Capability domain
Control & Operational Design
Learn to turn decisions into controls, get help building them, and have them audited
Controls people can actually operate
This is where a management system stops being a document. Requirements, policies and treatment decisions become procedures, lifecycle control points and named responsibilities, or they become nothing at all.
Overview
The gap is between designing and running
Controls fail in the gap between the people who design them and the people who run them. A treatment decision is taken in a meeting, written as a procedure, and handed to people whose actual work it does not fit. They keep working the way that works.
So the useful question is not whether a control exists but whether it survives contact with the day: whether it has an owner who can change it, whether it fits the process it sits inside, and whether anyone would notice if it quietly stopped happening.
Academy
Deepen your expertise
All modules →Each module can be taken on its own and trains the calls a practitioner has to make without being prompted. Our professional tracks bundle these modules into role- and discipline-specific curricula, with a final exam and capstone project.
Advisory
Build and improve your controls
Learn more →We support you in translating assessed risks and governance decisions into proportionate treatment measures, operational controls, and clear responsibilities embedded in daily work.
The four phases below are the life of a management system, and an engagement can begin at any one of them.
01
Design
Designing practical risk treatments and operational controls
Translate risk decisions into control measures
Define control objectives, types, and responsibilities
Design process-integrated control points
Align controls with workflows and system interfaces
Structure operational documentation and procedures
02
Operate
Executing controls in real operational workflows
Implement control measures and procedures
Execute controls within business processes and workflows
Monitor control performance and operational effectiveness
Handle exceptions, deviations, and control failures
Provide operational support across process interfaces and teams
03
Assure
Assessing control effectiveness and operational execution
Conduct control effectiveness reviews and implementation checks
Evaluate control design against risk and operational context
Test control execution across processes and systems
Review control evidence, traceability, and documentation
Identify gaps, weaknesses, and improvement actions
04
Evolve
Improving controls and operational design over time
Improve control measures and operational practices continuously
Adapt controls to changing risks, processes, and systems
Integrate new requirements into control frameworks
Optimise process interfaces and control effectiveness
Support scalable and resilient operational design
Audit
Assess your controls
Learn more →An audit of controls tests whether they are operated rather than owned: whether the people running them know they are controls, whether the evidence is a by-product of the work rather than an errand, and whether a failure would surface.
Audits are organised by discipline rather than by capability domain, because the criteria they test against live in the standards.
Insights
What we have written on this
All insights →Where do you need support?
A short conversation to understand your current situation and discuss possible next steps.
Other capability domains
By discipline