Control testing

This is the Control Testing stage. In real GRC work, you are testing two separate things:

  • Design effectiveness: Is the control properly designed to address the risk/requirement?
  • Operating effectiveness: Is the control actually being performed consistently?
OrderTabWhat you do in real lifeLondonBuild example
1Select ControlSelect the control you need to test.AC-002: Quarterly user-access review
2Identify Control ObjectiveConfirm what the control is supposed to achieve.Ensure inappropriate/unauthorised access is identified and removed.
3Review Control DesignCheck whether the control, as designed, can actually achieve the objective.Does the procedure require all users to be reviewed quarterly by an authorised person?
4Determine Design EffectivenessDecide whether the control is appropriately designed.Effective — the procedure addresses the identified risk.
5Define Testing PeriodEstablish the period you are testing.Q1–Q2 2026
6Select SampleSelect transactions/users/events to test.Select 20 employees from the access population.
7Inspect EvidenceExamine the actual evidence for your sample.Review access-review records for the 20 employees.
8Test PerformanceCheck whether the control was actually performed as required.Was each user’s access reviewed?
9Test FrequencyVerify the control operated at the required frequency.Were reviews performed every quarter?
10Test Approval / AccountabilityVerify the appropriate person performed or approved the control.IT Manager approved the review.
11Record ExceptionsDocument anything that failed your test.2 of 20 users had no documented review.
12Determine Operating EffectivenessDecide whether the control operated effectively during the period.Partially Effective
13Document ConclusionWrite your final testing conclusion and rationale.Control is well designed but operating effectiveness is partially effective due to 2 exceptions.

Example of the actual test

Control:

AC-002 — User access is reviewed quarterly.

Control objective:

Ensure inappropriate access is identified and removed.

Design effectiveness test

You ask:

“If LondonBuild follows this control exactly as written, will it address the risk?”

You find:

  • Review occurs quarterly ✅
  • All systems are included ✅
  • IT Manager is responsible ✅
  • Inappropriate access must be removed ✅
  • Review must be documented ✅

Design conclusion: EFFECTIVE ✅


Operating effectiveness test

Now you test whether LondonBuild actually did it.

You select 20 users.

TestExpectedActualResult
User 1 access reviewedYesYes✅ Pass
User 2 access reviewedYesYes✅ Pass
User 3 access reviewedYesNo❌ Exception
User 4 access reviewedYesYes✅ Pass
User 20 access reviewedYesYes✅ Pass

Suppose you find 2 exceptions out of 20.

You document:

Operating effectiveness: Partially Effective

because the control exists and is generally operating, but there are exceptions that need to be addressed.

The important distinction

QuestionWhat you’re testing
Is the control properly designed?Design Effectiveness
Is the control actually being performed?Operating Effectiveness
Did the test identify exceptions?Testing Result
What happens because of the exception?Gap / Risk
What needs to be fixed?Remediation