Appearance
Journey: Control Failure to Remediation
What happens between a control degrading and the organisation knowing it is fixed.
Fictional example.
Day 0 — The signal
Control CTL-2026-0022 — Endpoint Disk Encryption is instrumented with two indicators:
| Indicator | Rule | Mandatory |
|---|---|---|
| Encryption enforced | all_pass | Yes |
| Recovery key escrowed | all_pass | No |
Scope SCP-2026-0011 holds 1,420 endpoints after a subsidiary acquisition earlier in the year.
The daily collector reaches the newly acquired endpoints for the first time. Evaluation:
| Indicator | Expected | Fresh | Pass | Fail | Coverage | Status |
|---|---|---|---|---|---|---|
| Encryption enforced | 1,420 | 1,420 | 1,389 | 31 | 100% | fail |
| Recovery key escrowed | 1,420 | 1,420 | 1,387 | 33 | 100% | fail |
Derived control effectiveness: ineffective — the mandatory indicator failed.
Note what changed and what did not
Coverage went from 87.3% to 100% because the collector finally reached the acquired estate. Nothing got worse; the measurement got complete.
The 31 unencrypted endpoints had been unencrypted for months. They were invisible, not absent.
Day 0 — Downstream effects, automatic and not
Automatic:
| Effect | Where |
|---|---|
Control effectiveness moves to ineffective | Control assurance |
Requirement satisfaction moves to not_satisfied on three mapped obligations | Requirement assurance |
A risk review recommended signal appears on RSK-2026-0018 | Risk register |
| The signal names the indicator, the count and the reason | Signal drilldown |
Not automatic:
| Not created | Why |
|---|---|
| A finding | Whether this is a deficiency is a judgement |
| An action plan | A remediation commitment needs an owner who agrees to it |
| A change to the risk rating | Ratings are human judgements about business context |
The platform surfaced; it did not conclude
A degrading control produces a recommendation with full explainability. A person decides what it means.
Here the answer is obvious. It is not always: three failing service accounts on a decommissioning path is a different situation from three live administrator accounts, and only a person knows which one this is.
Day 1 — Human judgement
The Compliance Analyst reviews the signal drilldown. All 31 endpoints are in the acquired subsidiary and were never enrolled in the endpoint management platform.
She raises finding FND-2026-0203:
| Field | Value |
|---|---|
| Source | Regulatory / Requirement Assessment |
| Severity | High |
| Description | 31 endpoints in the acquired subsidiary are not encrypted and are not enrolled in endpoint management |
| Owner | Head of Infrastructure |
| Due | 45 days |
| Linked | CTL-2026-0022, three requirements, RSK-2026-0018 |
Day 1 — Risk review
The Risk Manager opens RSK-2026-0018 — Unauthorised disclosure of data at rest.
Signals showing:
| Signal | Detail |
|---|---|
| Indicator failure — High | IND-2026-0044: 31 of 1,420 endpoints unencrypted |
| Open finding — High | FND-2026-0203, raised today |
He reviews and raises the residual rating from Medium to High, recording:
"31 endpoints holding subsidiary customer data are unencrypted and unmanaged. Residual raised to High pending remediation. Reassess on completion of the enrolment programme."
The rating moved because a person moved it
The platform recommended review. It did not rerate. The Risk Manager applied judgement about what 31 endpoints in one subsidiary means for this specific risk, which is not derivable from the indicator result.
Days 3 to 45 — Remediation
Action plan ACT-2026-0311:
| Role | Person |
|---|---|
| Owner | Head of Infrastructure |
| Approver | Compliance Manager |
| Verifier | Senior Compliance Analyst |
Milestones:
| Milestone | Due | Outcome |
|---|---|---|
| Inventory and confirm the 31 endpoints | Day 10 | Met — 29 confirmed; 2 already decommissioned |
| Enrol in endpoint management | Day 25 | Met on day 31 |
| Enforce encryption | Day 40 | Met — 27 encrypted; 2 unsupported hardware |
| Verify indicator passing | Day 45 | Partial |
The two unsupported endpoints run legacy hardware in the subsidiary's branch network, scheduled for replacement in eight months.
Exception EXC-2026-0058 is requested: 240-day validity, compensating controls of physical security, restricted network segment and no customer data at rest, reassessment at day 200.
The CRO approves it.
Day 45 to 52 — Verification
The owner marks the action plan complete on day 45.
Day 48. The verifier checks. The indicator now reports:
| Metric | Value |
|---|---|
| Expected | 1,418 — two decommissioned endpoints removed from scope |
| Fresh | 1,418 |
| Pass | 1,416 |
| Fail | 2 |
| Status | fail |
The mandatory indicator still fails. Effectiveness is still ineffective.
The verifier does not close it. He returns the plan:
"Enrolment and encryption confirmed for 27 endpoints. The two remaining are covered by EXC-2026-0058, but the exception was approved after the plan was submitted and is not linked to the finding. Link the exception before closure so the residual position is traceable."
Day 50. The exception is linked. Day 52. The plan is verified and the finding closed by the Compliance Manager.
Day 52 — The resulting position
| Element | State |
|---|---|
| Control effectiveness | ineffective — mandatory indicator still failing on 2 endpoints |
| Requirement satisfaction, 3 obligations | not_satisfied |
| Governance disposition | accepted_deviation, referencing EXC-2026-0058 |
| Finding | Closed |
| Action plan | Completed and verified |
| Risk residual | Reviewed |
The control is still ineffective, and that is correct
Twenty-nine of 31 endpoints were fixed. Two remain unencrypted under an approved, expiring, compensated exception.
The control has not achieved its objective. The organisation has formally accepted the residual gap. Both statements are true and both are visible.
Day 200 — Reassessment
The exception reassessment date arrives as a Workbench task and a calendar entry.
The hardware replacement is on schedule for month eight. The CRO renews for a further 60 days with an updated justification noting the replacement date.
Day 254. The hardware is replaced, the endpoints are encrypted, and the indicator passes at 1,418 of 1,418.
- Control effectiveness →
effective - Requirement satisfaction →
satisfiedon all three obligations - Governance disposition →
compliant - Exception → closed early
- Risk residual → reassessed by the Risk Manager back to Medium
What the journey demonstrates
| Principle | Where it appeared |
|---|---|
| Coverage completing is not degradation | Day 0 — 87% to 100% coverage revealed a pre-existing gap |
| Mandatory failure gating | 31 of 1,420 endpoints made the control ineffective |
| The platform surfaces; people decide | The risk rating moved because the Risk Manager moved it |
| Completion is not closure | Day 48 — verification returned the plan |
| An exception does not satisfy | Day 52 — satisfaction stayed not_satisfied |
| Exceptions expire | Day 200 — renewal was a decision, not automatic |