Fin Maverick
Foundations VocabularyAccounting & ReportingEconomics & MacroQuant Methods & ProgrammingBusiness & Company AnalysisCorporate Finance & ValuationBehavioural Finance
Banking & Market InfrastructureFixed Income & RatesDerivatives & Structured ProductsPublic EquitiesTransactions & DealsPortfolio ConstructionFunds & AMCs
Private Markets & AlternativesRisk, Treasury & ControlAI & Digital FinanceStochastic Calculus & PricingWealth & Personal FinanceIndian Markets & RegulationProfessional Practice
CalculatorComparison
Frameworks
Explore Bootcamps
Equity ResearchPortfolio ManagementMutual Fund MasteryFinancial LiteracyInvestment Banking Analyst
Private Equity AnalystHedge Funds AnalystBreaking Into VCBreaking Into QuantsAI For Finance
Financial Analyst ProgramRisk Management ProgramPrivate Wealth ManagementDebt Capital MarketsDerivatives Foundation
Explore Internships
Equity Research InternMutual Fund Intern
Portfolio Management InternFinancial Literacy Intern
Explore Micro Courses

Equity Research6

Writing an Investment ThesisBuilding a Discounted Cash FlowReading an Annual Report FastReading a Sector Before a CompanySpotting Quality of Earnings Red FlagsBuilding a Revenue Forecast From Drivers

Portfolio Management3

Rebalancing: When, Why and What It CostsStrategic and Tactical Asset AllocationMeasuring Risk in a Portfolio

Mutual Fund Mastery3

Comparing Funds Without Being FooledHow a NAV Is Struck and Which Day You GetReading a Fund Factsheet Properly

Derivatives Unlocked4

Hedging a Real ExposureThe Greeks, PracticallyFutures, the Basis and What Moves ItReading an Option Payoff

AI For Finance2

Retrieval and Grounding for FinanceDocument Extraction in Finance

Breaking Into Quants4

Backtesting a StrategyHypothesis TestingCleaning Financial DataRegression for Finance

Breaking Into VC3

Sizing a MarketReading a Term Sheet as a FounderHow a Venture Round Actually Works

Financial Analyst Program4

Common Size and Trend AnalysisReading a Cash Flow StatementRatio Analysis That Says SomethingBuilding a Working Capital Schedule

Risk Management Program2

Credit Exposure and How It Is ReducedValue at Risk and What It Hides

Investment Banking Analyst3

Precedent Transactions and Why They DifferReading a Term Sheet StructurallyBuilding a Comparable Companies Table

Private Wealth Management3

Tax Aware Portfolio DecisionsBuilding a Client Risk ProfileGoal Based Planning Arithmetic

Debt Capital Markets3

Analysing an Issuer's CreditDuration and What It Does Not Tell YouBond Pricing and Yield Mechanics

Private Equity Analyst2

Fund Waterfalls and CarryThe LBO in Structure

Hedge Funds Analyst2

Short Selling MechanicsLong Short Mechanics
Courses
Explore Career Roadmaps
Investment Banking AnalystEquity Research AnalystVC AnalystPrivate Equity AnalystHedge Funds Analyst
Quant AnalystAI For FinanceFinancial Analyst ProgramPrivate Wealth ManagementDebt Capital Markets
Risk Management ProgramDerivatives FoundationPortfolio ManagementMutual Fund Mastery
PartnershipsShowdown
Log inSign up
Risk Management Program · CoreTrack
1Risk, Treasury & Financial Control
iRisk Foundations
Risk Appetite, Tolerance, Capacity…The Risk Taxonomy and UniverseRisk Register vs Risk MatrixStress TestingScenario Analysis vs Stress TestingImpact and LikelihoodLikelihoodThe Risk EventRisk Assessment
iiEnterprise Risk Management
Enterprise Risk ManagementThe Four Risk TreatmentsRisk CultureRisk MaturityRisk Monitoring
iiiRisk Governance
Risk GovernanceHow to set a…The Risk PolicyThe Risk OwnerThe Risk Committee and Its CharterThe Risk Limit FrameworkRisk EscalationHow to set a…
ivCredit and Counterparty Risk
Collateral AgreementsCollateral vs NettingProbability of DefaultExposureCounterparty ExposureConcentration Risk vs Wrong Way RiskCounterparty Risk vs Credit RiskHow to assess Counterparty ExposureHow to assess Concentration Risk
vMarket Risk
Market RiskSensitivity MeasuresThe Hedging PolicyInterest Rate Risk in the Banking BookIRRBB vs Market RiskExpected ShortfallEconomic Value of EquityVaR BacktestingOpen PositionValue at RiskValue at Risk and Expected ShortfallEconomic Value SensitivityFX ExposureValue at Risk vs Expected ShortfallEarnings at Risk vs…FX Transaction Risk vs…How to measure Interest…How to measure Foreign…
viLiquidity Risk
Liquidity Stress TestingLiquidity Gap vs Liquidity BufferMaturity MismatchThe Debt Maturity ProfileFunding ConcentrationSurvival HorizonThe Contingency Funding PlanNet Stable Funding RatioLiquidity Risk vs Funding RiskLiquidity Coverage RatioLiquidity Gap and BufferHow to run a Liquidity Gap Analysis
viiOperational Risk
Operational LossThe Loss EventRisk and Control Self AssessmentException ManagementInformation Security as a…Segregation of DutiesIssue ManagementThe Near MissRoot Cause Analysis in RiskThe Fraud TriangleCyber Risk vs Third Party RiskHow to run a…How to assess Third…
viiiRisk Reporting, Data and Model Risk
Model RiskModel Validation vs BacktestingHow to run Model ValidationData Governance in RiskModel Risk vs Data RiskKey Risk IndicatorsManagement InformationRisk ReportingRisk ScoreEarnings at RiskRisk Adjusted ReturnEarly Warning IndicatorsHow to build a KRI Dashboard
ixTreasury
Corporate TreasuryAsset Liability ManagementIntragroup FundingThe Treasury PolicyThe Treasury Management SystemThe Cash ForecastCash Pooling and ConcentrationHow to build a Cash Forecast
xFinancial Controls and Assurance
Control AssuranceThe Control LifecycleThe Assurance MapThe Audit FindingIssue RemediationInternal Financial ControlsControl Design vs Control EffectivenessHow to map Internal Financial ControlsHow to test Control…Control DeficiencyMaterial Weakness
xiOperational Resilience
Operational ResilienceBusiness Continuity and Disaster RecoveryBusiness Continuity vs Operational…Crisis ManagementDisaster RecoveryIncident Management

