Controls are the processes, policies, and automated systems implemented to mitigate inherent risks. A compliance program must test both the design and the operational effectiveness of these controls to ensure they work as intended.
Control Classification Matrix
Controls are categorized by how and when they intervene in a risk event:
- Preventative Controls: Designed to stop a violation or error before it occurs. These are the most cost-effective controls.
- Operational Example: System configurations that block wire transfers to sanctioned countries.
- Detective Controls: Designed to identify and flag exceptions, violations, or errors after they happen.
- Operational Example: Reconciling transaction logs daily to flag unapproved account access.
- Corrective Controls: Actions taken to fix a problem, restore systems, or update policies after a detective control flags an issue.
- Operational Example: Restructuring a database configuration after a data breach to secure exposed information.
Evaluating Control Effectiveness
Compliance testing teams look for two distinct types of control failures:
- Design Failures (Design Effectiveness): The control is structured poorly and would fail to stop the risk even if executed perfectly. For example, a policy requires double signatures for large payouts, but sets the authorization threshold well above the firm’s average transaction volume.
- Operational Failures (Operating Effectiveness): The control is designed correctly but fails in practice because it is executed poorly, ignored, or handled by untrained staff. For example, a system accurately flags suspicious transactions for review, but analysts clear the alerts without performing the required background checks.