NORA
Back to Resources
Perspectives

Why “We Have Controls in Place” Is Not the Same as “Our Controls Are Working”

The most common answer in a risk assessment is also the least informative. Here’s what to ask instead.

8 min read

There is a phrase that appears in nearly every risk assessment, across every industry, in organizations of every size: “we have controls in place.”

It is offered genuinely. The person saying it believes it. They implemented the control, documented it, and moved on. From their perspective, the box is checked and the risk is managed.

What the phrase does not tell you — and what the assessment almost never asks — is whether the control is working. Not whether it exists. Whether it is functioning as intended, in the environment that exists today, in the workflows that people actually follow.

Those are not the same question. And the gap between them is where most assessment findings live.

It’s Not Interrogation. It’s Perspective Shift.

The instinct when hearing this is to assume the solution is more scrutiny — harder questions, more evidence requests, a more adversarial posture toward the asset owner. That instinct is wrong.

Asset owners are not hiding things. They are answering the questions they’ve been asked, from the perspective they’ve always been asked to answer from. The problem is not that they’re being evasive. It’s that nobody has ever asked them to look at their own environment from a different angle.

The right questions don’t pressure asset owners into admissions. They reframe the conversation in terms of the asset owner’s actual day-to-day work — their workflows, their team structures, their operational realities — and let the risk surface naturally through the answers.

That reframe is the difference between an assessment that confirms what people believe and one that surfaces what they haven’t thought to question.

The HR System: When Three Teams Each Did Their Job and the Risk Still Got Through

Here is how access control gaps actually happen in HR systems — not through carelessness, but through a handoff problem that no single team owns.

The HR manager knows the rules of the road. A Senior Manager should only be able to see data for their direct reports — not every employee who carries the same title tier across the organization. That boundary is not a security best practice. It is a business rule, grounded in how the organization actually structures accountability and privacy.

The IAM team knows best practices. When they approved the entitlement model for the HR system, they designed roles based on job levels — Senior Manager, Director, VP — because that is the framework they work within. Role-based access control is correct practice. But the IAM team doesn’t live inside the HR workflows every day. They don’t necessarily know that a Director in Finance has no legitimate reason to see compensation data for people in Engineering. They approved a model that was technically sound and operationally incomplete.

IT implemented what they were given. The roles exist. The access controls are in place. The assessment records them as such.

What the assessment never asks is the question that would have caught this: “Can a Senior Manager in your system see data for employees outside their direct team?”

That question, asked of the HR manager, would have surfaced the business rule immediately. The HR manager knows the answer. They may have raised it during implementation and been told it was something to revisit later. But the traditional assessment doesn’t ask them to evaluate the entitlement model against the business rules they operate by — it asks whether controls exist, and they do.

This is the gap that lives in almost every system in every organization. IT and Security know best practices. Asset owners know the rules of the road. The assessment process almost never puts those two bodies of knowledge in the same conversation — and the risk that lives between them goes unscored.

The CRM: What the Logs Are Not Watching

Sales systems are among the highest-risk assets in any organization. They contain the full customer and prospect database, deal history, contact relationships, and in many cases pricing and contract terms. They are also among the assets where access controls get the least scrutiny — because they’re designed to be easy to use, and ease of use and precision of access tend to work against each other.

A traditional assessment asks: “Do you have access controls in place for your CRM?” Yes. “Is access restricted to authorized users?” Yes. Both checkmarks recorded.

Here are the questions that produce a different conversation:

“Can a sales rep who puts in their notice today still access their full pipeline from a personal device tonight?”

Most organizations don’t have a clean answer to that question. The rep’s access is tied to their employment status, but the process for revoking it when someone resigns — as opposed to when IT processes a formal offboarding — is rarely defined or immediate.

Then the follow-up:

“When did someone last review download or export activity in your CRM — and would you know if a rep had pulled the full contact database in the last thirty days?”

Organizations don’t proactively monitor CRM export activity. The logs exist. The data is there. But nobody is reviewing it unless something has already gone wrong. A sales rep who decides to leave — or who has already decided and hasn’t said so yet — can download the entire customer database weeks before their departure is known, and the organization will almost certainly not find out until long after the fact, if ever.

The control exists. The gap is in whether anyone is watching it work.

The Finance System: The Policy Says One Thing, the System Allows Another

Accounts payable systems carry a specific version of this problem. Segregation of duties — the principle that the person who initiates a transaction should not be the person who approves it — is well understood by security and finance teams alike. It appears in frameworks. It gets documented in policies.

What the IAM team approved, in many organizations, is a role model based on job titles and departments. What the AP manager knows — because they work in the system every day — is whether those roles actually enforce the separation at the system level, or whether the policy exists on paper while the system allows the same person to create a vendor and approve a payment to them.

The question that surfaces it: “Can someone in your AP system who creates a new vendor also approve a payment to that vendor?”

The AP manager may know the answer is yes. They may have flagged it. They may simply have assumed that the IAM team’s approval of the role model meant the control was enforced. The assessment doesn’t ask them to look at the gap between the policy intent and the system behavior — so the gap stays invisible.

The Pattern Across All of Them

None of these are failures of bad actors or negligent teams. They are failures of translation — between the people who know security best practices and the people who know how the business actually runs.

IT and IAM and Security know the frameworks. They know what controls should look like in the abstract. What they don’t always know is the specific rules of the road that govern each asset — the business logic, the workflow boundaries, the organizational context that determines whether a technically correct control is actually doing what it needs to do.

Asset owners know those rules. They live in them every day. But the traditional assessment process asks them compliance questions, not workflow questions — and compliance questions don’t require them to engage the knowledge that would surface the real findings.

The right questions start from the workflow. They ask the asset owner to evaluate their environment not from the perspective of whether a control was implemented, but from the perspective of how their system actually behaves when real people use it to do their real jobs. That is the perspective that finds what three technically correct teams can collectively miss.

“We Have Controls in Place” Is the Beginning of the Conversation

The phrase is not wrong. It is incomplete. Controls in place is the starting point, not the finding. The finding comes from what happens next — from the questions that ask the asset owner to walk through how their system actually works, to describe what someone could do in a scenario the IT team never modeled, to explain whether the business rules they follow every day are reflected in the access model someone else designed.

Most of the time, asset owners know more than the assessment ever captures. They know the gaps. They know the edge cases. They may have even raised them at some point and watched them deprioritized.

The right questions just have to give them somewhere to put it.

See How NORA Asks the Right Questions

NORA guides your asset owners through plain-English assessments built to surface operational reality — not just documented policy. The result is a risk score that actually reflects your exposure.