Skip to main content
Category: Controls Management

Control Procedure

Also known as: Control Activity
Simply put

A control procedure is a specific, defined step or method an organization uses to safeguard something or check it against set parameters, helping ensure a process operates as intended. It differs from the process itself, which is the underlying activity being performed. In practice, control procedures are the concrete actions that put a control's intent into effect.

Formal definition

A control procedure is a documented, repeatable method that operationalizes an internal control, performing a safeguarding or checking function against defined parameters within a process. It is distinct from the broader process it governs and from a control objective, which states the outcome the control is intended to achieve; the control procedure is the mechanism by which that objective is pursued. Control procedures should not be conflated with audit procedures, which are the independent methods auditors use to obtain evidence about how a control is designed and whether it is operating effectively. The specific design, wording, and applicability of a control procedure typically vary by organization, system, and jurisdiction, and this entry does not address implementation tooling or legal advice.

Why it matters

Control procedures are the operational layer where a control's intent becomes a repeatable action. An organization may articulate sound control objectives, but those objectives are only pursued in practice through the specific, defined steps that safeguard something or check it against set parameters. Without well-defined control procedures, the connection between what an organization intends to achieve and what actually happens within a process can break down, leaving stated controls existing only on paper.

A recurring source of confusion is treating the control procedure as if it were the same as the process it governs or the objective it serves. The process is the underlying activity being performed; the control objective states the outcome the control is intended to achieve; and the control procedure is the concrete mechanism by which that outcome is pursued. Keeping these distinct matters because it clarifies who is responsible for performing the control, what the control is meant to accomplish, and how its effectiveness can later be evaluated.

Equally important is not conflating control procedures with audit procedures. A control procedure is a management activity embedded in a process, whereas an audit procedure is the independent method an auditor uses to obtain evidence about how a control is designed and whether it operates effectively. Preserving this separation protects the independence and objectivity of assurance activities and prevents an organization from mistaking the act of running a control for the act of testing it.

Who it's relevant to

Compliance officers
Compliance professionals rely on control procedures to translate control objectives into concrete, repeatable actions embedded in day-to-day processes. Clear procedures help demonstrate that adherence to internal policies and applicable requirements is being pursued through defined mechanisms rather than assumed.
Internal auditors
Internal auditors need to distinguish the control procedures being performed by management from the audit procedures they themselves use to obtain evidence about how those controls are designed and whether they operate effectively. Maintaining this distinction preserves the independence and objectivity of the assurance activity.
Risk managers
Risk managers care about control procedures as the practical means by which controls safeguard something or check it against defined parameters, helping ensure a process operates as intended. Understanding the specific procedures in place informs judgments about how uncertainty within a process is being treated.
Governance professionals
Those responsible for governance structures benefit from clarity on where the control procedure sits relative to the process it governs and the control objective it serves. This distinction supports accurate assignment of responsibility for performing controls versus evaluating them.

Inside Control Procedure

Control Objective
The specific outcome the control procedure is intended to achieve, such as preventing unauthorized access or ensuring the accuracy of financial reporting. A control procedure operationalizes a control objective; the two are distinct, with the objective describing the desired state and the procedure describing the steps taken to reach it.
Prescribed Steps or Activities
The documented sequence of actions personnel are expected to perform to execute the control, such as reviewing, approving, reconciling, or restricting. This is the operational core that differentiates a procedure from a higher-level policy or standard.
Assigned Responsibility
Identification of the role or function accountable for performing the control. In the three lines model of the IIA, control procedures are typically executed by first line operational management, while second line functions may design or monitor them.
Frequency and Timing
How often the control is performed, for example continuously, per transaction, daily, or periodically. This distinguishes preventive controls, which act before an event, from detective controls, which identify issues after they occur.
Evidence and Documentation
Records demonstrating that the control was performed as designed, commonly relied upon by assurance functions and, where applicable, by auditors testing operating effectiveness. Evidence supports the control but is distinct from the control activity itself.

Common questions

Answers to the questions practitioners most commonly ask about Control Procedure.

Is a control procedure the same as a policy?
No. A policy states management's intent and expected outcomes at a high level, whereas a control procedure specifies the detailed, step-by-step actions carried out to operate a control. Policies typically sit above standards and procedures in the governance hierarchy; a control procedure is the operational layer that describes how a given control is actually performed. Conflating the two obscures the difference between what the organization intends and how it is executed.
Does having a documented control procedure mean the control is effective?
Not necessarily. A documented procedure describes the intended operation of a control (its design), but effectiveness also depends on whether the procedure is consistently performed as written over time (operating effectiveness). A well-written procedure that is not followed, or that is poorly designed, may still leave risk inadequately treated. Documentation supports, but does not by itself demonstrate, effectiveness.
How detailed should a control procedure be?
The level of detail commonly reflects the risk being addressed, the complexity of the activity, and who performs it. Procedures typically include enough specificity to allow a competent person to perform the control consistently, such as the trigger, the steps, the responsible role, and the evidence produced. Excessive detail can make procedures hard to maintain, while insufficient detail can lead to inconsistent execution. This entry does not prescribe a fixed format, as practices vary by organization and framework.
Who should own and maintain a control procedure?
Ownership commonly rests with management in the function that performs the control, consistent with first line responsibilities in the three lines model. Second line functions may set expectations or review design, while assurance functions may evaluate procedures independently. Keeping these roles distinct helps preserve the objectivity of assurance activities. Specific ownership arrangements depend on the organization's structure and governance model.
How often should a control procedure be reviewed or updated?
Review frequency typically depends on the risk addressed, the rate of change in the underlying process or systems, and applicable framework or regulatory expectations. Many organizations review procedures periodically and also following significant changes, such as new systems, reorganizations, or changes in obligations. This entry does not specify a mandatory interval, as requirements vary by jurisdiction, sector, and internal policy.
What evidence should a control procedure produce?
A control procedure commonly identifies the records or artifacts generated when the control operates, such as approvals, reconciliations, logs, or sign-offs, which can later support monitoring or independent testing. Defining expected evidence within the procedure helps make performance verifiable. The specific evidence appropriate to a given control depends on its nature and the assurance needs of the organization; this entry does not address tooling or retention specifics.

Common misconceptions

A control procedure and a policy are the same thing.
They occupy different levels. A policy typically states intent and expectations at a high level, a standard specifies mandatory requirements, and a control procedure describes the concrete steps performed to meet those requirements. Conflating them obscures where a gap actually exists.
Having a control procedure in place guarantees the associated risk is addressed.
A control procedure reduces but does not eliminate risk; residual risk commonly remains after controls operate. Controls may also fail in design or operation, which is why assurance functions test their effectiveness rather than assume it.
The function that audits a control procedure is responsible for performing it.
Assurance activities are distinct from management activities. Under the three lines model of the IIA, the party executing a control differs from the independent function providing assurance over it; blurring this undermines objectivity and independence.

Best practices

Map each control procedure explicitly to the control objective and the risk it is intended to address, so its purpose and scope remain clear.
Assign clear ownership by role, distinguishing who performs the control from who monitors or provides assurance over it, consistent with the three lines model.
Document the steps, frequency, and timing precisely enough that the control can be performed consistently and its operating effectiveness can be tested.
Specify and retain the evidence the control produces, so its performance can be demonstrated to reviewers and, where applicable, auditors.
Classify the control as preventive or detective to confirm it operates at the intended point in the process relative to the risk.
Review control procedures periodically and when objectives, processes, or applicable requirements change, and note that specific obligations may vary by jurisdiction, industry, and organization size.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide