Every threat with a decided tier needs a remediation task, the plan needs an attestation within ninety days, and overdue critical items surface rather than sitting quietly.
The risk analysis finds the gaps. This is the separate Required obligation to do something about them, and it is where a clinic that did the hard part still fails, by finding everything and fixing nothing.
Risk management does not run on a policy document. It runs on the risk engine itself, sitting over your risk analysis and reconciling findings against action.
Six requirements:
The fourth requirement is the reconciliation. A finding you decided to remediate but never created a task for shows as a gap, which is exactly the failure mode where the analysis becomes an exhibit against you: documented knowledge of a risk with no record of acting on it.
The system reconciles records and dates. It tracks that tasks exist for decided findings, that they are on schedule, and that the plan carries a recent attestation. It does not evaluate whether a remediation actually reduced risk, or whether the plan’s contents are adequate to the findings.
The ninety-day attestation window matters here. A plan attested a year ago is not current under this check, which prevents the plan from becoming the same stale artifact the risk analysis was supposed to replace.
A signed risk analysis, an attested plan with a recent date, a tier decision on every applicable threat, and a task record for every finding you decided to act on. The answer to the question that follows “you knew about this,” which is: and here is what we did.
The regulation: read the rule behind this control.
No pressure, no pitch. Book a 20-minute call, or just email a question and we'll point you the right way.