A control is any policy, procedure, system configuration, or mechanism designed to mitigate a risk. When evaluating a control, risk practitioners must separate its conceptual design from its day-to-day operational execution. This assessment follows two sequential verification steps:
[Control Assessment Portal]
│
├──► 1. Design Effectiveness Assessment (DEA)
│ └── Verifies: "If executed perfectly, is this control structurally sound?"
│
└──► 2. Operating Effectiveness Testing (OET)
└── Verifies: "Does the control function reliably in daily practice?"
Design Effectiveness Assessment (DEA)
The DEA evaluates whether a control is conceptually capable of mitigating its target risk. It asks: “If this control operates exactly as written, will it successfully prevent or detect the risk event?” If a business unit implements a manual spreadsheet check sheet to detect duplicate payments, the control design may be weak because it still relies on manual human review and is prone to oversight.
Operating Effectiveness Testing (OET)
Once a control passes its DEA, it undergoes OET to verify that it functions reliably over time. This testing involves extracting statistically valid samples of past control executions and reviewing the evidence to confirm that the designated operator performed the control correctly, consistently, and in accordance with the documented policy guidelines.