Skip to main content
Version: 1.0.0-beta

Findings & Remediation

The Findings module manages the complete lifecycle of audit observations — from initial documentation through management response, remediation, follow-up testing, and closure.

What Is a Finding?

A finding represents a gap between what should happen (criteria) and what is happening (condition). AIIA uses the CCCER framework for structured finding documentation:

ComponentDescriptionExample
ConditionWhat is happening"15% of payments lack proper approval"
CriteriaWhat should happen"Policy requires dual approval for all payments > SAR 50,000"
CauseWhy the gap exists"System approval routing was misconfigured after ERP upgrade"
EffectRisk/impact of the gap"SAR 2.3M in payments processed without proper oversight"
RecommendationHow to fix it"Reconfigure approval routing and perform retrospective review"

Key Capabilities

CapabilityDescription
CCCER FrameworkStructured finding documentation
Severity RatingCritical, High, Medium, Low classification
Management ResponseIntegrated response workflow
Action PlansRemediation tracking with owners and due dates
EscalationAutomated escalation for overdue items
Follow-Up TestingValidate that remediation is effective
Recurring DetectionAI identifies patterns across engagements
Version HistoryFull version control for finding revisions

Finding Lifecycle

Severity Classification

SeverityDescriptionTimeline
🔴 CriticalSignificant risk to the organization; requires immediate action30 days
🟠 HighMaterial weakness requiring prompt attention60 days
🟡 MediumControl gap that should be addressed90 days
🟢 LowMinor improvement opportunity180 days

AI-Assisted Finding Documentation

FeatureDescription
Draft FindingAI drafts CCCER components based on test results
Severity SuggestionAI recommends severity based on impact analysis
Recurring DetectionAI identifies similar findings from past engagements
Recommendation GenerationAI suggests remediation approaches
Language ReviewAI checks for clarity, objectivity, and blame-free language

Getting Started

  1. Document Findings → — Create your first finding
  2. Action Plans → — Set up remediation tracking
  3. Track Remediation → — Monitor progress
  4. Escalation Rules → — Configure automatic escalation
  5. Follow-Up Testing → — Validate remediation
  6. Field Reference → — Complete field documentation