Every organization operates through processes, and every process depends on controls to keep it running safely, efficiently, and in compliance with applicable laws and standards. Yet not all controls are created equal. Some controls genuinely reduce risk, catching errors before they cascade into losses, preventing fraud before it drains resources, and stopping safety incidents before they harm workers or the public. Other controls exist only on paper, providing the appearance of risk management while failing to deliver any meaningful protection. Understanding the difference between effective controls and nominal controls is fundamental to operational risk management, and it is a distinction that Canadian business owners, non-profit operators, and risk managers must master if they are to protect their organizations from the kinds of process failures that destroy value, harm people, and attract regulatory scrutiny.
A control, in the context of operational risk, is any measure designed to prevent, detect, or correct an unwanted outcome. Controls can take many forms. A policy requiring two signatures on cheques above a certain threshold is a control. A software system that automatically flags transactions exceeding normal parameters is a control. A safety inspection conducted before each shift in a manufacturing facility is a control. Training that teaches employees how to handle hazardous materials is a control. The weekly reconciliation of inventory counts against recorded quantities is a control. Each of these measures is intended to reduce the likelihood or severity of something going wrong, whether that something is theft, error, injury, or non-compliance. Controls are the mechanisms through which organizations translate their risk appetite into operational reality, and they represent the practical embodiment of an organization's commitment to managing its exposures.
The Canadian Standards Association, through CSA Z1600 and related standards, provides guidance on how Canadian organizations should approach risk management, including the design and implementation of controls. The International Organization for Standardization's ISO 31000 framework, which is widely adopted across Canadian industries as of the date of authorship, similarly emphasizes the importance of controls that are proportionate to the risks they address, integrated into organizational processes, and subject to ongoing monitoring and review. These frameworks recognize that controls are not static artifacts but living components of an organization's risk management system, requiring continuous attention to ensure they remain fit for purpose. In Quebec, where the civil law tradition shapes organizational obligations somewhat differently than in common law provinces, the principle remains the same: organizations must take reasonable measures to prevent foreseeable harms, and controls are the primary means through which this obligation is discharged.
What makes a control effective? An effective control reliably achieves its intended purpose under the conditions in which it operates. This seemingly simple definition contains several important elements. First, an effective control must have a clearly defined purpose tied to a specific risk or set of risks. A control that exists without a clear connection to an identified risk is likely to be ignored, circumvented, or applied inconsistently. Second, an effective control must be reliable, meaning it works consistently across different situations, different personnel, and different time periods. A control that functions perfectly when a particular manager is present but fails when that manager is absent is not reliable. Third, an effective control must be appropriate to the conditions in which it operates. A control designed for a small organization with five employees may become impractical and therefore ineffective when the organization grows to fifty employees. Similarly, a control designed for a slow-paced environment may fail entirely in a high-pressure, fast-moving operational context. The conditions under which controls operate matter enormously, and effective controls are designed with those conditions in mind.
Nominal controls, by contrast, are controls that exist in form but not in substance. They appear in policy documents, procedure manuals, and risk registers, yet they fail to deliver the risk reduction they promise. Nominal controls are perhaps the most dangerous type of control failure because they create a false sense of security. When an organization believes it has a control in place, it may not look for the underlying risk that the control was supposed to address. The risk continues to build, unobserved and unmanaged, until it materializes in a way that can be devastating. Nominal controls are common across Canadian organizations of all sizes and sectors, not because managers are careless or dishonest, but because the gap between designing a control and ensuring that control actually works in practice is larger than most people appreciate. Controls can become nominal through several pathways, each of which deserves attention from anyone responsible for operational risk.
The first pathway to nominal control status is design failure. Some controls are nominal from the moment they are created because they were never designed to address the actual risk in a meaningful way. Consider a policy requiring employees to report all safety incidents within twenty-four hours. On its face, this appears to be a reasonable control, ensuring that management becomes aware of safety problems promptly. But what happens after the incident is reported? If the policy does not specify who receives the report, how the report is analyzed, what triggers a response, and how corrective actions are tracked to completion, the reporting requirement does little more than generate paperwork. Incidents are reported and then forgotten, or they are reviewed by someone who lacks the authority or resources to address them. The underlying risk, that safety problems are not identified and corrected before they cause serious harm, remains unaddressed despite the existence of the policy. This is a design failure that renders the control nominal rather than effective.
