The Remediation Plans module is the central hub for tracking every remediation plan created across your risk assessments, ensuring mitigation work is visible, owned and followed through to completion.
1. Overview
Every plan created on a risk is listed here with its RP reference, its linked risk and demand, its responsible, its due date with a live SLA countdown, and its status: Open, Pending Validation, Completed or Cancelled. An analytics strip at the top summarises the plans by status and highlights the Overdue count; clicking it applies the overdue filter.
Note: The list view is read-only. To work on a plan, open it (or its demand): the plan's detail page lets you update the RP Responsible, Description, Due Date and Implementation Challenges, and manage its status.
2. Due dates and SLA
Each plan tracks its deadline with a due date and an optional SLA. The due date chip opens the due date and SLA history: setting a new date requires a justification of change, and every change is kept in the plan's Due Date Change History. A plan is overdue when its due date is past and it is not completed or cancelled.
3. Completing a remediation plan
Completion is a two-step validation when a review workflow is enforced:
- Set RP as Completed: only the RP Responsible can take this action, and only while the plan is Open. With an Analyst or Assurance workflow enforced the plan moves to Pending Validation; with no enforcement it completes directly.
- Confirm Completion: with the Assurance review enforced, only an Assurance member can confirm, moving the plan to Completed.
4. Reopening a remediation plan
A completed plan can be reopened with Reopen RP, returning it to Open. Under an enforced workflow this is reserved for the Assurance (or Analyst) reviewers.
5. Deleting a remediation plan
Delete RP permanently deletes the plan after a confirmation. A completed plan must be reopened before it can be deleted.
Warning: Avoid deleting a remediation plan without proper justification: keeping the record maintains traceability and compliance with risk governance practice.
Privacy note. Personal details in this revision have been removed, masked or replaced for privacy. The original is retained privately.