CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingMedium

A global manufacturing company is implementing a new enterprise resource planning (ERP) system. The project team has identified a high risk of data integrity issues due to potential errors during data migration from legacy systems. To address this, they plan to implement automated data validation scripts, conduct reconciliation checks after migration, and establish a clear data ownership matrix. Which type of control is primarily being designed and implemented for the reconciliation checks?

  1. ACompensating control
  2. BDetective control
  3. CCorrective control
  4. DPreventive control
Show answer & explanation

Correct answer: B. Detective control

Reconciliation checks are performed after data migration to identify if errors have occurred. This characteristic makes them detective controls, as they aim to discover issues that have already happened.

Why the other options are wrong

  • A. Compensating controls provide an alternative mechanism to achieve a control objective when a primary control is not feasible or effective, which is not the primary role of a reconciliation check here.
  • C. Corrective controls fix issues identified by detective controls, but the check itself is detective.
  • D. Preventive controls aim to stop an error from occurring in the first place (e.g., automated validation scripts).

Detective Controls

Controls designed to identify and alert about undesirable events that have already occurred.

  • Act after an event has taken place.
  • Aim to discover errors or irregularities.
  • Examples: audit trails, intrusion detection systems, reconciliation.

Memory trick: PDC: Prevent, Detect, Correct.

More Risk Response and Reporting questions