Issue Management: Tracking a Weakness Until It Closes
An issue is a known weakness carrying a named owner, an agreed action and an agreed date. A risk might happen, a loss already has, and an issue is the one in between: wrong now, nothing gone wrong yet. Tracking it means holding two measures apart, its age from the day it was raised and whether it has passed the date agreed. At this invented bank, 92 are open and 31 are past due.
Everything in this guide rests on one separation that a register makes very easy to lose. How long a weakness has existed and whether anybody is late fixing it are two different facts, and neither one settles the other. A weakness can be eighteen months old and entirely on track. Eighteen months is honestly what the fix needs. Another can be three weeks old and already past a date its owner picked. A report showing only the first has described the shape of the pile and has said nothing at all about whether the people who promised to clear it are doing so.
The separation between the two is worth holding on to. Almost every mistake in this subject is a version of collapsing it. The counts here come from Vindhya Commercial Bank Limited, an invented mid-sized Indian commercial bank, and every figure below is that bank's own. At the reporting date it carries 92 open weaknesses. Thirty one of them have gone past a date somebody agreed. The oldest of those thirty one is 412 days beyond its date. Three numbers, and what follows sets out what each one measures, what none of them measures, and which of them the bank should be managed on.
What is an issue, and how is it different from a risk and from a loss?
Start in a housing society. The object is the same and nothing about it is technical. The managing committee keeps three lists without ever calling them that. The first list is things that could go wrong: the lift is eleven years old and one day it will fail, the monsoon might flood the basement again. The second list is things that have already cost money: the pump burnt out in April and the replacement came to Rs 38,000/-. The third list is different from both. The overhead tank has a hairline crack. The crack has not flooded anything. The crack has not cost anybody a rupee. But it is cracked, everybody knows it is cracked, a plumber has quoted Rs 26,000/- to reline it, and the secretary has told the residents it will be done before the rains.
The third list is the issue register, and it is a separate list for one reason: its entries are wrong now and have not yet caused anything. The first list is risk: a possibility, with a likelihood and a consequence attached, and a decision about whether to accept it or do something about it. The second list is loss: history, an amount, a cause, a date. An issueA known weakness with a named owner, an agreed action and an agreed date, sitting between a risk that might happen and a loss that has. is the state in between. Something in the arrangement is not working the way it was designed to, nobody has been hurt by it yet, and there is still time.
Take that into the bank and nothing changes except the vocabulary. A risk in this bank's register might read that a customer instruction could be executed twice because one release step is enough to send it. A loss reads that on a particular day an instruction was executed twice and Rs 42.0 crore left the building. An issue reads that the release step still allows one person to send an instruction alone, that the head of the affected process is the named owner, that the agreed action is to split the release into two hands, and that the agreed date is month 4. Same underlying weakness, three different objects, and they live in three different records because they answer three different questions.
Now the part that actually matters for how a register behaves. An issue is the only one of the three where an action and a date are the whole point of the entry. The bank's risk register does name a risk owner, and the reader has already met that idea; a risk owner decides how the risk is treated and lives with the treatment. But a risk that is accepted carries no fix and no deadline. There is nothing to fix yet. A loss carries no deadline either. The thing has happened, and the only remaining questions are how much and why. Only an issue carries the triple: a person, a change, and a day by which the change will be there. Take away any one of the three and what is left is a note.
The triple is worth pressing on. Missing any one leg of it explains why issue registers rot in a very particular way. An entry with no owner is a complaint. An entry with no action is an observation. An entry with no date is an intention. All three of those can sit in a spreadsheet looking exactly like an issue. With nothing to be late against, none of them can be tracked.
What actually separates an issue from a risk and from a loss?
Where do issues actually come from?
Nobody sits down to write an issue register. The register fills itself, through five doors, and knowing which door an entry came through says something useful about that entry before a word of it has been read.
The first door is the process where a business rates its own controls. The self assessment asks the people who run a thing to say honestly which of their own controls work. A control the owner has just admitted does not work is a weakness with a person already attached, so the ones marked as not working become weaknesses by definition. At this invented bank that assessment ran across nine processes numbered PR1 to PR9 and covered 214 key controls, and it is the single largest source of what sits in this register. The assessment process itself is covered under control self assessment.
