Controls & Treatment

How to record control effectiveness on Mac

You can do this with RiskOS, a risk register for macOS. Four strengths, one status that decides whether any of them counts, and every linked risk re-scored the moment you choose.

A control's strength is the one field on it that changes numbers somewhere else. Rate it generously and the register quietly reports a level of safety nobody can evidence; rate it harshly and real work stops counting. The rating is not a compliment to the team that built the thing but a claim about how much of the exposure it removes, and it has to survive being asked about.

Note

Strength only counts once the control is in place. A planned control, however strong it will be when it runs, reduces nothing yet, and RiskOS says so rather than counting it early.

Where control effectiveness lives

Choose Controls in the sidebar. RiskOS keeps every control you rely on in one table: reference, name with its detail beneath it, type, status, an Effectiveness meter, owner, the number of risks linked to it, and the next review date. The meter fills one to four segments and always carries its word beside it, so the column reads at a glance and still reads for someone who cannot separate the colours.

Select a row and the panel on the right opens that control: its name, description, type, status, owner, the effectiveness picker with its descriptor underneath, the next review date and the evidence notes. Status and effectiveness are the two fields that decide what the control is worth to the register. Changes save as you type.

The same rating appears from the other side. Open any risk and its Controls section lists every linked control with its status and its strength, so you can see at once whether the thing holding a risk down is operating or merely intended.

Record control effectiveness, step by step

  1. Open the control

    Choose Controls in the sidebar and click the control you want to rate. The search field covers the list, so type part of a name or a reference such as CTL-0002 to reach it. If the control does not exist yet, press N while you are in this section to create one.

  2. Confirm the status before you touch the strength

    Check the status field first. Only controls that are implemented or operating reduce risk, so the strength you are about to record has no effect at all while the status says planned. Set the status to what is true today, not to what is expected by the end of the quarter, and the two fields will tell a consistent story.

  3. Choose the strength

    Open the effectiveness picker and choose Low, Moderate, High or Very High. The meter fills to match and a short descriptor appears beneath it, naming what that rating claims — roughly, how well documented, how consistently operated and how well tested the control is. Choose against the descriptor rather than against how much effort the control took to build.

  4. Write the evidence behind the rating

    Use the evidence notes to record what makes the rating defensible: the test you ran, the date, the sample size, who reviewed it and where the output is kept. A strength with a sentence behind it is an assessment. A strength on its own is an opinion, and it is the first thing anyone auditing the register will pull on.

  5. Set the next review date

    Give the control a next review date so the rating has an expiry rather than a permanent existence. Effectiveness decays quietly: staff change, coverage drifts, an exception is granted and never withdrawn. The Controls table carries the review date as a sortable column, so the ratings living on old evidence are easy to spot.

  6. Check which risks re-scored

    The Risks column on the control's row counts how many risks are linked to it. Editing a control's status or effectiveness re-scores every risk that derives from that control, immediately and without asking. Open one of them and read its residual score and its matrix markers, which will have moved to reflect the rating you recorded.

  7. Clear any divergence warning

    If a risk carries an effectiveness value set by hand and that value disagrees with the controls linked to it, the risk's panel points out the divergence. Decide which record is out of date. Either bring the control's rating into line with reality, or leave the hand-set value in place and say in the risk's description why you overrode it.

  8. Raise an action if the rating is lower than you want

    A rating below what the risk needs is a piece of work, not a complaint. Add a remediation action in the control's own panel, with an owner and a due date, describing what would move it up a step — a documented procedure, a completed test, an independent review. It then joins every other open action in the register.

The four strengths

Four points, deliberately. What matters is that everyone rating controls in your register reads them the same way, so agree the readings below, or your own version of them, before a second person starts rating.

The four control effectiveness ratings and what each one claims
StrengthMeterWhat the rating claims
Low1 of 4Something exists, but it is informal, partial or unproven. Expect it to take very little off the exposure.
Moderate2 of 4In place and working in the ordinary case, with known gaps: incomplete coverage, thin evidence, or a manual step that depends on one person remembering.
High3 of 4Documented, operated consistently and tested, with evidence you could show someone. The everyday ceiling for a well-run control.
Very High4 of 4All of the above, plus independent assurance and evidence that failures are caught quickly. Reserve it, or the top of the scale stops meaning anything.

Choosing between two neighbouring ratings

Most arguments are between adjacent points, and one question settles them: what would you show someone who asked you to prove it? A document, a test result and a date puts you at High. "Everyone knows we do that" puts you at Low, whatever the intent behind it. Evidence produced by someone inside the process puts you at High rather than Very High.

When two people still disagree, take the lower rating and write the disagreement into the evidence notes. A register that errs downwards is conservative; one that errs upwards reports safety it cannot demonstrate, which is the failure mode that matters.

Why there is no percentage here

Effectiveness is a judgement about a control, recorded on the control, which RiskOS then uses to work out what is left of each risk that relies on it. A named four-point scale means the same word means the same thing on every row, so two controls rated High are genuinely comparable. A finer scale would only invite an argument about whether something is a 62 or a 68, and produce no better decision at the end of it.

Status decides whether the strength counts

Strength and status are separate fields answering separate questions. Strength asks how good this control is. Status asks whether it is doing anything yet. RiskOS reads them together, and status is the gate.

How each control status affects the strength you recorded
StatusDoes the strength count?What the pair is saying
PlannedNoAgreed and scheduled, doing nothing. CTL-0003 Quarterly restore rehearsal is rated High and still takes nothing off RSK-0007 until it runs.
ImplementedYesIn place. Its strength now counts towards every risk linked to it.
OperatingYesIn place and running as intended. A risk that follows its controls automatically takes the strength of its strongest operating control.
RetiredNoWithdrawn. The risks that leaned on it re-score upwards, which is precisely the signal you want to see.

What happens when you retire a control

Retiring a control is not a tidying-up exercise; it is a change to your exposure, and the register treats it as one. Every risk that derived its effectiveness from the retired control is re-scored without it, so residual scores rise and any risk that crosses your appetite threshold is flagged wherever it appears. Use the show-retired toggle above the Controls list to bring it back into view.

Where the rating is read

One rating on one control is read in several places, all from the same figure. Knowing where it surfaces stops a casual edit from becoming a surprise in a board pack three weeks later.

Where a control's effectiveness rating is used across RiskOS
WhereWhat the rating does there
The Controls tableFills the Effectiveness meter. Sort on the column to bring the weakest controls to the top, and read the Risks count beside each one to see how much is leaning on them.
A risk's Controls sectionShows each linked control with its status and strength, so the reason a residual score sits where it does is visible on the risk itself.
The residual scoreA risk set to derive from its controls follows its strongest operating control. The methodology decides whether that reduction lands on likelihood, on impact, or on both.
The divergence warningAppears on a risk whose hand-set effectiveness disagrees with the controls linked to it. RiskOS does not pick a side; it shows you the disagreement.
Framework coverageA requirement counts as covered only when a mapped control is implemented or operating. Strength tells you how well it is covered once it is.
ReportsThe controls section of a report carries each control with its status and strength, taken from the same snapshot as every other section, so the figures always agree.

One strong control beats several weak ones

Linking five Low controls to a risk does not add up to a High one. A risk that follows its controls takes the strength of the strongest control that is actually operating, which is the honest reading: one well-tested measure stands between you and the event, and informal habits beside it do not compound into assurance. If the residual score is not where you want it, the work is to raise one control, not to link more.

Troubleshooting

I raised the effectiveness and nothing moved

Check the control's status. While it is planned, its strength counts for nothing anywhere in the register. If the status is right, check the risk: it may hold an effectiveness value set by hand rather than deriving one from its controls, in which case the risk's panel shows the divergence instead of quietly following the control.

The risk shows a different strength from the control

That is the divergence warning doing its job. A hand-set value on the risk and a rating on the linked control have drifted apart. Nothing is broken and nothing has been overwritten. Decide which is out of date, update it, and the warning clears. Switching the risk back to deriving from its controls clears it too.

Scores went up and I did not re-rate anything

Something changed on a control. Retiring one, dropping its strength, or an import that updates a control's status or effectiveness all re-score every risk relying on it. Each risk's History keeps every assessment with the reason behind it, which is the quickest way to find what moved and when.

I cannot find a control I know I rated

Two filters sit above the Controls list and either can hide a row. The type filter narrows the list to one kind of control, and retired controls stay hidden until you switch the show-retired toggle on. Clear both, then search by name or by reference such as CTL-0009.

Every control we have is rated High

Rating inflation, and it costs you the scale. If nothing sits at Low or Moderate, the column has stopped separating anything and residual scores across the register are flattering. Re-rate against the evidence question, starting with the controls nobody has tested this year.

A routine that keeps the ratings current

Effectiveness is the field most likely to go stale, because nothing visible happens when it does. A few habits keep it honest.

  • Rate the status first, every time. The strength is meaningless until the status says the control is in place, and most confused residual scores start with a planned control that everyone assumes is running.
  • Sort by effectiveness, weakest first. The bottom of that sort, read alongside the Risks count, is your list of single points of failure in priority order.
  • Attach a date to every rating. Set the next review date when you set the strength, so a two-year-old rating announces itself rather than looking current.
  • Test before you promote. Move a control up a step because a test passed, not because the project closed. High is a claim about evidence, and Very High is a claim about independent evidence.
  • Downgrade as readily as you upgrade. A missed test, a waiver or a departed owner is a reason to drop a step. The risks that relied on it re-score at once, which is the register telling you something true.
  • Turn gaps into actions. Whenever you settle on a rating lower than the risk needs, add the remediation action in the control's own panel with an owner and a date.
  • Re-read the evidence notes at review time. If the note no longer describes what happens, the rating has expired whatever the date says.

Frequently asked questions

What does control effectiveness mean?

It is how much of a risk a control actually removes, recorded on the control itself rather than guessed at on each risk. RiskOS offers four strengths — Low, Moderate, High and Very High — and uses the rating, together with the control's status, to work out the residual score of every risk linked to it.

How many control effectiveness ratings does RiskOS use?

Four: Low, Moderate, High and Very High, shown as a meter that fills one to four segments with the word beside it. A short descriptor under the picker names what each rating claims, so two people rating different controls are answering the same question rather than inventing their own scale.

Why did my residual risk score not fall when I raised a control's effectiveness?

Almost always the control is still planned. Only implemented or operating controls reduce risk, so a planned control takes nothing off however strongly it is rated. The other cause is a risk holding an effectiveness value set by hand: it follows your value, not the control, and shows a divergence warning when the two disagree.

Do two controls reduce a risk more than one?

Not automatically. A risk deriving its effectiveness from linked controls takes the strength of its strongest operating control, so adding weaker controls beside it changes nothing. Link them anyway for the record, but if you need the residual score lower, the work is to strengthen or replace the control that is already carrying the risk.

How often should control effectiveness be reviewed?

Give every control a next review date and treat the rating as expiring on it. Annually suits stable controls; quarterly suits anything manual, newly built or supporting a risk above appetite. The Controls table shows the review date as a sortable column, so the ratings living on old evidence are easy to find.

What is the difference between control status and control effectiveness?

Status says whether the control is doing anything: planned, implemented, operating or retired. Effectiveness says how good it is when it does. Status is the gate — a Very High control that is only planned reduces nothing — and effectiveness is the size of the reduction once that gate is open.

Can I set effectiveness on the risk instead of the control?

Yes. A risk can derive its effectiveness from its linked controls automatically, or keep a value you set by hand when the control catalogue has not caught up with what you know. When a hand-set value disagrees with the linked controls, the risk's panel points out the divergence rather than choosing between them for you.

Does anything I record about a control leave my Mac?

No. Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine. Control names, evidence notes and ratings stay where you put them and travel only when you export or back them up yourself.