Skip to content

Enacted Control Verification And Closure

Verify controls as enacted, not merely as documented, and close the gap when paper controls and real operating practice diverge.

Core idea

Verify controls as enacted, not merely as documented, and close the gap when paper controls and real operating practice diverge.

Enacted-Control Verification and Closure applies when an organization relies on a documented control, procedure, approval, safeguard, monitor, barrier, or rule but the actual operating system may enact something different. The intervention names the nominal control and its intended hazard or invariant, samples work-as-done under representative conditions, gathers evidence of actual control behavior, classifies nominal-actual gaps, distinguishes safe adaptation from degraded protection, and routes material discrepancies to redesign, resource relief, procedure update, acceptance, or retirement.

This archetype should be used when an organization is at risk of believing a control exists because it is documented, while the real operating system has drifted, adapted, bypassed, or substituted that control. The important move is to verify the enacted control and then close the nominal-actual gap.

Problem signature

A nominal control is documented and treated as effective, but assurance samples the documented form more than the enacted form. The result is a false control claim: managers, regulators, dashboards, or downstream systems believe a barrier exists even though real practice bypasses, weakens, substitutes, delays, or locally reinterprets it.

Common triggers

  • A high-stakes control, safeguard, approval, checklist, alarm, access rule, interlock, monitoring step, or separation-of-duties rule is being relied on for safety, compliance, security, quality, or risk reduction.
  • Evidence of effectiveness is mostly documentary, self-attested, or generated by the same group that owns the control.
  • Actual work happens under load, time pressure, exception handling, degraded tooling, handoffs, maintenance windows, or local constraints not represented in the nominal procedure.
  • Operators maintain performance through workarounds, tacit expertise, informal coordination, reserve consumption, or exception paths.
  • A near miss, audit finding, incident, unexplained metric drift, or recurring waiver suggests the control may not operate as imagined.
  • The organization has incentives to preserve the appearance of control, such as compliance deadlines, customer certification, production pressure, or liability exposure.

Symptoms

  • Audit files are complete but frontline practice does not match the documented procedure.
  • Controls pass when demonstrated under clean conditions but fail during real workload, night shifts, degraded-mode operation, or cross-boundary handoffs.
  • Operators describe a “real way” of doing the work that differs from the training deck or official process.
  • Exception, override, waiver, break-glass, or manual-backdoor paths are used so often that they become the de facto process.
  • A control owner reports green status while incidents, near misses, rework, or manual rescues continue to accumulate.
  • Evidence samples are selected from records that already survived the process, not from the operating population where failures or bypasses arise.
  • The same paperwork sign-off is used to prove control design, control operation, and control effectiveness without separate tests.
  • Local teams preserve safety by using hidden slack or expertise that the nominal control does not recognize.
  • A finding is closed because the procedure was updated, but no one checks whether actual work changed.

Root tension

Formal controls make assurance legible, but real work adapts to constraints. The organization needs stable control claims, while operators need workable practice. If assurance trusts legibility over enactment, the system accumulates hidden exposure behind a clean nominal surface.

Intervention pattern

Create a nominal-actual control verification loop: define the control claim, trace how the control is actually enacted under representative conditions, classify deviations by risk and function, and force a closure decision that either changes the nominal record, changes the actual system, accepts a bounded exception, or retires the control claim.

Action logic

  1. Identify the specific control claim being relied on and the hazard, invariant, obligation, or decision it supports.
  2. Separate design adequacy, operating presence, and operating effectiveness so paperwork cannot satisfy all three by default.
  3. Construct a work-as-done sampling plan that includes ordinary, pressured, degraded, exceptional, and boundary conditions.
  4. Gather enacted evidence through observation, reperformance, logs, interviews, process traces, physical inspection, and direct tests.
  5. Compare documented nominal behavior with enacted behavior and record mismatches without collapsing them immediately into blame.
  6. Classify gaps as harmless adaptation, necessary compensation, hidden dependency, evidence failure, degraded control, bypassed safeguard, or obsolete nominal requirement.
  7. Rate each gap by risk, frequency, detectability, reserve consumption, reversibility, and downstream reliance on the control claim.
  8. Choose a closure route: redesign the control, update the procedure, add resources, remove friction, train, automate, enforce, formalize a safe adaptation, accept an exception, or retire the false claim.
  9. Retest actual operation after closure rather than closing the finding when the document changes.
  10. Set a cadence and trigger signals for repeated nominal-actual verification.