Control Design vs Control Effectiveness: Two Different Tests

Control design asks whether an activity would meet its objective if it happened exactly as written every time. Control effectiveness asks whether it did happen. The first is judged on the written control, the second on a sample over a period. The two tests run on different populations, they fail for different reasons, and their pass rates multiply rather than average.

Two sentences arrive about the same control and sound like one sentence said twice. The first says the control is well designed. The second says it is operating effectively. A reader who takes those as two ways of saying the thing works has merged two separate tests. A control can pass either test and fail the other, the two are settled by different kinds of evidence, and the fix for one buys nothing against the other.

One distinction carries the whole subject. Control designWhether the activity would meet its objective if it happened exactly as written, every time. asks what the activity would achieve if it were performed perfectly, so it can be answered about a control that has never once been performed. Control effectivenessWhether a properly designed control actually operated as stated throughout the period. asks what happened on days that have already gone, so it cannot be answered about such a control at all. One is about the shape of the thing. The other is about the record of it.

Are these two tests two versions of one question?

No, and the cleanest way to see it is to notice what kind of question each one is. Design asks a conditional questionOne answered under a hypothesis, so it can be settled by reading the control and walking one case.: if this activity happened exactly as written, every single time, would the thing it exists to prevent still be able to happen? A hypothesis does not need history to settle it, so it is answered by reading the control against its objective and following one case through. Operating effectiveness asks a factual questionOne answered by evidence about what happened, so it needs a sample spread across the period.: over a stated stretch of time, did the activity happen as stated? The factual question has no hypothesis in it at all, and only evidence about days already passed can settle it. Every other difference between the two tests, including the populations they run on and the way their results combine, follows from that one split.

The shape is easier to feel on a familiar street. A housing society decides that its night guard must write every visitor's name into a register at the gate, and that written rule is the control. Suppose the guard writes every name faultlessly for a year. If the register records a name and nothing else, it still does not say which flat let the visitor in, when they left, or whether anybody read it the next morning. Filled in perfectly for a year, that register could not tell anybody a stranger stayed inside the building after midnight, and that failure is reached without looking at a single night of it. Whether it was filled in at all is the other question, and no argument settles that one. Settling it takes looking: at which nights, at how many entries, at whether the handwriting stops while the regular guard was on leave. The first question was answered by reading; the second can only be answered by counting.

One control, and the two questions that are asked of it ONE KEY CONTROL The visitor register is written at the gate each night THE CONDITIONAL QUESTION If it happened exactly as written, every time, would it meet its objective? SETTLED BY Reading the control against its objective, and walking one case. THE FACTUAL QUESTION Over the stated period, did the activity actually happen as stated? SETTLED BY Evidence about days that have passed, spread across the period. A hypothesis needs no history to settle it. A fact about last year cannot be reasoned out at all.
The two boxes hang off the same control and take different kinds of answer, which is why one of them can be settled by reading and the other one can only be settled by going and looking at what actually happened.

Get them the wrong way round and both failures are quiet. Answering the conditional question with history produces a sentence that sounds strong and proves nothing: it has worked every month for two years. Answering the factual question with reasoning produces a worse one. The sentence sounds like evidence: the procedure requires it, so it must be happening.

Derivatives Foundation Bootcamp — Fin Maverick

What does the design test actually ask, and what settles it?

The design test starts from the objective, the statement of what must not go wrong. The test then reads the control activity, meaning what somebody actually does, and asks a single question of the pair: is this activity, performed perfectly, capable of meeting that objective? The design test is a test of capability rather than of behaviour, and capability is a property of the written control rather than of the person performing it.

Three things settle it, and none of them is a sample: the objective stated properly, the written control itself, and a walkthroughFollowing one transaction through the control from start to finish to see what the control would do. of one case from one end of the control to the other. A control cannot be judged well designed in the abstract, only well designed for something, and many design failures are a control perfectly capable of meeting an objective nobody actually had. The walkthrough is run not to see whether the control usually happens but to see what it would do with a case it was built to catch, and one case is enough because the exercise inspects a mechanism rather than sampling anything. One walkthrough answers a design question for the same reason that opening one lock reveals what kind of lock it is, and that is why the answer does not improve when a hundred cases are walked instead of one.

