Skip to main content

Control effectiveness

A control's status tells you whether its evidence is present and current. Its effectiveness is a separate judgement of whether the control is actually reducing the risk it is meant to address, and the two are tracked separately.

Written by Taylor Laing

Complete is not the same as Effective: A control can be Complete on status (all required documents, policies, and tests in place) and still be Not Assessed for effectiveness. Evidence being current means the paperwork is there; effectiveness means someone has judged that the control works. Report on both, not just status. For status, see Assigning control owners and managing renewals.

The effectiveness ratings

Effectiveness is a qualitative rating with four values:

Rating

Meaning

Effective

The control is working as intended and reducing the risk

Partially Effective

The control helps, but has gaps or isn't fully reliable

Ineffective

The control is not reducing the risk in practice

Not Assessed

Effectiveness hasn't been judged yet (the default)

Alongside the rating, a control carries effectiveness notes (the reasoning behind the judgement) and two dates: the last effectiveness review and the next effectiveness review, so you can see when the rating was last confirmed and when it's due to be looked at again.

How effectiveness is set

Effectiveness is set and updated through a Review: a person examines the control and records their judgement. The control detail page has a dedicated effectiveness dialog for this, and it logs an "Effectiveness updated" entry to the activity log whenever the rating changes. Reviews record an outcome of Approved, Approved with conditions, Changes requested, or Rejected. For how reviews are raised and completed, see Assigning and completing reviews.

Effectiveness can be triggered by an incident

An incident can prompt a fresh look at whether a control is working. When an incident calls a control's effectiveness into question, the effectiveness review can be triggered from that incident, linking the re-assessment back to what happened. This keeps your effectiveness ratings grounded in real events rather than being a one-off exercise.

Why it matters

Status keeps your evidence honest; effectiveness keeps your programme honest. A register full of Complete controls that have never been assessed for effectiveness looks compliant on paper but tells you nothing about whether workers are actually safer. Use effectiveness ratings to find the controls that are evidenced but unproven, and put them through a review.

Did this answer your question?