No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Risk

Root Cause Analysis: Right-Sized Guidance Before the Crisis Hits

RCA guidance helps a company avoid improvisation, apply consistent criteria and distinguish fixing an incident from fixing its cause

by Jonny Frank, Kaitlyn Cecala and Annie Budra
August 25, 2026
in Risk
tree roots overlapping

Companies do not need an elaborate root cause analysis policy, Jonny Frank, Kaitlyn Cecala and Annie Budra of consultancy StoneTurn write. They need practical written guidance addressing when to consider RCA, how far to go, who should participate, what to document and how to determine whether corrective action worked.

The worst time to decide how to perform a root cause analysis (RCA) is after a serious compliance failure has become a board, senior management or regulator issue. By then, the organization may face compressed deadlines, privilege concerns, incomplete facts and competing views about whether the problem is isolated or systemic. Even when everyone agrees that the company should fix the root cause, they may disagree about what that means, how deep to go, who should lead, what to document and when corrective action is enough.

RCA sits at the center of the remediation narrative: Why did this happen? Does a similar risk exist elsewhere? What evidence shows the fix works?

Regulators and prosecutors ask the same questions. The DOJ’s corporate enforcement and voluntary self-disclosure policy requires companies seeking its benefits to demonstrate “timely and appropriate remediation,” including a “thorough analysis of the causes of underlying conduct (i.e., a root cause analysis)” and, where appropriate, remediation of those causes. The CFTC’s 2026 cooperation policy similarly makes timely and appropriate remediation a condition for certain declinations and cooperation credit.

The trend is not only domestic. The OECD’s 2021 anti-bribery recommendation encourages countries to consider timely and appropriate remediation when rewarding good corporate behavior. Norway’s Okokrim corporate-penalty guidelines for international corruption cases likewise consider prevention, self-reporting, cooperation and corrective action. Although the legal mechanics differ, companies increasingly must show how they understood and addressed the causes of misconduct.

Despite this, many companies still lack written RCA guidance. Some have not converted RCA from an ad hoc exercise into a repeatable process. Others worry that a policy will create a standard that plaintiffs, regulators or monitors can use against them. That concern is real: Guidance that overpromises, requires a full RCA for every incident or mandates impractical steps creates unnecessary risk.

The answer is right-sized guidance that preserves judgment while making decisions more consistent and defensible.

The decision to conduct an RCA

Guidance should not require a full RCA whenever something goes wrong. Instead, it should require a risk-based assessment of two questions: How likely is the issue to reflect a broader risk? And, how serious would the consequences be?

Likelihood should encompass future recurrence, present read-across and past look-back. Could the same failure happen again? Could it exist in another business unit, geography, product, third-party relationship, system or control process? Could it have occurred before but remain unidentified?

Impact factors may include legal or regulatory exposure; financial, customer, employee or investor harm; accounting or reporting implications; reputational damage; senior management or board concern; and signs of weakness in the control environment or culture.

Some companies score likelihood and impact against risk appetite. A low score may support a documented rationale and immediate fix; a moderate score, a limited RCA; and a high score, a formal RCA with read-across, senior oversight, look-back work or a formal remediation plan. The thresholds matter less than the discipline they create.

Scoring should guide, not replace, judgment. Fraud, senior-management involvement, intentional misconduct, concealment, retaliation, repeat findings, financial reporting, significant harm or control-environment weaknesses may warrant an RCA regardless of score. Legal, contractual, regulatory or board mandates should also override ordinary thresholds.

us doj building with flag
Featured

Once You’ve Decided to Self-Disclose, Here’s How to Do It Right

by Sean M. Farrell and Thomas F. Rybarczyk
July 29, 2026

Read moreDetails

Document the decision

A company may reasonably decide not to conduct a full RCA. It should not appear to have made no decision at all. A concise decision record should identify the issue, factors considered, rationale for the selected RCA level, immediate corrective action and circumstances that would prompt reconsideration. It can later explain why the company treated one incident as isolated and another as requiring deeper analysis.

Contemporaneous documentation also guards against hindsight by showing that the company considered relevant factors and made a reasoned decision consistent with its guidance.

At a minimum, RCA guidance should address scope, ownership, required questions, expected output, trend review and the circumstances in which remediation should be tested.