Inside Vindhya Commercial Bank Limited, an invented bank of Rs 96,000 crore whose figures are illustrative throughout, the design test was run on all 214 key controlsThe controls an institution has decided are the ones it would notice the absence of, and therefore the only ones on the testing list. across its nine processes PR1 to PR9. The design test produced two numbers and nothing else: 198 controls were judged capable of meeting their objectives, and 16 were not. Not one of the 16 was found by watching anybody work. All 16 were found by reading.

The design test: three inputs, one verdict, and no sample anywhere 1 THE OBJECTIVE What must not go wrong. No advance is carried at a stale collateral value. 2 THE WRITTEN CONTROL Who does it, when, against what, what evidence is left, and what happens when it finds something. 3 ONE WALKTHROUGH One case followed end to end, to see what the control would do with it. THE VERDICT THIS TEST GIVES Performed perfectly, every time, would this activity meet that objective? YES, so it is well designed NO, so it carries a design gap and the testing stops there Nothing about anybody's diligence enters this answer at all. At the invented bank, this test ran on all 214 key controls and produced 198 passes and 16 design gaps.
Three inputs feed the design verdict and not one of them is a sample of days, which is why a design gap can be found on a control nobody has ever performed and why walking a hundred cases would not improve the answer.

A negative verdict stops the work rather than qualifying it. If the register at the gate cannot say who is still inside the building, there is no point counting how many nights it was filled in. No answer to the operating question could change the conclusion, so a negative design verdict makes that question unanswerable in the only sense that matters. The arithmetic of the two populations is a consequence of that sentence.

Try it out

A tester says a control is well designed because it has worked every month for two years. What has gone wrong?

What does the operating effectiveness test actually ask, and what settles it?

The operating effectiveness test starts where the design test left off, with a control already judged capable, and asks a question about the world rather than about the control: over months 1 to 12, did this activity happen, in the way the control says, every time it was supposed to? The operating test is a test of behaviour rather than of capability, and behaviour is a property of a period rather than of a document.

Evidence with a particular shape settles it. Not the procedure. The design test already read the procedure. Not a conversation with the person who performs the control. A conversation is a claim and not a record. The evidence is the artefacts the control left behind on the days it ran: the signed reconciliation, the timestamp on the release, the exception log with somebody's initials against it. A control performed diligently in months 1 to 4 and abandoned in month 10 looks flawless to a sample drawn in month 3, so those artefacts are counted on a sample of occasions drawn across the whole period rather than clustered at one end.

The everyday version is a parent checking whether a child did the homework set for the year. The school diary records what was set, the design question, and nothing about what happened. Learning that means opening books from different months, and opening only the first fortnight gives a confident and wrong answer. A sample that does not reach across the period measures the beginning of the period and reports it as the whole of it. An operating conclusion therefore names the period it covers.

At the invented bank the operating test ran across months 1 to 12, and month 12 is the reporting date. The operating test produced two numbers of its own: 172 controls were found to have operated as stated, and 26 were not. The 26 differ from the 16 that fell at the design test not in severity but in what was wrong. Every one of the 26 could have met its objective and did not get performed the way it said.

The same control, the same year, two samples The shaded block is the 11 working days in month 10 when this control did not run at all. A SAMPLE DRAWN ACROSS THE WHOLE PERIOD did not run 1 2 3 4 5 6 7 8 9 10 11 12 Month 10 is inside the sample, so the days it did not run are found. A SAMPLE DRAWN AT ONE END OF THE PERIOD did not run 1 2 3 4 5 6 7 8 9 10 11 12 Six occasions, all of them before month 4, and the same failure is invisible. Both samples are clean-looking work. Only one of them measured the period the conclusion names.
Both lines carry the same number of marks against the same control, and only the sample spread across the whole period touches the month in which the control stopped running.

One more property of the operating test is the source of most of the confusion on this subject. The operating test never runs first, and it cannot. Until somebody has decided that the activity is capable of meeting its objective, a diligent record of the activity happening is a record of something whose value is unknown. The order is not a convention that could have gone the other way, it is forced by what the two questions are.

Which six things separate the two tests?

Both tests are now defined on their own terms, so they can be laid against each other. Six criteria do the work, numbered DE1 to DE6 so that each can be named without being restated. DE1 is the question itself, and the other five are consequences of it rather than independent facts to memorise.

DE1, the question: design asks whether it would work, operation asks whether it did. DE2, what settles it: the written control read against its objective plus one walkthrough, against artefacts from a sample of occasions drawn across the whole period. DE3, the population: all 214 key controls, against only the 198 that passed design. DE4, what a failure is: a control that could not have met its objective, against one that could have and did not happen as stated. DE5, the fix: change the control, against make the existing control actually happen. DE6, what a pass buys: capability with nothing said about whether anybody performed it, against an operating pass that buys nothing at all on a badly designed control.