Decision rules

  • If the only evidence is the control document, policy, or checklist template, treat the control as designed but not yet verified as enacted.
  • If actual practice differs from nominal practice but preserves the control intent more safely or feasibly, update the nominal control rather than suppressing the adaptation.
  • If actual practice bypasses the hazard barrier or relies on hidden reserve, treat the gap as material even when no incident has yet occurred.
  • If samples are chosen by the control owner or from low-stress contexts only, expand sampling before claiming effectiveness.
  • If a control is routinely waived, overridden, or bypassed, decide whether the exception path is the real control and verify that path explicitly.
  • If corrective action changes documentation but not operating conditions, require post-closure retesting.
  • If disclosure of actual practice would trigger punishment, create an independent and no-blame channel before relying on interview evidence.
  • If the control claim is used by downstream models, certifications, audits, or governance decisions, publish scope limits and confidence qualifiers with the control status.

Invariants to preserve

  • Control claims remain tied to enacted evidence, not just nominal design.
  • The hazard or invariant protected by the control remains visible during verification.
  • Safe local adaptations are distinguished from dangerous bypasses.
  • Material gaps cannot be closed by documentation update alone without actual-operation evidence.
  • Sampling includes the conditions where control failure is plausible, not only ideal demonstrations.
  • The process preserves enough psychological safety and independence for actual practice to be reported.
  • Accepted exceptions are bounded, owned, reviewed, and visible to downstream reliance.

Target outcomes

  • Reduced false assurance from paper controls, checklist completion, and self-attestation.
  • Earlier detection of bypassed safeguards, normalized deviations, and controls that exist only nominally.
  • Better alignment between procedures, training, tooling, incentives, and real work constraints.
  • Clearer distinction between design adequacy, operating presence, and operating effectiveness.
  • More credible audit, certification, safety case, and governance claims.
  • Fewer recurring incidents where the postmortem discovers that everyone believed a control was in place but actual work had moved around it.
  • Improved trust between assurance functions and operating teams because adaptation can be surfaced and repaired rather than hidden.

Key components

ComponentDescription
Nominal Control Specification Role. States the documented control, safeguard, procedure, limit, owner, evidence requirement, and intended risk reduction. Notes. This is the paper or system-of-record version of the control; it must be precise enough to test against actual practice.
Enacted Control Trace Role. Captures observable evidence of how the control is actually executed, bypassed, adapted, deferred, or substituted during real work. Notes. The trace can come from observation, logs, interviews, process mining, artifact review, or direct performance testing.
Work-as-Done Sampling Plan Role. Samples the enacted control across shifts, sites, loads, edge cases, handoffs, maintenance windows, and abnormal operating modes. Notes. The plan deliberately avoids sampling only polished demonstrations, written procedures, or low-stress nominal conditions.
Nominal-Actual Gap Classifier Role. Classifies differences between the documented control and enacted control as harmless local adaptation, compensating practice, degraded control, bypassed safeguard, unrecorded dependency, or evidence failure. Notes. The classifier prevents all gaps from being treated alike; some deviations improve safety, while others silently remove protection.
Bypass and Workaround Inventory Role. Records recurring routes around the nominal control, including local reasons, incentives, frictions, constraints, and informal compensations. Notes. Workarounds often reveal design-for-implementation failures rather than operator negligence alone.
Control-Effectiveness Evidence Rule Role. Defines what evidence is sufficient to show that the control operates when needed, at the required cadence, with adequate authority, coverage, and response. Notes. A signed checklist or policy statement is not automatically evidence of actual control effectiveness.
Discrepancy Severity and Risk Rating Role. Ranks nominal-actual differences by hazard exposure, frequency, detectability, reserve consumption, regulatory impact, and reversibility. Notes. This keeps minor documentation drift from crowding out severe hidden control loss.
Corrective Closure Route Role. Routes each material gap to control redesign, procedure update, training, resource relief, enforcement, exception acceptance, or formal retirement. Notes. Closure means the actual system and nominal record are reconciled, not merely that an audit finding is closed administratively.
Drift Monitoring Cadence Role. Sets when the nominal-actual comparison is repeated and which signals trigger earlier retesting. Notes. Actual control states change with staffing, workload, tooling, incentives, suppliers, production pressure, and operating context.
Independence and No-Blame Safeguard Role. Protects the verification process from producer bias, punishment-driven concealment, and managerial incentives to preserve a paper-success story. Notes. People must be able to reveal work-as-done without automatically being punished for local adaptation.

