Skip to content

Journey: Control Failure to Remediation

What happens between a control degrading and the organisation knowing it is fixed.

Fictional example.


Day 0 — The signal

Control CTL-2026-0022 — Endpoint Disk Encryption is instrumented with two indicators:

IndicatorRuleMandatory
Encryption enforcedall_passYes
Recovery key escrowedall_passNo

Scope SCP-2026-0011 holds 1,420 endpoints after a subsidiary acquisition earlier in the year.

The daily collector reaches the newly acquired endpoints for the first time. Evaluation:

IndicatorExpectedFreshPassFailCoverageStatus
Encryption enforced1,4201,4201,38931100%fail
Recovery key escrowed1,4201,4201,38733100%fail

Derived control effectiveness: ineffective — the mandatory indicator failed.

Note what changed and what did not

Coverage went from 87.3% to 100% because the collector finally reached the acquired estate. Nothing got worse; the measurement got complete.

The 31 unencrypted endpoints had been unencrypted for months. They were invisible, not absent.


Day 0 — Downstream effects, automatic and not

Automatic:

EffectWhere
Control effectiveness moves to ineffectiveControl assurance
Requirement satisfaction moves to not_satisfied on three mapped obligationsRequirement assurance
A risk review recommended signal appears on RSK-2026-0018Risk register
The signal names the indicator, the count and the reasonSignal drilldown

Not automatic:

Not createdWhy
A findingWhether this is a deficiency is a judgement
An action planA remediation commitment needs an owner who agrees to it
A change to the risk ratingRatings are human judgements about business context

The platform surfaced; it did not conclude

A degrading control produces a recommendation with full explainability. A person decides what it means.

Here the answer is obvious. It is not always: three failing service accounts on a decommissioning path is a different situation from three live administrator accounts, and only a person knows which one this is.


Day 1 — Human judgement

The Compliance Analyst reviews the signal drilldown. All 31 endpoints are in the acquired subsidiary and were never enrolled in the endpoint management platform.

She raises finding FND-2026-0203:

FieldValue
SourceRegulatory / Requirement Assessment
SeverityHigh
Description31 endpoints in the acquired subsidiary are not encrypted and are not enrolled in endpoint management
OwnerHead of Infrastructure
Due45 days
LinkedCTL-2026-0022, three requirements, RSK-2026-0018

Day 1 — Risk review

The Risk Manager opens RSK-2026-0018 — Unauthorised disclosure of data at rest.

Signals showing:

SignalDetail
Indicator failure — HighIND-2026-0044: 31 of 1,420 endpoints unencrypted
Open finding — HighFND-2026-0203, raised today

He reviews and raises the residual rating from Medium to High, recording:

"31 endpoints holding subsidiary customer data are unencrypted and unmanaged. Residual raised to High pending remediation. Reassess on completion of the enrolment programme."

The rating moved because a person moved it

The platform recommended review. It did not rerate. The Risk Manager applied judgement about what 31 endpoints in one subsidiary means for this specific risk, which is not derivable from the indicator result.


Days 3 to 45 — Remediation

Action plan ACT-2026-0311:

RolePerson
OwnerHead of Infrastructure
ApproverCompliance Manager
VerifierSenior Compliance Analyst

Milestones:

MilestoneDueOutcome
Inventory and confirm the 31 endpointsDay 10Met — 29 confirmed; 2 already decommissioned
Enrol in endpoint managementDay 25Met on day 31
Enforce encryptionDay 40Met — 27 encrypted; 2 unsupported hardware
Verify indicator passingDay 45Partial

The two unsupported endpoints run legacy hardware in the subsidiary's branch network, scheduled for replacement in eight months.

Exception EXC-2026-0058 is requested: 240-day validity, compensating controls of physical security, restricted network segment and no customer data at rest, reassessment at day 200.

The CRO approves it.


Day 45 to 52 — Verification

The owner marks the action plan complete on day 45.

Day 48. The verifier checks. The indicator now reports:

MetricValue
Expected1,418 — two decommissioned endpoints removed from scope
Fresh1,418
Pass1,416
Fail2
Statusfail

The mandatory indicator still fails. Effectiveness is still ineffective.

The verifier does not close it. He returns the plan:

"Enrolment and encryption confirmed for 27 endpoints. The two remaining are covered by EXC-2026-0058, but the exception was approved after the plan was submitted and is not linked to the finding. Link the exception before closure so the residual position is traceable."

Day 50. The exception is linked. Day 52. The plan is verified and the finding closed by the Compliance Manager.


Day 52 — The resulting position

ElementState
Control effectivenessineffective — mandatory indicator still failing on 2 endpoints
Requirement satisfaction, 3 obligationsnot_satisfied
Governance dispositionaccepted_deviation, referencing EXC-2026-0058
FindingClosed
Action planCompleted and verified
Risk residualReviewed

The control is still ineffective, and that is correct

Twenty-nine of 31 endpoints were fixed. Two remain unencrypted under an approved, expiring, compensated exception.

The control has not achieved its objective. The organisation has formally accepted the residual gap. Both statements are true and both are visible.


Day 200 — Reassessment

The exception reassessment date arrives as a Workbench task and a calendar entry.

The hardware replacement is on schedule for month eight. The CRO renews for a further 60 days with an updated justification noting the replacement date.

Day 254. The hardware is replaced, the endpoints are encrypted, and the indicator passes at 1,418 of 1,418.

  • Control effectiveness → effective
  • Requirement satisfaction → satisfied on all three obligations
  • Governance disposition → compliant
  • Exception → closed early
  • Risk residual → reassessed by the Risk Manager back to Medium

What the journey demonstrates

PrincipleWhere it appeared
Coverage completing is not degradationDay 0 — 87% to 100% coverage revealed a pre-existing gap
Mandatory failure gating31 of 1,420 endpoints made the control ineffective
The platform surfaces; people decideThe risk rating moved because the Risk Manager moved it
Completion is not closureDay 48 — verification returned the plan
An exception does not satisfyDay 52 — satisfaction stayed not_satisfied
Exceptions expireDay 200 — renewal was a decision, not automatic

OrviQ Enterprise Governance, Risk & Compliance Platform