Skip to main content
Category: Controls Management

Implement

Also known as: Implementation, Put into effect, Carry out
Simply put

To implement means to put a plan, decision, or policy into effect by carrying out the actions needed to make it operational. In a GRC setting, it commonly refers to the act of turning a designed control, policy, or process from an intention into working practice. The term describes the doing stage that follows planning or design.

Formal definition

As a verb, to implement is to execute or put into effect a defined plan, policy, standard, procedure, or control so that it becomes operational within an organization. Implementation is generally understood as a management activity distinct from the prior design or approval of the item being implemented, and distinct from any subsequent assurance activity that evaluates whether the item was implemented as intended and is operating effectively. In governance, risk, and compliance usage, the meaning is typically qualified by its object, for example implementing a control, a framework, or a regulatory requirement, and the specific steps, evidence, and responsibilities involved vary by context and are out of scope for this general definition. Note that the term also has an unrelated noun sense meaning a tool or instrument, which does not apply in the GRC context.

Why it matters

In governance, risk, and compliance work, a well-designed control, policy, or framework delivers no value until it is actually put into effect. The gap between what an organization has approved on paper and what it does in practice is a recurring source of exposure: a risk treatment that has been decided but not carried out leaves the underlying risk untreated, and a policy that exists only as a document does not change behavior. Distinguishing the act of implementing from the prior act of designing or approving helps clarify where accountability sits when something intended does not become operational.

The distinction also matters for assurance. Because implementation is a management activity, it is separate from any later evaluation of whether the item was implemented as intended and is operating effectively. Confusing the two can obscure who is responsible for putting a control into practice versus who independently assesses it. Keeping this separation clear supports the objectivity of assurance functions and avoids the situation where those who carry out a control are also the sole judges of whether it works.

Precision in language is a further reason the term deserves attention. Implement is sometimes used loosely or interchangeably with words such as incorporate, and the same word also carries an unrelated everyday sense meaning a tool or instrument. In GRC usage the intended meaning is almost always the verb sense of putting a plan, policy, or control into effect, and being explicit about the object being implemented reduces ambiguity in policies, risk registers, and audit findings.

Who it's relevant to

Compliance officers
Compliance professionals rely on the term when moving policies and regulatory requirements from approval into operational practice, and when documenting that intended measures have actually been carried out rather than merely decided.
Risk managers
Risk managers use implementation to describe the point at which an agreed risk treatment or control is put into effect. Until treatment is implemented, the associated risk generally remains untreated, so tracking implementation status is central to managing exposure.
Internal auditors and assurance functions
For those providing assurance, the term marks a boundary they must respect: implementation is a management activity, distinct from the independent evaluation of whether an item was implemented as intended and is operating effectively. This separation supports auditor independence and objectivity.
Governance professionals
Those responsible for governance structures and decision rights use the term to distinguish the approval or design of a plan or policy from the subsequent responsibility for putting it into effect, clarifying accountability for the doing stage.

Inside Implement

Control Deployment
The act of putting designed controls into operational use, translating documented control designs into working processes, system configurations, or manual activities performed by responsible personnel.
Policy and Procedure Operationalization
Converting approved policies and standards into executable procedures, so that stated requirements are reflected in day-to-day activities carried out by the relevant lines of responsibility.
Roles and Accountability Assignment
Allocating who performs, owns, and oversees each activity. Implementation commonly assigns operational execution to first line functions, with second line typically providing guidance and oversight, distinct from third line assurance.
Change and Communication
The training, communication, and change management needed for affected staff to understand and adopt new or revised controls, policies, or processes.
Evidence and Records
The documentation and records generated as controls operate, which may later support monitoring, review, or independent assurance activities.

Common questions

Answers to the questions practitioners most commonly ask about Implement.

