Stage 4 · CAPA
You raise the finding and set the severity. The auditee owns the CAPA — root cause, corrective action and deadline — and tracks it to closure.
Privileged access granted without periodic review.
You raise it against the control and categorise the severity. That call is yours — the AI never makes it.
No recertification cadence defined for privileged accounts.
The organisation records the root cause, writes the plan and sets the deadline. It is their fix to own.
access-review-q1.pdf — uploaded 26 Mar by M. Sepp
The auditee tracks every open finding in one view, and closure is gated on attached evidence.
Raised 14 Mar · cause recorded · plan committed · evidence on file · closed 02 Apr.
A year later you start from the record — what was promised, and whether it was done.
The problem
The finding is raised, exported to a spreadsheet, emailed to the client — and then goes quiet. A year later you return and nobody can say what the root cause was, who owned it, or whether it was ever fixed. The follow-up audit starts with a fresh round of interviews instead of a record.
What Kimova does
You make the call on severity. From there the exchange is with the auditee, and Kimova keeps it honest.
You bringA finding, categorised by you
A CAPA the auditee owns end to end — root cause, plan, deadline
You bringA first-pass root cause drafted by the AI
Something the auditee edits and submits, with severity left to you
You bringA year between audits
A record of what was promised, and whether it was actually done
What it changes
What was raised, what caused it, what was promised and what was delivered are already on file when the follow-up audit begins.
One view of every open CAPA with owners and deadlines, instead of a spreadsheet per audit and a scramble before you return.
'We've handled it' can't quietly become a closed CAPA you're accountable for.
Bring a finding from a real engagement and we'll run it through the handover — raised, owned, evidenced, closed.
Book a 30-minute walkthroughThe audit, end to end