An issue rating influences who is informed, how quickly corrective action is expected and which risks receive scarce attention. If similar weaknesses receive different ratings across teams, the label stops being a reliable management tool.

01

Common criteria create a shared language

Leaders define how actual and potential customer harm, legal or compliance exposure, financial loss, operational disruption, data impact and control breakdown affect severity. The method distinguishes the seriousness of the weakness from the effort required to fix it.

Clear criteria reduce reliance on labels such as significant or urgent without explaining why. Examples and thresholds support judgment, but they do not replace consideration of facts that fall between standard cases.

02

Evidence matters more than organizational rank

The proposed rating is supported by the issue's scope, duration, affected population, control design, detected outcomes and plausible consequences. A confident presentation by a senior owner is not evidence that the exposure is small.

People with appropriate independence can question assumptions, request missing information and identify connected weaknesses. Challenge is separated from personal criticism so teams can debate the rating without discouraging early reporting.

03

Calibration compares similar cases

A cross-functional forum reviews borderline or material issues against prior decisions and issues in other business areas. Comparing cases helps prevent one team from routinely understating weaknesses while another assigns the highest rating to every exception.

The group records why differences are justified. Two issues involving the same control can deserve different ratings if their scale, customer effect, duration or compensating controls are materially different.

04

Severity drives a proportionate response

The classification informs escalation, reporting, interim controls, target dates, resource decisions and the level of approval needed for any extension. A severe issue generally requires faster and more senior attention, but it still needs a corrective plan that can work.

Urgency and severity are related but not identical. A lower-impact weakness may need immediate containment, while a complex high-severity issue may require a longer permanent fix supported by strong interim protection and close oversight.

05

Ratings can change when the facts change

New customer impact, broader scope, control failure or effective containment can change the assessment. Any upgrade or downgrade is documented with the evidence, authority and consequences for the response plan rather than being used to make overdue work appear healthier.

Leaders review rating patterns, aging, extensions and closure validation across the portfolio. Consistent classification helps them see where risk is accumulating and whether the organization is fixing important problems—not merely improving reported statistics.

Sources

Read the primary material

Banking Explained prioritizes regulators, official publications and first-party announcements.