Findings
Remediation plans are graphs, not checklists
Activities depend on each other. Modelling that dependency is the difference between a plan that reflects reality and a task list that quietly stalls.
- Activity dependencies, so blocked work is visibly blocked
- Multiple assignees per finding
- Evidence reviewed and accepted, not merely uploaded
- Severity and origin type recorded on every finding
Privileged access review not evidenced
Traced to control · raised from assessment
Export current privileged accounts
IT Ops
Confirm owner for each account
System owners
Remove unowned accounts
IT Ops · waiting on “Confirm owner for each account”
Attach review evidence
Security · waiting on “Remove unowned accounts”
Evidence is reviewed and accepted, not just attached
Traceability
Every finding keeps its thread
Findings arrive from assessments, risks, third-party issues, and field campaigns, and keep the link back to wherever they came from and the control involved.
- Origin type recorded so the source is never lost
- Links back to controls, risks, assets, and business processes
- Activity comments and finding comments kept separate
- Full audit log per finding
- PaymentsDomain
- Card acquiringCapability3 risks2 policies
- Merchant settlementService4 controls2 assets
- Daily reconciliationProcess1 risk2 controls1 finding
Every level links out to risks, controls, policies, findings, assessments, and assets
Evidence
Submitted, then reviewed
Evidence carries a type and a status, and passes through an explicit review step, so closure means someone competent accepted the proof, not that a file was attached.
- Evidence type and status tracked per item
- Explicit review records against submitted evidence
- Activity status distinct from finding status
- Notifications raised on the events that matter
Level 3: Well Defined
A standard process is defined and followed across the organisation.
Every question in the control library carries its own written descriptor at each level.
Framework alignment
Works with your control frameworks
This module shares the platform control library. Map national frameworks and global standards alongside jurisdiction-specific authorities.
Solutions by role
Built for your team
See findings and remediation in your environment
A walkthrough scoped to your entities, your frameworks, and the way your programme is actually run.