Closure evidence
Definition
Documentation that demonstrates a finding has been remediated. Acceptable evidence types vary by control: updated policies with effective dates, configuration screenshots, vulnerability scan results, training attendance records, or third-party assessment reports.
Related terms
- Finding owner
- The individual or team accountable for implementing the corrective action specified in a management action plan. The finding owner is typically the...
- Follow-up verification
- An independent check, usually by internal audit or the compliance function, that reviews closure evidence and confirms the control gap has been...
- Management action plan (MAP)
- A formal document issued in response to an audit finding, recording the agreed corrective action, the accountable owner, the target closure date,...
- Recurring finding
- An audit finding that has appeared in two or more consecutive audit cycles despite previous remediation commitments. Recurring findings indicate that the...
- Risk acceptance
- A formal decision by an authorised senior manager to tolerate a finding without full remediation, typically because the cost of remediation exceeds...
Explained in
- Remediation Tracking and Management Action PlansDocumentation that demonstrates a finding has been remediated. Acceptable evidence types vary by control: updated policies with effective dates, configuration...