
A regulator, an auditor or an incident hands you a finding. The reflex, under pressure and short of time, is to make it go away: fix the specific thing named, write it up, close the action, report it green. Six months later a version of the same problem surfaces somewhere else, because you treated the symptom and left the cause in place. This is the most common and most expensive mistake in remediation, and it is entirely avoidable.
A finding is not a punishment. It is information you would otherwise have paid for with a much larger failure. It points at a weakness in your system while that weakness is still cheap to fix. The organisations that get stronger after a finding are the ones that treat it as a symptom to be traced, not an item to be closed. The ones that keep getting caught are the ones that got very good at closing actions and never asked why the action was needed.
Symptom versus cause, in one example
Say the finding is: a payment was approved without the required second sign-off. The symptom fix is to reprimand the person and re-send the policy. Feels done. But ask why it happened. The second approver was on leave and there was no cover. Why? Because the process has no rule for absences. Why? Because it was designed for a smaller team and never updated. The real fix is a cover rule and a review of the process, not a stern email. Fix the email version and it happens again the next time someone takes leave. Fix the cause and it stops.
The solution, as a root-cause and CAPA method
Trace it to the cause, then fix it so it cannot return
- Contain it. Deal with the immediate issue so no further harm is done. This is first aid, not the cure.
- Ask why, five times. Keep asking until you reach something about the system, not the person.
- Name the real cause. If your answer is "human error" or "training", you have not finished. Why did the system let the error through?
- Design the corrective action against the cause, and a preventive action so the same class of problem cannot recur elsewhere.
- Assign an owner and a date, and change the process or the control, not just the wording.
- Check it held. Come back in ninety days and confirm the fix is real, not just documented.
The two words that hide most causes
When a root-cause exercise ends at "human error" or "more training needed", it has usually stopped one question too early. People make errors, always. A good system expects that and catches them. So the real question is never just why did the person get it wrong, but why did nothing stop the wrong thing from proceeding. That second question is where the durable fix lives, and it is the one that "retrain the individual" is designed to avoid, because retraining is cheap, fast and changes nothing.
Questions to ask of any corrective action
- Are we fixing the symptom that was named, or the cause underneath it?
- If our answer is "human error", why did the system allow it through?
- Would this fix stop the same class of problem happening elsewhere?
- Have we changed a process or a control, or only re-sent a policy?
- Who checks, in ninety days, that the fix actually held?
A regulator's finding feels like a bad day. Handled well, it is one of the cheapest ways to make your business genuinely stronger, because someone has just shown you a weakness before it cost you dearly. Trace it past the symptom to the system, fix the cause so the whole class of problem cannot return, and check that the fix held. Do that and each finding leaves you better than it found you. Keep closing actions without asking why, and you will keep meeting the same problem wearing a new name, right up until the day it stops being a finding and becomes a headline.
Notes and sources
From the book
Compliance Beyond Ticking the BoxTurn compliance from a cost you endure into a system that protects the business and drives its growth.
