Risk and Resilience

Who Retires a Control?

Nothing in the risk discipline retires a control, so the estate compounds unowned, and the assurance function that reviews it can only ever find there is too little.

EraNorth Insights · 30 Aug 2026 · 14 min read

Nothing in the risk discipline retires a control, so the control estate is a permanent, unowned, compounding cost and risk position, and the assurance function that reviews it can only ever find that there is not enough of it.

Put one question to an executive team: what is the cost and risk position of the controls this enterprise no longer needs? The conversation will stall, and not on the arithmetic. It will stall on the noun. Nobody can say which controls those are, because no instrument the enterprise operates records the answer and no role is accountable for producing it.

The absence is structural, and visible in the discipline's own documentation. A risk has a carefully described lifecycle: identified, analysed, treated, monitored, then closed — retired when its trigger window has passed, resolved when it was contained, transferred when another party formally accepts it. Closure requires a retirement date and a reason. Every register, worksheet and plan template in general use tracks a risk from first entry to final disposition.

Now look at the companion document. The controls register in common use carries three things: a reference to the risk, a short description of it, and details of what is in place. No owner. No installation date. No review date. No cost. No state whose value could be no longer required. The same material that prints this three-column template also draws a summary diagram in which the controls register carries a control identifier and an owner. The picture promises fields the template does not contain, and the discipline has not noticed.

The consequence compounds quietly. Each control is cheap on the day it is added and permanent thereafter, and the enterprise pays for all of them continuously — in money, and in the slower currency of signatures, cycle days and skilled hours spent producing evidence rather than output.

The function chartered to review all this cannot correct it. Its instrument scores a control as adequate or inadequate, implemented or partly implemented, and holds no value that means the control should go. A review whose vocabulary contains no word for surplus finds a deficit every time it looks, is right every time, and the estate grows.

The Strategic Context

Consider a hypothetical heavy equipment rental business: excavators, telehandlers, generators and lighting towers hired to civil contractors and mine sites. Its economics are turnaround. A machine off hire and not yet re-hired earns nothing, and the difference between a good branch and a poor one is measured in hours.

Its control estate was built one incident at a time, and every addition was correct on the day. A tip-over produced a pre-hire inspection sheet and a second signature. A bad debt produced a credit check on every new account regardless of size. An injury on a client site produced operator competency verification before release. A theft produced geofence alerting monitored at branch level.

A decade on, the fleet is younger, the machines carry telematics from the factory, the credit exposure sits with a finance partner, and the branch runs a checklist assembled from decisions taken by people who have all since left. Nobody has removed a step, and the reason is not caution. No procedure exists by which a person could: no form, no authority, no register field, no meeting whose purpose is to consider it.

The estate is therefore a strategic position, not an operational nuisance: an indefinite, unpriced commitment against the one resource the business competes on. This article takes the individual control as its unit; what reaches a governing body in the first place, and what accumulates below the threshold that decides, belongs to [Related article: Escalation Sized by One Risk].

What Leaders Commonly Misread

The first misreading is that the control estate is priced somewhere. It is not. A control is bought once and paid for continuously, in different currencies. The purchase appears as a project cost or an audit action. The payment appears as cycle time, headcount drift and a slower answer to a customer, spread across cost centres with no reason to attribute it to a decision taken years earlier.

The second is that assurance would raise it. Its scale measures one direction, and so do the incentives: a reviewer who recommends keeping a redundant control is never wrong in any traceable way, while one who recommends removing it owns the next incident personally. Nothing in that asymmetry is corrupt; it is what the role was built to do, and it produces a monotonic estate.

The third and most consequential is that closing a risk closes its control. Closure procedures are precise about retiring a risk and formal about transferring one, requiring the receiving party to acknowledge and accept. Not one line addresses the control installed to manage it. Worse, the control is often the reason the risk closed, which makes it look indispensable exactly when it should be re-examined. A related belief, that removal offends layered defence, holds only where the layers answer live threats; layers standing over a threat that has changed shape are sediment, not depth.

Reframing the Issue

A control is not a decision. It is a standing liability with an indefinite term and no break clause.

Every other continuing obligation an enterprise carries is structured with an end. A lease expires. A licence is renewed. A role is re-established at each budget. Each forces a named person to re-justify it on a stated date, and the enterprise treats that as elementary. The control estate is the only commitment of comparable scale entered into permanently, by default, at the discretion of whoever was in the room after the last incident.

The second reframe comes from the discipline's own account of treatment. Doctrine holds that every risk response generates secondary risks: cost, complexity, new access points, skill atrophy, and the false assurance that stops anyone looking. A control retained after its purpose has lapsed is therefore a pure risk position, carrying all of the secondary risk and none of the primary benefit. Keeping it is not the conservative choice. It is an unhedged one.

This article concerns what happens to a control after it exists. How one comes to be authorised at all, and why the instrument approving it has no field for what it will cost, is the subject of [Related article: The Only Spend With No Business Case] and is not argued here.

The Estate Nobody Owns

The lifecycle stops at the risk

The asymmetry is easy to verify inside any enterprise. Ask for the lifecycle states a risk can occupy and a documented list appears: open, in progress, monitored, closed, transferred, retired, materialised. Ask for the states a control can occupy and there is silence, because there are none.

The register has no field for surplus

The controls register is a cross-reference table. It links a risk to a description of what is in place so an assessor can judge whether the residual rating is credible. What it cannot do is hold a management position about the control itself, having no column in which one could be written. Adding a column is trivial; nobody has, because nobody owns the estate the register describes.

