Work the deficiencies that failed control tests raise, move them through remediation to a passing retest, or accept the risk with a justification and a review date.
A deficiency is the record that a control test failed and what was done about it. The product also calls it an exception: the failure policy Open an exception creates one, and a control's Exceptions tab shows its Deficiency history. Deficiencies are never created by hand. Each one ends in one of two ways: a passing retest closes it, or someone accepts the risk instead of fixing the control.
A deficiency is different from a segregation exception, which lets someone test a control they also operate. For those, see govern control definitions and versions.
Product location: /qms/controls/deficiencies. Open Deficiencies in Controls.
Task | What you need |
|---|---|
See the Deficiency register and a control's deficiency history | View controls ( |
Record the cause, change severity, owner or due date, move a deficiency between stages, and record the retest | Manage controls ( |
Accept the risk | Accept control risk ( |
Admins can do all of these. Buttons you cannot use are not shown.
Product location: /qms/controls/deficiencies. Open Deficiencies in Controls.
A failing test raises a deficiency when the failure policy that applies is Open an exception, Exception, then CAPA or Create an action item. It is raised when the result counts: as soon as the test is saved, or, if the control needs a second approver, when the result is approved. A rejected result raises nothing. Log only raises nothing, and CAPA directly opens a CAPA without a register entry. See test a control and get it signed off.
The new deficiency gets a reference number, a title naming the control and what failed, and:
Setting | How it is set |
|---|---|
Severity | Critical when the design has gaps and the control did not run as designed. High when the design has gaps, or the control did not run as designed. Medium when it only ran with gaps. Low is available when you reassess a deficiency. |
Due date | By default 7 days after the deficiency is raised for Critical, 14 for High, 30 for Medium and 60 for Low. |
Owner | The implementation's owner, or the control's owner if the implementation has none. |
Status | Open |
The owner receives Control Deficiency Raised. Under Exception, then CAPA, a corrective CAPA with the source Control Test Failure is also opened, linked to the control and the deficiency, with the CAPA severity critical for a critical deficiency, major for high, and minor for medium or low. Work it in QMS; see manage corrective and preventive actions. Under Create an action item, an action item is assigned to the owner with the same due date.
Product location: /qms/controls/deficiencies. Open Deficiencies in Controls.
Open Controls, then Deficiencies. The Deficiency register starts with figures for the whole organisation:
Figure | What it counts |
|---|---|
Still outstanding | Deficiencies that are Open, Being fixed or Awaiting retest. |
High or critical | Outstanding deficiencies of those severities. |
Past their date | Outstanding deficiencies whose due date has passed. |
Risk accepted | Deficiencies settled by accepting the risk. |
Escalated to CAPA | Deficiencies with a CAPA. |
Closed by retest | Deficiencies closed by a passing retest. |
Filter with Any status, Any severity, Any owner, Outstanding only and Overdue only; Clear filters resets them. The table shows Reference, Control, Severity, Owner, Due (with, for example, 5 days overdue, or for an accepted risk Until a date or No expiry), Status and Escalated to (the CAPA number, or Action item).
Product location: /qms/controls/deficiencies. Open Deficiencies in Controls.
Select a row to open it. The top of the dialog shows the Control, Implementation, Where, Period tested, Design and Operation verdicts, the Policy applied and where it came from, and any CAPA with its status.
Under Work this deficiency:
Enter Why did the control fail? This is the field most often left blank and the one a reviewer needs most.
Adjust Severity, Owner or Due if your assessment differs, and choose Save.
Move the deficiency on as work progresses:
Status | Button to reach it | Allowed from |
|---|---|---|
Being fixed | Start fixing it | Open, Awaiting retest |
Awaiting retest | Ready to retest | Open, Being fixed |
Open | Back to open | Being fixed |
There is no button to close a deficiency. The panel How this closes explains why and offers Open the control.
