The short answer
Freeze exception populations for comparable periods, normalize cause codes without erasing originals, link reopened and repeated instances, measure arrivals, completions, age, reviewer touch time where supportable, and downstream exposure, then choose separately between upstream correction, review-capacity change, control redesign, or a scoped acceptance decision.
Key takeaways
- Repeated labels do not necessarily share a cause.
- Backlog volume alone cannot distinguish demand from capacity.
- Fix recurrence upstream before adding permanent review labor.
Build comparable exception cohorts
Record period, account/process, exception identity, original cause label, normalized cause family, source version, first seen, reopened link, consequence class, owner, disposition, and closure evidence. Keep unknown separate from other.
Do not merge recurring dollar values when the underlying records differ.
Diagnose recurrence and flow together
| Pattern | Supporting evidence | Likely control response | Do not conclude |
|---|---|---|---|
| Same cause, repeated source | Stable upstream version and cohort | Correct source/control then retest | Reviewer is slow |
| Broad age growth | Arrivals exceed supported completions | Reprioritize or add bounded capacity | Exceptions are low quality |
| High reopen rate | Closure fails repeat evidence check | Improve acceptance/review evidence | More closures solve it |
| One reviewer bottleneck | Eligible work waits by assignment | Cross-train or redesign segregation | Self-review is independent |
Issue two decisions, not one blended score
The recurrence decision names systemic, repeated but unrelated, isolated, or unknown. The capacity decision names adequate, temporarily constrained, structurally constrained, or unmeasured. Assign a separate action and retest for each.
NIST audit-review and capacity-planning concepts are useful analogies, not a property-accounting standard.
Close with recurrence and capacity decisions with separate owners
Name the population, cutoff, evidence version, owner, decision, unresolved exceptions, next checkpoint, and downstream records updated. Preserve the earlier state rather than replacing it with a clean current screen.
Reopen the record when a late event, changed source, new affected item, or downstream consequence invalidates the signed conclusion.
Operational checklist
Mark your progress, then save a working copy. Selections reset when you leave this page. A checked box is not an approval or evidence of completion.
☐
Comparable periods frozen
☐
Original and normalized causes retained
☐
Reopened items linked
☐
Arrival/completion/age measured
☐
Consequences stratified
☐
Recurrence and capacity decided separately
☐
Correction retest scheduled
0 of 7 marked
Edge cases
- A cause label changed mid-period: bridge both versions.
- Touch time is unavailable: state the measurement gap rather than estimating it.
- One severe exception dominates: report consequence separately from counts.
Sources and references
Follow each source to check the underlying claim. Access checks and professional review are different steps.
1. Primary source · National Institute of Standards and Technology
SP 800-53 Rev. 5: Security and Privacy Controls for Information Systems and OrganizationsAudit correlation, contingency planning, capacity planning, and access-control concepts can inform bounded operating tests.
Source checked 2026-09-18
Automated source-access check: 2026-09-18.
Continue the workflow
Portfolio reconciliation sign-off samplingProperty-management close calendar dependency registerReconciliation reviewer-independence exception recordRevision history
2026-09-18
Initial Phase 6 operational article with distinct intent, original artifact, source limits, and AI-assisted technical review.