Skip to content
Reference

Compliance Remediation and Issue Management: From Finding to Validated Closure

The short version

Compliance issue management is the process by which an institution records a finding (from an examination, audit, independent test or self-identification), determines its root cause, assigns a corrective action plan with an owner and deadline, tracks it to completion, and has a party independent of the remediation validate that the fix works before the issue is closed. Supervisory findings follow the same path under agency guidance: the Federal Reserve's SR 13-13 requires a written board response, a timeframe and examiner confirmation before an MRA or MRIA closes, and the OCC and FDIC's 2026 final rule sets the standard for when an MRA may be issued. The IIA's Global Internal Audit Standards (Standard 15.2) set out how internal audit confirms implementation.

Compliance issue management is the governed process by which an organization records a compliance deficiency, analyzes its cause, plans and carries out corrective action, and confirms through independent validation that the deficiency has been corrected before the issue is closed. It applies to findings from supervisory examinations, internal audit, independent testing, regulatory look-backs, complaints and self-identified issues. The same structure appears in the supervisory guidance of the federal banking agencies and in the Institute of Internal Auditors' Global Internal Audit Standards.

Sources of findings and their weight

Findings differ in formality and in who must be told when they close.

SourceTypical formWho confirms closure
Supervisory examinationMatter Requiring Immediate Attention (MRIA), Matter Requiring Attention (MRA), violation, or a non-binding supervisory observation.The examining agency, which may rely on internal audit's validation work.
Formal enforcement actionArticles of a written agreement or consent order.The agency, often with an independent consultant's review.
Internal audit or independent testingAudit finding rated by significance.Internal audit or the independent tester.
Self-identifiedIssue raised by the first or second line, for example after a control failure.A party independent of the remediation, commonly compliance testing or internal audit.

Supervisory findings: MRAs and MRIAs

The Federal Reserve's framework is set out in SR 13-13 / CA 13-10, "Supervisory Considerations for the Communication of Supervisory Findings" (2013). It defines MRIAs as matters of significant importance and urgency that the Federal Reserve requires a banking organization to address immediately, including matters posing significant safety-and-soundness risk, significant noncompliance with laws or regulations, repeat criticisms that have escalated through inaction, and, in consumer compliance, matters with potential for significant consumer harm. MRAs are important matters the organization is expected to address over a reasonable period. SR 13-13 requires that communications of MRAs and MRIAs specify a timeframe for completion, requires the board of directors to respond in writing with its corrective action and timeframes, and states that an MRA or MRIA remains open until examiners confirm the corrective action. Action plans that extend beyond one supervisory cycle for safety-and-soundness matters, or beyond twelve months for consumer compliance, are to include interim progress targets. An MRA that is not addressed in a timely manner may be elevated to an MRIA.

For national banks and FDIC-supervised institutions, the OCC and FDIC adopted a joint final rule on August 27, 2026, effective November 2, 2026 (12 CFR Part 4 for the OCC; 12 CFR Part 305 for the FDIC), defining "unsafe or unsound practice" and limiting when an MRA may be issued. Under the rule, an MRA may be issued for a practice that is contrary to generally accepted standards of prudent operation and that could reasonably be expected to materially harm the bank's financial condition or present a material risk of loss to the Deposit Insurance Fund, or that has already caused material harm, or for an actual violation of a banking or banking-related law or regulation, which the rule's preamble states includes anti-money laundering, counter-terrorist financing and sanctions laws and regulations (OCC Bulletin 2026-40). The OCC issued a revised Policies and Procedures Manual on MRAs, PPM 5400-11, at the same time (OCC Bulletin 2026-41). The Federal Reserve did not join the rule; it updated its Statement of Supervisory Operating Principles in May 2026, including on the standards for issuing MRAs and MRIAs. Issues that do not meet the MRA standard may be communicated as supervisory observations, which do not carry the same formal response and tracking requirements.

