Root cause
The mechanism that produced a weakness, found by asking "why" until the answer stops describing one instance and names how the file was assembled or how a control was designed. Fixing the root cause governs a category of findings.
Defined in 5 GAGE programs, which carry 9 distinct definitions of it. The wording above is taught in AI Governance: Applied Mastery.
How each discipline defines it
The same term does different work depending on who is using it. These are the definitions as each program teaches them, unedited.
The earliest identifiable decision or condition in a causal chain that, had it been different, would have prevented the failure or substantially reduced its severity. A root cause is not necessarily a careless or unreasonable decision; well-reasoned engineering judgments, made under real constraints, are frequently documented as root causes once their consequences become clear. (see Topic 3.3)
The underlying condition that is the necessary and sufficient cause of an observed failure, as distinct from the symptom (the observed behavior) and from proximate causes (conditions that contributed to the failure but whose absence would not have prevented it). Finding the root cause is the goal of the diagnostic procedure; fixing only symptoms leads to recurrence.
A single, primary explanation for why an incident occurred. This topic treats the search for one root cause with caution, since real incidents commonly involve multiple independent contributing factors that each need their own remediation.
The mechanism that produced a weakness, found by asking "why" until the answer stops describing one instance and names how the file was assembled or how a control was designed. Fixing the root cause governs a category of findings.
The specific, evidenced point of failure that produced an incident, distinguished from a symptom (what was first noticed) and from an unfalsifiable general claim (such as "the model is unreliable").
Where it is taught
The exact lessons this term appears in. The first 7 topics of every program are free with a free account.
- After the Incident · Rollout, Monitoring, and Incident Response, Agentic AI Governance: Applied Mastery
- The post-incident review: fixing the estate, not blaming the intern · Data Incidents, AI Data Governance: The Data Chair
- Governance that survives: rebuilding the file so the next attack finds less · Adversarial Governance, AI Governance: Applied Mastery
Terms it appears with
Not an alphabetical neighbourhood: these are the terms taught in the same lessons, ranked by how often they appear together.