Compensating control
Also known as: Alternative control, Substitute control, Mitigating control
An alternative security measure put in place when a primary requirement cannot be met due to technical or business constraints. It must provide an equivalent level of risk mitigation as the original control it replaces. This ensures that the objective of the standard is still achieved despite the absence of the mandated tool or process.
Why it matters
Without one, a missing mandatory requirement results in a "Non-Compliant" finding during an audit. This can lead to the loss of critical certifications like PCI DSS or SOC 2, potentially triggering breach of contract with B2B clients. The CISO or Risk Owner is typically held accountable for any residual risk left open. Financial costs include potential regulatory fines and increased cyber insurance premiums.
In practice
An auditor identifies these during the testing phase after a gap analysis reveals a missing primary control. They request evidence such as configuration files, system logs, or a formally signed "Risk Exception" document. This process produces a Compensating Control Worksheet that maps the alternative measure to the original requirement's intent. In first-year engagements, auditors scrutinize the logic and effectiveness of these substitutes heavily. Repeat engagements focus on whether the control has remained operational since the last assessment.
Worked example
FinTechFlow Inc. uses a legacy mainframe from 2004 that does not support Multi-Factor Authentication (MFA) for administrative access. During a October 2023 audit, the auditor requested MFA logs but found none exist for this system. FinTechFlow presented evidence of an isolated network VLAN and strict IP whitelisting that limits access to three specific jump servers. The auditor verified these restrictions via firewall rules and quarterly access reviews. Consequently, the requirement was marked as "Compliant" based on the alternative measure.
Common mistakes
- Using it as a label for any secondary control rather than a replacement for an impossible primary one. This leads to confusion during risk assessments.
- Failing to document exactly why the original control is technically unfeasible. Auditors will reject substitutes if they believe the primary control was simply ignored for convenience.
- Assuming that adding "more" of a different control automatically equals equivalent strength. This creates a false sense of security while leaving the actual vulnerability open.
- Neglecting to set an expiration date or review cycle for the exception. Over time, technical upgrades may make the original control possible, rendering the substitute unnecessary and inefficient.
Frequently asked questions
What is a compensating control?
It is a secondary safeguard used when a mandatory security requirement cannot be implemented. Its purpose is to mitigate the risk to a level equal to that of the primary control.
How does it differ from a mitigating control?
A mitigating control generally reduces any identified risk, whereas a compensating control specifically replaces a required standard's mandate to achieve compliance. One is about general risk reduction; the other is about meeting a specific regulatory or framework obligation.
How do I document one for an auditor?
Create a worksheet that lists the original requirement, the reason it cannot be met, and the detailed steps of the alternative measure. Include a formal sign-off from management acknowledging the risk.
What evidence should I provide to prove it works?
Provide technical artifacts such as firewall logs, configuration screenshots, or audit trails showing the substitute is active. You must also show that the control is monitored and reviewed regularly.
When is the best time to identify these in a compliance cycle?
During the initial gap analysis phase before any formal auditing begins. Identifying them early allows you to test their effectiveness and obtain management approval before the auditor arrives.
More terms
IT general controls · Conformity assessment · Unqualified opinion · Adverse opinion · Control owner · Right to be forgotten · Subprocessor · Assertion