Join our Newsletter — 33% off our NHI Course

What breaks when a control exists on paper but not in operation?

The control can no longer be relied on to prevent or detect misstatements on time, so the organisation may have a hidden reporting gap even if the process appears documented. That usually means evidence, authority, or execution discipline is missing, and auditors will treat the issue as more than a minor paperwork defect.

What It Means When a Control Exists on Paper but Fails in Operation

A documented control is only useful if it is consistently performed, evidenced, and able to influence outcomes. When design and operation diverge, the control may exist in policy while failing in practice, which creates false assurance. The result is often a control deficiency that affects audit reliance, issue severity, and confidence in the reporting process.

Why the Gap Matters to Reporting, Assurance, and Control Design

The important distinction is between having a process description and having a control that actually works under normal conditions. A control that is not executed on time, by the right owner, or with the right evidence cannot be relied on to prevent or detect errors. That means the organisation may still have exposure even if the documented control looks complete.

This is especially material where the control is meant to catch misstatements, approvals, or exceptions before they flow into a report or ledger. If execution discipline is weak, the control may miss the very events it was supposed to stop, and the documentation can hide that weakness until testing exposes it.

What Breaks in Practice When Operation Does Not Match Design

Several things fail at once. First, the control no longer provides dependable prevention or detection. Second, ownership becomes unclear because staff can point to documentation without proving that anyone actually performed the step. Third, the evidence trail becomes thin, which makes it hard to show that the control operated consistently over time.

That gap also creates a monitoring problem. Management may believe the control is working because the procedure exists, but the lack of operating evidence means exceptions can accumulate unnoticed. In practice, the organisation is then relying on intention rather than control performance.

Where the issue involves reporting controls, auditors and reviewers usually care less about the formality of the write-up and more about whether the control was timely, precise, and repeatable. A control that cannot be demonstrated in operation is often treated as a substantive weakness, not a cosmetic documentation issue.

Risk and Threat Considerations

A control that exists only on paper creates false confidence, which can let reporting errors, override, or unauthorized activity persist undetected. The main risk is not the missing document, but the missed prevention or detection window that should have limited the error before it became material.

Failure mechanism: The stated control is not executed, not evidenced, or not owned tightly enough to operate on schedule, so exceptions are not caught when they occur.

Impact: The organisation can accumulate hidden reporting gaps, fail audit testing, and discover too late that the control was never reliable enough to support assurance.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 and SOC 2 (AICPA) define the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 CA-2 — Control Assessments Assesses whether controls are operating as intended, which fits paper-only control failures.
AU-2 — Event Logging Operational evidence is often what proves a control actually ran and produced traceable results.
Recommendation — Test control operation with evidence, not just documentation. Retain logs or records that demonstrate the control executed on time.
NIST CSF 2.0 GV.OV-01 — Oversight Governance oversight must confirm controls are performed, evidenced, and effective in practice.
Recommendation — Review operating evidence and escalate controls that are only documented.
ISO/IEC 27001:2022 A.5.36 — Compliance with policies, rules and standards for information security Controls must be followed in operation, not only written into policy.
Recommendation — Verify that policy requirements are implemented and followed consistently.
SOC 2 (AICPA) CC4.1 — Monitoring Activities Monitoring helps detect when a control exists in design but fails in execution.
Recommendation — Monitor control performance and investigate gaps between design and operation.

Practitioner Guidance

What to verify: Test the control from end to end, not just the policy. Confirm who performs it, when it is performed, what evidence is retained, and whether the evidence shows the control actually influenced the outcome.

Decision rule: If you cannot produce timely, unbroken evidence of operation for the period under review, treat the control as weak for assurance purposes even if the procedure is documented.

What good looks like: The control has a clear owner, a repeatable cadence, objective evidence, and an outcome that can be traced back to the control step without relying on oral confirmation or informal habit.

Practitioner takeaway: Documentation supports control design, but assurance depends on observed execution, if the operation is not provable, the control should not be trusted to carry risk.