Six criteria, and five of them follow from the first THE DESIGN TEST THE OPERATING TEST DE1 THE QUESTION Would it meet its objective if performed exactly as written, every time? Did it actually happen as stated, throughout the period the conclusion names? DE2 WHAT SETTLES IT The written control read against its objective, plus one walkthrough. Artefacts from a sample of occasions drawn across the whole period. DE3 THE POPULATION All 214 key controls, because nothing has been ruled out yet. Only the 198 that passed design, and that is deliberate. DE4 WHAT A FAILURE IS 16 design gaps: the activity could not have met the objective however well done. 26 operating failures: it could have met the objective and it did not happen as stated. DE5 THE FIX Change the control itself, so that a perfect run would work. Make the existing control actually happen every time. DE6 WHAT A PASS BUYS Capability, and no word at all on whether anybody did it. Nothing whatever, where the design test was failed. Every count belongs to one invented bank and none of it is a fact about any real institution.
Reading down either column gives one complete test rather than half of a shared one, and every row after the first is a consequence of the question at the top of that column.

The columns come before the rows. Each column is a whole instrument: a question, a method, a population, a kind of failure, a kind of fix and a kind of assurance bought. Going across comes second. Only then do the differences stop being a list and start being one difference expressed six times.

Why does the second test run on 198 controls and not on all 214?

DE3, the population, is where most of the arithmetic trouble on this subject begins. The design test ran on all 214 key controls because at that point nothing had been ruled out. The operating test ran on 198, being the 214 less the 16 that carried a design gap. A reader who has met a lot of sampling reads that 198 as a shortcut: somebody had less time, so they tested fewer. The 198 is the opposite of a shortcut, and the reason it is not one settles every rate the testing produces.

The question is what an operating result on one of those 16 would mean. Suppose one is tested anyway, on a sample spread properly across months 1 to 12, and comes back perfectly clean. The finding is that a control which could not meet its objective was performed reliably. The objective is no closer to being met, and the money spent finding out is gone. An operating result on a control that failed its design test is not a weak answer, it is an answer to a question whose value was destroyed by the earlier result. Worse, those controls would then carry a clean operating result and an unmet objective in the same list as controls that genuinely work, and somebody would eventually average the list.

The 16 are easy to overreach on, so be exact about what the record holds. Not one of them was tested for operation. Not tested and failed, not tested and passed: never asked. Any picture that splits those 16 by operating outcome is asserting a result the testing never produced, so they are drawn here as one block with the question left blank.

Two tests, two populations, and one block nobody asked about All three bars are drawn at the same scale, so every width is a count of controls. THE POPULATION 214 key controls THE DESIGN TEST, ON ALL 214 198 designed effectively 16 THE OPERATING TEST, ON THE 198 ONLY 172 operating effectively 26 the grey block is those same 16 controls, and the operating question was never asked of them 172 of the original 214 came through both tests. 42 controls fell, 16 at the first test and 26 at the second.
The grey block at the right of the bottom bar is not a pass and not a failure, because those 16 controls were never tested for operation at all and no result exists to draw.

A stray percentage does more damage on this subject than on almost any other, so the table carries the same six counts as rows, with the denominator named on every rate. The two pass rates sit on different bases, and nothing should put them beside each other without saying so.

What was measuredCountOut ofRate
Designed effectively19821492.5 per cent
Carried a design gap162147.5 per cent
Operating effectively, of those tested for operation17219886.9 per cent
Operating failures, of those tested for operation2619813.1 per cent
Operating failures as a share of the whole population2621412.1 per cent
Came through both tests17221480.4 per cent

Two rows of that table are the same 26 controls at two different rates, 13.1 per cent and 12.1 per cent, and neither is wrong. The two rates answer different questions: what share of the tested population failed to operate, and what share of the whole population did. The rate changed without a single control moving. A rate is a count and a decision about a denominator, and nothing shows it more plainly.

Try it out

Why was operating effectiveness tested on 198 controls rather than on all 214?

What does a failure of each one look like, and what fixes it?

DE4 and DE5 belong together. In practice one is never met without the other. A design gapA control that could not meet its objective even if performed perfectly, here a failure at stage CL3. is a control that could not have met its objective however well it was performed. The trade finance example in this invented bank is the shape everybody recognises once they have seen it: one person could both check the shipping documents and release the instrument. Performed impeccably by somebody who takes real care, the control still cannot do the thing a second pair of eyes exists to do. There is no second pair of eyes. The failure can be spotted from the written control alone, without ever learning whether anybody performed it.

An operating failureA properly designed control that was not performed as stated, here a failure at stage CL4. is the other creature entirely. The control would have worked, and the design test passed it on its merits. Then in the actual year it did not happen the way it says: the reconciliation was not run in four months of twelve, or the collateral valuation feed went unchecked for 11 working days in month 10 while everybody meant to check it was busy with something that had a deadline. Nothing is wrong with the control. Something was wrong with the year.

Now DE5, the fixes. Closing a design gap means changing the control: rewriting it so a different person releases what a first person checked, resourcing that second person, or building a system rule that refuses a release by the checker. Closing an operating failure means changing nothing about the control and everything about whether it happens: cover for the months the person was on leave, capacity so that deadline work does not eat routine work, and somebody accountable for the months it did not run. The two fixes cost different things, buy different things, and neither touches a single control in the other group.

