Risk and compliance operations where every finding reaches the area that must fix it — and closes with evidence
Mi Retail is the operations center for governance, risk and compliance teams: the reported incident, the risk assessment, the corrective actions spread across areas and the audit verification become work items with an owner, a state and evidence. Your GRC platform keeps the register and the controls; Mi Retail makes sure the areas actually act.
Why do corrective actions stall after an incident or an audit finding?
Corrective actions stall because the GRC team can record the risk but cannot execute the fix: the fix belongs to procurement, finance, operations or IT, areas that never open the risk register. The action travels as an email and a row in a spreadsheet, and the next audit discovers it never closed.
-
The register is not where the work happens
The risk and the finding live in the GRC platform; the people who must fix them live in their own tools.
-
Follow-up means chasing
Compliance spends its week asking area managers for status updates and evidence by email.
-
Evidence arrives at audit time
Proof that a control was changed is collected the week before the audit, if anyone can still find it.
How do GRC teams handle this today?
Most governance, risk and compliance teams keep the risk register and the audit program in a GRC platform or a spreadsheet, and chase corrective actions through email and follow-up meetings.
Specialized software
What it does well
Risk registers, control libraries, audit programs and policy repositories are structured, versioned and reportable.
Where the work leaves it
The corrective action leaves the platform: the areas that must fix the process rarely work in it, so assigning, unblocking and proving the fix continue by email and spreadsheets until the next audit.
GRC platforms — e.g. Archer, MetricStream, AuditBoard1
Indie and AI-built apps
What it does well
A corrective action tracker or a findings form built in days gives compliance a list quickly.
Where the work leaves it
It is one more list the areas must remember to check, with no link to their daily work, no escalation and no evidence standard an auditor can rely on.
No system at all
What it does well
A shared spreadsheet of findings and a monthly follow-up meeting are familiar and flexible.
Where the work leaves it
Owners change, due dates slide without anyone noticing, and closing a finding means collecting screenshots and emails the week before the audit.
Keep your GRC platform. Mi Retail takes over where the work leaves it: between compliance, the areas that must fix the process and the auditors who verify it.
Start freeHow does a compliance incident become corrective actions that actually close?
A new supplier was paid before its due-diligence check cleared. Here is how the incident moves through Mi Retail — from the report to the risk assessment, the corrective actions in two areas and the audit verification — with the state of each work item on Tuesday afternoon.
Step by step
- Risk & compliance Completed
Supplier paid before due diligence
An accounts payable analyst reports that Halden Supply was paid before its due-diligence check cleared, and compliance records it as an incident work item that holds the whole case.
- Risk & compliance Completed
Assess risk · supplier onboarding
Compliance rates likelihood and impact, links the control that failed and opens finding F-17 with corrective actions for procurement and finance.
- Procurement Completed
Re-run due diligence · Halden Supply
Procurement re-runs the full due-diligence check on the supplier as a child work item and attaches the report and the screening result.
- Finance Ready
Approve temporary risk acceptance
The CFO, as risk owner, decides whether Halden stays active with payments on hold until the new control is live, with the assessment and the options in front of them.
- Finance Blocked
Block payments to unverified suppliers
Finance must add a payment block for suppliers without cleared due diligence; the work item is blocked until the ERP administrator opens the next change window, and the reason is on record.
- Procurement In progress
Update onboarding procedure · train buyers
Procurement updates the supplier onboarding procedure and records which buyers completed the walkthrough of the new steps.
- Internal audit New
Verify finding F-17 and close
Once every corrective action closes with evidence, internal audit tests a sample of new suppliers and closes the finding, or reopens the action that did not hold.
One work item, opened
The CFO, as risk owner, decides whether Halden stays active with payments on hold until the new control is live, with the assessment and the options in front of them.
What changes for the GRC team
- Every finding has corrective actions with an owner, a state and a due date inside the areas that must act.
- Compliance sees what is blocked and why, without asking anyone for a status update.
- Risk acceptances and exceptions are decided on the work item, with the reason and the expiry on record.
- Internal audit verifies closures against evidence captured while the work happened.
Apps involved
- Risk In StoneOS
- Controls In StoneOS
- Incidents In StoneOS
- Corrective Actions In StoneOS
- Audit In StoneOS
- Obligations In StoneOS
- The GRC platform you already use Keep your current system
Frequently asked questions: Governance, risk & compliance
What is Mi Retail for governance, risk and compliance teams?
Mi Retail is an operations center that manages the human work around governance, risk and compliance. Your GRC platform or register keeps the risks, controls, policies and audit program; Mi Retail handles what has to happen when one of those records needs people to act. A reported incident, a risk assessment, a corrective action for another area, a risk acceptance that needs a decision and an audit verification each become an Operational Work Item with an owner, a state, a due date and evidence. The areas that must fix the process receive their part in their own My Work, compliance sees what is blocked and why, and internal audit reviews closures against the evidence captured along the way.
Does Mi Retail replace our GRC platform or risk register?
No. Your GRC platform — or the spreadsheet that works as your register — stays the system of record for risks, controls, policies, audit plans and ratings, and Mi Retail never keeps a second register. Mi Retail covers the part those tools were not built for: getting people outside the GRC team to act. The register can say that a control failed and a corrective action is due; Mi Retail manages who must carry it out, what it is waiting for, when it must escalate and with which evidence it can close. The areas never have to learn the GRC platform. Keep your GRC platform; Mi Retail takes over where the work leaves it.
How does an incident move from the first report to a closed finding?
An incident is reported — through a form, an area manager or a system alert — and compliance records it as an incident work item that holds the whole case. Compliance assesses likelihood and impact, links the control that failed and opens corrective actions as child work items for each area that must act. If a temporary risk acceptance is needed, it goes to the risk owner as an approval. Each area closes its action with evidence, and a blocked action carries its reason, so compliance knows exactly what is missing. When every action is closed, internal audit tests the fix and closes the finding, or reopens the action that did not hold.
How are corrective actions assigned across several areas and followed until they close?
Each corrective action is a child work item of the finding, assigned to a person in the area that must act — procurement, finance, operations, IT or human resources — with a due date and a clear description of the expected result. The owner sees it in My Work next to the rest of the day, not in a platform they rarely open. Area coordinators see their team’s actions in Team Operations and can reassign them. When an action depends on something outside the area, such as a system change or a supplier document, it is marked blocked with the reason. Compliance sees every action of every finding in one place, by age and state, without sending a single status email.
How are risk acceptances and policy exceptions approved?
A risk acceptance or a policy exception is an approval work item in the risk owner’s queue, with the assessment, the options, the compensating measures and a due date attached. The risk owner approves or rejects from the work item, and the decision is recorded with its reason, its scope and its expiry. If the decision is not made in time, the coordinator sees it at risk and can escalate it to the next level, which receives the same context instead of a forwarded message. When a temporary acceptance expires, a follow-up is created so the exception is reviewed rather than silently becoming permanent. Leadership sees only the acceptances that exceed the lower levels.
How does internal audit verify and close a finding in Mi Retail?
Internal audit receives a verification work item for the finding once its corrective actions are closed, with every action, owner, date and piece of evidence linked to it. The auditor can test a sample, request more evidence from a specific action or reopen it if the fix did not hold, and each of those steps is recorded as part of the same trail. Control & Assurance gives audit a view across findings: which are open, which are overdue, which were reopened and which areas keep missing their dates. Because evidence is captured while the work happens, audit reviews facts instead of rebuilding them from emails and screenshots.
Does Mi Retail make us compliant or certify anything?
No. Mi Retail does not certify an organization, interpret regulations or decide whether a control is adequate; those judgments belong to your compliance team, your auditors and, where relevant, your regulators. What Mi Retail provides is operational discipline around those judgments: every incident, action, approval and verification has an owner, a state, a due date and evidence, and the trail shows who decided what and when. That record can support an audit or a regulatory review, because it shows that the organization acted on what it found. The conclusion about compliance, however, always stays with the people and bodies responsible for it, not with the software.
How do obligations, policy reviews and contract deadlines become work?
Obligations, policy reviews and contract milestones generate work on a calendar, and Mi Retail turns each one into a work item when it needs a person. A regulatory report due at quarter end, a policy that must be reviewed every year, a contract renewal notice or a supplier certificate about to expire becomes a work item with an owner and a due date well before the deadline. The owner prepares the deliverable, the approver signs it off from the same work item and the result is stored as evidence. Compliance sees upcoming obligations by area and date, and nothing depends on someone remembering a date in a spreadsheet.
Who sees what, and can sensitive incidents be kept restricted?
Each role sees what it is responsible for. Area owners see only the corrective actions assigned to them, compliance sees the incidents, findings and actions of the whole program, internal audit sees the trails it must verify, and executives see in Executive Operations only the findings and acceptances that need their decision. Sensitive incidents, such as an internal investigation, can live in a restricted workspace where only the designated people see the case, while the resulting corrective actions go to the areas without exposing the details behind them. Access follows the organization’s identity structure, so when someone changes role, what they see changes with them.
Can suppliers, external auditors or other organizations take part?
Yes, when they have their own organization on Mi Retail. A request to a supplier — an updated certificate, a completed questionnaire, evidence of a corrective action on their side — can travel as a derived work item that lands in the supplier’s own intake queue; you follow its state and result without seeing their internal work, and your finding closes when theirs does. An external audit firm can take part the same way, or as an external collaborator with a limited surface that shows only the shared work and the evidence it must review. Each organization keeps its privacy, and the exchange stops depending on email threads that nobody can reconstruct later.
Which StoneOS apps come with the Governance suite?
The Governance suite of StoneOS brings apps for the domain work of governance, risk and compliance: contracts, obligations, policies, records, risk, controls, compliance, audit, incidents and corrective actions. They sit on top of the Business Core apps every team uses, such as Docs, Drive, Sheets, Chat and To-do. Those apps keep the depth of each domain — the risk register, the control library, the audit program. Mi Retail is where the work they generate meets the people who must act: a control that failed its test, an obligation coming due or a corrective action for another area lands as a work item in the right queue. If you keep your current GRC platform, it stays the record.
Does Mi Retail work for a one-person compliance function as well as a large group?
Yes. In a small organization, compliance is often one person who also runs finance or operations, and Mi Retail adapts: one Today view with open incidents, actions due this month and upcoming obligations, without committees or hierarchies that do not exist. In a large group, the same work items are distributed across a central risk team, compliance officers per business unit, area owners, internal audit and an audit committee, each with its own surface, and escalations reach the right level. The way an incident, an action or a verification is represented does not change, so the program can grow from one person to several teams without migrating anything.
How does a GRC team get started with Mi Retail?
Start with the findings that are already open, rather than modeling the whole GRC program. Create a workspace for compliance, invite the owners of the areas that have corrective actions pending and move those actions into Mi Retail as work items with an owner and a due date. Within a few weeks you will see which actions are blocked, which areas miss their dates and where evidence is missing. Then bring in incident reporting and risk acceptances, invite internal audit to verify closures, connect the GRC platform or register you already use and, if it fits, add the Governance suite apps from StoneOS. Mi Retail is free to start.
Put the work in motion with Mi Retail
Start free with your team, bring in the systems you already use, and give every request an owner, a state and a result.
Run the GRC program on StoneOS
Policies, risks, controls and audits run in StoneOS Governance. Mi Retail makes sure every area acts on them.
Arjun Mehta