The Assurance Gap: Why Documented Controls and Working Controls Are Different Things

The Assurance Gap featured image

Every organization that has suffered a serious incident has, somewhere in a drawer, a document proving it was protected. The policy was signed. The control was documented. The audit, at some point in the past, passed. And then the breach arrived through the gap between what the paper said and what the systems did.

This article is about that gap: why controls decay even in well-run organizations, what the data says about the distance between documented and operating defences, and how leaders close the gap with evidence rather than assertion.

At a glance

  • Exploitation is a top breach method: one in five breaches involved vulnerability exploitation in the Verizon 2025 DBIR, the world’s largest annual study of real breaches, a 34% year-on-year rise, second only to stolen credentials.
  • Remediation is where paper meets reality: only 54% of vulnerable edge devices were fully remediated in the observation period, at a median of 32 days, and nearly one in three known exploited vulnerabilities remained entirely unpatched.
  • The perimeter now includes everyone else’s: third-party involvement in breaches doubled from 15% to 30% in a single year.
  • Assurance must therefore be continuous: a control verified once a year is true for one day a year, by definition.

Controls Decay: Entropy Is the Default

A control is a promise about behaviour: that access will be reviewed, that changes will be approved, that backups will be tested, that patches will land within a window. The day the control goes live, the promise is usually kept. Then entropy begins. The administrator who owned the process moves on, and the quarterly review slips a month. An exception granted during a deadline becomes the silent new normal. A system is migrated, and half the control migrates with it. Nobody decides to stop doing the control; it simply stops being done the way the document says it is.

This drift is not a scandal. It is the natural state of complex systems under change pressure. The scandal is pretending it does not happen, which is what an assurance regime built on point-in-time documents implicitly does.

The Anatomy of the Gap

The gap has a recognizable anatomy. On the documented side sit policies, approved designs, and audit artefacts: coherent, dated, and inert. On the operating side sit the actual behaviours of systems and people under real workload: partial, shifting, and alive. The gap is everything that is true on the first side and quietly false on the second: the access review that has not been performed since the last audit, the tested backup that has never been restored, the patch window that internet-facing systems routinely miss, the vendor control assumed because a contract said so.

Two column diagram contrasting documented controls with operating controls and the gap between them
The assurance gap: every control is documented on one side and operating on the other, and assurance is the discipline of proving the two columns still match.

Most assurance regimes examine the left column, because the left column holds still. Incidents only ever occur in the right one.

The Gap, Quantified

The Verizon 2025 Data Breach Investigations Report reads like a measurement of the gap itself. Vulnerability exploitation featured in one in five breaches, up 34% in a year, with exploitation of edge devices and VPNs surging eightfold to 22% of those breaches. These were not exotic zero-days: they were known vulnerabilities with available patches. Yet only 54% of vulnerable edge devices were fully remediated across the year, the median fix took 32 days, and nearly one in three known exploited vulnerabilities remained completely unpatched. Somewhere, a patch management policy documented a standard the estate was not meeting. That document, and the 46% of devices, together are the assurance gap in its purest form.

The perimeter version is just as measurable: third-party involvement in breaches doubled to 30% in a single year, while most vendor governance programmes still consist of a questionnaire returned once at onboarding. Assumed controls are documented controls with a longer fuse.

Closing the Gap: Evidence Over Assertion

Organizations that close the gap do three things consistently. First, they test controls the way reality does: sampling live transactions, restoring actual backups, and walking real change tickets end to end, rather than reading the procedure about them. Second, they instrument what matters: continuous controls monitoring that checks access, patching, configuration, and backup status against policy automatically, so drift is detected in hours instead of at the next audit. Third, they buy independence: someone whose only job is to find the gap, with no incentive to certify the document, which is the role independent assurance has always played in mature governance regimes.

From Annual Snapshot to Always-On Assurance

The structural fix is temporal. A traditional audit is a snapshot: high resolution for one day, blind for the other 364. Continuous assurance replaces the snapshot with a signal: a stream of evidence showing each control operating, or failing, in near real time. The snapshot still matters for the board and the regulator, but it becomes a checkpoint on a line that is watched all year, not a solitary island of confidence.

Timeline contrast between annual audit snapshots and continuous assurance monitoring
Point-in-time assurance checks one day a year; continuous assurance watches the line all year, catching drift as it happens rather than at the next audit.

The economics already favour the shift: organizations making extensive use of security automation, which is the machinery of continuous assurance, identified and contained breaches an average of 80 days faster and about R30 million ($1.9 million) cheaper in the IBM 2025 dataset.

What Leaders Should Do Now

1. Audit three controls this quarter, operationally. Pick access review, backup restoration, and patching of internet-facing systems. Test what actually happens, not what the procedure says. The results will reorganize your risk register.

2. Instrument the crown jewels first. Continuous monitoring of the ten controls that protect revenue-critical systems beats annual assurance of two hundred procedural ones.

3. Put internet-facing remediation on a war footing. With edge exploitation up eightfold, a 32-day median fix time is an open invitation. Edge devices deserve hours-to-days, not weeks.

4. Re-underwrite your vendors. Assume the questionnaire is stale. Ask current vendors for evidence of the three controls that would hurt you most if they failed.

5. Ask for the gap report at board level. The most valuable slide in assurance is not the list of controls that passed. It is the list of documented controls that could not be evidenced as operating, with owners and dates.


Sources: Verizon Data Breach Investigations Report 2025; IBM Cost of a Data Breach Report 2025.

The healthiest sentence in governance is a proved one: this control is documented, and here is yesterday’s evidence that it operated. Producing that sentence, control by control, is what Lebone Marang and Summer does with executives and audit committees: independent, evidence-based assurance that closes the gap between the organization you have documented and the one that actually runs. If you suspect the two have drifted apart, we should talk before an incident does the audit for you.

Facebook
Twitter
WhatsApp
Email