Ideally, your organization has effective controls, but in practice, controls don’t always operate the way they were designed to. Sometimes, the right control exists, but there’s a breakdown somewhere between the control’s design and its execution.
These situations generally fall into four categories: design gaps, execution gaps, override gaps and monitoring gaps.
Control Design Gaps
A control design gap occurs when a control doesn’t address the actual risk it is intended to address.
For example, a leadership team may believe that recovery systems can be restored within eight hours because backups exist. The technology team may know the restoration process takes closer to 48 hours. The control exists, but the business expectation and operational reality don’t match.
Design gaps can also appear when governance decisions are not reflected in the technology environment. Organizations may establish policies and expectations, but systems are not configured to support them. Procedures may leave out critical risk points, and controls may occur at the wrong point in the process.

Control Execution Gaps
Control execution gaps occur when controls are appropriately designed, but they are not performed consistently.
Organizations typically encounter this when processes aren’t documented and knowledge lives in one employee’s head rather than within the organization itself. When responsibilities transition to someone new, the process becomes difficult to follow because it wasn’t ever formally documented.
Training gaps, turnover, workload pressures and unclear responsibilities can create the same result. The control exists, but the execution becomes inconsistent.

Control Override Gaps
Override gaps occur when people work around established controls.
A common example is when someone needs access to a system immediately, so the normal approval process is skipped. The same thing can happen with approval requirements, procedures and security controls. What begins as an exception can gradually become standard practice.
Leadership behavior can also contribute to override gaps. Employees are less likely to follow a control when leaders make exceptions for themselves.

Control Monitoring Gaps
A control monitoring gap occurs when organizations assume controls are working but don’t verify that they are working.
Many systems contain logging, reporting and alerting capabilities that can identify unusual activity. In some environments, those capabilities are available but never enabled. In others, the information is collected but not reviewed.
Monitoring gaps also appear in access reviews. Organizations are often surprised to find active accounts belonging to employees who left months or years earlier. Access reviews either aren’t happening or aren’t happening consistently.
The same principle applies to audit trails. Organizations sometimes assume they have visibility into system activity, only to discover the audit trail was never activated.

Looking Beyond the Control Gap
A fraud incident may start with an email, and an access issue may surface during an employee termination. The event is usually what gets attention first, but the control breakdown that caused it may have started much earlier.
Looking at the event alone rarely shows the full picture. Looking at how the control was designed, performed, monitored and maintained often provides a clearer view of what happened and where additional weaknesses may exist.
Several themes appear repeatedly when organizations evaluate their control environment.
- Communication – Managers, HR and technology teams need to be working from the same information. Gaps often emerge when responsibilities are assumed but not clearly assigned.
- Documentation – Processes that exist primarily through individual knowledge become more difficult to transfer, review and execute consistently over time.
- Visibility – Organizations need to know where information lives, who has access to it and what activity is occurring within their systems. Logging, monitoring and reporting capabilities provide information, but only when they are enabled and reviewed.
- Operating conditions – Backup strategies, recovery expectations, access restrictions and approval requirements can drift from the way the organization functions in practice.
Learn More and Connect With an Advisor
Controls are intended to support the way an organization operates. Over time, systems change, access expands, responsibilities shift and workarounds develop. Revisiting controls periodically (and addressing any control gaps that you find) can help confirm that they still reflect current practices, current risks and current expectations.
To learn more, contact your Warren Averett advisor directly, or ask a member of our Risk Advisory & Assurance team or Warren Averett Technology Group to reach out to you to start the conversation.

Back to Resources