Optional components

Control Owner and Operator Split

Distinguishes the accountable control owner from the people who execute or depend on the control. Useful where assurance is distorted because the owner sees only reports from the operating edge.

Reserve Consumption Signal

Shows whether the control works only because operators spend hidden slack, overtime, local expertise, or informal favors. Hidden reserve consumption is often the first sign that nominal control has become brittle.

Exception and Waiver Register

Records approved departures from nominal control and tests whether temporary exceptions have become the real operating model. A waiver register prevents normalized exceptions from disappearing into routine practice.

Evidence Chain Traceability

Links observations, logs, samples, interviews, and tests back to the specific control claim they support. Traceability protects against vague assurance evidence that cannot be used to evaluate control effectiveness.

Mechanisms

Work-as-Done Audit

Observes and reconstructs how the control is actually performed under ordinary and pressured operating conditions.

Document-to-Practice Trace Matrix

Maps each documented control requirement to real execution evidence, missing evidence, substitutions, and deviations.

Control Performance Walkdown

Walks through the control in the field or live system to verify that the specified barrier, approval, interlock, monitoring, or response path actually works.

Safeguard Bypass Probe

Tests whether users can or routinely do route around the nominal safeguard, and why the bypass is locally attractive.

Operator Shadowing and Contextual Inquiry

Elicits actual practices, constraints, tacit steps, and compensating work from the people closest to execution.

Process-Mining Nominal-Actual Comparison

Compares event logs or workflow traces with the documented process to reveal missing steps, out-of-order paths, and unrecorded variants.

Exception, Waiver, and Override Log Review

Finds controls that are nominally mandatory but routinely waived, overridden, postponed, or accepted as exceptions.

Corrective Action Effectiveness Retest

Rechecks the actual control after closure to verify that the gap did not persist under a new label.

Line-of-Defense Sample Reperformance

Independently reperforms a sample of control actions or approvals instead of relying only on the control owner’s evidence packet.

Near-Miss and Deviation Review

Uses near misses, deviations, small losses, and weak signals to select controls whose actual performance should be retested.

Parameter dimensions

  • control criticality: Low-consequence controls can use lighter sampling; safety-critical, security-critical, or rights-affecting controls need independent evidence and retesting.
  • evidence source independence: Evidence is stronger when it is not selected, interpreted, and closed by the same actor who owns the control.
  • operating-condition coverage: Verification should include ordinary operation, high load, exceptions, degraded modes, and boundary cases.
  • nominal-actual gap tolerance: Some gaps are safe adaptations; others remove the very invariant the control was supposed to protect.
  • closure authority: The pattern requires someone with authority to redesign controls, update procedures, accept exceptions, or stop relying on the control claim.
  • disclosure safety: The more punitive the environment, the more protected the evidence channel must be.

Applicability

Works well when

  • The control claim is important enough that false assurance would matter.
  • Actual practice can be observed, traced, reperformed, or inferred from credible evidence.
  • Operators, control owners, and assurance functions can distinguish learning from punishment.
  • The organization is willing to change either the control design or the nominal procedure when reality shows a mismatch.
  • There is enough sampling coverage to include edge cases, degraded modes, handoffs, exceptions, and high-load conditions.
  • Closure authority exists; findings can be translated into design, resource, procedural, training, tooling, or governance changes.

Weak when

  • Access to real work is blocked, staged, or politically filtered.
  • The assurance function is rewarded only for confirming compliance, not for discovering control loss.
  • The nominal control is so vague that actual behavior cannot be tested against it.
  • The system punishes honest reporting of workarounds, making enacted evidence unreliable.
  • Controls change faster than verification cadence and evidence traceability can keep up.
  • The review treats every deviation as operator error rather than possible evidence of design-for-implementation failure.

