1. Explain the scenario, not just the failure
Connect the gap to the affected asset, process, third party or control. Describe what could happen, who is affected and which evidence is missing. A concrete scenario separates an operational issue from an exposure that needs management attention.
- Observed fact and observation date
- Affected asset, service or process
- Expected control and evidence
2. Assess probability, impact and exposure
Use a suggested assessment as a starting point, then review it against the organization’s context. The score should explain priority, not replace a conversation about regulatory, financial or operational consequences.
- Probability: what makes the scenario likely
- Impact: what is lost if it happens
- Exposure: which part of the business is affected
3. Choose treatment and an owner
Decide whether the risk is mitigated, accepted or transferred. For mitigation, specify the measure and expected evidence; for acceptance or transfer, retain the approval and its conditions.
- A clear owner and, where needed, reviewer or approver
- Start, due and review dates
- A verifiable completion criterion
4. Turn treatment into executable work
Create a task only when there is no open task for the same gap. Include control context, recommended steps, expected evidence and links so the assignee does not need to reconstruct the problem.
- Avoid duplicate tasks for an already assigned gap
- Keep the task, gap and control connected
- Use the review date to prepare the next check
5. Close with evidence and re-audit
Completing a task does not automatically make a control compliant. Review the change or document, update residual risk and use review or re-audit to decide whether the answer changed.
- Evidence demonstrates change, not only intent
- Residual risk may still require acceptance
- The owner and auditor retain the final decision