The second door is a loss event. Something went wrong and cost money, somebody worked out why, and the why is still there. Notice the direction of travel. The reversal catches people out. The loss record is closed the moment the amount is final. The weakness that produced it stays open until it is fixed. A loss shown as closed while the weakness that caused it sits open in the issue register is not a contradiction, it is two records doing two different jobs.
The third door is a near miss, and it is the cheapest of the five. Something almost went wrong and did not, usually because one person happened to notice. The weakness is identical to the one a loss would have exposed and it has arrived with no bill attached. At this bank the near misses are numbered N1 to N5 and are covered under near miss reporting.
The fourth door is a complaint. A customer says the thing did not work. Complaints arrive one at a time and each looks like an individual grievance. The grievance framing is exactly why the weakness underneath them takes so long to be recognised. Forty separate people saying a statement is confusing is one weakness, not forty.
The fifth door is an independent review, meaning somebody who does not run the process comes and tests it. At this bank, independent testing covered all 214 controls and found 198 designed effectively and 16 carrying a design gap, then tested the operation of those 198 and found 172 effective and 26 not. The independent testing produced 42 findings, being 26 operating failures plus 16 design gaps. The bank publishes 92 open issues and it publishes 42 findings, and it says nothing at all about how the two sets relate, so the two counts stand separately with no bridge between them. The gap sits in the record, not in the arithmetic. When a record will not support a claim, the right response is to stop rather than to estimate.
The five doors have one thing in common and it is easy to miss. Every one of them is a detection route, so a register only ever holds weaknesses that something found. A weakness nobody has found is not missing from the register because it has been dealt with. The weakness is missing because nobody has looked in that corner yet. The size of a register is therefore partly a measure of how hard the institution is looking. A register that jumps after a review is usually a sign of something working rather than something failing.
What has to be on an issue before anybody can track it?
Six fields, and the test for each one is the same: remove it and see whether the entry is still trackable. If it is, the field was decoration. If it is not, the field is load bearing. Only six survive that test.
The first is the weakness itself, written as what is wrong rather than as what should be done. The wording sounds like a small drafting point and it is not. An entry reading that the release step still allows one pair of hands to send an instruction alone describes a state of the world, and that state can be revisited later and checked for change. An entry reading that the bank will implement dual release describes somebody's plan, and the only thing available to check is whether the plan was carried out. The closure test set out below depends on being able to go back and see whether the recorded fact is still true, so the weakness belongs on the register as a fact about the world.
The second is why it matters, meaning the consequence if nobody does anything. Consequence is the field that stops a register from becoming a flat list of two hundred equally urgent complaints. Two entries can look identical in effort and be worlds apart in consequence, and the only place that difference is visible is here.
The third is the named owner, and the emphasis is on named. Not a team, not a department, not a job title with three people in it. One person. An action with two owners has none. The named owner is the field that quietly decides whether a register works, and it is also the field most often filled in with something that looks like an answer and is not.
The fourth is the agreed action, and the emphasis this time is on agreed. Somebody who did not write the entry has to have said yes to the action, out loud, and that somebody is normally the owner who will be measured against it. An action drafted by the person who found the weakness and never accepted by the person who has to do it is a request, and requests do not go overdue because nobody ever committed to them.
The fifth is the agreed date, the same word doing the same work. The agreed date is the single most consequential field on the entry. Every measure of lateness is a comparison against it and nothing else. Just as important is what the agreed date is not: it is not an estimate of how long the fix will take, and it is not a date the person who found the weakness would prefer. The agreed date is a promise, made by a named person, on a day they chose.
The sixth is status. Status sounds like housekeeping and is not. Status is what separates an issue that is being worked on from one that has been quietly abandoned, and it is the field a register uses to remember that a date was changed. The memory of a moved date carries weight. The whole of the extension problem set out below lives inside it.
Now put it back into the housing society. The crack in the tank is the weakness. If it goes another monsoon the ceiling below comes down is why it matters. The secretary is the named owner. Reline the tank is the agreed action. Before the rains is the agreed date, and notice how weak that is compared with a day. Status is what the register says when the plumber does not turn up. The same six fields carry a cracked water tank and a payment release control, and the reason they work for both is that none of them is about finance at all: they are the minimum set that makes a promise checkable by somebody who was not in the room.
What does an ageing profile show, and what does it quietly hide?
