  8. Any revised due date with its reason and approver
  9. Current status
  10. Validation evidence behind closure

The count of open issues past their due date, and the aging distribution of the open population reach the board from this register, both of which issue tracking software derives automatically.

Evidence Supervisors Ask For

Per Federal Reserve supervisory letter SR 13-13, matters requiring immediate attention are of significant importance and urgency and must be addressed immediately, while matters requiring attention are expected to be addressed over a reasonable period.

The same guidance requires a written response setting out corrective actions and timeframes, interim progress targets where remediation runs past one examination cycle, and Reserve Bank follow-up until examiners confirm resolution.

The OCC and the FDIC narrowed that standard in a final rule published on 1 September 2026 and effective 2 November 2026. An MRA may be issued where a practice is imprudent and could reasonably be expected to materially harm the institution’s financial condition or present material risk to the Deposit Insurance Fund, or has already caused such harm, or where it is an actual violation of law.

Examiners test the framework by sampling the population of open issues at a chosen date, the aging and past-due counts, the documented root cause for a material issue, the workpaper behind a closed issue, the trail of due-date extensions and their approvals.

Supporting the Framework with Issue Management Software

Predict360 provides Issues Management, Internal Audit and Findings Management, and Regulatory Examination and Findings Management modules on one platform.

Findings and remediation tasks are assigned to accountable business owners, who develop action plans, update progress and document completion against expected completion dates. Request a demo below to learn more.

Frequently Asked Questions

What is the difference between a risk and an issue?

A risk is exposure that may occur, assessed by likelihood and impact. An issue is a control failure or requirement breach that has already occurred, assessed by severity and remediated to closure. They belong in separate registers because they are measured differently: risks against appetite, issues against due dates.

Does every issue need a root cause analysis?

Root cause analysis scales with severity. A high severity issue cannot close without a documented root cause, because a fix applied to a symptom leaves the failure able to recur. Low severity issues can close on the corrective action alone, provided the register records why formal root cause analysis was skipped.

What evidence do examiners expect for issue management?

Examiners typically request the population of open issues at a given date, the aging and past-due distribution, documented root cause for material issues, the validation workpaper behind a sample of closed issues, and the history of due-date extensions with approvals.

Streamline Risk Management

The Predict360 Enterprise Risk Management Software ensures managers have complete visibility of enterprise risk on a single dashboard.

Request Demo
  • Cloud-Based
  • Risk Repository
  • Assess Risks
  • Real-time Monitoring