Skip to main content
The Findings module is ISOwl’s Corrective Action Plan (PAC) tracker. It gives you a structured workflow to register non-conformities and opportunities for improvement, assign owners, set deadlines, track progress, and close findings with closing evidence.
The Findings module is separate from the Audit module. The Audit module is a log for findings identified during formal internal audits. The Findings module is where you manage the full remediation lifecycle.

Finding statuses

Findings move through three statuses:
StatusDescription
AbiertoFinding registered; no remediation progress yet (0%).
En TratamientoRemediation is underway (progress 1–99%).
CerradoFinding resolved; progress is 100% and a closed timestamp is recorded.
Status transitions are driven automatically by the progress value. Setting progress to 0 sets status to Abierto, any value 1–99 sets En Tratamiento, and 100 sets Cerrado. Clicking the Cerrar button directly sets progress to 100 and status to Cerrado in one action.

Registering a new finding

1

Navigate to Findings

Open the Findings module from the left sidebar.
2

Click Add Finding

Select Add Finding to open the registration form.
3

Complete the finding details

Fill in the required information:
FieldDescription
IDAuto-generated identifier (e.g., HAL-001)
TypeNC Mayor, NC Menor, Observación, or OFI
RequirementISO 27001 clause or subclause reference (e.g., 4.1)
DescriptionClear description of the finding
PACCorrective action plan — what will be done to resolve it
ResponsiblePerson or team accountable for resolution
Due dateTarget completion date (YYYY-MM-DD)
4

Submit

Click Save. The finding is created with status Abierto and progress at 0%.

Updating a finding

As remediation work progresses, update the finding to reflect current status:
1

Locate the finding

Find the finding in the PAC tracker table.
2

Edit the finding

Click the edit control on the finding row to open the update form.
3

Update fields

You can update the following fields:
  • Progress — Percentage complete (0–100)
  • Responsible — Reassign if ownership changes
  • Due date — Extend or bring forward the deadline
  • PAC — Refine the corrective action description
  • Closing evidence — Document or reference to evidence of resolution
4

Save changes

Click Save. The tracker table reflects the updated values immediately.
Update the Progress field regularly to keep your closure rate KPI accurate on the Security Metrics dashboard.

Closing a finding

1

Confirm resolution

Before closing, ensure the corrective action has been implemented and closing evidence is documented.
2

Add closing evidence

Enter a reference to the closing evidence (e.g., a document ID, test result, or meeting minute) in the Closing evidence field.
3

Click Close Finding

Select the Close Finding action. ISOwl automatically sets:
  • Status → Cerrado
  • Progress → 100%
  • Closed at → current timestamp
Closing a finding is a permanent action. Once a finding is marked Cerrado, its status and progress cannot be rolled back through the UI.

Finding lifecycle

Finding types and required actions

TypeDescriptionCorrective action required?
NC MayorMajor non-conformityYes — mandatory corrective action
NC MenorMinor non-conformityYes — corrective action required
ObservaciónObservationRecommended — monitor closely
OFIOpportunity for improvementOptional

Findings data reference

Each finding record contains the following fields:
FieldTypeExample
idstringHAL-001
typestringNC Mayor
requirementIdstring4.1
descriptionstringFinding description
pacstringCorrective action plan
responsiblestringAna García
dueDatestring2025-12-31
progressnumber0100
closingEvidencestringEvidence reference
statusstringAbierto | En Tratamiento | Cerrado
createdAtISO date2025-01-15T10:30:00.000Z

Frequently asked questions

The Audit module is an immutable log of findings identified during formal internal audits. The Findings module is the active corrective action tracker where you manage the full remediation lifecycle — assigning owners, setting deadlines, tracking progress, and recording closure evidence.
The Tasa de Cierre (closure rate) KPI on the Security Metrics dashboard is calculated from the ratio of closed findings to total findings. Keeping progress updated ensures an accurate picture of your remediation health.
A finding is counted as overdue (Hallazgos Vencidos) when its due date has passed and its status is still Abierto. The Security Metrics dashboard shows a count of overdue open findings.
Yes. The PAC tracker table supports filtering by finding type and status to help you focus on the most critical items.

Build docs developers (and LLMs) love