Management action plan (MAP)
Definition
A formal document issued in response to an audit finding, recording the agreed corrective action, the accountable owner, the target closure date, and the expected evidence of completion. Also called a corrective action plan (CAP) in some frameworks.
Related terms
- Closure evidence
- Documentation that demonstrates a finding has been remediated. Acceptable evidence types vary by control: updated policies with effective dates, configuration screenshots, vulnerability...
- Finding owner
- The individual or team accountable for implementing the corrective action specified in a management action plan. The finding owner is typically the...
- Follow-up verification
- An independent check, usually by internal audit or the compliance function, that reviews closure evidence and confirms the control gap has been...
- Recurring finding
- An audit finding that has appeared in two or more consecutive audit cycles despite previous remediation commitments. Recurring findings indicate that the...
- Risk acceptance
- A formal decision by an authorised senior manager to tolerate a finding without full remediation, typically because the cost of remediation exceeds...
Explained in
- Remediation Tracking and Management Action PlansA formal document issued in response to an audit finding, recording the agreed corrective action, the accountable owner, the target closure date, and the expec...