Companies do not need an elaborate root cause analysis policy, Jonny Frank, Kaitlyn Cecala and Annie Budra of consultancy StoneTurn write. They need practical written guidance addressing when to consider RCA, how far to go, who should participate, what to document and how to determine whether corrective action worked.
The worst time to decide how to perform a root cause analysis (RCA) is after a serious compliance failure has become a board, senior management or regulator issue. By then, the organization may face compressed deadlines, privilege concerns, incomplete facts and competing views about whether the problem is isolated or systemic. Even when everyone agrees that the company should fix the root cause, they may disagree about what that means, how deep to go, who should lead, what to document and when corrective action is enough.
RCA sits at the center of the remediation narrative: Why did this happen? Does a similar risk exist elsewhere? What evidence shows the fix works?
Regulators and prosecutors ask the same questions. The DOJ’s corporate enforcement and voluntary self-disclosure policy requires companies seeking its benefits to demonstrate “timely and appropriate remediation,” including a “thorough analysis of the causes of underlying conduct (i.e., a root cause analysis)” and, where appropriate, remediation of those causes. The CFTC’s 2026 cooperation policy similarly makes timely and appropriate remediation a condition for certain declinations and cooperation credit.
The trend is not only domestic. The OECD’s 2021 anti-bribery recommendation encourages countries to consider timely and appropriate remediation when rewarding good corporate behavior. Norway’s Okokrim corporate-penalty guidelines for international corruption cases likewise consider prevention, self-reporting, cooperation and corrective action. Although the legal mechanics differ, companies increasingly must show how they understood and addressed the causes of misconduct.
Despite this, many companies still lack written RCA guidance. Some have not converted RCA from an ad hoc exercise into a repeatable process. Others worry that a policy will create a standard that plaintiffs, regulators or monitors can use against them. That concern is real: Guidance that overpromises, requires a full RCA for every incident or mandates impractical steps creates unnecessary risk.
The answer is right-sized guidance that preserves judgment while making decisions more consistent and defensible.
The decision to conduct an RCA
Guidance should not require a full RCA whenever something goes wrong. Instead, it should require a risk-based assessment of two questions: How likely is the issue to reflect a broader risk? And, how serious would the consequences be?
Likelihood should encompass future recurrence, present read-across and past look-back. Could the same failure happen again? Could it exist in another business unit, geography, product, third-party relationship, system or control process? Could it have occurred before but remain unidentified?
Impact factors may include legal or regulatory exposure; financial, customer, employee or investor harm; accounting or reporting implications; reputational damage; senior management or board concern; and signs of weakness in the control environment or culture.
Some companies score likelihood and impact against risk appetite. A low score may support a documented rationale and immediate fix; a moderate score, a limited RCA; and a high score, a formal RCA with read-across, senior oversight, look-back work or a formal remediation plan. The thresholds matter less than the discipline they create.
Scoring should guide, not replace, judgment. Fraud, senior-management involvement, intentional misconduct, concealment, retaliation, repeat findings, financial reporting, significant harm or control-environment weaknesses may warrant an RCA regardless of score. Legal, contractual, regulatory or board mandates should also override ordinary thresholds.
Document the decision
A company may reasonably decide not to conduct a full RCA. It should not appear to have made no decision at all. A concise decision record should identify the issue, factors considered, rationale for the selected RCA level, immediate corrective action and circumstances that would prompt reconsideration. It can later explain why the company treated one incident as isolated and another as requiring deeper analysis.
Contemporaneous documentation also guards against hindsight by showing that the company considered relevant factors and made a reasoned decision consistent with its guidance.
At a minimum, RCA guidance should address scope, ownership, required questions, expected output, trend review and the circumstances in which remediation should be tested.
- Scope should match the risk. A limited RCA may focus on one process, control, function, business unit or geography. An enhanced RCA may require document review, data analysis, interviews, control testing, look-back work or read-across. Scope should remain adjustable as facts develop.
- Ownership should be clear. Legal, compliance, internal audit, human resources, finance, operations and the business may contribute, but the guidance should identify who decides whether RCA is required, leads it, approves conclusions and owns corrective action.
- Questions should go beyond symptoms. What incentives or pressures contributed? What weakness in controls, supervision, training, escalation, data, governance or culture allowed the issue? Was it isolated, repeated or systemic? Could it exist elsewhere or have occurred before? Were earlier warning signs missed? What facts support the conclusions?
- Output should identify the issue, scope, information considered, root causes, read-across, limitations, recommended next steps and any plan to test corrective action. Details should reflect the issue’s seriousness and the confidence management needs to place in the conclusions.
- Consider trends. Wells Fargo investigated thousands of employees for opening unauthorized customer accounts between 2002 and 2016, repeatedly treating termination of individuals as the solution. The bank did not conduct a root cause analysis until 2017 and later paid $3 billion to resolve criminal and civil investigations.
Connect root causes to remediation & testing
RCA should lead to a decision about corrective action, and that decision should distinguish correcting the incident from fixing its cause. Disciplining an employee, refunding a customer or updating a procedure may address the event but not the underlying conditions that allowed it. The question is what risk remains after the company corrects the immediate incident.
Depending on that remaining risk, the response may range from documentation and monitoring to targeted corrective action, a formal remediation plan, control redesign, governance changes, broader read-across, independent testing or board reporting.
Testing is how the company confirms the cause was addressed; it’s not an add-on. It answers a management question: What evidence will show that the company changed the condition that allowed the problem? A lower-risk issue may call for owner certification, a spot-check or recurrence monitoring. A systemic issue may require sampling, analytics, interviews, control-performance testing, senior reporting or independent validation.
Read-across may reveal that a local failure reflects broader weaknesses in the same conditions. The response should expand with the risk, potentially including prior-transaction testing, control redesign, clarified accountability or board reporting. Guidance should require management to decide whether testing is necessary, what evidence will suffice, who will test, when testing will occur and how exceptions will be addressed.
Avoid turning guidance into a trap
Practical guidance should avoid overpromising. It should define minimum expectations, preserve discretion and require documentation when management departs from ordinary thresholds or work steps.
It should also address privilege and investigative discipline. Because RCA often runs alongside an internal investigation, the company should define workstream ownership, privilege protocols, interview sequencing and how early hypotheses will be validated. RCA conclusions should not outrun the facts, but early control, governance, incentive or culture hypotheses may help identify issues requiring attention if the investigation validates them.
The objective is proportionality, not a rigid checklist: enough discipline to choose and explain the right level of effort for the risk.


Jonny Frank
Kaitlyn Cecala
Annie Budra