Ninety two entries is too many to read, so a register is nearly always presented as an ageingHow long an issue has been open, measured from the date it was raised. profile: how long each entry has been open, measured from the day it was raised, sorted into bands. Vindhya Commercial Bank uses five bands numbered AG1 to AG5, and here is the whole table.
| Band | Age from the date raised | Issues | Share | Cumulative |
|---|---|---|---|---|
| AG1 | 0 to 30 days | 28 | 30.4% | 30.4% |
| AG2 | 31 to 90 days | 22 | 23.9% | 54.3% |
| AG3 | 91 to 180 days | 18 | 19.6% | 73.9% |
| AG4 | 181 to 365 days | 15 | 16.3% | 90.2% |
| AG5 | over 365 days, with no upper edge at all | 9 | 9.8% | 100.0% |
| Total | open at the reporting date | 92 | 100.0% |
Every figure is Vindhya Commercial Bank Limited's own and invented. 28 plus 22 plus 18 plus 15 plus 9 is 92, and the five shares add to 100.0 per cent exactly.
The shape comes first. The counts fall as the bands get older, from 28 down to 9. A register where things do eventually get closed has exactly that shape. Counts that rose as the bands got older would mark a register where nothing ever leaves, and no further analysis would be needed to know it.
Now read what the shape leaves out. The shape says nothing about lateness. Age is measured from the day a weakness was raised, and lateness is measured against the day somebody promised to fix it. Age and lateness are different clocks started by different people. The shape says nothing about severity either: a band holds entries by their age and by nothing else, so AG1 could be 28 trivial documentation gaps or 28 things that will take the bank down, and the table would look identical.
And then there is the edge of the table. The edge is the most important thing in it. AG5 has a floor of 365 days and no ceiling whatsoever. An open top like that makes AG5 an overflow rather than a band. An ageing bucketOne band of an ageing table, where the top band is usually open-ended and therefore caps nothing. at the top of a table is almost always open in this way, and the effect is that every entry which has been open for four hundred days, eight hundred days or four years lands in the same cell and becomes indistinguishable from every other. Nine issues sit there. The table will not say whether the oldest of them is a year and a day old or six years old, and no arithmetic performed on this table can invent that information. The missing ceiling matters again below, where it decides what the average age of this register is allowed to be called.
One more habit worth building. The two oldest bands together hold 15 plus 9, being 24 of 92 or 26.1 per cent. A quarter of everything on this register has been open for more than six months. The 26.1 per cent is worth knowing, and by itself it is not a verdict. Whether six months is a long time depends on what the fixes involved actually require. A change to a screen takes an afternoon. A change to how a core system releases payments takes a release cycle, sign off from people who did not raise the issue, and a window in which it can safely be deployed. A register full of the second kind will age and be perfectly well run, so neither 92 open nor 33.7 per cent overdue is good or bad on its own.
Bands AG4 and AG5 hold 15 and 9 issues. What share of this register has been open for more than six months, and what does that share on its own say?
Why are age and overdue two different measures?
The separation the whole guide rests on, stated as plainly as it can be: age is counted from the day the weakness was raised. OverdueWhether an issue is past the date its owner agreed to, which is a different measure from its age. is counted against the day the owner promised to have it gone. Two clocks, started by two different people, for two different reasons, and neither one can be worked out from the other.
Consider a snag list on a new flat. A household moves in and lists eleven things: a door that sticks, a tap that drips, a switch plate that is loose, a bathroom tile with a hairline crack. Every one of those snags is now the same age. All eleven were raised on the same afternoon. But the builder gave a different date for each: the switch plate on Saturday, the tile when the mason is next in the building, the door after the monsoon when the wood has settled. Three weeks later every snag on that list is exactly three weeks old and only some of them are late, and no amount of staring at the ages will identify which ones.
Now the bank. The register carries 92 open weaknesses aged into the five bands set out above. Separately, 31 of those 92 are past the date their owners agreed to, being 33.7 per cent of the register. The 92 and the 31 are not two views of the same fact. Two different instruments produced them, measuring two different things. The record does not say which bands the 31 sit in, so the 31 cannot be distributed at all across AG1 to AG5.
Follow what that means for two real entries. An issue can sit in AG4 at two hundred days old and be perfectly on track. The fix is a change to how a core system releases payments, the owner said month 9 from the start, and it is month 8. Nothing about that entry needs anybody's attention. Another can sit in AG1 at three weeks old and already be past a date its owner agreed to. A promise made three weeks ago has already been broken and nobody has said why, and the entry needs attention today. Age is a fact about the register and overdue is a fact about a commitment, and only the second one is about people.
Which of the two should an institution be run on? Overdue, and the reason is not a preference. Age is not something anybody can be accountable for. Nobody chose it, it is simply how long the thing has been sitting there, and shouting at a person about the age of an entry whose agreed date is still three months away is asking them to explain a number they did not set. The agreed date, by contrast, was chosen by the owner. Missing it is a fact about a person and a promise, and it is the only number on this register that anybody can properly be asked about. Vindhya Commercial Bank reports the ageing profile and manages on the overdue count, and that is the right way round. Report the shape; manage the promises.
One issue is 200 days old and not past its agreed date. Another is 20 days old and already past its agreed date. Which one needs attention today?
There is one more consequence of the two clocks and it is easy to walk past. The oldest thing on this register depends entirely on which instrument is picked up, and the two answers are not just different numbers, they are different kinds of number.
By age, the oldest entry sits in AG5 at more than 365 days from the day it was raised. AG5 has no ceiling, so the table will not say how much more. By overdue, the oldest is 412 days beyond a date somebody agreed. One small piece of reasoning makes this interesting. A date can only be agreed after the weakness is raised. Nobody promises to fix something before knowing about it. So an entry that is 412 days past its agreed date has been open for 412 days plus however long its owner was originally given. The 412 day entry is necessarily more than 412 days old and therefore necessarily one of the nine in AG5, and the register can prove that without knowing a single one of the nine actual ages.
The register cannot prove that this same entry is the oldest by age. There are eight others in that band and any of them could have been raised earlier. Two superlatives, two instruments, and the honest sentence is that the oldest overdue distance on this register is 412 days while the oldest age is simply unknown above 365. Quoting one as though it were the other converts a distance into an age. The category error is the same as reading a speedometer as a milometer.
What is the largest number of days on this register, and which of the two instruments produced it?
What is the average age of an open issue here?
A committee that has been shown five bands will almost always ask for one number instead: what is the average age of an open issue? The question is fair and the register can answer it, but only in a particular form, and the form matters more than the figure.
Do the arithmetic first. The table gives counts by band and not ages, so the ages have to be assumed, and the honest assumption is the middle of each band. AG1 runs 0 to 30 days, so take 15. AG2 runs 31 to 90, so take 60. AG3 runs 91 to 180, so take 135. AG4 runs 181 to 365, so take 273. AG5 runs over 365 days and has no far edge, so it has no middle at all and the only defensible figure to put in is its near edge of 365. Then multiply and add: 28 times 15 is 420, 22 times 60 is 1,320, 18 times 135 is 2,430, 15 times 273 is 4,095 and 9 times 365 is 3,285. The five products come to 11,550 issue-days. Divide by the 92 issues carrying them and the answer is 125.5 days.
Two of those midpoints are rounded, and saying so out loud matters. A reader who redoes the sum should arrive at the same figures. The exact middle of 31 to 90 is 60.5 and the exact middle of 91 to 180 is 135.5, and using both unrounded gives 11,570 issue-days and 125.8 days instead of 125.5. The answer barely moves. Rounding the midpoints, in other words, is not what limits this number. Something else is.
The last band is what limits it. The nine issues in AG5 have been entered into the sum at 365 days each, and 365 is the smallest age any of them can possibly have. One of them, as the previous section proved, is more than 412 days old. The others could be four hundred days old or four years old and the table would look exactly the same. Every one of those nine is therefore contributing at least what it should and possibly far less. No correction is available: the missing quantity is not uncertain within a range, it is unbounded above. A number built on an open-ended band can only move upward when the real ages arrive. Upward-only movement makes it a floorA computed value that can only be a minimum, because part of the underlying data has no upper bound. and not an average.
So the sentence to write on the report is that the average age of an open issue is at least about 126 days. Not that it is 126 days. The three words at least are the entire difference between a number that can be defended and a number that cannot, and they cost nothing. Say it the second way in a room and somebody will eventually ask why an issue that has been open for three years is being counted at 365 days, and the answer, that the table has no room to record it, is a much worse answer to give under questioning than in advance.
