Skip to main content
Category: Internal Controls

Preventive and Detective Controls

Also known as: Preventative Controls, Detective Controls, Preventive Controls
Simply put

Preventive controls are steps put in place to stop errors, fraud, or other unwanted events before they happen, while detective controls are designed to find and flag problems after they have occurred so they can be corrected. Both are common types of internal control activities that organizations use together to manage risk. Detective controls are especially valuable for catching an issue before a small problem grows into a larger one.

Formal definition

Preventive and detective controls are two complementary categories of internal control activities that are typically classified alongside a third category (often described as corrective). A preventive control activity is designed to avoid an unintended event or result before it occurs, for example by stopping misstatements arising from fraud or error at the point of origin. A detective control activity is designed to discover, identify, and enable correction of errors or irregularities after they have occurred, generally through monitoring, reconciliations, and reviews, ideally in time to prevent a minor issue from escalating. In practice, control ownership and operation typically rest with management as part of the first line of defense, and the specific mix of preventive and detective controls depends on the organization's risk profile, processes, and applicable framework. The design and operating effectiveness of each control should be evaluated separately; a well-designed control still requires evidence that it operates as intended. This entry is educational and not audit, legal, or compliance advice.

Why it matters

Preventive and detective controls are foundational building blocks of an organization's internal control environment. Because no single control is perfect, organizations generally rely on a combination of the two: preventive controls aim to stop errors, fraud, or other unwanted events at the point of origin, while detective controls exist to catch what slips through. This layered approach matters because it reflects a practical reality of risk management, that some issues will inevitably occur despite the best preventive measures, and the ability to identify them quickly can be the difference between a minor correction and a significant loss.

Detective controls are particularly valuable for their timing. As described in the evidence, they are designed to surface an issue after it has occurred but before a small problem turns into a large one, typically through monitoring, reconciliations, and reviews. For boards, general counsel, and compliance and risk leaders, understanding the interplay between these two categories helps clarify where an organization is investing in prevention versus early detection, and whether that balance is appropriate to its risk profile.

It is important to remember that the presence of a control on paper is not the same as an effective one. A well-designed control still requires evidence that it operates as intended, and design effectiveness and operating effectiveness should be evaluated separately. This distinction is central to how assurance functions assess whether controls are actually managing the risks they were established to address.

Who it's relevant to

Chief Compliance and Risk Officers
Risk and compliance leaders use the distinction between preventive and detective controls to assess whether an organization's control mix is appropriate to its risk profile. Understanding which controls stop issues at the source versus which surface them after the fact helps in prioritizing where to strengthen prevention and where to invest in earlier detection.
Internal Auditors and Assurance Functions
Assurance professionals evaluate both the design and the operating effectiveness of preventive and detective controls, recognizing that a well-designed control still requires evidence that it operates as intended. The two categories are typically assessed as part of a broader classification of control activities, and auditors examine detective controls, such as monitoring, reconciliations, and reviews, for their ability to catch issues before they escalate.
Management and Control Owners
Ownership and operation of these controls typically rest with management as part of the first line of defense. Managers are responsible for designing and running the specific mix of preventive and detective controls suited to their processes, and for ensuring those controls function in practice rather than existing only on paper.
Board Members and Audit Committees
Directors exercising oversight benefit from understanding how an organization balances prevention against early detection. While the operation of controls sits with management, the board's oversight role includes probing whether the overall control framework is designed to prevent unwanted events where possible and to detect and correct issues quickly when they occur.

Inside Preventive and Detective Controls

Preventive Controls
Controls designed to stop errors, fraud, or undesirable events from occurring in the first place. Typical examples include segregation of duties, authorization and approval requirements, access restrictions, and system-enforced validation rules. They act before a transaction or event is completed.
Detective Controls
Controls designed to identify errors, irregularities, or control failures after they have occurred so they can be investigated and remediated. Common examples include reconciliations, exception reports, management reviews, and internal audit testing. They act after the event, often to catch what preventive controls miss.
Complementary Relationship
Preventive and detective controls generally work together rather than in isolation. Because no preventive control is fully reliable, detective controls provide a second layer to surface failures; the appropriate mix depends on the risk, cost, and the entity's risk appetite.
Control Design vs. Operating Effectiveness
For either control type, design effectiveness (whether the control, as configured, would address the risk) is distinct from operating effectiveness (whether it actually functions as intended over a period). Both dimensions typically require separate evaluation.
Ownership and Accountability
Under a three-lines model, management (first line) typically owns and operates preventive and detective controls, risk and compliance functions (second line) provide oversight and challenge, and internal audit (third line) provides independent assurance over their effectiveness. The board and its committees oversee the overall control environment rather than operating controls.
Inherent vs. Residual Risk Context
Controls are applied to inherent risk to reduce it toward residual risk. The selection and calibration of preventive and detective controls is generally driven by the level of residual risk an organization is prepared to accept.

