Thinking / System design· Part 9 of 10 in From exception to decision
Closure should require evidence
Closing an exception should be the result of demonstrated conditions, not simply an administrative change of status.
- Closure
- Evidence
- Exceptions
- Governance
31 August 2026
On this page
Most workflow systems have a final status.
Closed.
Done.
Completed.
Resolved.
The status is useful because records cannot remain open forever.
But there is a risk when closure becomes something a user selects rather than something the evidence supports.
For material exceptions, the organisation should be able to explain why closure was justified.
Closure is often administratively simple
A conventional workflow might ask:
Resolution notes: __________ Status: Closed
That may be adequate for a routine service request.
It is less convincing for:
- an accepted safety deviation,
- a compliance exception,
- an integrity impairment,
- a material contractual obligation,
- or a management risk acceptance.
In those cases, closure represents an organisational statement:
We believe this matter no longer requires active governance.
That should have a basis.
Closure criteria can be explicit
The exact criteria will depend on the exception.
But a governance system might test:
- Has the exception been resolved?
- Are required actions complete?
- Is required evidence present?
- Has the expected control state been restored?
- Are related obligations satisfied?
- Is residual risk acceptable?
- Have decision conditions been fulfilled?
- Has required verification occurred?
- Is any follow-up monitoring still active?
Closure then becomes the consequence of those answers.
Not every criterion needs to apply to every case.
The useful idea is that the criteria are defined rather than assumed.
Resolved and closed are different
This distinction is important.
Resolved might mean:
The responsible team believes the cause has been addressed.
Verified might mean:
The required evidence shows that the expected state has been restored.
Closed might then mean:
All governance requirements associated with the case are complete.
That allows a record to be technically resolved but still remain open because, for example:
- a regulator acknowledgement is outstanding,
- effectiveness monitoring continues,
- a related obligation remains active,
- or independent verification has not occurred.
That is more accurate than using one status to represent several different realities.
Closure authority may differ from action ownership
The person who performs the work should not always be the person who decides that the governance matter can be closed.
For minor issues, that separation may be unnecessary.
For higher-consequence matters, it can be important.
For example:
Maintenance completes repair. Engineering verifies functionality. Operations confirms normal state. Authorised manager closes the exception.
Different roles provide different evidence.
That creates a stronger governance chain than:
Task owner clicks Closed.
Some exceptions should reopen automatically
Closure is not necessarily permanent.
Suppose the same control fails again shortly afterwards.
The new occurrence may be:
- a completely new event,
- recurrence of the previous issue,
- evidence that remediation failed,
- or evidence of a systemic weakness.
A useful system should retain those relationships.
For example:
EX-1842 closed → same condition returns 12 days later → EX-1918 linked as recurrence
That allows the organisation to see patterns that individual workflows hide.
Repeatedly closing the same exception may be evidence that the underlying operating model is not actually being corrected.
Closure history becomes assurance evidence
Once closure has structure, the organisation can ask:
- Which exception types reopen most often?
- Which actions repeatedly fail verification?
- Which temporary decisions are repeatedly extended?
- Which obligations are frequently at risk?
- Which teams close issues without independent evidence?
- Where is remediation time increasing?
- Which controls generate recurring exceptions?
That turns exception history into evidence about governance effectiveness.
The focus starts to move away from:
How many issues are open?
toward:
How well does the organisation resolve the conditions that create them?
That is a more useful management question.
Closure is a decision
For material matters, closure should be understood as another decision.
The organisation is taking the position that:
- sufficient evidence exists,
- required actions have occurred,
- obligations are satisfied or appropriately transferred,
- controls are restored,
- and no further active governance is required.
That position should be traceable.
Which evidence supported it?
Who had authority?
Was independent verification required?
When did closure occur?
If the issue later recurs, what had previously been considered sufficient?
Those questions matter because governance itself needs to be open to scrutiny.
And that brings us to the final layer.
If the organisation has designed the controls, managed the exception, made the decision, performed the actions and approved the closure, who asks whether that whole process was actually reliable?