Reading a floor as an average is the commonest arithmetic mistake made on an ageing table anywhere, and it is not confined to registers of weaknesses. A band labelled over five years, over ninety days, over ten lakh: every one of them is an instruction that any number computed from it is a minimum. The repair is never to invent a ceiling. The repair is to write the word floor beside the figure and, if somebody genuinely needs the average, to go and collect the nine actual dates. For nine records that is an afternoon of somebody's time.
Why can the average age of these 92 issues only be stated as a floor?
What closure rate does a register actually need?
Ninety two open. Thirty one past due. About 126 days at the least. Every number so far describes a stock, meaning what is sitting there at one moment, and a stock cannot show whether it is being worked on. Showing that takes two flows: how many weaknesses arrive in a period and how many leave it.
Consider a bucket under a tap. The water in it is the stock. The water can be measured to the millilitre every morning and still leave open whether the bucket is filling, emptying or holding. The level this morning is the result of the tap and the drain, and the level shows neither. Ninety two is exactly that kind of number. Ninety two is the level.
The register does not publish its flows, but one of them can be inferred. Band AG1 holds the issues that are 0 to 30 days old, and there are 28 of them. The last month therefore produced 28 new entries. The 28 in band AG1 stands in for the arrival rateHow many new issues are raised in a period, which is the number a closure rate has to beat. and it is a working assumption rather than something the bank records: one month is one observation, and a review that lands twenty findings on a Tuesday would put a lump in that band that has nothing to do with the underlying pace. With that caveat stated plainly, arrivals are taken at 28 a month.
Now the other flow. The closure rateHow many issues are closed in a period, which has to exceed the arrival rate before any stock moves. is how many are closed in the same month, and the stock moves by the difference. Twenty eight in and twenty two out means the pile grows by six. Twenty eight in and thirty four out means it falls by six. And twenty eight in and twenty eight out means the pile does not move at all. Break-even is the number the rest of this guide turns on.
Work the cases. Close nothing and the stock is 92 plus 28 a month, reaching 428 by month 12. Close 14 a month and it grows by 14 a month, reaching 260 by month 12. Close 28 and it is 92 at month 1, 92 at month 6, 92 at month 12 and 92 for as long as anybody keeps reporting. Close 36 and it falls by 8 a month, so the 92 takes 92 divided by 8, being 11.5 months, to disappear. Close 42 and it falls by 14 a month, clearing in 92 over 14, being 6.6 months. Close 56 and it falls by 28 a month, clearing in 3.3.
Turned round, the question becomes what it takes to clear the existing pile inside a year while still absorbing everything new. Clearing it requires the 28 that arrive plus a twelfth of the 92 that are already there: 28 plus 92 over 12 is 28 plus 7.67, being 35.67, so 36 a month. The whole distance between a register that never clears and a register that is empty in a year is eight issues a month. At this bank eight issues is one working day's decisions. Eight a month is the most useful number on this register, and nothing in the ageing table hints at it.
Ninety two issues are open and about 28 arrive each month. Before the control below is moved: what happens to this register if 28 are closed each month?
Move the closure rate and watch the pile
Arrivals are held at 28 a month, which is band AG1 read as a monthly pace. The register starts at 92 open. Drag the closure rate and the line redraws out to month 24.
Closing 28 issues a month against 28 arriving, this register stands at 92 open in twelve months and never clears. At this break-even the 31 overdue never moves either.
Assumptions on screen: the arrival rate of 28 a month is read off band AG1, being the issues aged 0 to 30 days, and is the reader's own assumption rather than a figure this invented case records. Arrivals are assumed steady and they are not: an independent review lands a batch at once. Closure is assumed to take issues in no particular order. A register worked oldest first clears the overdue count faster and the stock at the same rate. Every count belongs to Vindhya Commercial Bank Limited, invented. Educational illustration.
The failure: the report that looks like control and is stagnation
Nobody has to hide anything for this one to happen. The failure is produced by arithmetic and it arrives dressed as good news.
Suppose this bank closes 28 a month, exactly what arrives. Month 1 report: 92 open, 31 overdue. Month 2: 92 open, 31 overdue. Month 6, month 9, month 12: 92 open, 31 overdue. Twelve consecutive papers carrying the same two numbers to the digit. Anybody who has sat in a committee knows how that reads. The flat line reads as a register under control. Volatility is what people have been trained to worry about, and a flat line is the absence of volatility. Somebody may even say that the position has been held steady through a difficult year.
