This is the Control Testing stage. In real GRC work, you are testing two separate things:
- Design effectiveness: Is the control properly designed to address the risk/requirement?
- Operating effectiveness: Is the control actually being performed consistently?
| Order | Tab | What you do in real life | LondonBuild example |
|---|---|---|---|
| 1 | Select Control | Select the control you need to test. | AC-002: Quarterly user-access review |
| 2 | Identify Control Objective | Confirm what the control is supposed to achieve. | Ensure inappropriate/unauthorised access is identified and removed. |
| 3 | Review Control Design | Check whether the control, as designed, can actually achieve the objective. | Does the procedure require all users to be reviewed quarterly by an authorised person? |
| 4 | Determine Design Effectiveness | Decide whether the control is appropriately designed. | Effective — the procedure addresses the identified risk. |
| 5 | Define Testing Period | Establish the period you are testing. | Q1–Q2 2026 |
| 6 | Select Sample | Select transactions/users/events to test. | Select 20 employees from the access population. |
| 7 | Inspect Evidence | Examine the actual evidence for your sample. | Review access-review records for the 20 employees. |
| 8 | Test Performance | Check whether the control was actually performed as required. | Was each user’s access reviewed? |
| 9 | Test Frequency | Verify the control operated at the required frequency. | Were reviews performed every quarter? |
| 10 | Test Approval / Accountability | Verify the appropriate person performed or approved the control. | IT Manager approved the review. |
| 11 | Record Exceptions | Document anything that failed your test. | 2 of 20 users had no documented review. |
| 12 | Determine Operating Effectiveness | Decide whether the control operated effectively during the period. | Partially Effective |
| 13 | Document Conclusion | Write your final testing conclusion and rationale. | Control is well designed but operating effectiveness is partially effective due to 2 exceptions. |
Example of the actual test
Control:
AC-002 — User access is reviewed quarterly.
Control objective:
Ensure inappropriate access is identified and removed.
Design effectiveness test
You ask:
“If LondonBuild follows this control exactly as written, will it address the risk?”
You find:
- Review occurs quarterly ✅
- All systems are included ✅
- IT Manager is responsible ✅
- Inappropriate access must be removed ✅
- Review must be documented ✅
Design conclusion: EFFECTIVE ✅
Operating effectiveness test
Now you test whether LondonBuild actually did it.
You select 20 users.
| Test | Expected | Actual | Result |
|---|---|---|---|
| User 1 access reviewed | Yes | Yes | ✅ Pass |
| User 2 access reviewed | Yes | Yes | ✅ Pass |
| User 3 access reviewed | Yes | No | ❌ Exception |
| User 4 access reviewed | Yes | Yes | ✅ Pass |
| … | … | … | … |
| User 20 access reviewed | Yes | Yes | ✅ Pass |
Suppose you find 2 exceptions out of 20.
You document:
Operating effectiveness: Partially Effective
because the control exists and is generally operating, but there are exceptions that need to be addressed.
The important distinction
| Question | What you’re testing |
|---|---|
| Is the control properly designed? | Design Effectiveness |
| Is the control actually being performed? | Operating Effectiveness |
| Did the test identify exceptions? | Testing Result |
| What happens because of the exception? | Gap / Risk |
| What needs to be fixed? | Remediation |