Consulting Practice

How to Write a Corrective Action Plan After an Audit Finding

The short version

A corrective action plan (CAP) is the deliverable written in response to one audit or exam finding: what the problem is, why it occurred, what actions are being taken, how the outcome will be measured, and who confirms the fix held. It is narrower than a remediation plan, which sequences an entire findings register into tiers and a program timeline. A reviewer tests three things: whether the problem statement is stated without the proposed fix, whether the root cause is specific enough to test, and whether someone other than the person responsible for the control failure confirms the closure. The remaining fields are formatting.

A corrective action plan is the written record of how one audit or examination finding is closed. It is the artifact a follow-up audit, a sponsor bank, or an examiner consults to determine whether a previously identified control failure was addressed and whether the fix was independently confirmed.

This guide covers the field set a defensible CAP contains, how each field is written so that it survives review, a worked example, the conditions under which a standing SMART-goal tracker is the better-fitting format, and the conditions under which a single finding calls for a team-run CAPA rather than a document written by one consultant.

The CAP compared with a remediation plan

A CAP responds to one finding. It states the problem, names a verified root cause, lists the specific actions being taken, sets a measurable outcome, and names who confirms the fix held. The program-wide roadmap that takes an entire findings register and sequences it into prioritized tiers with a governance structure is a remediation plan, a different deliverable. The guide to AML program gap analysis covers how findings become that broader roadmap. A single engagement typically produces one remediation plan and many CAPs, each CAP closing one item the remediation plan sequences.

The CAP field set did not originate in compliance. It traces to project-management and manufacturing-quality practice: government program offices use it to track deviations, and the FDA's Quality System Regulation has required a documented corrective-and-preventive-action process for medical device manufacturers since the 1990s. ISO 9001 makes it the mechanism for closing any nonconformity under a certified quality system. Compliance consulting adopted the same discipline because the underlying problem is identical: a control failed, and someone independent needs to see, in writing, that it will not fail the same way twice.

How reviewers use a corrective action plan

Whether the finding comes from a BSA/AML independent test, a SOX ICFR audit, or a HIPAA risk analysis, the reviewer's question is whether the program is self-correcting or accumulating findings. An examiner reading a BSA/AML independent test checks whether prior findings were closed before reading much else, and the same sequence appears in a SOX ICFR audit and a HIPAA compliance audit. A CAP written in general terms leaves the finding open in substance and available for citation on the next test cycle.

The corrective action plan field set

The field order below is drawn from the corrective action plan template published by the California Department of Technology's California Project Management Framework (CA-PMF), a public government template recognizable to reviewers of formal action plans. The fields are completed in the order given rather than alphabetically.

FieldWhat goes in it
CAP IDA unique identifier for tracking, distinct from the finding's own ID.
Associated finding / issue IDThe direct link to the source finding in the findings register. A CAP with no traceable parent is not auditable.
TitleA brief, descriptive title, not a restatement of the finding number.
OwnerThe role managing the plan to closure, not necessarily the person doing the underlying work.
PriorityCritical, high, medium, or low, tied to the finding's own severity rating.
Change request necessaryWhether the fix requires formal change control before it can be implemented.
Expected implementation dateThe target completion date.
Actual date implementedFilled in at closure. Documents whether the plan ran on time.
Problem definitionWhat went wrong, stated specifically. Never the proposed fix.
Root cause evaluationThe verified finding from the root-cause investigation, not a theory.
Action stepsThe corrective actions and activities, in sequence.
Alternatives consideredOther options evaluated and why they were not chosen. Strengthens defensibility of the fix that was.
Improvement metric and timeframeThe measurable outcome expected, and when it will be measured.
Implementation verificationHow and by whom completion will be confirmed.

Writing each field so it survives review

Problem definition: the statement without the proposed fix

A CAP that describes the fix in place of the problem gives the reviewer nothing to verify. "The bank should implement enhanced transaction monitoring rules" states a remedy rather than a condition. A problem definition names what happened, specifically enough that a person outside the engagement can verify it: which control, what population, what timeframe, what magnitude. "Transaction monitoring rule TM-14 did not alert on 22 wire transfers over the $10,000 threshold between March and May because the rule's dollar parameter was configured against the wrong account type" is a problem statement, and it contains no remedy. A reviewer can inspect the rule configuration and confirm the claim independently.

Root cause evaluation: specific enough to test

"Insufficient rigor" and "human error" are descriptions of an investigation that stopped before reaching a cause. A defensible root cause names a specific, falsifiable organizational failure: a rule that was never re-tested after a system migration, an owner role that was vacant for four months, a policy that described a control the tooling could not perform. The guide to 8D vs. 5 Whys vs. fishbone covers the tools an investigation of this kind draws on. Whatever tool produced the cause, the cause is verified before it is recorded: whether removing the suspected cause would have prevented the problem, and whether the evidence supports that conclusion rather than the team's agreement that it is plausible.

