13. Control Debt

11 July 2026

“Every control solves yesterday’s uncertainty. The question every organisation forgets to ask is whether yesterday’s uncertainty still exists.”

Most executives understand technical debt. Software accumulates compromises that were reasonable when made but become increasingly expensive to maintain as the surrounding environment changes. Eventually the organisation spends more effort preserving the system than improving it. Governance suffers from precisely the same phenomenon, although it receives far less attention. Organisations steadily accumulate controls that once addressed genuine concerns but whose original purpose has faded, whose assumptions no longer hold, or whose effectiveness has never been questioned since their introduction. Unlike technical debt, however, governance debt often masquerades as diligence. The very existence of more controls is interpreted as evidence of maturity rather than complexity.

This gradual accumulation rarely happens through deliberate design. Every audit finding, operational incident, regulatory change or executive concern encourages another approval, another review, another checklist or another mandatory document. Individually these additions appear reasonable because each responds to a specific event. Collectively they produce an operating environment in which decision-makers spend increasing amounts of time satisfying governance mechanisms whose contribution to better decisions becomes progressively less certain. Organisations eventually discover that they are controlling activities rather than improving them.

The result is what may be described as Control Debt: the accumulation of governance controls whose ongoing cost exceeds the confidence they provide. Like financial debt, it is not inherently undesirable. Borrowing allows investment before resources are available, and temporary governance controls often allow organisations to respond quickly to emerging risks. The problem arises when these temporary measures become permanent obligations. Interest accumulates in the form of slower decisions, higher administrative overhead, duplicated assurance activities and declining organisational adaptability.

Controls Are Investments, Not Permanent Fixtures

A control is often presented as though it were an unquestionable organisational asset. Once implemented it acquires an aura of permanence. Documentation describes how it operates. Auditors verify its execution. Management reports record its effectiveness. Yet this perspective mistakes the implementation of a control for its purpose.

Controls exist because organisations cannot eliminate uncertainty. They provide confidence that decisions are being executed consistently, assets are being protected or obligations are being fulfilled. Their value therefore lies entirely in the confidence they generate relative to the effort required to operate them. This relationship is dynamic rather than static. As technology changes, organisational capability improves and external risks evolve, the same control may provide significantly less value than it once did. Equally, automation may allow another control to achieve the same confidence at a fraction of the operational cost.

Organisations rarely revisit this calculation. Once embedded within policy, systems or audit programmes, controls acquire institutional legitimacy. Removing them feels inherently dangerous because it appears equivalent to reducing governance itself. The conversation becomes centred on the possibility of introducing additional risk rather than asking whether the control still contributes meaningful assurance. Over time the organisation forgets that every control was originally justified by a specific decision problem. The mechanism survives while the problem quietly disappears.

The Hidden Cost of Confidence

The expense associated with controls is often underestimated because organisations measure only their direct implementation cost. A checklist appears inexpensive because completing it takes only a few minutes. An additional approval seems harmless because managers routinely approve requests. Another monthly report requires only a small amount of administrative effort. Viewed individually, these costs appear negligible.

Their true impact emerges only when examined across the entire decision architecture. Every control introduces waiting time, consumes managerial attention, requires evidence, creates exceptions that require interpretation and generates data that someone must review. Controls rarely operate independently. One approval triggers another. One compliance report feeds several committees. Multiple teams collect similar evidence for different assurance purposes. What appears to be a small operational burden at the point of implementation becomes a substantial organisational overhead when multiplied across thousands of routine decisions.

The hidden cost extends beyond administrative effort. Controls influence behaviour. Employees naturally optimise for successful navigation of governance processes rather than organisational outcomes. Time is invested in producing documentation that satisfies reviewers rather than improving operational execution. Managers become increasingly occupied validating compliance with processes they no longer have the capacity to evaluate critically. Confidence becomes confused with documentation. Organisations gradually invest more effort proving that work has been governed than ensuring the work itself achieves its intended purpose.

When Controls Stop Informing Decisions

An effective control changes behaviour because it provides information that influences a decision. A segregation-of-duties review may identify inappropriate access before fraud becomes possible. A reconciliation may reveal financial discrepancies requiring investigation. A peer review may detect defects before deployment. In each case the control contributes information that enables better judgement.

