The Risk of Control Obsolescence
- Michael G. Bradshaw, CPA

- Aug 13
- 2 min read
One of the lesser discussed challenges in enterprise risk management is that controls can become obsolete without becoming obviously ineffective. A control may continue to operate exactly as designed while the risk environment around it has fundamentally changed.
Consider an organization whose cybersecurity controls were designed around human-generated threats. The controls may include authentication, access reviews, phishing awareness and periodic vulnerability assessments. Yet the emergence of increasingly capable AI-enabled threats changes the speed, scale and nature of the underlying risk. The control has not necessarily “failed.” Rather, its risk-to-control alignment has deteriorated.
This concept deserves greater prominence within ERM and internal audit: control relevance should be assessed alongside control design and operating effectiveness. The same principle applies beyond cybersecurity. Changes in technology, regulation, business models, supply chains and customer behavior can gradually invalidate assumptions embedded in established controls.
A mature organization should therefore periodically ask: What assumptions did this control depend upon? Are those assumptions still valid? Has the underlying risk changed faster than the control environment? Are we measuring control activity rather than actual risk reduction? This shifts internal audit from a retrospective assurance function toward a more forward-looking assessment of organizational resilience. It also changes the meaning of continuous improvement. Improvement does not necessarily mean adding more controls. Sometimes it means removing controls that no longer address the most important risks and redirecting resources toward emerging exposures.
For management, this creates an important governance principle: the objective of the control environment is not to preserve yesterday's safeguards. It is to maintain alignment between risk, strategy, information and action. Excellence in the systematic ability to recognize when the organization has outgrown its existing approach—and deliberately build the next one.
Comments