Assurance can only ever find a deficit

Consider a hypothetical not-for-profit disability services provider funded per hour of support delivered. Every control it adopts converts paid support time into unpaid administrative time, so its control estate is funded directly out of service. Each control arrived properly, after an incident, an audit finding or a funding review.

Now run the annual review. The reviewer can find controls that are inadequate and controls only partly implemented, and will recommend strengthening both. No finding is available that reads: this provider spends too much of its delivered service on control, and here are the four to withdraw. Over a decade of competent reviews the support-to-administration ratio moves one way, and no individual decision was wrong.

The environment moves and the control does not

The discipline states plainly that treatments are not set and forget, and that a control suited to one threat environment must be reviewed as that environment evolves. It also records the more uncomfortable case: a control installed against one threat can create the conditions for a different one. Neither proposition is supported by an instrument capable of expressing the withdrawal it implies. The teaching says the estate must be pruned; the toolkit contains no shears.

Decision Framework

The control retirement review is an annual exercise run on one function at a time. It begins by adding the four fields the controls register lacks: installation date, the risk reference that caused the control, the named owner, and annual cost in the unit that binds the business — hours, signatures, cycle days, a fraction of a scarce role. Five tests then apply, each with a default disposition.

TestQuestionDefault disposition
1. OriginWhich risk entry caused this control, and what is its status?Risk closed, transferred or untraceable: the control enters the retirement queue
2. SubstitutionHas anything installed since addressed the same cause?Two controls, one cause: only the stronger is retained unless someone argues the layering in writing
3. EnvironmentIs the threat shaped as it was when this was installed?Shape changed: re-specify or withdraw, never carry forward
4. Secondary riskWhat exposure does the control itself create, and does it net positive?Net not positive: retire
5. Binding costWhat does it consume yearly of our binding resource?Top decile: re-justified annually by its named owner

Three rules make the review bite.

The burden of proof sits with retention. A control whose originating risk is closed or untraceable is retired unless someone puts their name to keeping it. That inversion does most of the work, because estates compound for one reason: removal has always required an argument and retention has never required one.

Every retirement carries a reinstatement trigger recording what would have to occur for the control to return. That converts retirement from an irreversible bet into a monitored decision, and removes most of the personal risk that stops capable people recommending it.

No new control is approved without naming the control it replaces, or stating that it replaces none. That statement makes accumulation visible when it happens rather than a decade later.

The review produces three lists — retained, retired, referred — and a named executive signs the retirement list. Which executive may sign it, and what that authority is worth against what a control commits the enterprise to, is a separate mechanism examined in [Related article: What May They Cost You?].

From Strategy to Execution

Immediately. Take one process in one function and list every check, sign-off, inspection and report it contains. Against each, name the risk that put it there. The controls nobody can attribute are the finding, and they are usually a third of the list. It takes an afternoon and settles whether the problem is real.

Over the next two quarters. Add the four missing fields to the controls register and populate them for the largest function. Make the control retirement review a standing annual obligation of the body that already receives assurance reports. Adopt the replacement rule for new controls at once: it costs nothing and halts growth while the backlog clears.

Over the longer horizon. Change what assurance is asked to report. A function chartered only to find gaps will find them forever, accurately. Give it a mandate to report the net position — what is missing and what is surplus — with a scoring value capable of expressing the second. Until a report can recommend withdrawal without its author bearing the whole downside, no framework will retire anything.

Signals to Monitor

The clearest signal is attributability. When people inside a function cannot say which risk a control answers, that control is already unowned, whatever the register shows.

Watch the ratio of controls added to controls removed over a rolling three years. A denominator that has been zero for the life of the enterprise means the estate is unmanaged by definition, whatever its assurance rating.

Watch cycle time in processes whose scope has not changed, and the count of signatures on a routine transaction over five years. Quiet drift in a stable process is the estate reporting its own growth.

Watch for workarounds. When capable people route around a control rather than through it, they have made a judgement the governance system is not equipped to make, and made it without a record.

Questions for the Leadership Team

  1. How many controls are in force in our largest operating function, and where is that list held?
  2. For the ten most time-consuming, which risk register entry caused each, and what is that entry's status today?
  3. When was a control last formally withdrawn here, by whom, and under what authority?
  4. What does our control estate consume each year of the resource that constrains us, and who calculated it?
  5. Which of our controls answer a threat whose shape has changed materially since installation?
  6. Has any assurance report ever recommended removing a control, and if not, what would have to change for one to?

Closing Perspective

An estate that only grows is nobody's decision, and that is the difficulty. Every addition was justified, every reviewer competent, and the aggregate is a commitment no board approved and no executive owns.

Retiring controls will sometimes be wrong. A withdrawn control will occasionally prove to have been the one that mattered, and the enterprise will pay for that visibly, with a name attached. Retaining every control is also sometimes wrong, and the enterprise pays continuously and invisibly, in slower decisions and diverted capacity that never appear as a loss. The asymmetry between how those two errors are experienced is the whole reason the estate compounds. An enterprise unwilling to be occasionally wrong about removal has chosen to be permanently wrong about accumulation.

The responsibility is narrow and does not delegate well. Somebody has to be authorised to say that a control is no longer needed, and to be judged on the net position rather than on the next incident. In most enterprises that person does not exist, and the estate is not waiting for permission to keep growing.


About EraNorth Insights
EraNorth Insights publishes practical analysis on strategy, projects, operations, transformation and decision intelligence for professional and organisational use. About EraNorth.