Control Design vs Operation
A control that is well designed and never runs fails exactly like one that is absent.
3 to work through
-
beginner Multiple choice
A quarterly access review is documented, approved and assigned an owner. The evidence shows it was performed in January and in September, and not in the other two quarters. The auditor calls the control ineffective. The owner argues the control is well designed. Who is right?
2 min answer -
beginner
On 31 January 2017 GitLab lost about six hours of database data after an engineer removed the wrong directory during replication troubleshooting. The company had five backup and replication mechanisms. None of them produced a usable recent restore. What does that say about the difference between a control being designed and a control operating?
2 min answer -
advanced
An audit finds a control that is well designed and was not operating for four months. Why does that distinction matter and what causes it?
1 min answer
4 terms in this topic
Control Design vs Operating Effectiveness
The distinction between a control being correctly designed to address a risk and it actually having worked consistently over a period.
practiceFail-Closed Control
A control that blocks when it cannot evaluate, rather than allowing the action through - so that a broken control is visible immediately instead of s…
conceptOperating Effectiveness
Whether a control actually ran, consistently, over a period — as distinct from whether it was well designed, and the harder of the two to demonstrate.
conceptSilent Control Failure
A control that has stopped operating while still reporting success, so the organisation keeps making decisions on the assumption that it is protectin…
Neighbouring topics
Assurance, Audit & Model Risk
General material on assurance, architectural governance and risk oversight.
Audit Evidence
Producing durable, tamper-evident proof as a by-product rather than as a project.
Certification Impact on Architecture
What SOC 2 and ISO 27001 actually require of a design, and what they do not.
Continuous Controls Monitoring
Testing controls continuously instead of sampling them once a year.
Segregation of Duties
Splitting authority so no single actor can both make and approve a change.
Change Advisory vs Automated Gates
Replacing a weekly board with evidence a machine produces on every change.
Risk Appetite
The stated tolerance that tells you which risks you are allowed to accept.
Risk Assessment Methods
Qualitative matrices, FAIR and scenario analysis, and the illusion of a precise score.
Security Design Review
Reviewing an architecture for security while changing it is still cheap.
Architecture Compliance Checks
Automating conformance to standards so review effort goes to the genuinely novel.
Exception & Waiver Management
Time-boxed, owned deviations with a remediation date, rather than permanent silence.
Design Authority
How an ARB should decide, what it should not review, and how it avoids becoming a queue.
Three Lines Model
Ownership, oversight and independent assurance, and where architecture sits in it.
Model Risk Management
Inventory, validation, monitoring and challenge for models that make consequential decisions.
AI Risk Tiering
Classifying a use case by potential harm, and the obligations each tier triggers.
Model Documentation
Model cards, intended use, limitations, and the record a regulator will ask for.
Model Evaluation & Red-Teaming
Adversarial testing of a probabilistic system with no fixed expected output.
Bias & Fairness Controls
Measuring disparate outcomes, choosing a fairness definition, and living with the trade-off.
Human-in-the-Loop Design
Meaningful review rather than a rubber stamp, and designing against automation bias.