This is a concept/portfolio site by Quell Studio — Alden Advisory is not a real firm. Read more

Insights — Article

The Control Nobody Owns Is the One That Fails

By Benjamin Foster

Reviewing control failures across a range of engagements, I've noticed the same precondition recurring with unusual consistency: the control that failed wasn't poorly designed. It was a control whose ownership had drifted, informally, after a reorganisation, without anyone updating the documentation to reflect who was genuinely responsible for it.

This drift happens quietly. A control gets assigned to a named role. That role gets restructured, merged, or eliminated eighteen months later, and the control's ongoing oversight gets informally absorbed by whoever seems adjacent to it — without a deliberate decision that this person is now accountable, and often without that person even being fully aware they've inherited the responsibility.

The control keeps appearing in the risk register, documented and apparently intact. What's missing is genuine, active ownership — someone who checks on it regularly because they understand, specifically, that it's theirs to check. A control in this state can pass a documentation audit indefinitely while being functionally unmonitored.

The failures I've reviewed that trace back to this pattern share a common feature afterward: nobody had lied about the control's status, and nobody had deliberately neglected it. The ownership had simply drifted, silently, until an incident made the gap undeniable.

Institutions serious about preventing this need a recurring, active re-verification process — not an annual documentation review, but a genuine check asking each control's named owner to describe, specifically, what they did recently to exercise oversight. If the answer is vague, the control is drifting, and it's considerably cheaper to catch that drift in a review than in an incident.

Browse more insights

All articles