Common questions

Answers to the questions practitioners most commonly ask about Preventive and Detective Controls.

Are preventive controls always better than detective controls?
No. Neither type is inherently superior; they serve different purposes and are generally most effective in combination. Preventive controls aim to stop an error or undesirable event from occurring in the first place (for example, segregation of duties or system access restrictions), while detective controls are designed to identify events that have already occurred (for example, reconciliations or exception reports). Because no preventive control is perfect and some risks cannot be fully prevented, detective controls provide an important backstop. The appropriate mix typically depends on the nature of the risk, its likelihood and impact, cost considerations, and the organization's risk appetite. This is a matter of control design judgment rather than a fixed rule.
Doesn't having a control in place mean the risk is addressed?
Not necessarily. The existence of a control speaks to control design, but effective risk management also depends on operating effectiveness, whether the control actually functions as intended over time. A well-designed preventive or detective control that is not consistently performed, is overridden, or is applied to the wrong population may leave residual risk higher than expected. Distinguishing design from operating effectiveness is central to control assurance work, and assessing both is typically part of how management and assurance functions evaluate whether a risk is adequately mitigated. This entry is educational and not a substitute for a controls assessment conducted by qualified professionals.
How do we decide whether a given risk needs a preventive control, a detective control, or both?
The decision generally turns on factors such as the likelihood and potential impact of the risk, the feasibility and cost of preventing it, and the tolerance for detecting an issue after it occurs. Where the impact of an event is severe or difficult to reverse, organizations often emphasize preventive controls; where prevention is impractical or costly, detective controls may carry more weight. Many control environments layer both so that detective controls catch what preventive controls miss. This is a design judgment made by management, typically informed by the organization's risk appetite and tolerance, and it can vary by process, jurisdiction, and entity type.
Who is responsible for designing and operating these controls versus overseeing them?
In many organizations that follow a three-lines model, management (as the first line) typically owns the design and day-to-day operation of preventive and detective controls within business processes. Risk and compliance functions (often described as a second line) may set standards, provide guidance, and monitor. Internal audit or a comparable assurance function (a third line) typically provides independent assurance over whether controls are designed and operating effectively. The board and its relevant committees generally exercise oversight rather than operating controls themselves. Specific allocations of responsibility vary by framework, sector, and organizational structure.
How can an organization test whether a detective control is operating effectively?
Testing operating effectiveness generally involves evaluating whether the control was performed as designed, by the appropriate person, over the relevant period, and applied to the correct population of transactions or events. Common approaches described in practice include examining evidence that the control was executed (such as reviewing completed reconciliations or documented follow-up on exceptions), assessing timeliness, and confirming that identified issues were investigated and resolved. Frequency and rigor of testing typically depend on the risk the control addresses. The specific methodology and sample selection should be determined by qualified assurance or audit professionals, as this entry does not constitute audit guidance.
What are common weaknesses that can undermine preventive and detective controls?
Frequently discussed weaknesses include management override of controls, inadequate segregation of duties, controls that are documented but not consistently performed, detective controls that run too infrequently to be timely, and controls applied to an incomplete population. Reliance on manual steps can introduce inconsistency, while automated controls may fail silently if not monitored. A further limitation is that detective controls, by definition, identify events after they occur, so residual risk may remain between occurrence and detection. Identifying and remediating such weaknesses is typically a matter for management with assurance from relevant functions, and depends on the specific facts of each control environment.

Common misconceptions

Detective controls are inferior to preventive controls and should be minimized.
Neither type is inherently superior; they serve different purposes. Preventive controls avoid an event, while detective controls catch what slips through and may be more practical or cost-effective for certain risks. Most control environments rely on a deliberate combination of both, calibrated to the risk.
A well-designed control automatically means the control is effective.
Design effectiveness and operating effectiveness are distinct. A control may be well designed on paper yet fail in practice due to inconsistent execution, override, or degraded performance. Both dimensions typically need to be assessed separately.
Implementing preventive and detective controls eliminates the underlying risk.
Controls generally reduce risk from an inherent to a residual level but do not remove it entirely. Residual risk remains, and no combination of controls provides absolute assurance.

Best practices

Map preventive and detective controls to specific risks and to the residual risk level the organization is prepared to accept, rather than adding controls indiscriminately.
Assess both design and operating effectiveness for each control, and document the basis for concluding a control functions as intended over the relevant period.
Use detective controls deliberately to compensate where preventive controls are impractical, costly, or susceptible to override, and reassess the balance as risks change.
Clarify control ownership consistent with a three-lines model: management operates the controls, second-line functions provide oversight and challenge, and internal audit provides independent assurance.
Report the state of the control environment to the appropriate board committee for oversight, distinguishing management's operational responsibilities from the board's oversight role.
Periodically review the control mix in light of changes to processes, systems, and risk appetite, treating control effectiveness as ongoing rather than a one-time assessment.