Action steps and alternatives considered

The corrective actions are listed as a sequence, each with an owner role and a date, rather than as a paragraph of narrative. The record notes whether the fix requires a formal change request, since that flag affects both the timeline and the approval path. At least one alternative that was considered and rejected is documented, together with the reason. A CAP that records no alternatives gives the reviewer no basis for comparing the selected action against the options available.

Improvement metric and timeframe: SMART formulation

The metric states the completed condition in numbers and the date on which it will be measured. "Transaction monitoring rule TM-14 will alert on 100% of wire transfers over $10,000 in the affected account type, confirmed by a sample of 25 transactions post-implementation" is measurable; "monitoring will be improved" is not. An unmeasurable goal can be declared closed but not demonstrated closed.

Implementation verification: the named verifier and the interval

The CAP names the person or role who confirms the action was implemented and, separately, the person or role who confirms months later that it held. The two checkpoints are distinct, and collapsing them into one sign-off is a recurring defect in review. The party confirming closure is not the party that implemented the fix or the party responsible for the original control failure. This is the same independence principle that governs who can perform BSA/AML independent testing: the party grading the work cannot be the party that did it.

Two tracks: the single-finding CAP and the standing SMART tracker

A material finding with regulatory or examiner exposure calls for the full field set above. A lower-tier finding, or a standing programmatic goal not tied to one discrete finding, such as raising training-completion rates a set number of points in a cycle, fits a lighter format: a SMART goal statement, an action-step table with owners and dates, and a running Assessment/Alterations log reviewed on a set cadence rather than only at closeout.

SituationTrack
Material finding, real regulatory or examiner exposureFull CAP field set, above
Lower-tier finding, or a standing programmatic goal not tied to one findingSMART-goal tracker with a running Assessment/Alterations log

The Assessment/Alterations log is the lighter format's distinguishing feature: at each review point, record what the data actually shows and what changed about the plan as a result, for example, "interim measurement showed 70% completion against the 95% goal; root cause traced to one location's staff lacking platform access; alteration: IT ticket filed, extended check-in added." That produces an audit trail of a plan being actively managed, which is more persuasive to a reviewer than a plan that was either on track or silently abandoned with no record either way.

Escalation to a team CAPA

A CAP is a document one consultant writes and one client owner executes. Where the finding traces to a vendor's own control failure, where containment has to occur before the root cause is known, or where no single person on the client's side holds the authority to close every action step, the response is structured as a team-run corrective and preventive action process rather than a solo CAP. The 8D method is the standard form: a named cross-functional team, a mandatory interim containment step before the cause is known, and separate verification and validation checkpoints at every action rather than a single sign-off at the end. Where a vendor's control failure surfaced the finding, the same discipline structures the corrective action request issued to the vendor, in place of an unverified vendor assurance that the issue is resolved.

The boundary test has two parts: whether the response requires a team with authority across functions, and whether a customer, vendor, or examiner needs containment evidence before the cause is known. An affirmative answer to either indicates a team CAPA. One client owner closing one control gap, with no outside party awaiting containment, indicates a CAP.

Where a CAP fails review

Primary sources

Common questions

What is a corrective action plan in a compliance context?
A corrective action plan (CAP) is the deliverable that responds to one audit or exam finding: it states the problem, the verified root cause, the specific actions being taken, the measurable outcome expected, and who confirms it was implemented and held. It is narrower than a program-wide remediation plan, which sequences an entire findings register into a prioritized roadmap.
What should a corrective action plan template include?
At minimum: a unique ID linked to the source finding, an owner, a priority, a problem statement that does not smuggle in the fix, a verified root cause, the action steps taken with alternatives considered, a measurable improvement metric and timeframe, and a named implementation-verification step. This field set is drawn from public project-management and quality frameworks and is recognizable to most examiners and auditors.
How is a corrective action plan different from a remediation plan?
A remediation plan sequences an entire findings register, often dozens of gaps, into tiers with a program-wide timeline and governance structure. A corrective action plan responds to a single finding. Most engagements produce one remediation plan and many CAPs, with each CAP closing one item the remediation plan sequences.
Who should verify that a corrective action plan was actually implemented?
Someone independent of whoever implemented the fix, the same principle behind independent testing being performed by someone independent of the program it reviews. A CAP that names the person who broke the control as the person who confirms it is fixed will not survive a careful review.
When does a single corrective action plan need to become a team CAPA instead?
When the finding traces to a vendor's own control failure, when real containment has to happen before the root cause is known, or when no single person has the authority to close every action step alone. In those cases a team-run process such as 8D, with a named team, a mandatory containment step, and separate verification and validation checkpoints, fits the finding better than a solo CAP.
About this library

This reference library is maintained by Rupture Labs, the company behind Compliance Command Center, compliance software built and reviewed by practitioners. Contact.