Getting this backwards is expensive in both directions. Redesigning a control that would have worked solves a problem the institution does not have, and it usually makes the control heavier. A heavier control quietly makes the operating failure more likely next year. Enforcing a control that could never have met its objective makes a defective thing happen more reliably, and produces the most dangerous artefact in this subject: a clean record on a control that does not work.

Two fixes, and neither one reaches the other column Same institution, same year, same budget holder, and two entirely different purchases. CLOSING A DESIGN GAP THE PROBLEM One person checks the documents and releases the instrument. WHAT CLOSING IT MEANS Rewrite the control, resource a second person, or build a system rule that refuses a release by the checker. WHAT IT BUYS A higher ceiling on what the control could ever deliver. CLOSING AN OPERATING FAILURE THE PROBLEM A reconciliation that would have worked was not run for four months. WHAT CLOSING IT MEANS Cover for leave, capacity so deadline work stops eating routine work, and a named person for the months missed. WHAT IT BUYS More of what the current design was already able to deliver. Closing all 16 design gaps performs no reconciliation, and performing every reconciliation redesigns no control. The two budgets do not substitute for one another at any price.
The crossed arrow in the middle is the whole claim of this picture, because a rupee spent redesigning a control does nothing for the controls that were simply not performed.
Try it out

A control is well designed and was not performed in four months of twelve. What kind of fix does it need?

Debt Capital Markets Bootcamp — Fin Maverick

What does a pass on either test actually buy?

DE6 is the criterion readers underrate, and the one that turns the other five into something usable. A design pass buys capability and nothing else: performed as written, this activity would meet its objective. A design pass says not one word about whether anybody has ever performed the control, and it cannot. No evidence about behaviour went into producing it. A control can hold a clean design verdict and have been performed on none of the days in the period it is about.

An operating pass is stranger. What it buys depends on a result from the other test. On a well designed control it buys the thing everybody wants: the objective was being met, on the evidence, over the period. On a badly designed control it buys nothing. The design test has already established that the activity does not meet the objective even when it happens perfectly. So the pass says the activity happened, and can say nothing at all about the objective.

The asymmetry is the argument for the order of the two tests. The value of an operating result is conditional on a design result; the value of a design result is conditional on nothing. One of these two tests can stand alone and the other cannot, and it is not the one most institutions report first. A pack that leads with an operating percentage has led with the number whose meaning depends on a number it has not shown.

Try it out

A badly designed control passes its operating test with a clean sample of forty items. What has been learned?

Can a control pass one test and fail the other?

In both directions, and the two combinations look nothing alike on the ground. Start with well designed and badly performed. The monthly reconciliation is a good control: it compares two independent records, it is done by somebody who did not produce either of them, and a difference forces an investigation before the month closes. In the year it happened in eight months and did not happen in four. Everybody involved could describe the control accurately, and the evidence is simply not there for a third of the period. The reconciliation is a design pass and an operating failure, and the fix is a rota rather than a redesign.

The other direction is the one that hurts. Somebody performs a check every single working day, on time, with the evidence filed, and the design test then finds that the person doing the checking is the person who releases the payment. The checker who also releases is a design failure sitting under an exemplary record. The most diligent operating record in the institution can sit on a control that could never have caught the thing it exists to catch. The finding is demoralising to receive, which is exactly why it has to name which stage failed.

The two combinations meet in one rule about language. Calling either of those controls ineffective, with no further word, is accurate and useless. The first needs a rota and the second needs a second person, and a report that says only ineffective sends both fixes to the wrong place half the time. The word ineffective, on its own, destroys the only piece of information the testing actually produced.

The four combinations, and why only three of them exist OPERATING TEST PASSED OPERATING TEST FAILED DESIGN TEST PASSED EFFECTIVE It could meet its objective and it did happen as stated, on the evidence, across the period. Fix needed: none. WELL DESIGNED, NOT PERFORMED The monthly reconciliation ran in eight months of twelve and not in the other four. Fix needed: a rota, not a rewrite. DESIGN TEST FAILED THE OPERATING QUESTION WAS NEVER ASKED One person checks the shipping documents and releases the instrument. It may have been performed impeccably every working day, and it could not have met its objective on any of them. No operating result exists for this row. Fix needed: a second person, not a rota. Cell size here is a logic position and never a count of controls. The counts are in the three bar picture above.
The bottom row is drawn as one block rather than two because a control that failed the design test was never tested for operation, so no evidence exists to put on either side of that row.

What happens when the two rates are put together?

Combining the two results is where careful people produce a wrong number in good faith. The counts alone answer it with addition, and starting from the counts is the whole trick.

Try it out

16 controls failed design and 26 failed operation. Before any computation: what share of the original 214 came through both tests?

Here is the whole worked instance in one place. Vindhya Commercial Bank Limited holds 214 key controls across nine processes PR1 to PR9, and both tests were run in the twelve months to the month 12 reporting date. The design test, the conditional one, ran on all 214: 198 passed and 16 carried a design gap, so the design pass rate is 198 over 214, being 92.5 per cent. The operating test, the factual one, ran on only the 198 that passed design: 172 passed and 26 did not, so the operating pass rate is 172 over 198, being 86.9 per cent.

Now put the two together. The two rates multiply. 92.5 per cent of 86.9 per cent is 80.4 per cent, and 80.4 per cent of 214 is 172, which is exactly the count that came through both tests. The identity is not a coincidence and not an approximation: the second rate is measured on the survivors of the first, so applying it to the survivors is the only thing that can be done with it. The result is the end to end rateThe share of the original population that came through both tests, which is the product of the two rates., the only one of the three rates that describes the population the bank actually runs.

