concept

Operating Effectiveness

Whether a control actually ran, consistently, over a period — as distinct from whether it was well designed, and the harder of the two to demonstrate.

Auditors assess two things separately, and the distinction matters more than it appears. Design effectiveness asks whether the control, as specified, would address the risk if operated. Operating effectiveness asks whether it did operate, throughout the period, without exception.

A control can be perfectly designed and fail entirely on the second. The quarterly access review that was skipped twice. The alert that was routed to a channel nobody watched. The scanner that stopped running when its credentials expired and reported nothing, which looked identical to reporting no findings.

Demonstrating operation over a period is where the effort goes, and it is why automation changes the economics of compliance rather than merely the effort. A manual control is evidenced by samples — an auditor selects twenty-five instances from the period and examines them — so a single missed instance in the sample is an exception. An automated control that emits a record per execution is evidenced by the complete population, and the gaps are visible without sampling.

The design implication is to make evidence a by-product of the control's operation rather than something assembled afterwards. A control that runs and leaves no durable trace is, for assurance purposes, a control that cannot be shown to have run.