Compliance issue management is the process by which an institution records a finding (from an examination, audit, independent test or self-identification), determines its root cause, assigns a corrective action plan with an owner and deadline, tracks it to completion, and has a party independent of the remediation validate that the fix works before the issue is closed. Supervisory findings follow the same path under agency guidance: the Federal Reserve's SR 13-13 requires a written board response, a timeframe and examiner confirmation before an MRA or MRIA closes, and the OCC and FDIC's 2026 final rule sets the standard for when an MRA may be issued. The IIA's Global Internal Audit Standards (Standard 15.2) set out how internal audit confirms implementation.
Compliance issue management is the governed process by which an organization records a compliance deficiency, analyzes its cause, plans and carries out corrective action, and confirms through independent validation that the deficiency has been corrected before the issue is closed. It applies to findings from supervisory examinations, internal audit, independent testing, regulatory look-backs, complaints and self-identified issues. The same structure appears in the supervisory guidance of the federal banking agencies and in the Institute of Internal Auditors' Global Internal Audit Standards.
Sources of findings and their weight
Findings differ in formality and in who must be told when they close.
| Source | Typical form | Who confirms closure |
|---|---|---|
| Supervisory examination | Matter Requiring Immediate Attention (MRIA), Matter Requiring Attention (MRA), violation, or a non-binding supervisory observation. | The examining agency, which may rely on internal audit's validation work. |
| Formal enforcement action | Articles of a written agreement or consent order. | The agency, often with an independent consultant's review. |
| Internal audit or independent testing | Audit finding rated by significance. | Internal audit or the independent tester. |
| Self-identified | Issue raised by the first or second line, for example after a control failure. | A party independent of the remediation, commonly compliance testing or internal audit. |
Supervisory findings: MRAs and MRIAs
The Federal Reserve's framework is set out in SR 13-13 / CA 13-10, "Supervisory Considerations for the Communication of Supervisory Findings" (2013). It defines MRIAs as matters of significant importance and urgency that the Federal Reserve requires a banking organization to address immediately, including matters posing significant safety-and-soundness risk, significant noncompliance with laws or regulations, repeat criticisms that have escalated through inaction, and, in consumer compliance, matters with potential for significant consumer harm. MRAs are important matters the organization is expected to address over a reasonable period. SR 13-13 requires that communications of MRAs and MRIAs specify a timeframe for completion, requires the board of directors to respond in writing with its corrective action and timeframes, and states that an MRA or MRIA remains open until examiners confirm the corrective action. Action plans that extend beyond one supervisory cycle for safety-and-soundness matters, or beyond twelve months for consumer compliance, are to include interim progress targets. An MRA that is not addressed in a timely manner may be elevated to an MRIA.
For national banks and FDIC-supervised institutions, the OCC and FDIC adopted a joint final rule on August 27, 2026, effective November 2, 2026 (12 CFR Part 4 for the OCC; 12 CFR Part 305 for the FDIC), defining "unsafe or unsound practice" and limiting when an MRA may be issued. Under the rule, an MRA may be issued for a practice that is contrary to generally accepted standards of prudent operation and that could reasonably be expected to materially harm the bank's financial condition or present a material risk of loss to the Deposit Insurance Fund, or that has already caused material harm, or for an actual violation of a banking or banking-related law or regulation, which the rule's preamble states includes anti-money laundering, counter-terrorist financing and sanctions laws and regulations (OCC Bulletin 2026-40). The OCC issued a revised Policies and Procedures Manual on MRAs, PPM 5400-11, at the same time (OCC Bulletin 2026-41). The Federal Reserve did not join the rule; it updated its Statement of Supervisory Operating Principles in May 2026, including on the standards for issuing MRAs and MRIAs. Issues that do not meet the MRA standard may be communicated as supervisory observations, which do not carry the same formal response and tracking requirements.
Elements of an issue record
Whatever the source, a complete issue record contains the same elements:
- Condition and criteria: what was found and the requirement it falls short of, with the citation. IIA Standard 14.2 defines a finding as the difference between the criteria and the condition.
- Significance rating: the priority assigned under a documented methodology (IIA Standard 14.3 requires findings to be prioritized by significance).
- Root cause: the underlying reason the condition exists, not only its symptom.
- Corrective action plan: the specific actions, each with a single accountable owner and a target date.
- Interim measures: compensating controls in place while the permanent fix is built.
- Status history: dated progress updates, date changes with reasons, and the approvals for any extension.
- Evidence of completion and validation: what the owner submitted, what the validator tested, and the validator's conclusion.
