Detect
To detect means to discover or notice the presence of something that is hidden, unclear, or not otherwise obvious, often by using a special method, equipment, or investigation. In a governance, risk, and compliance setting, the term generally refers to identifying issues, errors, or misconduct that have already occurred or are underway.
In general usage, to detect is to discover or observe the existence of something partly hidden or not clearly apparent, typically through a deliberate method, test, or investigation rather than by chance. Within governance, risk, and compliance practice, 'detect' commonly describes the class of activity aimed at identifying events, control failures, or noncompliance after they have begun, and is generally distinguished from preventive activity intended to stop such events from occurring. The precise application of the term depends on the framework, control taxonomy, and context in use, and this entry addresses the word's general meaning rather than any single defined regulatory or framework term.
Why it matters
In governance, risk, and compliance practice, detection is one of the core lines of protection against issues that preventive measures fail to stop. No control environment eliminates every error, control failure, or instance of misconduct at the point of occurrence, so the capacity to discover problems that are already underway or have already happened is generally what limits the duration and severity of harm. Detective activity is what surfaces the issue so it can be escalated, investigated, and remediated.
Because detection concerns identifying something that is partly hidden or not otherwise apparent, its effectiveness typically depends on deliberate methods, tests, or investigation rather than chance discovery. A weak detection capability can allow problems to persist and compound before anyone notices, while a well-designed one shortens the window between an event and its identification. This is why detective activity is generally treated as complementary to, not a substitute for, preventive activity.
This entry addresses the general meaning of the word rather than any single defined regulatory or framework term. How detection is designed, who owns it, and what standard applies will depend on the framework, control taxonomy, jurisdiction, and facts in a given organization, and this material is educational rather than legal, audit, or compliance advice.
Who it's relevant to
Inside Detect
Common questions
Answers to the questions practitioners most commonly ask about Detect.