Control effectiveness

Control effectiveness lets a risk's score reflect how well the controls linked to it are actually performing. Rather than setting residual risk severity in isolation, the system combines the effectiveness ratings of linked controls according to configurable rules and produces a Calculated Residual Risk Score for the risk. When controls degrade, the score reflects it; when they improve, likewise.

How the feature is organized

The feature has two sides that move independently:

  • Controls Each control is rated for Design Effectiveness (is the control well-designed for its purpose) and Operating Effectiveness (is it actually working as intended). These ratings live on the control record and can be updated independently of any specific risk the control is linked to.
  • Risks A dedicated Control Effectiveness view on the risk record shows all linked controls, their current effectiveness ratings, their weights in the calculation, and the resulting Calculated Residual Risk Score.

Understanding that these two sides can move independently is essential to understanding the Save and Sync actions described below.

Setup

Control effectiveness is controlled by a global setting that is off by default. Nothing related to the feature appears in the product until a System Admin turns it on.

Once the global setting is on, a System Admin must configure at least one Included relationship type in the Configuration Hub. This defines which kind of link between a risk and a control the system treats as "this control mitigates this risk" for the purposes of the effectiveness calculation. The Included relationship is required: setup cannot proceed without it.

Note

If a user opens the Control Effectiveness view on a risk before a relationship type has been configured, the view displays a message indicating that setup is incomplete and prompting configuration. An empty or message state always means "not yet configured"; it never means that no controls are linked to the risk. No relationship type is pre-selected automatically for new organizations; an admin must actively select and confirm one.

Calculation modes and comparison views

Weighted Average and Custom are saved calculation modes: selecting one determines how the Calculated Residual Risk Score is produced and stored.

The Control Effectiveness score on a residual risk is an aggregated score derived from the effectiveness ratings of the controls linked to that risk. Depending on configuration, the aggregation can be based on the controls' Design Effectiveness, their Operating Effectiveness, or both combined. The aggregation itself is governed by a selectable methodology that determines how individual control ratings roll up into a single Control Environment score for the risk.

Weighted Average

The Control Environment score is the weighted average of all linked controls' effectiveness ratings. Each control contributes to the total according to its assigned weight. New controls enter with a weight of 0 and existing weights are not automatically rebalanced, so weights need to be set manually to reflect intended influence. This methodology is the balanced default: no single control dominates, and the environment score reflects the collective picture.

When a new control is linked to a risk that already has weights distributed across existing controls, the new control enters with a weight of 0. Existing controls retain their previously set weights. The system does not automatically rebalance weights when controls are added or removed; deliberate weighting decisions are never silently overwritten. If the new control should contribute to the score, its weight must be set manually.

Custom

The Control Environment score is calculated using manually entered values that the customer provides directly, rather than derived from the linked controls' ratings by rule. This methodology is for cases where the standard aggregation logic doesn't reflect the customer's actual assessment approach — for example, when they follow a proprietary internal scoring framework, or when they want to override the calculated value based on qualitative judgment. Switching away from Custom back to a rule-based methodology will overwrite the manually entered values, so a confirmation is required.

Best case

The Control Environment score reflects the effectiveness of the strongest-performing control(s) linked to the risk. This methodology answers: 'If we assume our best control is what matters most, how effective is our environment?' Useful when the customer wants an optimistic view, or when they operate on a redundancy model where a single strong control can carry the environment.

Worst case

The Control Environment score reflects the effectiveness of the weakest-performing control(s) linked to the risk. This methodology answers: 'How exposed are we based on our weakest link?' Useful for a conservative view, and typically preferred by risk teams who want the score to reflect the environment's most vulnerable point.

Calculated and Saved values

The Control Effectiveness view shows two related values:

  • Calculated What the score currently computes to, based on the freshest data available.
  • Saved What has actually been committed to the risk record.

These two values can diverge for two distinct reasons - changes you make on the view itself, and changes that originate elsewhere in the system. The Save and Sync actions handle each reason separately.

Save

Save becomes active when you have made changes on the Control Effectiveness view itself: adjusting a control's weight or switching the saved calculation mode. Selecting Save commits those on-screen edits to the risk record. Save does not react to changes happening elsewhere in the system.

Note

Design Effectiveness and Operating Effectiveness ratings are not editable from this view. Those values live on the control record and are updated there.

Sync

Sync becomes active when data has changed elsewhere (on a linked control, through automation, or through a link or unlink action) in a way that makes the Calculated value diverge from what is Saved on the risk. Selecting Sync pulls those external changes onto the risk record, updating the Saved score to match the current Calculated value.

Before you sync, a diff view shows exactly what will change: for example, a control's operating effectiveness rating moving from Effective to Partially Effective, a control being added, or a weight shifting. The change is never applied without review.

Action When to use it
Save Commit changes you made on this view (weights, calculation mode).
Sync Accept changes that originated elsewhere: on a linked control or through automation.

Unsynced changes alert

When Sync is available, a banner at the top of the view indicates that there are unsynced changes from linked controls. This makes the state visible proactively rather than relying on you to notice the button is active.

Data refresh cadence

The Control Effectiveness view is a derived view of control data. Changes propagate on a scheduled cadence, not in real time:

  • Structural changes New control attribute definitions or new control types can take up to 24 hours to appear in Risk Manager, on a scheduled daily sync.
  • Value changes Updates to existing attribute values, such as a revised Design Effectiveness rating, refresh approximately once per hour.

The view is always a slightly-lagged reconcilable snapshot, not a live feed. If a change made elsewhere is not yet visible on the risk-side view, the cadence above indicates when it will appear. The Sync action then pulls those refreshed values onto the risk record once they are visible.

Notification email

An email notification is sent when a change to a linked control's effectiveness affects a risk. The email is a bundled daily digest, it summarizes the net difference since the previous email, not a log of every individual event. If a value changed and then changed back within the same day, the digest reflects the final state only.

The purpose of the email is to prompt the recipient to return to the Control Effectiveness view and reconcile using Sync, not to serve as a complete record of what changed.

Audit history

A full audit trail of every individual change to every linked control is not available in this release. The diff view surfaces the current difference between Saved and Calculated, but the product does not display a scrollable history of past changes, who made them, or when. Reconciliation is expected to happen at the point of Sync, based on the visible diff.

Best fit

The feature is best suited to organizations, or teams within an organization, where risk ownership and control ownership sit with the same person or team. When one person owns both sides, the reconciliation model is straightforward: they see a change, understand its origin, and sync.