Nothing has been cleared. Not one of the original 92 need have gone. The bank could be closing the twenty eight easiest arrivals of each month while the same 92 sit underneath untouched, and the report would be identical to a report from a bank that had cleared the lot and replaced it with fresh work. Two completely different institutions produce the same twelve monthly reports, and the stock figure cannot tell them apart. The stock is the one number that survives the difference.
The overdue count goes the same way. At break-even it holds at 31, and 31 looks like a stable proportion rather than a queue of the same thirty one promises being missed for the twelfth month running. Neither figure moves, and the reason neither moves is exactly the reason both should be alarming.
Two numbers settle it, and both appear nowhere on the report: how many arrived and how many were closed. Put those in the report and the twelve months separate instantly. Twenty eight in and twenty eight out is stagnation. Twenty eight in and thirty six out is a register that will be empty before the next annual cycle, and it shows a falling stock from month one. A committee handed only the stock has been handed the one figure that cannot answer the question it is being asked to answer. Ask for the flows. The flows are two integers and somebody already knows them both.
Twelve consecutive reports show 92 open and 31 overdue. Is this register under control?
What does moving a date do to the count?
There is a second half to this failure and it attacks the other measure. Overdue is counted against a date somebody agreed. A date somebody agreed can be agreed again.
Call that an extensionA new agreed date replacing the old one, which removes an issue from the overdue count without changing the weakness.: the owner comes back before the date arrives, explains that the fix needs another quarter, and a new date is recorded. Nothing improper has happened. Sometimes an extension is the honest thing to do. A date set in ignorance of what the fix required should be replaced by a date set in knowledge of it, and a register full of dates nobody believes is worse than a register whose dates move for stated reasons.
But look at what it does to the measurement. An issue extended the week before it would have tipped over never appears in the overdue count at all. Not once, not for a day. The weakness is exactly as present as it was, the fix is exactly as far away, and the number that is supposed to detect all of that has been reset to zero for that entry. Do it consistently and a register can report zero overdue every month for years while nothing whatever is being fixed. An overdue count on a register where dates move easily measures willingness to extend and not progress, and the two are almost opposites.
So the overdue count is never a figure to read alone. The overdue count belongs beside the number of extensions granted in the same period. Zero overdue and zero extensions is a register doing well. Zero overdue and forty extensions is a register doing nothing and reporting beautifully. Thirty one overdue and zero extensions is a register in trouble that is at least saying so. A register that does not count its extensions cannot be read at all, in either direction, and adding that count costs one column.
Applied to this bank, the test passes. The treatment so far has been hard on this bank, so the result is worth stating. Thirty one of the 92 are sitting in the overdue count, being 33.7 per cent of the register, and one of them is 412 days beyond its date. Nobody quietly re-dated that entry to make it disappear, and an institution that was managing the count rather than the weaknesses would have re-dated it a year ago. Whatever else is wrong here, the dates are not being moved to flatter the number, and that is a real thing to notice about a register.
A register reports zero overdue issues every single month. What should be seen before believing it?
What actually closes an issue?
One question is left and it is the one most registers answer wrongly. An entry goes to closed. On what basis?
The common basis is that the agreed action was carried out. The owner said a second checker would be added to the release queue, the second checker has been added, and the entry is marked done. Completion is a real fact and it is worth recording, but it is not the fact the register exists to establish. The agreed action was somebody's judgement, made months earlier and often under time pressure, about what would remove the weakness. Judgements are wrong sometimes. The second checker can be added exactly as promised and the duplicate releases can carry on. The queue they were coming from was not the queue anybody was watching.
The basis that works is closure evidenceProof that the weakness is gone, as distinct from confirmation that the agreed action was carried out.: something showing the weakness itself is no longer there. Not a statement that the action is complete. Something that could be handed to a person who was not in the room when the issue was raised and who has no reason to take anybody's word for it. Confirmation that the action was done is a claim about effort, and evidence that the weakness is gone is a claim about the world, and only the second one closes anything.
