← University
Process Failure and Control Breakdowns
0 of 6

A regional food processing company in southwestern Ontario had operated for more than 15 years with a reputation for reliable production and steady growth. The company employed approximately 120 workers across 2 facilities, processing locally sourced agricultural products for distribution to grocery chains and food service operators throughout central Canada. Its operations depended on a series of interconnected processes: receiving raw materials from suppliers, inspecting inputs for quality and safety, processing and packaging products according to food safety protocols, and coordinating logistics for time-sensitive deliveries.

The company maintained a documented food safety management system, including hazard analysis and critical control point protocols, sanitation schedules, temperature monitoring procedures, and equipment maintenance checklists. Supervisors were responsible for verifying that workers followed established procedures, and the quality assurance manager conducted periodic internal audits. On paper, the control framework appeared comprehensive. In practice, the gap between documented procedures and daily operations had widened over several years without anyone formally acknowledging the drift.

A series of events over an 8-month period brought these gaps into sharp focus. Production line workers had developed informal shortcuts to meet throughput targets during peak seasons, including bypassing certain sanitation steps when equipment appeared visually clean and deferring temperature log entries until the end of shifts rather than recording them at prescribed intervals. Supervisors, facing pressure to maintain output volumes, had tacitly accepted these deviations. When a new quality assurance coordinator raised concerns about inconsistencies between documented procedures and observed practices, the production manager dismissed the concerns as academic, noting that the company had never experienced a serious incident.

The situation changed when a routine inspection by a provincial food safety authority identified multiple non-conformities, including incomplete sanitation records, temperature logs with retroactive entries, and equipment maintenance deferrals that exceeded manufacturer specifications. The inspector issued a compliance order requiring corrective action within 45 days and indicated that further violations could result in licence suspension. Within weeks, the company also received notification from a major grocery chain customer that it was conducting its own supplier audit in response to the regulatory findings.

Senior management now faces urgent questions about how the company's control framework eroded, why deviations became normalized across multiple production teams, whether existing controls were ever validated for effectiveness, and how to rebuild both the operational risk record and the credibility of the company's food safety assurance to regulators and customers. The executive team includes the founder serving as chief executive, a chief operating officer responsible for both facilities, and a recently hired risk and compliance director whose mandate suddenly expanded from policy development to crisis response.

Control Testing and Validation: Confirming Controls Actually Work

Control testing and validation represents one of the most overlooked yet critical activities in any operational risk management program. Organizations invest considerable resources in designing and implementing controls, yet many fail to systematically verify whether those controls actually function as intended. This gap between control design and control reality creates a dangerous blind spot, one where management believes risks are being mitigated while vulnerabilities persist undetected. The discipline of control testing and validation addresses this gap by establishing structured methods to confirm that controls operate effectively, consistently, and in accordance with their design specifications. Without rigorous testing, controls become assumptions rather than assurances, and organizations discover their weaknesses only when failures occur and damage has already been done.

The conceptual foundation for control testing derives from a straightforward principle: trust but verify. An organization might implement a control requiring dual approval for purchases exceeding five thousand dollars, but unless someone periodically checks whether that control is actually being followed, there is no way to know if it functions in practice. Control validation goes beyond simply confirming that a control exists on paper. It examines whether the control is being executed properly, whether employees understand their responsibilities within the control framework, whether exceptions are being handled appropriately, and whether the control remains relevant given changes in the business environment. This validation process connects directly to Canadian standards and frameworks governing organizational governance and risk management. The Canadian Standards Association's CAN/CSA-ISO 31000 standard, as of the date of authorship, emphasizes that risk treatment measures must be monitored and reviewed for effectiveness on an ongoing basis. Similarly, organizations subject to federal regulation through frameworks such as the Office of the Superintendent of Financial Institutions Guideline E-21 on Operational Risk Management are explicitly required to establish processes for assessing the effectiveness of their control environment. While these specific regulatory requirements apply most directly to federally regulated financial institutions, the underlying principles inform best practices across all Canadian sectors and organizational types.

That’s the free preview

You’ve reached the end of what’s open to read. The rest of this lesson is part of a $149 course — purchasing unlocks it, or sign in if you already have access.