Does 'implement' mean the same thing as 'design' when it comes to controls?
No. Implementation and design are distinct phases. Design concerns defining what a control, policy, or process should do and how it is intended to operate; implementation concerns putting that design into operation within the organization. A control can be well designed but poorly implemented, or implemented in a way that departs from its design. In assurance work, evaluators typically assess design effectiveness and operating effectiveness separately, and implementation sits between the two, confirming that a designed control has actually been placed into operation before its ongoing effectiveness can be tested.
Once a policy or control is implemented, does that mean it is effective and the objective is achieved?
Not necessarily. Implementation means a control or process has been placed into operation; it does not by itself demonstrate that it operates effectively over time or that the underlying objective is met. Effectiveness is established through monitoring and testing of operation, not through the act of implementation alone. Treating implementation as equivalent to effectiveness is a common misconception that can leave residual risk unaddressed and give false assurance.
Who is typically responsible for implementing a control or policy within the three lines model?
In many organizations using the IIA's three lines model, implementation of controls and adherence to policies commonly sits with the first line, the operational management that owns and manages risk day to day. The second line, such as risk and compliance functions, typically supports, advises on, and monitors implementation but does not usually own operational execution. The third line, internal audit, provides independent assurance over how implementation has been carried out and should not implement controls it later audits, to preserve independence and objectivity. Responsibilities vary by organization and how it has structured its governance.
How can an organization evidence that a control has actually been implemented?
Evidence of implementation commonly includes records showing the control has been placed into operation, such as approved and communicated policy documents, configuration records, system logs, sign-offs, training completion records, or samples showing the control was performed. The specific evidence appropriate depends on the nature of the control and the organization's context. Note that implementation evidence typically demonstrates only that a control exists and has been put into operation at a point in time; demonstrating that it operates consistently requires evidence gathered over a period.
What is the relationship between implementing a control and treating a risk?
Implementation is often the execution stage of a chosen risk treatment. In risk management processes such as those described in ISO 31000, once a treatment option is selected, which may include modifying risk through controls, implementation puts that treatment into effect. Implementation applies to a treatment already decided; the decision on whether and how to treat a risk against risk appetite and tolerance is a separate, earlier step. This entry does not cover how to select among treatment options.
What should be considered when planning to implement a new policy or control across an organization?
Considerations commonly include clarifying ownership and accountability, communicating the change to affected personnel, providing any needed training, aligning the control with existing processes and systems, and establishing how its operation will subsequently be monitored. Jurisdictional, sectoral, and organizational context typically shapes what is appropriate. This entry does not address specific tooling, project management methodologies, or implementation specifics, which vary by organization and are outside its scope.

Common misconceptions

Implementation is complete once a policy or control has been designed and approved.
Design and approval are distinct from implementation. A control that exists on paper is not operating until it is deployed, assigned to accountable parties, and performed in practice; a documented control objective differs from the control that actually achieves it.
Implementing a control guarantees the associated risk is eliminated.
Implementation typically reduces risk from an inherent to a residual level, but residual risk commonly remains. Controls may have design or operating limitations, and no control can be presumed to guarantee an outcome.
The function that implements a control can also provide independent assurance over it.
Implementation is a management activity performed by operational (first line) functions. Independent assurance over the implemented control is a separate activity that relies on the objectivity and independence of an assurance function, such as internal audit; conflating the two undermines that independence.

Best practices

Clearly assign ownership and accountability for each implemented control or procedure, distinguishing who executes it, who oversees it, and who provides independent assurance.
Trace each implemented control back to the control objective, policy, or risk it is intended to address, so that operationalization reflects the original intent.
Support implementation with appropriate training, communication, and change management so affected personnel understand and can perform the new or revised activities.
Capture and retain evidence that controls are operating as intended, enabling later monitoring, review, and independent assurance.
Confirm that implementation reduces risk to a residual level within the organization's stated risk appetite and tolerance, and record any remaining residual risk.
Account for jurisdictional, sectoral, and organizational context when implementing, since applicable obligations and expected practices may differ across settings.
Promotional banner for the Pentest Readiness checklist download