Skip to main content
Category: Internal Controls

Detective Controls

Also known as: Detective Control, Detective Control Activity
Simply put

Detective controls are checks designed to find errors, irregularities, or other problems after they have already happened, rather than stopping them in advance. Once an issue is identified, management can act to correct it before a small problem grows into a larger one. Common examples include reconciliations, reviews, and monitoring or alerting systems.

Formal definition

A detective control is a control activity designed to discover and enable the timely correction of an unintended event, error, or irregularity after it has occurred. In contrast to preventive controls, which aim to stop problems before they arise, detective controls operate after the fact and typically function by detecting, logging, and alerting on events so that management can investigate and remediate. Detective controls are generally deployed alongside preventive controls as complementary components of an internal control system supporting risk management; their effectiveness depends on both appropriate design and consistent operation. This entry is educational and not legal, audit, or compliance advice; the specific controls appropriate to an organization depend on its facts, jurisdiction, sector, and applicable framework.

Why it matters

No internal control system can prevent every error, irregularity, or breakdown. Preventive controls are designed to stop problems before they arise, but they can fail, be circumvented, or simply not anticipate a particular scenario. Detective controls fill this gap by discovering issues after they have occurred, giving management the opportunity to investigate and remediate before a small problem turns into a larger one. For this reason, detective controls are generally deployed alongside preventive controls as complementary components of a broader control environment.

The value of detective controls lies in timeliness. A reconciliation, review, or monitoring alert that surfaces an issue quickly narrows the window during which an error can compound or an irregularity can go unaddressed. In security contexts, detective controls that detect, log, and alert on events are widely regarded as a foundational part of a control framework, supporting both response and later analysis. Their contribution to risk management depends, however, on both sound design and consistent operation over time; a well-designed detective control that is not reliably performed provides limited assurance.

Because detective controls operate after the fact, they do not eliminate the underlying risk of an event occurring; they reduce the risk that such an event goes undiscovered and uncorrected. The specific mix of preventive and detective controls appropriate to any organization depends on its facts, sector, applicable framework, and its own assessment of risk, and involves professional judgment rather than a single correct answer.

Who it's relevant to

Management
Management is typically responsible for designing, implementing, and operating detective controls as part of the day-to-day control environment. When a detective control surfaces an error or irregularity, it is generally management that investigates the cause and takes corrective action, and management that decides how detective and preventive controls should be combined to address a given risk.
Internal Auditors and Assurance Functions
Internal audit and other assurance functions commonly evaluate whether detective controls are appropriately designed and operating effectively, and whether they provide the level of assurance management and the board rely on. Their role is to assess and report on controls rather than to own or operate them, preserving their independence from the activities they review.
Compliance and Risk Officers
Compliance and risk professionals often consider how detective controls, such as monitoring, reviews, and alerting, contribute to the timely identification of issues within their areas of responsibility. Because detective controls address risks that have already materialized, they are frequently a factor in judging whether residual risk is being kept within the organization's stated appetite.
Boards and Audit Committees
Boards and their audit or risk committees generally exercise oversight of the internal control system rather than operating individual controls. They typically seek assurance that a sensible balance of preventive and detective controls exists, that significant issues detected are escalated and remediated, and that the assurance functions reporting to them can evaluate control effectiveness reliably.
Security and IT Teams
In technology and security settings, detective controls that detect, log, and alert on events are considered a foundational part of a control framework. Security and IT teams typically design and monitor these controls to identify incidents after they occur and to support investigation, response, and later analysis.

Inside Detective Controls

Definition and Purpose
Detective controls are control activities designed to identify and surface errors, irregularities, or control failures after they have occurred, rather than stopping them from happening. They generally support timely detection so that management can respond, investigate, and remediate.
Relationship to Preventive Controls
Detective controls typically operate alongside preventive controls, which are designed to stop an error or irregularity before it occurs. Many control frameworks describe a layered approach in which detective controls act as a check on events that preventive controls did not, or could not, prevent.
Common Examples
Illustrative detective controls include reconciliations, exception and variance reports, physical inventory counts, monitoring and log reviews, and independent verifications or after-the-fact reviews. The specific mix depends on the process, entity, and risks involved.
Control Design vs. Operating Effectiveness
A detective control has a design (whether the control, if operating as intended, is capable of detecting the relevant issue) and an operating effectiveness (whether it actually functioned as designed over a period). These are distinct attributes and are typically assessed separately.
Ownership and Roles
Detective controls are generally designed and operated by management as part of the first and second lines. Internal audit and other assurance functions typically evaluate whether such controls are appropriately designed and operating effectively, rather than owning the controls themselves; the board and its committees provide oversight.
Residual Risk Considerations
Because detective controls identify issues after the fact, some exposure generally remains between the occurrence of an event and its detection and remediation. This timing gap is a relevant factor when considering residual risk and how quickly a control operates.

Common questions

Answers to the questions practitioners most commonly ask about Detective Controls.

Are detective controls a substitute for preventive controls?
No. Detective controls identify errors, irregularities, or breaches after they have occurred, whereas preventive controls aim to stop them from happening in the first place. The two are generally treated as complementary rather than interchangeable: a control environment typically relies on a mix of both, because no set of preventive controls eliminates all risk, and detective controls provide a means of catching what preventive measures miss. Relying solely on detection leaves the underlying event to occur before any response is possible.
Does having a detective control in place mean the related risk is adequately managed?
Not necessarily. The existence of a detective control speaks to control design, but management and assurance functions generally distinguish design from operating effectiveness. A control may be well designed yet fail to operate consistently, or it may detect issues too late to enable a meaningful response. Whether a risk is adequately managed depends on how the residual risk compares to the organization's risk appetite and tolerance, and that assessment involves professional judgment rather than the mere presence of a control.
Who is typically responsible for operating detective controls versus assessing them?
In many organizations, detective controls are owned and operated by management within business and support functions, often described as the first line in three-lines models. Risk and compliance functions may design or monitor certain detective controls, and internal audit typically provides independent assurance over whether they are designed and operating effectively. The board and its committees generally exercise oversight rather than operating the controls themselves. Specific role allocations vary by entity type, sector, and the governance model an organization adopts.
How can an organization test whether a detective control is operating effectively?
Testing generally focuses on operating effectiveness over a period rather than at a single point in time, and may include re-performance, inspection of evidence such as reconciliation records or exception reports, and sampling of instances where the control should have detected an issue. Assessors often consider whether exceptions the control identified were actually followed up and resolved, since a detective control that flags issues no one acts upon provides limited value. The appropriate approach depends on the control, the risk it addresses, and applicable audit or assurance standards.
What are common examples of detective controls in practice?
Examples frequently cited include reconciliations, exception and variance reporting, transaction monitoring, log reviews, physical inventory counts, and post-transaction reviews or audits. What qualifies as detective depends on timing and purpose: a control that operates after an event to surface anomalies is generally detective, while one that blocks an action before completion is generally preventive. Some controls have both preventive and detective characteristics, so classification often depends on how and when the control operates in a specific process.
How should detective controls be balanced against preventive controls when designing a control framework?
The balance typically reflects the nature of the risk, the cost and feasibility of prevention, and the organization's risk appetite. Where a risk event would be severe or difficult to reverse, organizations often weight controls toward prevention; where prevention is impractical or costly, detective controls may play a larger role, provided detection is timely enough to permit response. This is a matter of judgment informed by risk assessment rather than a fixed formula, and frameworks such as COSO's internal control model discuss control activities without prescribing a universal ratio. This entry is educational and not audit, compliance, or legal advice.

Common misconceptions

Detective controls prevent problems from occurring.
By definition, detective controls identify issues after they have occurred rather than stopping them in advance. Prevention is generally the function of preventive controls; detective controls typically complement, but do not replace, them.
If a detective control is well designed, it is necessarily operating effectively.
Design and operating effectiveness are distinct. A control may be appropriately designed to detect an issue yet fail in practice if it is not performed consistently, on time, or by a competent and independent party. Both attributes generally need to be evaluated.
Establishing detective controls is the responsibility of internal audit or the board.
Designing and operating controls is generally a management responsibility. Internal audit typically provides independent assurance over those controls, and the board provides oversight; attributing operational control ownership to assurance or oversight functions blurs important accountability lines.

Best practices

Map detective controls to the specific risks and processes they are intended to address, and consider how they work in combination with preventive controls to reduce residual risk.
Assess both the design and the operating effectiveness of each detective control, and document evidence that it was performed as intended over the relevant period.
Pay attention to the timeliness of detection, since the gap between an event occurring and its identification affects the exposure that remains before remediation.
Clarify ownership so that management designs and operates the controls, while assurance functions independently evaluate them and the board exercises oversight.
Ensure the individuals performing detective controls have appropriate competence and, where relevant, sufficient independence from the activity being reviewed.
Establish clear escalation and remediation pathways so that issues surfaced by detective controls are investigated and resolved rather than merely recorded.