Read as counts it needs no arithmetic beyond addition. 16 controls fell at the first test. 26 fell at the second. 16 plus 26 is 42. 42 of 214 is 19.6 per cent. 100 less 19.6 is 80.4. A rate carries a denominator somebody chose and a count carries nothing at all, so the counts never lie and the rates can. Every rate that follows carries its count underneath it, so the rate can be checked against the count rather than the other way round.

The same answer, reached without dividing one rate by another 1 16 controls fell at the design test. 2 26 controls fell at the operating test. 3 16 plus 26 is 42 controls that fell at one test or the other. 4 42 of 214 is 19.6 per cent of the population. 5 100 less 19.6 is 80.4 per cent, which is 172 of the 214 key controls. Not one rate was divided by another rate anywhere in that sequence, and no denominator had to be chosen.
Five steps of addition and one division reach the same 80.4 per cent that multiplying the two pass rates produces, which is why a reader working in counts cannot be misled by a denominator.
Investment Banking Analyst Bootcamp — Fin Maverick Ratio Analysis That Says Something — free micro-course from Fin Maverick

Why is averaging the two rates never right?

The mistake has one shape: two pass rates arrive in the same paper, somebody wants one number, and the two get averaged. The average of 92.5 and 86.9 is 89.7, and the figure sounds like a reasonable summary of two rates in the high eighties and low nineties. The average is not a summary of anything. 89.7 per cent is not a rounder version of 80.4 per cent, it is a different quantity wearing the same units.

Averaging two sequential pass rates

The usual defence is that averaging is a small approximation, close enough for a summary line, and that nobody makes a decision on the second decimal place. The defence would be worth hearing if the error were small and stable. The error is neither. Averaging is not an approximation at all, and it gets more flattering exactly as the controls get worse.

Hold the operating pass rate at this bank's 86.9 per cent, meaning 172 of the 198 tested for operation, and move only the design pass rate. At a design pass rate of 100 per cent, the true end to end rate is 86.9 per cent and the average says 93.4 per cent, a gap of 6.6 points. At this bank's actual 92.5 per cent, the truth is 80.4 per cent and the average says 89.7 per cent, a gap of 9.3 points. At 50 per cent, the truth is 43.4 per cent and the average says 68.4 per cent, a gap of 25.0 points. The error triples as the institution's controls deteriorate, and that is the last direction in which a measure ought to become kinder.

And there is no rate at which it comes right. Set the product equal to the average and solve for the design pass rate: it would have to be 117.8 per cent. More than every control in the population passing is what averaging would need in order to be correct, so the two readings never meet anywhere a real institution can stand. Averaging is an arithmetic impossibility rather than a matter of degree, and that is why the word approximation cannot be used about it at all.

The cost is not abstract. A committee told 89.7 per cent believes about 192 of its 214 key controls are working. The count that came through both tests is 172. Twenty controls, sitting in nine processes PR1 to PR9, exist in the committee's picture and not in the institution.

Three figures in one paper, and the third one counts nothing EXTRACT FROM THE CONTROLS PAPER Design effectiveness 92.5 per cent Operating effectiveness 86.9 per cent Overall control effectiveness 89.7 per cent The third figure is the first two added and halved. Nothing in the paper says so. The two rates are sequential. The second is measured on the survivors of the first. They multiply. 92.5 per cent of 86.9 per cent is 80.4 per cent. That is 172 of 214 controls. 89.7 per cent is 20 more. Every count belongs to one invented bank, and none of it is a fact about any real institution.
The averaged figure sits in the same column and the same typeface as two figures that were actually measured, and nothing in the paper tells a reader that the third one was arrived at differently.
Try it out

A pack reports design effectiveness of 92.5 per cent, operating effectiveness of 86.9 per cent and overall control effectiveness of 89.7 per cent. What is wrong with the third figure?

Drawing the two readings against every possible design pass rate makes the claim visible in a way no single pair of numbers can. Hold the operating pass rate at 86.9 per cent, being the 172 of 198 this bank measured, and let the design pass rate run from 40 per cent to 100 per cent. The truth is a straight line through the origin, being the design rate multiplied by a constant. Half of the average is a number that does not move, so the average is also a straight line, but a flatter one that starts far higher. Two straight lines with different slopes cross exactly once, and the only question is where.

Two straight lines that never meet inside the possible range The operating pass rate is held at 86.9 per cent, being the 172 of 198 this invented bank measured. 40 50 60 70 80 90 100 40 50 60 70 80 90 100 design pass rate applied to the 214 key controls, per cent the average of the two rates the true end to end rate DESIGN PASS RATE 100 PER CENT truth 86.9 per cent average says 93.4 per cent gap 6.6 points 92.5 PER CENT, THIS BANK truth 80.4 per cent average says 89.7 per cent gap 9.3 points DESIGN PASS RATE 50 PER CENT truth 43.4 per cent average says 68.4 per cent gap 25.0 points The two lines would meet only at a design pass rate of 117.8 per cent, which is off this chart and impossible.
The gap between the two lines is widest at the left of the chart, so the wrong method flatters an institution most at exactly the moment its controls are in the worst condition.
Try it out

Design passes at 92.5 per cent and operation passes at 86.9 per cent of those. Before the control below is moved: is there any design pass rate at which averaging the two rates gives the right answer?