Neighbor distinctions

informal_structure_mapping

Informal Structure Mapping broadly reveals unofficial networks, workarounds, and influence paths. Enacted-Control Verification and Closure focuses on a specific control claim and asks whether actual operation still provides the intended protection.

independent_verification_oversight

Independent Verification Oversight supplies separated authority for a validity judgment. This archetype may use an independent verifier, but its central structure is the nominal-actual control comparison and closure loop.

observability_instrumentation

Observability Instrumentation creates or improves signals that reveal hidden state. This archetype uses evidence channels to test whether a claimed control is enacted and effective.

control_surface_creation

Control Surface Creation installs points of intervention. Enacted-Control Verification and Closure checks whether an existing surface actually exercises control under real conditions.

reconciliation_after_drift

Reconciliation After Drift repairs diverged records, states, or representations. This archetype repairs a specific assurance gap between nominal control record and actual control behavior.

construct_proxy_signal_validity_alignment

Construct Proxy Signal Validity Alignment tests whether a proxy signal supports an intended construct. Enacted-control verification tests whether the control itself exists in operation rather than whether a proxy measures a construct.

noise_bounded_measurement_interpretation

Noise-Bounded Measurement Interpretation limits claims made from noisy observations. This archetype can use uncertainty-aware evidence, but the main failure is false control assurance, not false precision.

reference_baseline_deviation_flagging

Reference Baseline Deviation Flagging flags departure from a baseline. This archetype goes beyond flagging by evaluating whether a nominal control claim is still true and closing the operational gap.

Variants

Work-as-Done Control Audit

A human-factors and safety variant that verifies controls by studying work as actually performed rather than work as imagined in procedures.

Distinctive feature: It emphasizes field observation, contextual inquiry, and respectful treatment of local adaptations.

Control Operating Effectiveness Testing

An audit and compliance variant that tests whether a designed control operated over the relevant period, population, and conditions.

Distinctive feature: It emphasizes sample evidence, operating period, reperformance, and sign-off criteria.

Safeguard Bypass Detection

A risk variant focused on detecting when protective controls are routinely circumvented because the nominal safeguard obstructs local production or recovery work.

Distinctive feature: It focuses on route-around behavior and the incentives that make bypass locally rational.

Configuration-Control State Reconciliation

A technical operations variant that compares intended control configuration with actual running state and repairs drift.

Distinctive feature: It focuses on machine-readable configuration and runtime state.

Tradeoffs and failure modes

Tradeoffs

  • Direct observation, reperformance, and representative sampling create assurance burden and may slow operations, but they reduce false confidence in paper controls.
  • No-blame discovery improves evidence quality but can frustrate accountability expectations when reckless bypassing is discovered.
  • Formalizing safe adaptations can improve reliability but may reduce local flexibility if codified too rigidly.
  • Aggressive closure of every gap can remove useful workarounds before the nominal control is redesigned to meet real constraints.
  • Publishing control-confidence limits improves honesty but may create reputational, regulatory, or contractual exposure.

Failure modes

  • Paper evidence laundering: The review accepts policies, screenshots, signatures, or training records as proof that the control operated. Mitigation: Require enacted evidence, reperformance, observation, or trace linkage for operating effectiveness claims.
  • Staged compliance theater: Teams prepare special demonstrations that differ from ordinary work. Mitigation: Sample unannounced, across contexts, and from operating records that were not prepared for the review.
  • Punitive workaround suppression: Operators are blamed for revealing adaptations, so actual practice disappears from view. Mitigation: Use no-blame evidence channels, separate intent from culpability, and examine design-for-implementation constraints.
  • Adaptation over-formalization: Every local workaround is converted into a rule without understanding context. Mitigation: Classify adaptations by control intent and preserve bounded local discretion where it improves safety.
  • Closure-by-document-update: Findings are closed when the nominal procedure changes even though actual practice is not retested. Mitigation: Require corrective action effectiveness retesting under representative operating conditions.
  • Sample blind spot: The sampling plan misses night shifts, high-load conditions, rare exceptions, handoffs, degraded modes, or edge populations. Mitigation: Use risk-weighted sampling and near-miss/deviation signals to select difficult cases.
  • Independence capture: The control owner controls evidence selection, interpretation, and closure. Mitigation: Add independent sampling, challenge authority, and traceable finding records.
  • False retirement of useful informal control: A workaround is eliminated because it violates nominal procedure, even though it was compensating for a design weakness. Mitigation: Evaluate whether the adaptation preserves the hazard invariant and redesign the nominal control before removal.

Examples

industrial_safety

A plant verifies that isolation and permit controls are actually used during maintenance under schedule pressure, not just that permit forms are filed.

Why it fits: The hazard barrier is nominally documented, but real work may rely on shortcuts, informal sequencing, or hidden expertise.

cybersecurity_and_access_governance

A privileged-access review is tested by sampling accounts, emergency overrides, and removal actions to confirm that approvals actually changed access.

