Compensating Control
A cheaper measure that reduces a risk enough to proceed, used deliberately and with an expiry, when the full control cannot be delivered in the available time.
When a required control cannot be built in the time available, the usual outcomes are both bad: ship without it and accept an unquantified risk, or delay and lose the business opportunity.
A compensating control is the third option — something materially cheaper that reduces the risk to an acceptable level, adopted explicitly, with the full control committed and dated.
Why it matters
It is frequently where architectural judgement adds the most value in a stakeholder conflict. The parties present positions — six weeks, twelve weeks, the paved road — and the architect's contribution is not adjudicating between them but finding the option that satisfies the underlying interests rather than the stated demands.
What makes one legitimate
- It addresses the same risk, not a different one that is easier to mitigate. A control reducing the likelihood substitutes poorly for one reducing the impact, and vice versa — the substitution must be argued.
- The residual risk is stated, so the person accepting it knows what they are accepting.
- It is accepted by someone with the authority to accept it, not by the engineer under deadline pressure.
- It has an expiry and an owner, with the full control scheduled rather than aspirational.
- It is recorded, so a pattern of compensating controls in the same area is visible.
Common forms
- Detection instead of prevention — you cannot prevent the condition in time, so you detect it quickly and respond. Weaker, sometimes sufficient, and it requires the response to be real.
- A manual process instead of an automated one, acceptable at low volume with a documented scaling limit.
- Narrowing the exposure — restricting the feature to a small population, a single region, or internal users while the full control is built.
- A tighter limit — a lower rate limit, a smaller transaction ceiling, a shorter retention — that bounds the damage the missing control would have prevented.
- Increased monitoring with a defined kill switch.
Industry example
The recurring situation is a feature with a customer commitment, a security requirement with a longer lead time, and a platform team wanting it built on a paved road that does not yet support it. Presenting three costed options — ship off-road with the control and accept migration debt, ship on-road late, or ship on time with a compensating control and a dated commitment — turns a deadlock into a decision.
The same pattern appears in regulated environments where a full audit capability cannot be delivered before a launch, and a narrower one covering only the highest-risk transactions is accepted for a defined period.
Failure scenarios
- The permanent temporary. The compensating control becomes the architecture because nobody scheduled the replacement. This is the dominant failure mode and it is prevented only by a date and an owner.
- Substituting a control for a different risk, so the original exposure is unchanged and everyone believes it is handled.
- Accepted by the wrong person, so the organisation has taken a risk nobody with authority agreed to.
- A pattern of them in one area, which indicates a systemic problem — usually that requirements arrive too late to shape design, or that the paved road lags the product's needs.
Trade-offs
A compensating control is by definition weaker than the control it replaces, and the residual risk is real. It also normalises shipping without full controls, which erodes over time if it is not tracked.
Against that, the alternative in practice is rarely "the full control on time" — it is shipping with nothing while everyone looks away. An explicit, time-bounded, accepted reduction is a substantially better outcome than an implicit one.
Interview question
"A launch is committed for six weeks. The required security control takes twelve. Give me three compensating options, tell me what residual risk each leaves, and tell me who signs it off."