Play with it

Move the design pass rate and watch the two readings refuse to meet

One variable: the design pass rate applied to the 214 key controls. Holding the operating pass rate still is the point of the control, so it stays locked at 86.9 per cent, being 172 of the 198 tested for operation.

Design pass rate: 92.5 per cent
The truth, the average, and the distance between them THE TRUTH the two rates multiplied 80.4 per cent THE NAIVE READING the two rates averaged 89.7 per cent 0 per cent 100 per cent 9.3 points CONTROLS THROUGH both tests, of the 214 172 of 214 Every count belongs to one invented bank and none of it is a fact about any real institution.
HELD CONSTANT
86.9 per cent
TRUE END TO END RATE
80.4 per cent
THE AVERAGE SAYS
89.7 per cent
GAP
9.3 points
At a design pass rate of 92.5 per cent, the true end to end rate is 80.4 per cent, being 172 of the 214 key controls, and the average of the two rates says 89.7 per cent, a gap of 9.3 percentage points.
Educational illustration. At a design pass rate of 100 per cent the truth is 86.9 per cent and the average says 93.4 per cent, a gap of 6.6 points. At this bank's 92.5 per cent the truth is 80.4 per cent, being 172 of 214 key controls, and the average says 89.7 per cent, a gap of 9.3 points. At 50 per cent the truth is 43.4 per cent and the average says 68.4 per cent, a gap of 25.0 points, computed from the underlying counts rather than from the rounded pair. The two readings would meet only at a design pass rate of 117.8 per cent, which is more than every control passing, so they never meet at all. Three conventions govern the figures here. The end to end rate is the product of the two rates. The control count beside it is that rate applied to 214 and then rounded to whole controls, because a fraction of a control cannot be tested, so at a few settings dividing the rounded count back by 214 gives a tenth of a point more than the rate itself. And the gap is computed from the underlying figures before either rate is rounded, so at a few settings the gap differs by a tenth of a point from subtracting the two rounded readings above it. The operating pass rate is held at 86.9 per cent, which is the setting the control holds fixed and is not a claim that this bank's operating rate is fixed. Every count belongs to this one bank.
Two sequential control rates multiply, and the average sits above both. See the difference.

Which of the two tests produced the number in front of the reader?

Most readers of a controls report never see two rates. Readers see one, in a sentence that says controls effective and gives a percentage, and the sentence does not say which test produced it or what it is a percentage of. Two questions settle it, and both are short enough to ask out loud in a meeting. Ask what it is a percentage of, and ask which of the two tests produced it. No committee paper asks either question on the reader's behalf.

Run them against this bank's own headline. Controls effective, 86.9 per cent. What is it a percentage of? Of 198, not of 214. The operating test only ran on the controls that passed design. Which test produced it? The operating one, so the 16 design gaps are not inside that figure at all, in either direction. The 86.9 per cent is a true statement about a population that is 16 controls smaller than the one the bank actually runs, and the figure for the population it does run is 80.4 per cent.

A second trap sits on that exact number, and it looks like a coincidence and is not. 86.9 per cent is the operating pass rate on the 198 tested. The same fraction is also the ceiling. If every one of the 16 design gaps were closed and the operating failure rate stayed where it is, the end to end result would be 186 of 214 controls, or 86.9 per cent of the whole population. The same fraction arrives twice because closing every design gap makes the design population and the operating population the same 214, so the end to end rate collapses onto the operating rate. A report carrying both must name which 86.9 per cent it means in the same sentence, every time.

One figure, two meanings, and only two questions between them CONTROLS EFFECTIVE 86.9 per cent denominator not stated, test not stated READING ONE, AND IT IS THIS BANK'S 172 of the 198 controls that passed the design test and were then tested for operation. The 16 design gaps are not inside it. READING TWO, A DIFFERENT OBJECT The ceiling: 186 of the whole 214, if every design gap were closed and the operating failure rate held. Same number, different population. What is it a percentage of? Which of the two tests produced it?
The same figure of 86.9 per cent describes two different populations in this bank, so a reader who asks for the denominator and the test recovers everything the headline threw away.
Try it out

A committee paper says controls effective, 86.9 per cent. What two questions settle what that number means?

When does the difference between the two tests change a decision?

A remediation budget arrives that can close the 16 design gaps or the 26 operating failures, and not both. If the two kinds of failure were versions of one problem, the cheaper repair would be the obvious purchase. The two kinds of failure are not versions of one problem, so each purchase has to be priced against what it can deliver, and the arithmetic gives a bound on each.

Buying the design fixes raises a ceiling. Close all 16 design gaps, hold the operating failure rate where it actually sits, and the effective count moves from 172 to 186 out of 214, a gain of 14 controls and 6.5 percentage points, and it stops there. The 186 is the ceiling this bank's current operating behaviour permits, and the share it represents, 86.9 per cent of the whole 214, is the ceiling sense of that figure rather than the operating pass rate on the 198. A design fix cannot make anybody perform anything, so no number of design fixes reaches 90 per cent while the operating failure rate is unchanged.