Product location: /qms/controls/{controlId} (fallback: /qms/controls/deficiencies). Open the deficiency and choose Open the control, then select the Tests tab.
Choose Open the control, then Tests, then Record a test.
Under Does this answer an open deficiency?, choose the deficiency.
Record the retest as usual and choose Save.
If the retest passes, the deficiency closes when the result counts: as soon as the retest is saved, or, if the control needs a second approver, when the retest is approved. It then shows How it closed; the register counts it under Closed by retest, and the control's Exceptions tab shows Retest passed with the date. If the retest fails, the original deficiency stays open and the retest raises a new one, so the register shows both attempts. Move the original back to Being fixed and continue.
A closed deficiency can no longer be edited, because what it looked like when it was settled is part of the record.
Product location: /qms/controls/deficiencies. Open Deficiencies in Controls.
Accepting the risk settles a deficiency without the control being fixed: your organisation decides to live with the exposure. It is permanent in the record. The section Accept the risk instead is available while the deficiency is not closed or already accepted.
Open the deficiency and go to Accept the risk instead.
Enter Why is this acceptable?, for example "Compensating control CTL-9 covers the same failure mode until the platform migration lands in Q1." It is required.
Enter Review it again on. It cannot be in the past. Leave it empty only if the acceptance is genuinely permanent.
Choose Accept the risk.
The acceptance is recorded in your name, as the person with Accept control risk who accepted it, together with the date and your justification. The status becomes Risk accepted, and the dialog shows Accepted by and Justification, which stay readable after any expiry.
From 14 days before the review date, the deficiency owner is reminded with Risk Acceptance Expiring. Once the review date has passed, the deficiency returns to Open by itself and must be remediated or accepted again with a fresh justification. An accepted deficiency cannot be reopened by hand.
Product location: /qms/controls/deficiencies. Open Deficiencies in Controls.
Once an outstanding deficiency is more than three days past its due date, the owner's manager receives Control Deficiency Overdue. If the owner has no manager recorded, nobody is escalated to. Managers are set on each person's user record; see link people to their managers.
Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control from the Library and select the Exceptions tab.
Open the control and select Exceptions. Deficiency history starts with If a test fails, this control will: and the policy in force, with its source: Set on the implementation., Inherited from the control. or The organisation default, because nothing more specific is set. The table lists each deficiency's Reference, Severity, Raised by, Status and Outcome: Retest passed with the date, or the CAPA number. Open the deficiency register to work any of them.
Product location: /qms/controls/deficiencies. Open Deficiencies in Controls.
Controls overview: the Open exceptions figure links to the register. See framework coverage and the Controls overview.
QMS: CAPAs opened by Exception, then CAPA or CAPA directly.
Risk register: the failing test lowers the control's effectiveness, which feeds residual checks on the risks it is linked to. See controls and residual challenges.
Reporting: the Control Exception Register report.
Product location: /qms/controls/deficiencies. Open Deficiencies in Controls.
The second-quarter test of AC-07 Quarterly access review on the production AWS account found three leavers with access: Ran, with gaps. The implementation's policy is Open an exception, and AC-07 requires a second approver.
When the quality manager approves the result, a Medium deficiency is raised, owned by the cloud platform lead and due 30 days later. They receive Control Deficiency Raised.
The cloud platform lead opens it and enters the cause: "The leaver process did not notify the AWS administrator." They choose Start fixing it, remove the three accounts and add the AWS administrator to the leaver checklist.
They choose Ready to retest.
The internal auditor records a test for July to September, chooses the deficiency under Does this answer an open deficiency?, samples 25 accounts with all satisfactory, and records Well designed and Ran as designed.
The quality manager approves the retest in Awaiting my approval, which closes the deficiency. It shows Closed by retest, and AC-07's Exceptions tab shows Retest passed.
Had the fix been months away, the quality manager could instead have accepted the risk with a justification naming the compensating monthly check, and a review date at the end of the quarter.