  • Scope should match the risk. A limited RCA may focus on one process, control, function, business unit or geography. An enhanced RCA may require document review, data analysis, interviews, control testing, look-back work or read-across. Scope should remain adjustable as facts develop.
  • Ownership should be clear. Legal, compliance, internal audit, human resources, finance, operations and the business may contribute, but the guidance should identify who decides whether RCA is required, leads it, approves conclusions and owns corrective action.
  • Questions should go beyond symptoms. What incentives or pressures contributed? What weakness in controls, supervision, training, escalation, data, governance or culture allowed the issue? Was it isolated, repeated or systemic? Could it exist elsewhere or have occurred before? Were earlier warning signs missed? What facts support the conclusions?
  • Output should identify the issue, scope, information considered, root causes, read-across, limitations, recommended next steps and any plan to test corrective action. Details should reflect the issue’s seriousness and the confidence management needs to place in the conclusions.
  • Consider trends. Wells Fargo investigated thousands of employees for opening unauthorized customer accounts between 2002 and 2016, repeatedly treating termination of individuals as the solution. The bank did not conduct a root cause analysis until 2017 and later paid $3 billion to resolve criminal and civil investigations. 

Connect root causes to remediation & testing

RCA should lead to a decision about corrective action, and that decision should distinguish correcting the incident from fixing its cause. Disciplining an employee, refunding a customer or updating a procedure may address the event but not the underlying conditions that allowed it. The question is what risk remains after the company corrects the immediate incident.

Depending on that remaining risk, the response may range from documentation and monitoring to targeted corrective action, a formal remediation plan, control redesign, governance changes, broader read-across, independent testing or board reporting.

Testing is how the company confirms the cause was addressed; it’s not an add-on. It answers a management question: What evidence will show that the company changed the condition that allowed the problem? A lower-risk issue may call for owner certification, a spot-check or recurrence monitoring. A systemic issue may require sampling, analytics, interviews, control-performance testing, senior reporting or independent validation.

Read-across may reveal that a local failure reflects broader weaknesses in the same conditions. The response should expand with the risk, potentially including prior-transaction testing, control redesign, clarified accountability or board reporting. Guidance should require management to decide whether testing is necessary, what evidence will suffice, who will test, when testing will occur and how exceptions will be addressed.

Avoid turning guidance into a trap

Practical guidance should avoid overpromising. It should define minimum expectations, preserve discretion and require documentation when management departs from ordinary thresholds or work steps.

It should also address privilege and investigative discipline. Because RCA often runs alongside an internal investigation, the company should define workstream ownership, privilege protocols, interview sequencing and how early hypotheses will be validated. RCA conclusions should not outrun the facts, but early control, governance, incentive or culture hypotheses may help identify issues requiring attention if the investigation validates them.

The objective is proportionality, not a rigid checklist: enough discipline to choose and explain the right level of effort for the risk.

Tags: Corporate CultureRisk Assessment
Previous Post

Why Small Gestures Matter in Chinese Business Culture

Jonny Frank, Kaitlyn Cecala and Annie Budra

Jonny Frank, Kaitlyn Cecala and Annie Budra

Jonny Frank, a partner with StoneTurn in New York, brings more than 40 years of public, private and education sector experience in forensic investigations, compliance and risk management.
Kaitlyn Cecala CPA, is a managing director at StoneTurn. She has assisted clients with a variety of corporate investigations related to fraud and embezzlement, improper revenue recognition and reserve manipulation.
Annie Budra, CPA, is a manager with StoneTurn. Her experience includes conducting comprehensive risk assessments for corporate internal control programs, as well as testing the design and effectiveness of processes and controls.

Related Posts

chinese flag flying over shanghai

Why Small Gestures Matter in Chinese Business Culture

by Catherine Xiang
August 25, 2026

Seemingly tiny interactions can have a big impact

capitol building

So You’ve Been Subpoenaed by Congress? How to Prepare for Lawmakers’ Grilling

by Robert S. Hoff and Julie A. Edelstein
August 18, 2026

A congressional investigation is a high-stakes event where the response matters as much as the underlying facts

ways and means meeting room

As Midterms Approach, Specter of Transcribed Interviews Rises for Non-Governmental Actors

by Jason McCullough, Diana Shaw and Peter Rechter
August 18, 2026

TIs are informal, but records are kept and they are increasingly being videotaped

woman checking clock in middle of night

The Hidden Link Between Sleep Deprivation & Fear of Failure at Work

by Melisa Buie
August 14, 2026

Compliance will never be low-stress, but it does not have to be self-defeating

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights