The Control Illusion
Merixa Insights Risk, Controls & Governance
Why existing controls can appear adequate while failing to protect the business when risk, ownership, evidence and monitoring are not maintained.
The control illusion forms when an organisation has control activities but cannot demonstrate that those activities are linked to current risks, owned by named individuals, evidenced through operation and reviewed at a frequency appropriate to the risk. The weakness is not always the absence of controls. It is often the absence of a maintained control framework.
An internal control framework is not a list of approvals, reconciliations and review steps. It is the structured relationship between risk, control design, ownership, evidence, monitoring and management review. COSO is a useful professional reference for this relationship, but the organisation still has to design controls that fit its own risk profile and operating environment.
The issue usually forms through two mechanisms: controls inherited from an earlier version of the business, and controls documented without being tested against operating reality. When both are present, leadership may believe the organisation is controlled because the control register is populated, while the control environment has stopped reflecting how work is actually performed.
Issue one - controls inherited from an earlier risk environment
Controls often remain in place long after the risk environment that created them has changed. A payment approval threshold may have been suitable when supplier volumes were low. A manual reconciliation may have been proportionate when there was one entity, one system and a short reporting chain. A review performed by a founder or finance lead may have been effective when the business was small enough for exceptions to be visible informally.
As the business grows, those assumptions change. Entity structures become more complex. Approval volumes increase. Systems multiply. Finance teams rely on people who understand how the workaround functions because the process has not been formally redesigned. The control still exists, but its design basis has weakened.
The result is a control environment that can look familiar while becoming less reliable. Management sees an activity being performed. It does not necessarily see whether that activity remains proportionate to the risk, whether it is evidenced properly, whether exceptions are resolved, or whether the control still protects the point of exposure it was intended to cover.
A control that cannot be linked to a current risk, named owner, operating evidence and review process is not a reliable control. It is a historical procedure that may or may not still protect the business.
Issue two - controls documented but not tested against operating reality
Documented controls can also create false assurance when the description does not match how the process operates. A policy may state that every new supplier is independently verified. In practice, urgent onboarding may bypass the documented route. A delegated authority matrix may exist, while exceptions are approved through email because the system workflow does not support the required threshold. A reconciliation may be signed off, but the reviewer may not test whether the reconciling items are valid, aged and resolved.
Testing is the discipline that closes this gap. It asks whether the control operated, whether evidence exists, whether the right person performed it, whether exceptions were followed up and whether the control still responds to the relevant risk. This is not internal audit language for its own sake. It is management discipline over whether the business can rely on its own controls.
Without that testing discipline, the organisation can maintain a control register without maintaining a control environment. That is where the control illusion becomes commercially important: the business believes it has assurance, but cannot demonstrate the basis for that assurance when challenged by a board, auditor, lender, buyer or regulator.
Questions that identify the control illusion
1. Can each key control be mapped to a current financial, operational, reporting or compliance risk?
2. Does each control have a named owner, evidence requirement, review frequency and escalation route?
3. When was the control last tested against how the process actually operates, not only how it is documented?
4. Which controls exist because the current business requires them, and which exist because a previous version of the business created them?
5. If a key control owner became unavailable, could the control still operate as designed without relying on undocumented personal knowledge?
If those questions expose gaps, the issue is not simply control documentation. It is control design. The first step is to identify which controls remain necessary, which require redesign, which require stronger evidence and which should be removed because they no longer respond to a current risk.
Merixa supports leadership teams in reviewing and redesigning internal control frameworks so that controls are linked to current risks, named ownership, operating evidence and management review. Review Merixa's risk, controls and governance support.
This article reflects professional opinion informed by practitioner experience in governance, internal control, risk management and audit-readiness work. References to COSO, ISO 31000, the FRC ISA (UK) suite, ACCA, AICPA & CIMA, IIA, CRMA, SOX, CFA Institute, FRS and GARP/FRM are used as contextual professional literature where relevant. They do not imply Merixa accreditation, certification, endorsement, internal audit status or formal adoption of any professional body standard. The article is not legal, regulatory, audit or assurance advice. Applicability of any specific framework or requirement depends on the organisation's jurisdiction, reporting framework, governance obligations, listing status, group structure and assurance environment. Merixa Advisory provides governance, controls and audit-readiness support, and this commercial context should be considered when evaluating the perspectives offered here.
