A compensating control is an alternative safeguard used when the preferred control cannot operate as designed. It can reduce risk during a genuine constraint, but only when leaders are explicit about the gap, the protection required and the conditions for returning to a durable design.
Start with the objective the missing control served
The owner describes the unavailable or deficient control, the risk it was meant to address, the affected process and the reason normal operation is not possible. Naming only the failed tool can miss the underlying objective, such as preventing unauthorized changes, detecting duplicate payments or protecting customer data.
The assessment considers exposure before the alternative is applied, including transaction volume, access, customer impact, duration and connected systems. This keeps the response proportionate and prevents a convenience measure from being labeled a control without showing which risk it reduces.
The alternative must provide credible protection
Management maps how the proposed safeguard prevents, detects or corrects the defined risk and where it operates in the process. Several narrower measures—such as restricted access, independent review and daily reconciliation—may be needed when no single alternative provides comparable coverage.
A manual review is not automatically equivalent to an automated control. Leaders consider skill, capacity, timing, data completeness, segregation of duties and the possibility that high volume or fatigue will make the alternative unreliable when it is most needed.
Scope, authority and duration should be explicit
The approval identifies which products, systems, locations or transactions are covered; who performs and reviews the control; what evidence is retained; and what conditions trigger escalation. The approving authority should match the residual risk and any policy exception or risk-acceptance requirements.
A compensating control has a start date, review frequency and target end state. Open-ended language can turn a temporary workaround into ungoverned process design, while an unrealistic deadline can encourage repeated extensions without addressing the root cause.
Evidence must show operation and effectiveness
Performance records show that the control happened for the full defined population and that exceptions were resolved. Testing separately asks whether the alternative actually addresses the risk at the required precision and speed rather than merely producing a checklist or signature.
Leaders monitor missed reviews, backlogs, overrides, incidents and changes in volume or complexity. A control that was reasonable for a short, low-volume period may become inadequate as conditions change, requiring restriction, added safeguards or faster remediation.
Closure means restoring a sustainable control environment
The owner fixes or replaces the preferred control, validates the new design, confirms it operates as intended and removes the temporary access, reports and procedures that are no longer needed. Evidence links the original gap to the final remediation and authorized closure.
A retrospective can reveal why the original control failed and whether similar dependencies exist elsewhere. Leaders use that learning to improve resilience and control design without treating the absence of a loss as proof that the temporary arrangement was sufficient.
Read the primary material
Banking Explained prioritizes regulators, official publications and first-party announcements.