Elements of an issue record

Whatever the source, a complete issue record contains the same elements:

Root cause

IIA Standard 14.3 requires internal auditors, when evaluating findings, to collaborate with management to identify root causes where possible. Its implementation guidance describes root-cause work as asking a series of questions about why the difference between criteria and condition exists. Structured methods such as the five whys, cause-and-effect (fishbone) analysis and the Eight Disciplines (8D) method are widely used; the reference on the Eight Disciplines method describes 8D's containment, root-cause and verification steps. A corrective action aimed at a symptom, for example re-working a backlog of alerts without addressing the staffing or tuning that created it, tends to produce a repeat finding, which SR 13-13 identifies as a ground for escalation to an MRIA.

Corrective action plans, owners and deadlines

A corrective action plan converts the root cause into actions. Each action has one accountable owner (a named individual, not a department), a target date the owner has agreed, and a defined deliverable that can be tested. Dates are set with the finding's severity in mind; for supervisory findings the agency's timeframe governs. The corrective action plan reference covers plan structure in detail. Progress is reported to senior management and, for significant issues, to the board or a board committee. IIA Standard 15.2 provides that when management has not implemented actions by the established completion dates, internal auditors obtain and document an explanation and discuss it with the chief audit executive, who determines whether senior management has, by delay or inaction, accepted a risk that exceeds the organization's risk tolerance.

Validation of closure

Closure of an issue is a separate step from completion of the action plan. The owner's statement that work is done is followed by validation: testing by a party independent of the remediation that the corrective action was implemented as designed and is operating effectively. IIA Standard 15.2 requires internal auditors to confirm that management has implemented recommendations or action plans through an established methodology that includes inquiry about progress, follow-up assessments performed on a risk-based approach, and updating status in a tracking system, with the extent of work scaled to the significance of the finding.

Validation applies the same techniques as any control test: a test of design to confirm the new control addresses the root cause, and a test of operating effectiveness over a period long enough to show the control runs consistently. The reference on control testing methods describes the sampling and documentation involved. SR 13-13 provides that Reserve Bank follow-up on MRAs may include reliance on validation work performed by internal audit, where the internal audit function is effective; in that case examiners review internal audit's workpapers and may meet with the staff who documented the resolution. Examiners document the rationale for closing an issue and communicate the result in writing.

Independence between remediation and testing

The party that designs or performs a remediation is not the party that validates it or independently tests it afterward. The principle is stated in several sources:

The reason is the same in each case: a remediator testing its own work has an interest in the result, so the validation carries no independent assurance. An institution that engages one party to remediate a finding commonly engages a different party, or its internal audit function, to validate the remediation and to perform the next independent test.

Primary sources

Common questions

What is the difference between an MRA and an MRIA?
Under Federal Reserve SR 13-13, an MRIA is a matter of significant importance and urgency that must be addressed immediately, such as significant safety-and-soundness risk or significant noncompliance with law. An MRA is an important matter to be addressed over a reasonable period. Both require a written board response and remain open until examiners confirm corrective action.
What changed for MRAs in 2026?
The OCC and FDIC adopted a joint final rule on August 27, 2026, effective November 2, 2026, that defines unsafe or unsound practice and limits MRAs to practices posing material financial risk or to actual violations of banking or banking-related law, including AML and sanctions laws. The Federal Reserve updated its Statement of Supervisory Operating Principles in May 2026.
What does validation of a closed issue involve?
A party independent of the remediation tests that the corrective action was implemented as designed and operates effectively over a period. IIA Standard 15.2 requires internal audit to confirm implementation using inquiry, risk-based follow-up assessments and a tracking system.
Why should the remediator not be the independent tester?
A party testing its own work has an interest in the result, so its conclusion provides no independent assurance. IIA Standard 2.2 presumes objectivity impaired when an auditor assesses an activity it was responsible for within the previous 12 months, and OCC Bulletin 2013-33 treats prior review of the same transactions as a conflict for an independent consultant.
What does a corrective action plan contain?
The root cause, specific actions, a single accountable owner and target date for each action, interim compensating controls, progress reporting, and a defined deliverable that a validator can test.
About this library

This reference library is maintained by Rupture Labs. We perform BSA/AML independent testing and automated control testing against every record, with each requirement cited to its rule. Talk to a practitioner.