A control is a measure that modifies risk. Controls may prevent events, detect change, correct conditions, limit consequences, or support recovery. Their value depends on design, operation, coverage, timing, and reliability.
Design effectiveness
Ask whether the control, if performed as intended, addresses a material cause or consequence. Consider coverage, frequency, precision, segregation, independence, and whether the control can be bypassed.
Operating effectiveness
Ask whether the control actually operated during the period, by the right people, using reliable information, with evidence and timely follow-up. A written procedure alone is not proof of operation.
Control types
| Type | Purpose | Example |
|---|---|---|
| Preventive | Reduce likelihood | Approval, barrier, validation rule |
| Detective | Reveal events or conditions | Reconciliation, alert, inspection |
| Corrective | Restore expected condition | Repair, data correction |
| Mitigating | Reduce consequence | Containment, backup capacity |
| Directive | Set required behaviour | Policy, standard, procedure |
Assurance and testing
Use evidence proportionate to the risk: observation, sample testing, logs, reconciliations, performance data, independent review, or audit. Consider common-mode failures and shared dependencies.
Control record
- Control objective
- Owner and operator
- Frequency and trigger
- Required evidence
- Performance standard
- Dependencies and failure modes
- Test method and latest result
- Remediation and escalation
Distinguish design and operation
A control may be well designed but inconsistently performed, or regularly performed but incapable of reducing the stated risk. Design effectiveness asks whether the control could achieve its purpose. Operating effectiveness asks whether it is performed as intended, by the right people, at the right frequency, with reliable evidence.
Use several forms of assurance
Evidence may include records, observation, interviews, data analysis, testing, reconciliation, incident trends, or independent review. Self-assessment can be useful but should not be the only evidence for critical controls. The depth and independence of assurance should reflect the consequences of failure and the confidence required.
Control review questions
- Which risk cause or consequence does the control address?
- Who owns, performs, and tests it?
- What evidence shows it operated?
- What dependencies could defeat it?
- What happens when the control fails or is unavailable?