Unit 3 of 4

6.3 — Findings Classification and Reporting

Findings classification ensures that the most critical issues receive immediate attention while providing a structured framework for remediation planning.

Findings Severity Classification
SeverityDescriptionRequired Action Timeline
CriticalImmediate risk to individuals or regulatory non-complianceImmediate action required
HighSignificant control weakness or material gapAction within 30 days
MediumControl improvement needed, moderate riskAction within 90 days
LowBest practice recommendation, advisoryNo mandatory timeline
5C Finding Structure (Standard in Professional Auditing)
01
Criteria

What was expected — the standard, requirement, or control that should be in place.

02
Condition

What was actually found — the factual observation during the audit.

03
Cause

Why the gap exists — root cause analysis of the deficiency.

04
Consequence

What is the risk or impact — the potential harm if not addressed.

05
Recommendation

What should be done — specific, actionable remediation steps.

5C Finding Example

Criteria: ISO 42001 requires AI impact assessments before deployment. Condition: The credit scoring model was deployed without an impact assessment. Cause: No formal pre-deployment review process exists. Consequence: Potential unfair treatment of loan applicants; regulatory non-compliance. Recommendation: Implement mandatory pre-deployment impact assessment gate with documented approval.

EXAM TIP

The audit report must be accessible to non-technical executives. Structure: Executive summary, scope/methodology, system description, findings by severity, management response (accept/partially accept/reject with action plan, responsible party, and target date), and appendices with detailed test results.

Key Points
Four severity levels: Critical, High, Medium, Low
5C finding structure: Criteria, Condition, Cause, Consequence, Recommendation
Reports must be accessible to non-technical executives
Management response with action plans and deadlines
Follow-up audits verify remediation
← Previous unitNext unit →