Buying the operating fixes collects what the current design can already deliver. Close all 26 operating failures with the 16 design gaps left open and the effective count is 198 of 214, or 92.5 per cent. The design pass rate reappears as a ceiling, for the mirror reason: when nothing fails at the second test, the end to end result collapses onto the first test's rate. 92.5 per cent means the design pass rate on 214 in one place and a ceiling produced by perfect operation in another, so the object has to be named every time the figure is written.

198 is larger than 186, and stopping there would be careless. The two figures rest on assumptions of very different strength. The design purchase assumes only that the current operating failure rate holds. The operating purchase assumes that every one of 198 controls operates perfectly for a whole period, a thing no institution has achieved. The arithmetic gives what each purchase can deliver at most, and it does not settle which one to buy. That judgement belongs to the people accountable for the controls. The household version is a flimsy latch that everybody fastens every night and a heavy deadbolt nobody has turned since the monsoon: a lock and the turning of a lock are two different things, and the same sentence carries into an institution with 214 of them.

The same split decides how somebody outside reads a control report. A lender sizing a borrower, or an analyst sizing a bank, is handed one conclusion and has to work out what it can carry. A design conclusion says the institution has built something capable. The statement is about architecture, and it survives a change of staff. An operating conclusion says it happened last year. The statement is about capacity, workload and attention, and it does not survive a bad quarter. The two statements decay at different speeds, and treating them as one number throws away which of the two is being relied on.

The last place it changes a decision is the one closest to money here. The collateral valuation control in process PR3 sits over Rs 8,640 crore of secured advances, being 15.0 per cent of net advances of Rs 57,600 crore, and the denominator has to be named because that same balance is 9.0 per cent of total assets of Rs 96,000 crore and both figures are exact. If that control carries a design gap, no amount of running it more carefully protects the valuation of that book. If it carries an operating failure, the control was capable and the year got in the way. The size of the book does not settle which, and only the two tests do.

Try it out

A remediation budget can close either the 16 design gaps or the 26 operating failures, not both. How does the difference between the two tests bear on the choice?

Risk Management Program Bootcamp — Fin Maverick

Where do the duties behind these two tests actually sit?

Nothing so far is national at all. The split between a conditional question and a factual one is a property of the two questions, and an institution anywhere would recognise both tests and both kinds of failure. The duty is not jurisdiction free: who has to report on internal control, to whom, in what form, and with what independent opinion attached. The duty and the body that holds its text are named below, and the text itself is read at the source.

Keeping to the body and the duty is practical. A section number, an applicability test, an exemption or a date is exactly the sort of thing that changes, and a document carrying one becomes quietly wrong without anybody noticing. Naming the body and the duty stays true, and it points to where to look. A pointer survives the next amendment.

Jurisdiction

Where an Indian institution's reporting duties on internal control sit

Where these two tests feed an Indian reporting duty on internal financial controls, that duty sits in the Companies Act, and its text, who it applies to, who is exempt and the form the report takes are held by the Ministry of Corporate Affairs at mca.gov.in. The assurance standard and the guidance note that govern how work of this kind is planned, performed and reported sit with the Institute of Chartered Accountants of India at icai.org. The obligations that bind a bank in addition, including its risk management arrangements and the standing of its internal audit function, sit with the Reserve Bank of India at rbi.org.in.

Section numbers, rule numbers, thresholds, applicability tests, exemptions, materiality levels, sampling minima and effective dates change. Name the duty, name the body, then read the current text at the source.

The five stages of a control in order, from the objective through to the testing that evidences it, are set out under the five stages of a control and are assumed here rather than restated; what this guide adds is the head to head, the two populations and the arithmetic of combining them. The step by step method for running either test, meaning how a walkthrough is performed, how a sample is drawn, what counts as evidence and what happens to an exception, is set out under the method for testing a control. The written finding and its five parts, the four point rating scale, issue remediation and ageing, the Indian internal financial controls assessment and the one material weakness in process PR3 each sit under their own subject. The self assessment as a process, exception management, segregation of duties and root cause analysis belong to the operational risk sequence. The audit of the financial statements themselves is covered elsewhere.

Sources

SourceDocumentSite
Ministry of Corporate AffairsThe Companies Act duty on internal financial controls: the text, who it applies to, who is exempt, and the form the report takesmca.gov.in
Institute of Chartered Accountants of IndiaThe assurance standard and the guidance note behind independent work on the design and the operating effectiveness of controlsicai.org
Reserve Bank of IndiaWhat binds a bank in India on internal control, risk management arrangements and the standing of the internal audit functionrbi.org.in

Vindhya Commercial Bank Limited is invented.
Educational material. Not advice on any investment, tax, budget or market position.

← PreviousNext →
Fin Maverick Micro CoursesExplore Micro Courses
Fin Maverick BootcampsExplore Bootcamps
Fin Maverick

Finance education that ends in a job, not a certificate that gathers dust. Built for young India.

LEARN
CalculatorsFrameworksComparisonsCareersShowdown
RESOURCES
All CoursesMicro CoursesBootcampsInternships
COMPANY
AboutJob openingPartnership
LEGAL
Privacy PolicyTerms & ConditionsContent LicenseReturn & Refund Policy
© 2026 FIN MAVERICK / BUILT FOR INDIA.DO FINANCE, DO NOT JUST READ ABOUT IT.