Why it fits: The control claim is not satisfied by the review spreadsheet; the actual access state must reflect the decision.

healthcare_operations

A medication double-check policy is observed across shifts to see whether staffing, interruptions, and urgency convert the check into a signature ritual.

Why it fits: A nominal safety control can become a paper surface if enacted practice cannot support it.

financial_internal_controls

A reconciliation control is reperformed for sampled periods and exceptions to see whether reviewers identified, escalated, and resolved discrepancies.

Why it fits: Operating effectiveness requires evidence that the control worked over the period, not just that the design exists.

site_reliability_engineering

A failover runbook is tested during degraded-mode drills to verify that the documented control path matches actual tooling, permissions, and response capacity.

Why it fits: The nominal response control may fail if the real environment or authority path differs from the runbook.

public_program_integrity

Eligibility checks are compared against actual casework, exceptions, and override decisions to see whether the formal rule is governing access.

Why it fits: Program assurance can rely on rule documentation while actual administration evolves around local constraints.

Extended example

A utility has a documented lockout procedure and annual training completion above 99 percent. An incident review finds that maintenance crews often begin preparation work before all isolation steps are complete because equipment availability windows are short. The assurance team creates a work-as-done sampling plan across crews, night shifts, contractors, and emergency repairs. Field observation, permit review, and interviews show three distinct gaps: a harmless local checklist reordering, a hidden dependency on one senior technician’s memory, and a dangerous bypass during short outages. The team updates the nominal procedure to include the safe reordering, adds tooling and scheduling reserve for isolation confirmation, removes the bypass path, and retests under time pressure. The final control claim states where the control is verified, which exception path remains bounded, and when the next drift check occurs.

Non-examples

  • Reading a control policy and marking it present without observing or testing actual operation.
  • Designing a new approval workflow before any nominal-vs-actual gap exists.
  • Using a control group in an experiment to isolate treatment effect.
  • Blaming frontline staff for a workaround without checking whether the nominal procedure was feasible.
  • Updating a procedure after an audit finding but never testing whether real work changed.

Review notes

Drafted as a full archetype because the target prime has zero direct or related coverage and existing neighbors do not center the nominal-control versus enacted-control assurance gap.

Common Mechanisms

  • Control Performance Walkdown
  • Corrective Action Effectiveness Retest
  • Document-to-Practice Trace Matrix
  • Exception, Waiver, and Override Log Review
  • Line-of-Defense Sample Reperformance
  • Near-Miss and Deviation Review
  • Operator Shadowing and Contextual Inquiry
  • Process-Mining Nominal-Actual Comparison
  • Safeguard Bypass Probe
  • Work-as-Done Audit

Compression statement

Enacted-Control Verification and Closure applies when an organization relies on a documented control, procedure, approval, safeguard, monitor, barrier, or rule but the actual operating system may enact something different. The intervention names the nominal control and its intended hazard or invariant, samples work-as-done under representative conditions, gathers evidence of actual control behavior, classifies nominal-actual gaps, distinguishes safe adaptation from degraded protection, and routes material discrepancies to redesign, resource relief, procedure update, acceptance, or retirement.

Canonical formula: assured_control = nominal_specification ∩ enacted_operation ∩ risk_relevant_evidence; if enacted_operation differs materially from nominal_specification, close_or_accept_gap_before_claiming_control

Abstractions this archetype builds on — directly (a source ingredient) or as a related pattern. Links follow the typed catalog namespace.

Built directly on (13)

  • Accountability: Responsibility for actions.
  • Bypassed Safeguard: A protective control is systematically routed around by the very operators it was meant to protect, because it imposes friction against a production task and the workaround is locally rewarded and globally invisible until the rare hazard arrives.
  • Data Integrity: Accuracy and consistency preserved.
  • Discrepancy-Driven Correction: Iteratively close the signed gap between a target and an observation.
  • Formal vs. Informal Structures: Official vs actual systems.
  • Nominal vs. Actual Control: Every control exists as a documented nominal form and an enacted actual form, and the assurance apparatus usually samples only the former.
  • Normalization of Deviance: An operating standard drifts outward because small departures, each repeatedly observed without immediate catastrophe, are reclassified as normal.
  • Observability: Infer internal state externally.
  • Procedure-Work Mismatch: A system's prescribed model of how work happens diverges systematically from how work is actually done, with the gap often load-bearing for performance, so the question is how the gap is managed rather than whether it can be eliminated.
  • Sampling (Representativeness): Representative subset selection.
  • Traceability: The infrastructure of bidirectional links that lets any element be followed backward to its origin and forward to its uses, turning opaque processes into auditable, queryable histories.
  • Validation: Confirming that an artifact actually solves the intended problem in its real operational context, as distinct from confirming it was merely built to specification.
  • Verification: Check that an object conforms to its specification via a defined procedure yielding evidence and a verdict.