The household version is exact. The builder telephones to say the plumber has been and the dripping tap is sorted. The call is confirmation of an action. Turning the tap on and watching it not drip is evidence. The two are not the same and everybody knows it in a kitchen. The oddity is that the distinction goes missing on a register where the stakes are larger.
How that evidence is designed, what makes it sufficient, who is entitled to test it and what happens when the test fails all belong to controls and assurance. Issue management itself runs from the day a weakness is written down to the day something can be produced showing it is gone, and stops precisely there.
What actually closes an issue?
Who actually uses any of this, and how?
A register of weaknesses sounds like an internal artefact that stops at the office door. A register does not stop at the office door, and at least three people outside the institution read one and act on it.
Start with the lender. A lender is the reader whose money is on the table. When a bank renews a working capital facility to a manufacturer, somebody in the credit team asks for the list of open control weaknesses in the borrower's own finance and treasury functions and the dates against them. The lender is not looking for a short list. A short list can mean a well-run company or a company that raises nothing. The lender is looking for the flows and the dates: how many were raised in the year, how many were closed, and whether the dates on the open ones have been moved. A borrower whose register has grown every quarter for two years, or whose every date has been extended twice, has told the lender something about how it runs itself that no ratio in the accounts will show. The credit team therefore asks these questions at renewal and not only at the audit.
Next the analyst reading a listed company. Companies incorporated in India report on their internal financial controls, and the shape of that duty sits in the Companies Act and the assurance standards behind it. An analyst does exactly the arithmetic above with that disclosure. A company that reports weaknesses identified and remediated is describing flows. A company that reports a stable number of open items year after year has produced the flat report of the failure block, and the honest response is to ask what arrived and what closed rather than to record the stability as comfort.
Then the household, and this one is not a metaphor. Possession of a new flat brings a snag list within a week: fourteen entries, some with dates from the builder and some without. Everything above applies without a single change. The count that matters is what has been raised and what has been signed off, not what is outstanding. The date each entry was given is kept separately from the day it was first written down. When the builder asks for an extension, it is recorded as an extension rather than replacing the old date silently. Six extensions on one entry is the only record that will show what has actually been happening. And nothing closes on a phone call. The tap gets turned on. A snag list run this way and a bank register run this way are the same instrument at two scales, and the household version is where most people will first feel why the flows matter more than the pile.
Where the obligations on tracking a weakness actually come from
The mechanism set out here is jurisdiction free. A weakness, an owner, an agreed date, an age counted one way and lateness counted another, and a flow of arrivals against a flow of closures all behave identically wherever the register sits. Countries differ on what an institution is required to do about identifying, tracking, escalating and closing a control weakness, and the sources for that are named below.
The operational risk framework surrounding all of this, including the seven event categories used elsewhere in operational risk, is published by the Basel Committee on Banking Supervision at the Bank for International Settlements, bis.org, and is the origin of what an Indian rule then implements. The Basel Committee is a standard setting body and not an Indian supervisor, so what actually binds a bank in India comes from the Reserve Bank of India at rbi.org.in. Confirm at those sources what a bank must identify, how it must track it and what it must escalate.
Where the institution is a company rather than a bank, the duty to report on internal financial controls sits in the Companies Act, whose text, applicability and exemptions come from the Ministry of Corporate Affairs at mca.gov.in, and the assurance work behind that reporting follows standards issued by the Institute of Chartered Accountants of India at icai.org.
An ageing requirement, a closure standard, an escalation timeline and a reporting threshold are all set by a supervisor rather than by a register, and they differ from one jurisdiction to the next. No count taken from a single bank can establish any of them.
Sources
| Source | Document | Site |
|---|---|---|
| Reserve Bank of India | What an Indian bank must actually do about identifying, tracking, escalating and closing a control weakness, and the operational risk expectations surrounding it | rbi.org.in |
| Bank for International Settlements | The Basel Committee on Banking Supervision publications setting out the operational risk framework that surrounds a register of control weaknesses | bis.org |
| Ministry of Corporate Affairs | The Companies Act duty on internal financial controls, its applicability and the form of the report, where the institution is a company rather than a bank | mca.gov.in |
| Institute of Chartered Accountants of India | The assurance standard and guidance note behind reporting on internal financial controls | icai.org |
Vindhya Commercial Bank Limited is invented.
Educational material. Not advice on any investment, tax, budget or market position.