Root cause
IIA Standard 14.3 requires internal auditors, when evaluating findings, to collaborate with management to identify root causes where possible. Its implementation guidance describes root-cause work as asking a series of questions about why the difference between criteria and condition exists. Structured methods such as the five whys, cause-and-effect (fishbone) analysis and the Eight Disciplines (8D) method are widely used; the reference on the Eight Disciplines method describes 8D's containment, root-cause and verification steps. A corrective action aimed at a symptom, for example re-working a backlog of alerts without addressing the staffing or tuning that created it, tends to produce a repeat finding, which SR 13-13 identifies as a ground for escalation to an MRIA.
Corrective action plans, owners and deadlines
A corrective action plan converts the root cause into actions. Each action has one accountable owner (a named individual, not a department), a target date the owner has agreed, and a defined deliverable that can be tested. Dates are set with the finding's severity in mind; for supervisory findings the agency's timeframe governs. The corrective action plan reference covers plan structure in detail. Progress is reported to senior management and, for significant issues, to the board or a board committee. IIA Standard 15.2 provides that when management has not implemented actions by the established completion dates, internal auditors obtain and document an explanation and discuss it with the chief audit executive, who determines whether senior management has, by delay or inaction, accepted a risk that exceeds the organization's risk tolerance.
Validation of closure
Closure of an issue is a separate step from completion of the action plan. The owner's statement that work is done is followed by validation: testing by a party independent of the remediation that the corrective action was implemented as designed and is operating effectively. IIA Standard 15.2 requires internal auditors to confirm that management has implemented recommendations or action plans through an established methodology that includes inquiry about progress, follow-up assessments performed on a risk-based approach, and updating status in a tracking system, with the extent of work scaled to the significance of the finding.
Validation applies the same techniques as any control test: a test of design to confirm the new control addresses the root cause, and a test of operating effectiveness over a period long enough to show the control runs consistently. The reference on control testing methods describes the sampling and documentation involved. SR 13-13 provides that Reserve Bank follow-up on MRAs may include reliance on validation work performed by internal audit, where the internal audit function is effective; in that case examiners review internal audit's workpapers and may meet with the staff who documented the resolution. Examiners document the rationale for closing an issue and communicate the result in writing.
Independence between remediation and testing
The party that designs or performs a remediation is not the party that validates it or independently tests it afterward. The principle is stated in several sources:
- IIA Standard 2.2 requires internal auditors to refrain from assessing specific activities for which they were previously responsible, and presumes objectivity impaired if an internal auditor provides assurance on an activity for which the auditor had responsibility within the previous 12 months. Where internal audit previously performed advisory work, the chief audit executive must confirm that the advisory work does not impair objectivity.
- OCC Bulletin 2013-33, on independent consultants in enforcement actions, gives as an example of a disqualifying conflict a consultant that previously reviewed the transactions it is now asked to evaluate, and requires disclosure of the consultant's prior work for the bank.
- The BSA/AML program rule requires independent testing for compliance (31 CFR 1020.210), and the FFIEC BSA/AML Examination Manual expects the tester to be independent of the functions tested; a firm that built or operates a remediated control is not independent of it. The BSA/AML independent testing reference describes that standard.
The reason is the same in each case: a remediator testing its own work has an interest in the result, so the validation carries no independent assurance. An institution that engages one party to remediate a finding commonly engages a different party, or its internal audit function, to validate the remediation and to perform the next independent test.
Primary sources
- Federal Reserve SR 13-13 / CA 13-10, Supervisory Considerations for the Communication of Supervisory Findings: Definitions of MRIAs and MRAs, required timeframes, board response, follow-up and closure, reliance on internal audit validation.
- OCC Bulletin 2026-40, Unsafe or Unsound Practices and Matters Requiring Attention: Final Rule: Joint OCC and FDIC final rule, August 27, 2026, effective November 2, 2026; standard for issuing MRAs.
- OCC Bulletin 2026-41, Revised Policies and Procedures Manuals for Bank Enforcement Actions and Related Matters and Matters Requiring Attention: Revised PPM 5400-11 (MRAs) and PPM 5310-3.
- Federal Reserve, Supervision and Regulation Report (June 2026), Supervisory Developments: Describes the May 2026 update to the Statement of Supervisory Operating Principles and standards for MRAs and MRIAs.
- The IIA, Global Internal Audit Standards (2024): Standards 2.2 (safeguarding objectivity), 14.2 and 14.3 (findings, root cause, significance), 15.2 (confirming implementation of action plans).
- OCC Bulletin 2013-33, Use and Review of Independent Consultants in Enforcement Actions: Independence and conflict expectations for consultants engaged under enforcement actions.
- 31 CFR 1020.210: Bank AML program rule, including independent testing for compliance.