Join our Newsletter — 33% off our NHI Course

What are the signs that regulatory compliance controls are not working properly?

Warning signs include inconsistent procedures, missing documentation, weak segregation of duties, delayed audits, and gaps between written policy and actual practice. In privacy and security contexts, uncontrolled access to sensitive information, poor monitoring, and unresolved findings are strong indicators that compliance is drifting. When controls cannot be evidenced, organisations should assume the programme is not reliably operating.

What the warning signs usually look like in practice

The clearest signal is not a single failed check, but a pattern of control drift. If procedures vary by team, evidence is incomplete, reviews happen late, and staff keep working around formal steps, the control may exist on paper but not in operation. That gap matters because regulatory compliance is only defensible when the control is repeatable, auditable, and applied consistently.

A compliant programme should leave a reliable trail of who did what, when, and under which authority. When that trail is thin or contradictory, the issue is often not documentation alone, it is operating discipline. Poor evidence quality, unresolved exceptions, and repeated manual workarounds usually indicate that the process is too fragile to withstand audit or regulatory scrutiny.

  • Written policy says one thing, but the actual workflow is different.
  • Approvals, reviews, or reconciliations are delayed or skipped.
  • Ownership is unclear, so issues are passed between teams without closure.
  • Evidence cannot be produced quickly and consistently.

Where compliance controls most often break down

Controls commonly fail at the handoff points: provisioning, access review, exception handling, remediation, and monitoring. In those moments, organisations may still believe the control exists, but the operating details no longer match the stated design. That is especially dangerous when compliance depends on segregation of duties, restricted access, or timely challenge and response.

A particularly important sign is when exceptions become normal operating practice. If people keep relying on informal approvals, expired access, or stale attestations, the control environment is drifting from governed process to convenience-driven behaviour. For security and privacy obligations, uncontrolled access to sensitive data and unresolved findings are especially strong indicators that the programme is no longer reliably enforced.

High-volume evidence failures also deserve attention. If the team can explain the control verbally but cannot demonstrate it with logs, tickets, approvals, or review records, the issue is usually systemic. The control may be present in policy language, but it is not yet operationally trustworthy.

How to tell whether the control is actually operating

The practical test is whether the control produces consistent, reviewable outputs under routine pressure. You should expect stable sampling results, predictable remediation times, and evidence that matches the policy stated intent. When those outputs fluctuate by business unit, system, or reviewer, the control is not functioning as a uniform compliance mechanism.

For programmes that touch access, confidentiality, or auditability, internal consistency is more important than intent. A good control is not one that is merely described well, it is one that can be observed in the same way every time it runs. If findings remain open across multiple cycles, or if audit requests repeatedly surface missing artefacts, the organisation should treat the control as unreliable until proven otherwise.

In identity-heavy environments, compliance weakness often appears as weak governance over privileged or long-lived access, incomplete recertification, and poor visibility into who still has access to what. NHIMG’s Ultimate Guide to NHIs shows why this matters at scale: modern enterprises often have far more non-human identities than human ones, which means weak control execution can multiply quickly across systems and environments.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8, NIST CSF 2.0 and NIST SP 800-63 set the technical controls, while ISO/IEC 42001:2023 define the regulatory obligations.

Framework Control / Reference Relevance
CIS Controls v8 6 — Access Control Management Access and review failures are core signs of controls not operating properly.
8 — Audit Log Management Missing or weak evidence often shows that logging and review controls are failing.
Recommendation — Enforce and review access restrictions to close gaps between policy and actual practice. Collect and review logs so control operation can be evidenced consistently.
NIST CSF 2.0 GV.RM-01 — Risk Management Strategy Compliance drift is a governance signal that control assurance is no longer reliable.
PR.AA-05 — Identity Management, Authentication and Access Control Uncontrolled access and weak segregation of duties are direct signs of access-control failure.
DE.CM-07 — Continuous Monitoring Poor monitoring and unresolved findings indicate the control environment is not being observed effectively.
Recommendation — Define and monitor risk tolerance so compliance gaps are escalated when assurance weakens. Tighten access controls and verify they match approved roles and responsibilities. Monitor control outputs continuously and investigate unresolved exceptions promptly.
ISO/IEC 42001:2023 8.2 — AI Risk Treatment Where compliance controls govern AI-enabled workflows, operating drift requires formal treatment and evidence.
Recommendation — Treat control failures as managed risks and require evidence of corrective action.
NIST SP 800-63 IAL — Identity Assurance Level When compliance depends on trustworthy access decisions, assurance failures show up in weak evidence and review.
Recommendation — Use assurance expectations to validate that access and identity evidence is trustworthy.

Practitioner Guidance

What to prioritise: Start with controls that should leave the clearest evidence, such as access approvals, periodic reviews, exception closure, and monitoring. If those are weak, broader compliance claims are usually overstated.

What to verify: Check whether the evidence matches the process design, not just whether a document exists. A control that cannot be demonstrated on demand is already degraded, even if it passes a policy review.

Decision rule: If the control’s output depends on a few individuals remembering to do the right thing, treat it as fragile and redesign it for repeatability, traceability, and escalation.

Practitioner takeaway: The most reliable sign of broken compliance is a gap between expected control behaviour and what can actually be evidenced under scrutiny.