Control Debt begins when controls continue operating after they have ceased informing meaningful decisions. Reports are generated because reports have always been generated. Signatures are collected although reviewers rarely reject submissions. Committees receive extensive documentation that few members have sufficient time to examine. Evidence is retained for years despite nobody consulting it outside routine audits. The control continues producing activity without producing insight.

This distinction is fundamental because governance often measures execution rather than influence. Organisations ask whether the control was performed instead of whether it altered a decision. A perfectly executed control that never changes behaviour contributes little beyond procedural reassurance. Yet because it demonstrates compliance, it frequently receives favourable audit outcomes and becomes increasingly difficult to question. The organisation becomes highly effective at maintaining governance processes whose relationship to organisational performance has quietly weakened.

Eventually control activity expands while decision quality remains unchanged. Governance grows more visible precisely because its practical contribution has become harder to demonstrate.

Why Control Debt Accumulates

The accumulation of Control Debt is driven less by poor governance than by organisational incentives. Introducing a new control is almost always easier than removing an existing one. Following an incident, executives understandably wish to demonstrate decisive action. Regulators expect visible responses. Auditors recommend improvements. Risk managers seek additional assurance. Each participant operates rationally within their responsibilities.

Few stakeholders receive equivalent recognition for eliminating obsolete controls. Removing a review, simplifying an approval or retiring a report exposes the organisation to visible criticism should a future incident occur. Maintaining unnecessary controls carries little comparable personal risk because its costs are dispersed across the organisation rather than attributed to a single decision-maker. Consequently governance expands through asymmetric incentives. Every significant event adds new controls, while almost no event encourages systematic removal of outdated ones.

Institutional memory reinforces this tendency. Organisations frequently remember the incident that justified a control but forget the context in which it occurred. Technologies change, organisational structures evolve and operating models mature, yet historical responses remain embedded within governance frameworks. Controls designed for manual environments survive after automation eliminates the underlying risk. Approval processes introduced during periods of organisational instability persist long after competence has been established. The governance landscape becomes a historical archive of previous anxieties rather than an architecture designed for present decisions.

Paying Down Governance Debt

Healthy organisations periodically examine not only whether controls operate effectively but whether they remain necessary. This requires a different form of governance review from traditional assurance activities. Rather than asking whether people followed the process, executives ask whether the process continues to justify its existence.

Such reviews naturally begin with the decision the control was intended to improve. If the decision no longer exists, if technology now addresses the underlying uncertainty, or if another mechanism provides equivalent confidence more efficiently, the control has become a candidate for retirement. Eliminating it is not a reduction in governance. It is governance adapting to current organisational reality.

This perspective also changes how new controls are introduced. Instead of assuming permanence, organisations recognise controls as design choices whose continued existence depends upon ongoing value. Some may be temporary responses to emerging risks. Others may require periodic renewal through explicit review. Governance thereby becomes capable of evolving alongside the organisation rather than simply accumulating additional procedural layers.

The objective is not to minimise controls indiscriminately. Organisations facing genuine uncertainty often require more assurance rather than less. The objective is proportionality. Every control consumes organisational capacity, and capacity devoted to obsolete governance cannot be invested in activities that genuinely improve decisions.

Conclusion

Control Debt illustrates a broader principle that runs throughout this philosophy: governance deteriorates when mechanisms become detached from the decisions they were created to support. Controls are indispensable because they increase confidence in execution, reduce uncertainty and enable responsible delegation. Yet these benefits depend upon continuous relevance rather than historical justification.

An organisation with fewer, well-designed controls frequently governs more effectively than one surrounded by procedural complexity. The difference lies not in the quantity of governance but in its precision. When every control can still explain the decision it improves, governance remains an active contributor to organisational performance. When that connection is forgotten, governance begins preserving itself rather than serving the organisation.

Like every form of debt, Control Debt is manageable when recognised early. Left unchecked, however, it quietly consumes organisational throughput, slows decisions and diverts attention away from the very purpose governance exists to fulfil: enabling people to make better decisions with greater confidence.