GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

GOV-007 Risk Treatment and Remediation Tracking

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Identified risks and control deficiencies have documented treatment plans with owners, target remediation dates, and current status. Progress against open findings is tracked and reported to management at defined intervals.

Rationale

Identifying and assessing risk has limited value unless treatment actions are assigned, tracked, and completed. A plan-of-action process closes the loop between assessment outputs and control improvement.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (12)

A&A-06Remediationfull
A&A-06Remediationfull
HIPAA-164.308.a.1.ii.BRisk Managementfull
NIS2-Art.21.4Corrective Measures on Non-Compliancefull
NIS2-CIR-2.1Risk Management Frameworkinformative
NIS2-CIR-2.3Independent Review of Information and Network Securityinformative
NIS2-CIR-3.6Post-Incident Reviewsinformative
CA-5Plan of Action and Milestonesfull
PM-4Plan of Action and Milestones Processfull
RA-7Risk Responsefull
MS-2.7-006AI System Security and Resilience Evaluation | MS-2.7-006full
CC4.2COSO Principle 17: Evaluates and Communicates Deficienciespartial

Evidence (2)

system_exporttechnicalautomated

Plan of action and milestones (POA&M) or remediation tracker documenting open risk findings with owners, target dates, and current status.

Example: POA&M or remediation tracker (Jira board, GRC platform, or spreadsheet), showing each open finding from risk assessments or audits with: finding ID, description, assigned owner, target remediation date, current status, and management-reported aging.

Test: Request the current remediation tracker or POA&M. Verify: (1) findings from the most recent risk assessment and audit are present, (2) each finding has a named owner, (3) target remediation dates are set and non-expired items are on track or have documented extensions, (4) the tracker is reviewed and reported to management, confirmed via meeting minutes or a status report referencing open items.

reportdocumentmanual

Management-level report on remediation progress showing aging, closure rates, and overdue items.

Example: Monthly or quarterly remediation status report (Confluence / GRC dashboard) submitted to the CISO or equivalent, listing total open findings, overdue items, and items closed in the reporting period.

Test: Request the last two remediation status reports. Verify: (1) reports were produced within the defined cadence, (2) open, overdue, and closed finding counts are present, (3) overdue items have documented extensions or escalations, (4) reports are addressed to or acknowledged by a named manager.

Questions (3)

boolean

Does your organisation maintain a tracked plan of action for open risk findings and control deficiencies?

This may be a plan of action and milestones (POA&M), a remediation tracker, or equivalent. Findings from risk assessments and audits should appear in it with current status.

select

How often is remediation progress against open risk findings reported to management?

MonthlyQuarterlySemi-annuallyAnnuallyOnly when escalatedProgress is not formally reported to management

Regular management-level reporting (monthly or quarterly) with aging, closure rates, and overdue items is the expected practice.

multi

What does each entry in the remediation tracker record?

A named ownerA target remediation dateThe current statusThe source of the finding, such as a risk assessment, an audit or an incidentThe date the entry was closedNone of the above

Options run from the most commonly held to the least. An entry with no target date cannot age. A tracker where nothing ages reports the same picture every period.