Remediation Process

In real GRC, remediation means turning the identified gap into a corrective action, assigning responsibility, setting a deadline, and then verifying that the problem has actually been fixed.

Remediation Process — Real-Life GRC

OrderTabWhat you do in real lifeLondonBuild example
1Start with GapTake the confirmed gap from your assessment.2 user accounts were not included in the quarterly access review.
2Identify Root CauseDetermine why the gap happened.The access-review process relies on a manually maintained user list.
3Define Remediation ActionDecide exactly what needs to change.Automate the user population reconciliation before each access review.
4Define Remediation ObjectiveState what the fix should achieve.Ensure 100% of active accounts are included in every quarterly review.
5Determine Remediation PriorityPrioritise based on risk/severity.High priority because inappropriate access could remain undetected.
6Assign Remediation OwnerGive one person accountability for completing the action.IT Manager
7Define TasksBreak the remediation into specific actions.Configure automated user list → test → update procedure → train IT staff.
8Set Target DateEstablish a realistic completion deadline.30 September 2026
9Implement FixThe control owner carries out the remediation.Automated reconciliation implemented.
10Collect Remediation EvidenceObtain proof that the fix was completed.System configuration + updated procedure + test results.
11Validate RemediationGRC checks whether the fix actually addresses the gap.Confirm automated report includes 100% of active accounts.
12Retest ControlPerform another control test where necessary.Test the next quarterly access review.
13Close GapClose only when sufficient evidence confirms the issue is resolved.GAP-001 → Closed
14Update Risk RegisterUpdate the associated risk and residual risk/status.Risk reduced after remediation.

Actual LondonBuild Remediation Record

FieldExample
Gap IDGAP-001
Risk IDR-001
RequirementISO 27001 A.5.18
ControlAC-002 — Quarterly Access Review
Gap2 of 20 sampled users had no documented access review
Root CauseManual user list does not always capture all active accounts
RemediationAutomate reconciliation of active accounts before each quarterly review
Remediation Objective100% of active accounts reviewed
PriorityHigh
OwnerIT Manager
Target Date30 September 2026
StatusIn Progress
Evidence RequiredAutomated report, updated procedure, completed review
ValidationGRC analyst verifies 100% account population
RetestNext quarterly access review
Final StatusOpen → Closed after successful validation

The most important thing

Don’t close a remediation just because the IT Manager says:

“We’ve fixed it.”

You need objective evidence that the fix was implemented and, where appropriate, retest the control.

The logic is:

Gap

Root Cause

Remediation Action

Owner + Deadline

Implementation

Evidence

Validation

Retesting

Gap Closed

And your full GRC workflow is now:

Framework → Requirement → Control Objective → Control Mapping → Crosswalk → Risk Event → Risk Register → Evidence → Testing → Gap → Remediation → Reporting

The next and final stage is Reporting — where you take everything you’ve discovered and turn it into information management can actually use.