The second pathway is implementation failure. A control may be well designed on paper but poorly implemented in practice. Implementation failures occur when the people responsible for executing the control do not understand how to do so, do not have the resources to do so, or do not believe the control is important. Training is often a critical implementation issue. A financial services firm in Ontario might implement a control requiring front-line staff to verify customer identity through a series of questions before processing certain transactions. The control is sound in principle, addressing the risk of fraud and helping the organization meet its obligations under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act as of the date of authorship. But if staff are not trained on why the verification matters, how to handle situations where customers become frustrated or uncooperative, and what to do when verification fails, the control will be applied inconsistently at best and abandoned at worst. Implementation failures often stem from a disconnect between those who design controls, typically managers and risk professionals, and those who must execute them, typically front-line staff working under time pressure and competing demands.
The third pathway is degradation over time. Controls that are effective when first implemented can become nominal as circumstances change and the control is not updated to match. This is particularly common in organizations experiencing growth, technological change, or shifts in their operating environment. A construction company in Calgary might implement a control requiring site supervisors to conduct daily safety walkthroughs and document their observations in a paper logbook kept in the site trailer. When the company operates two or three sites in close geographic proximity, this control works well. But as the company expands to operate a dozen sites spread across Alberta and British Columbia, the control begins to fail. Site supervisors, under pressure to keep projects on schedule, start conducting abbreviated walkthroughs or skipping days entirely. The paper logbooks are rarely reviewed by anyone other than the site supervisor who created them. When an incident occurs, management discovers that the logbooks are incomplete, inconsistent, and provide no meaningful evidence that safety inspections were actually conducted. The control has degraded into a nominal status because it was never adapted to the organization's changed circumstances.
The fourth pathway is deliberate circumvention. Sometimes controls become nominal because people actively work around them. This can happen for benign reasons, as when employees develop shortcuts to manage workload pressures, or for malicious reasons, as when someone seeks to commit fraud or conceal wrongdoing. Either way, the result is the same: the control ceases to function as intended. A common example involves segregation of duties, a fundamental control in financial management. The principle is straightforward: no single individual should control all aspects of a transaction from initiation through authorization to recording and reconciliation. In a mid-sized non-profit organization in Halifax, the finance policy might clearly specify that cheque requisitions must be prepared by one staff member, approved by a program manager, and issued by the finance director. In practice, however, the program managers may regularly be away from the office, creating pressure to process payments without their approval. Staff develop workarounds, perhaps obtaining pre-signed approval forms or routing urgent payments directly to the finance director, and over time these workarounds become normalized. The segregation of duties control still exists in the policy manual, but it no longer operates in reality.
Understanding these pathways to nominal control status is essential for anyone seeking to design controls that actually work. Effective control design begins with a clear understanding of the risk being addressed. What could go wrong? What are the causes and contributing factors? What are the potential consequences? How likely is this risk to materialize, and how severe would the impact be? Without this foundation, control design becomes guesswork, and the resulting controls are unlikely to be well matched to the risks they are supposed to address. Risk assessment methodologies, as described in ISO 31000 and adapted for various Canadian industries, provide structured approaches to this analysis. In healthcare settings, for example, organizations might use failure mode and effects analysis to identify potential points of failure in clinical processes and design controls accordingly. In resource extraction, organizations might use bowtie analysis to visualize the relationship between hazards, controls, and potential consequences. The specific methodology matters less than the discipline of rigorously analyzing risks before designing controls.
Once the risk is understood, effective control design requires thinking carefully about the control's mechanism of action. How will this control actually reduce risk? Will it prevent the risk from materializing in the first place, detect the risk early so that corrective action can be taken, or mitigate the consequences if the risk does materialize? Preventive controls are generally preferable to detective controls, and detective controls are generally preferable to corrective controls, because earlier intervention typically results in smaller losses. But the appropriate mix of controls depends on the specific risk and context. Some risks cannot be reliably prevented and must be detected and responded to quickly. Other risks can be effectively prevented through straightforward measures. The key is to understand how each control fits into the overall control framework and to ensure that the combination of controls provides adequate coverage of the risk.
Control design must also account for the conditions under which the control will operate. Who will be responsible for executing the control? What skills and knowledge do they need? What competing demands on their time and attention might interfere? What resources, tools, or systems are required? What happens when the usual control operator is absent due to illness, vacation, or turnover? Effective controls are robust to foreseeable variations in operating conditions. They include backup procedures for when primary operators are unavailable. They are documented clearly enough that someone unfamiliar with the process can understand what is required. They are integrated into the flow of work so that executing the control is a natural part of the job rather than an additional burden.
Mireille Tremblay founded a catering company in Montreal in 2019, starting as a sole proprietor operating from a licensed commercial kitchen shared with two other small food businesses. By 2024, the company had grown to employ fourteen staff and had moved to its own dedicated facility, serving corporate clients, wedding parties, and community events across the greater Montreal region. The company's growth had been rapid and largely driven by Mireille's personal energy and attention to detail. She had developed a strong reputation for quality and reliability, and referrals from satisfied customers had steadily expanded the client base. But the growth had outpaced the company's operational systems, and Mireille was increasingly worried about her ability to maintain the standards that had built her reputation.
Food safety was a particular concern. In the early days, Mireille personally oversaw all food preparation and could ensure that proper temperatures were maintained, cross-contamination was prevented, and all applicable food safety requirements under Quebec's food safety regulations were followed. As the company grew, she delegated more and more of the food preparation to her staff, many of whom had received food handler certification but lacked Mireille's years of experience and attention to detail. She implemented a control requiring staff to record food temperatures at critical points during preparation, storage, and transport, using a standardized form that she had downloaded from a food safety resource website. For the first several months, the forms were completed diligently and Mireille reviewed them weekly to identify any anomalies. But as the volume of events increased and Mireille spent more time meeting with clients and managing business operations, her weekly reviews became monthly, then sporadic, then effectively non-existent. The temperature logs continued to be completed because staff knew they were supposed to, but no one was actually reviewing them. When Mireille finally sat down to examine several months of logs, she noticed troubling patterns. Many entries showed suspiciously round numbers, suggesting that staff were estimating rather than actually measuring temperatures. Some forms were missing entirely. On at least three occasions, recorded temperatures were outside safe ranges, yet no corrective action had been taken or documented. The control had become nominal.
What Mireille's experience reveals is the critical importance of the complete control cycle. A control consists not merely of an activity that someone performs but of a closed loop that includes the activity, verification that the activity occurred properly, analysis of the results, and response to any exceptions or anomalies. The temperature logging itself was only the first element of what should have been a comprehensive food safety control. Without review, analysis, and response, the logging accomplished nothing beyond creating the illusion that temperatures were being monitored. Mireille's absence from the review process was a single point of failure that rendered the entire control ineffective. This pattern recurs across industries and organizational types. Controls that depend on a single person, controls that are not integrated into normal workflow, controls that generate data without clear responsibility for analyzing and acting on that data, all of these are prone to becoming nominal over time.
The implications for organizational risk management are significant. First, organizations must design controls that are robust to predictable variations in circumstances, including the absence of key personnel, changes in workload, and evolution of the operating environment. Second, organizations must monitor their controls on an ongoing basis to ensure they continue to function as intended. This monitoring should be commensurate with the significance of the risk being addressed: higher-risk controls warrant more frequent and rigorous monitoring. Third, organizations must be willing to adapt their controls as circumstances change. A control that worked well when the organization was small may need to be redesigned or supplemented as the organization grows. A control that worked well under one technology platform may need to be redesigned when the platform changes. Fourth, organizations must create accountability for control performance, assigning clear responsibility for ensuring that controls operate effectively and providing the authority and resources needed to discharge that responsibility.
Canadian organizations should ask themselves several questions when evaluating whether their controls are effective or nominal. For each significant control, is the purpose clear and documented? Does everyone responsible for executing the control understand how it is supposed to work and why it matters? Is there evidence that the control is actually being executed as designed, and is someone reviewing that evidence? What happens when the control identifies an exception or anomaly, and is there a clear escalation path and response process? Has the control been tested to verify that it works under realistic conditions, including conditions of stress or unusual circumstances? When was the control last reviewed and updated, and is it still appropriate for current operations? What are the backup arrangements if the primary control operator is unavailable? Could someone circumvent this control, and if so, would that circumvention be detected?
Organizations that cannot answer these questions satisfactorily for their critical controls should treat the situation as urgent. Nominal controls create liability exposure because they create evidence that the organization knew about a risk and purported to address it, yet failed to do so effectively. In the event of an incident, regulators, insurers, and potentially plaintiffs will scrutinize the organization's controls and compare what was written in policy documents to what actually happened in practice. The gap between nominal and effective controls can be the difference between a defensible position and an indefensible one.
Documentation practices deserve particular attention. Documentation serves multiple purposes in the control context. It provides evidence that controls were executed, enabling verification and supporting accountability. It creates a record that can be analyzed to identify trends and patterns. It preserves institutional knowledge that would otherwise be lost when personnel change. And it demonstrates to external parties, including regulators, auditors, and insurers, that the organization takes risk management seriously. But documentation is only valuable if it is accurate and if someone actually uses it. Documentation that is fabricated, perfunctory, or never reviewed is worse than useless because it creates false confidence and can constitute evidence of inadequate risk management. Organizations should design their documentation requirements to capture information that is genuinely useful and should ensure that the documentation is reviewed and analyzed on a regular schedule.
Technology can support effective controls, but it is not a panacea. Automated controls have significant advantages: they do not get tired, distracted, or demoralized, and they can operate continuously and consistently across high volumes of transactions. A software system that automatically rejects expense claims exceeding a certain threshold without management approval is likely to be more reliable than a manual review process that depends on a supervisor catching every exception. But automated controls have their own failure modes. They can be programmed incorrectly. They can fail to account for legitimate exceptions, creating workarounds that undermine the control. They can create a false sense of security if users believe the system is catching everything when in fact it is not. And they can become obsolete as business processes evolve, flagging the wrong transactions or failing to flag the right ones. Technology-based controls require the same ongoing monitoring and adaptation as manual controls, and the fact that a control is automated does not relieve management of responsibility for ensuring it actually works.
Ultimately, the distinction between effective and nominal controls comes down to organizational culture and leadership. Organizations where leaders take risk management seriously, where staff understand why controls matter, where there is genuine accountability for control performance, and where problems are surfaced and addressed rather than concealed, tend to have effective controls. Organizations where risk management is treated as a compliance burden, where controls are designed to satisfy external requirements rather than to genuinely reduce risk, where leaders are too busy or too distant to engage with operational details, tend to have nominal controls. Culture is hard to change, but it starts with leadership demonstrating through their actions that control effectiveness matters. When a leader notices that a control is not being followed and takes the time to understand why and to address the underlying issues, that sends a powerful message. When a leader ignores control failures or treats them as inevitable and unimportant, that also sends a message, one that will gradually erode control effectiveness throughout the organization.
Canadian business owners, non-profit operators, and risk managers should approach control design as a core competency, not an afterthought. The time invested in designing controls that actually work, monitoring their performance, and adapting them as circumstances change, pays dividends in reduced losses, improved compliance, and greater organizational resilience. The organizations that suffer catastrophic process failures are often those that believed their controls were working when in fact those controls had long since become nominal. The goal is not to create elaborate control frameworks that look impressive on paper but rather to create practical, robust, well-understood controls that reliably reduce risk in the real conditions of daily operations. That goal is achievable, but it requires discipline, attention, and the willingness to look honestly at whether controls are truly effective or merely nominal.