Also references 25 related abstractions

  • Attestation: A verifiable, principal-binding, tamper-evident mark lets a third party confirm who committed to what.
  • Calibration: Aligning a system's output to a trusted reference by measuring deviation, adjusting to reduce it, and monitoring for drift.
  • Certification: A trusted third party attests, after a defined evaluation, that an entity meets a standard, and issues a portable token downstream parties use as a substitute for re-doing the evaluation.
  • Configuration Drift: The silent, monotonic divergence between a system's recorded intended state and its actual running state, driven by accumulated out-of-band changes that bypass the record until a forced reconciliation exposes the gap.
  • Constraint: Limits possibilities to guide outcomes.
  • Control Sample: A deliberately matched comparator held alongside the case of interest so that the difference between them isolates the effect of the factor under test from the shared background.
  • Design for Implementation: Real-world feasibility.
  • Evidence: A defeasible, provenance-bearing relation between an observable trace and a hypothesis about an unobservable state.
  • Feedback: Outputs influence inputs.
  • Monitoring: Continuously observing a system's state to detect deviation from expected behavior and trigger a response, separating genuine signal from routine noise.

Variants

Narrower or domain-specific specializations that share this archetype's core structure. Recognized variants are established; candidate variants are provisional.

Work-as-Done Control Audit · domain variant · recognized

A human-factors and safety variant that verifies controls by studying work as actually performed rather than work as imagined in procedures.

  • Distinct from parent: The parent covers any nominal-actual control gap; this variant is centered on human work practice and sociotechnical safety.
  • Use when: Procedures, checklists, permits, or barriers exist but operators adapt them to real constraints; Safety assurance may be dominated by document review rather than field evidence; Local adaptations can be either resilience-preserving or risk-amplifying.
  • Typical domains: aviation maintenance, healthcare operations, industrial safety, emergency response
  • Common mechanisms: work as done audit, operator shadowing and contextual inquiry, control performance walkdown

Control Operating Effectiveness Testing · domain variant · recognized

An audit and compliance variant that tests whether a designed control operated over the relevant period, population, and conditions.

  • Distinct from parent: The parent includes safety and operational control gaps; this variant uses audit/compliance language and evidentiary thresholds.
  • Use when: A control has been designed and documented but must be shown to operate effectively over time; Evidence packets can be produced without proving real protection; Regulatory, financial, cyber, or quality assurance depends on control effectiveness.
  • Typical domains: financial controls, cybersecurity governance, quality management, regulatory compliance
  • Common mechanisms: line of defense sample reperformance, document to practice trace matrix, corrective action effectiveness retest

Safeguard Bypass Detection · risk or failure variant · recognized

A risk variant focused on detecting when protective controls are routinely circumvented because the nominal safeguard obstructs local production or recovery work.

  • Distinct from parent: The parent includes all nominal-actual gaps; this variant focuses specifically on bypassed safeguards.
  • Use when: A barrier, approval, interlock, checklist, or access rule exists but is inconvenient under pressure; Operators have informal ways to keep work moving around the safeguard; Rare hazards are controlled by a process whose actual use is uncertain.
  • Typical domains: process safety, medical device use, software security, rail operations
  • Common mechanisms: safeguard bypass probe, near miss and deviation review, operator shadowing and contextual inquiry

Configuration-Control State Reconciliation · domain variant · candidate

A technical operations variant that compares intended control configuration with actual running state and repairs drift.

  • Distinct from parent: The parent is cross-domain; this variant is specific to technical configuration drift.
  • Use when: Infrastructure, permissions, policy-as-code, feature flags, or device settings are supposed to enforce a control; Out-of-band changes can make the actual control state differ from the declared state; Downstream assurance relies on configuration records.
  • Typical domains: cloud infrastructure, industrial control systems, identity and access management
  • Common mechanisms: process mining nominal actual comparison, document to practice trace matrix, corrective action effectiveness retest

Near names: Actual Control Verification, Nominal-Actual Control Gap Closure, Paper Control vs. Real Control Audit, Work-as-Imagined vs. Work-as-Done Control Review, Control-in-Practice Assurance.