Line-of-Defense Sample Reperformance¶
Independent reperformance — instantiates Enacted-Control Verification and Closure
Independently re-executes a sample of control actions or approvals to see whether the control operated as claimed, instead of trusting the owner's evidence packet.
Line-of-Defense Sample Reperformance establishes whether a control operated by having someone other than the control's owner redo a representative sample of the control's own actions and checking whether the result matches what the owner recorded. Its defining move is independent re-execution as evidence: rather than reviewing the owner's assurance packet — which was selected, performed, and signed by the party with the strongest incentive to look green — a separate line of defense re-performs the reconciliation, re-runs the approval logic, or re-checks the access decision on sampled cases and sees if it reaches the same answer. The verdict is an operating-effectiveness judgment across a population, drawn from work the verifier did themselves, with independence from the owner as the property that makes the evidence worth anything.
Example¶
A bank relies on a month-end reconciliation control: an operations team is supposed to match the general ledger against sub-ledger detail, investigate every discrepancy above a threshold, and clear it with documented resolution before sign-off. The control owner's packet shows every period reconciled and signed. Internal audit — a second line independent of operations — runs a Line-of-Defense Sample Reperformance rather than reading the packet again. They draw a sample stratified toward the risky cases (large discrepancies, period-ends near quarter close, accounts with prior issues) and re-perform the reconciliation themselves from the source data.
For most sampled periods the audit's independent redo lands on the owner's number — evidence the control operated. But on a subset, reperformance tells a different story: a flagged discrepancy the packet marked "resolved" cannot be re-derived from the underlying entries, and two large items were netted in a way that made the reconciliation balance without actually being investigated. Because the verifier reached these conclusions by doing the work independently rather than reading the owner's summary, the finding carries weight the packet never could — and because the sample was drawn to a pre-set effectiveness rule, the result is stated as an operating-effectiveness rate over the period, not an anecdote.
How it works¶
- Draw an independent, risk-weighted sample. The verifier — not the owner — selects which control instances to re-perform, over-weighting the cases where failure would matter most, so the owner cannot curate the evidence.
- Re-execute the control action. The reconciliation is redone, the approval logic re-applied, the access change re-derived from source, producing the verifier's own result rather than a read of the owner's.
- Compare against a pre-set effectiveness rule. Each reperformed case is scored pass/fail against a stated criterion for what "operated correctly" means, and the sample rolls up into an operating-effectiveness conclusion.
- Preserve the owner/verifier separation. Sampling, execution, and judgment stay with a line of defense distinct from the control's owner, which is the whole source of the evidence's credibility.[n1]
Tuning parameters¶
- Sample size and stratification — larger, more risk-weighted samples give stronger population conclusions but cost verifier time; small clean samples over-reassure.
- Independence depth — a peer team, a second line, or a fully external party. More separation is more credible and more expensive to arrange.
- Effectiveness criterion strictness — how exactly the reperformed result must match to count as a pass, trading false alarms against missed failures.
- Source-data reach — re-performing from primary source versus from the owner's working papers; reaching to source is stronger but slower.
- Coverage period — how much of the operating period the sample must span to support a standing effectiveness claim.
When it helps, and when it misleads¶
Its strength is credibility through independence: because the verifier reaches the answer by doing the control's work rather than trusting a summary of it, the evidence resists the producer bias that hollows out self-attested assurance — the reason reperformance ranks among the strongest tests of controls in audit practice. It converts "the owner says it reconciled" into "an independent party re-derived it and it did (or didn't)."
Its failure mode is that reperformance proves the control could produce the right answer on the sampled cases, not that it did so at the time and for the right reason: a verifier redoing the work today may unknowingly supply diligence the original operator skipped, so a passing reperformance can flatter a control that only works when audit is watching. It is also blind to failures outside the sample. The classic misuse is letting the owner influence the sample or supply the source data, which quietly reintroduces the bias the mechanism exists to defeat. The guarding discipline is to keep sample selection and source access with the independent line, re-perform from primary data, and pair the test with observation when the concern is how the control runs unwatched, not just whether it can be made to balance.
How it implements the components¶
work_as_done_sampling_plan— the independent, risk-weighted selection of control instances to re-execute, drawn so the owner cannot curate the evidence.control_effectiveness_evidence_rule— a pre-set criterion for what a correctly-operating control instance looks like, against which each reperformed case is scored to yield an operating-effectiveness conclusion.control_owner_and_operator_split— locates sampling, execution, and judgment in a line of defense separate from the control's owner, the property that gives the evidence its credibility.
This mechanism establishes baseline effectiveness on a fresh sample; it does not re-check a control specifically after a corrective action to confirm a fixed gap stayed fixed (corrective_closure_route, discrepancy_severity_and_risk_rating, enacted_control_trace) — that is Corrective Action Effectiveness Retest.
Related¶
- Instantiates: Enacted-Control Verification and Closure — supplies independently-produced operating-effectiveness evidence that resists producer bias.
- Consumes: Near-Miss and Deviation Review can steer the sample toward the control instances most worth re-performing.
- Sibling mechanisms: Work-as-Done Audit · Operator Shadowing and Contextual Inquiry · Control Performance Walkdown · Document-to-Practice Trace Matrix · Process-Mining Nominal-Actual Comparison · Corrective Action Effectiveness Retest · Safeguard Bypass Probe · Exception, Waiver, and Override Log Review · Near-Miss and Deviation Review
Editorial Notes¶
Form Classification¶
Form family: Experiment, Test & Rehearsal
Rationale: Line-of-Defense Sample Reperformance operates as a bounded trial, probe, simulation, or rehearsal that generates evidence from performance because it independently re-executes a sample of control actions or approvals to see whether the control operated as claimed, instead of trusting the owner's evidence packet.
Independent corroboration: The frozen evidence defines Line-of-Defense Sample Reperformance as 'Independently re-executes a sample of control actions or approvals to see whether the control operated as claimed, instead of trusting the owner's evidence packet', so its operative form is Experiment, Test & Rehearsal.
Nearest alternative: Assessment, Review & Assurance — The check resembles assurance, but independent sample re-execution actively generates evidence from performance.
Review outcome: Independent reviewer agreement; medium confidence.
Origin Attribution¶
Primary origin: Accounting & Auditing
Origin pattern: Cross-disciplinary synthesis
Present-day reach: Specialized
Rationale: Independent reperformance is a recognized audit-evidence procedure in financial and internal-control auditing standards.
Related originating lineages:
- Statistics & Experimental Design — Risk-based sampling and operating-effectiveness inference materially shape which controls are independently re-performed.
Review resolution: Both independent reviews assign primary provenance to accounting_auditing. The queued secondary differences (alternate_origin_disagreement, origin_mode_disagreement) are reconciled by retaining statistics_experimental_design only as formative or independently established lineage(s), not merely as application domains. origin_mode=cross_disciplinary_synthesis records the provenance relationship, while domain_reach=specialized separately records applicability breadth. confidence=high preserves the more cautious assessment, and encyclopedia_synthesis=false records whether either reviewer identified a corpus-specific synthesis.
Review outcome: Reconciled after independent review; high confidence.
Notes¶
[n1] Reperformance is a recognized evidence-gathering technique in auditing standards (for example ISA 500 and PCAOB testing guidance): the auditor independently executes procedures or controls that were originally performed by the entity, and it is generally treated as more persuasive than inquiry or inspection precisely because the auditor produces the evidence rather than relying on the auditee's. ↩