Retiring controls that no longer earn their place: checks, sign-offs and rules that outlive their reasons

Controls are easy to add after an incident and almost never removed, so they pile up unpriced. How to trace each to its reason, test whether it still earns its place and retire it safely.

Every check, sign-off, inspection and rule in a business was added for a reason. A machine tipped over, so a second signature was added to the pre-hire inspection. A customer failed to pay, so every new account now needs a credit check. An injury occurred on a client’s site, so operators must show proof of competency before release. Each addition was sensible on the day. Each is cheap to add and, in practice, permanent.

Ten years later, the business runs a process assembled from decisions made by people who have mostly left, for reasons that may no longer apply. The equipment has changed, the customers have changed, a finance partner now carries the credit risk, and the process still includes every step. Nobody removed anything, not out of caution but because there was never a way to. No form, no authority, no meeting whose purpose was to ask whether a control should go.

This article explains why controls accumulate, why reviews tend to find only that more are needed, and how a small business can run a simple annual review that retires controls that no longer earn their place while keeping those that do. It is general information. Some controls are required by law, by licence conditions, by insurers or by contracts; check those obligations before removing anything, and ask your adviser or insurer where you are unsure.

Why controls pile up

Risks have a lifecycle: they are identified, assessed, treated, monitored and eventually closed. Controls usually do not. A typical risk list records the risk, its rating and “what is in place”. It rarely records who owns each control, when it was introduced, why, what it costs, or when it should be reviewed. Without those, there is nothing to prompt a question about whether a control is still needed.

Three things keep the pile growing:

  • Controls are bought once and paid for continuously. The cost is real but scattered: minutes added to every job, a second person’s time, delays waiting for approval, slower answers to customers. It rarely appears anywhere as a single figure.
  • Reviews only look one way. A typical review asks whether controls are adequate and implemented. It has no category for “surplus”. A reviewer who recommends keeping a redundant control is never visibly wrong; one who recommends removing it may be blamed for the next incident. So reviews, accurately and repeatedly, find that more control is needed.
  • Closing a risk does not close its control. When a risk is resolved, often because the control worked, the control stays. It looks indispensable exactly when it should be re-examined.

The pricing your risk controls article covers putting a cost on controls when they are introduced. This article is about what happens afterwards.

Keeping a control is not automatically the safe choice

It feels conservative to keep a control “just in case”. But every control has side effects: cost, complexity, delay, workarounds, skills that fade because a step is automated, and the false comfort that stops people looking. A control kept after its purpose has gone carries all of those side effects and none of the benefit.

Layered defences are valuable when each layer protects against a live threat. Layers that stand over a threat that has changed shape, or been removed, are sediment, not depth. The changing the odds or changing who pays article covers why controls built into design tend to outlast those that rely on people remembering. And a control designed for one situation can create conditions for a different problem: staff who are used to a second person checking their work may stop checking it themselves.

The four missing facts

Start by adding four facts to each control on your list:

  1. When it was introduced.
  2. Which risk or incident caused it.
  3. Who owns it now.
  4. What it costs each year, measured in whatever resource binds your business: hours, days of turnaround, signatures, or money.

The second fact is the most revealing. In many businesses, a large share of checks and sign-offs cannot be traced to any specific reason. Those are the first candidates for review.

Five tests for each control

TestQuestionDefault if the answer is weak
OriginWhich risk caused this control, and is that risk still live?Risk closed or untraceable: put the control on the retirement list
SubstitutionHas anything introduced since addressed the same cause?Two controls for one cause: keep the stronger unless someone argues for both in writing
EnvironmentIs the threat still shaped as it was?Changed: redesign or withdraw, do not simply carry forward
Side effectsWhat problems does the control itself create, and does it still come out ahead?Not clearly positive: retire
CostWhat does it consume each year of our scarcest resource?Among the most expensive: owner must re-justify it every year

Three rules that make retirement possible

Put the burden of proof on keeping, not removing. A control whose original risk is closed or untraceable is retired unless someone puts their name to keeping it, with a reason. Controls pile up for one reason: removing them has always needed an argument, while keeping them never has. Reversing that does most of the work.

Give every retirement a reinstatement trigger. Record what would have to happen for the control to come back, such as a particular incident, a change in customers or a rise in a measured indicator. That turns retirement from an irreversible bet into a monitored decision, and removes much of the personal risk that stops capable people recommending it.

One in, one out. When a new control is proposed, require it to name the control it replaces, or to state explicitly that it replaces none. That makes accumulation visible as it happens rather than a decade later.

The review produces three lists: retained, retired and referred for more information. The owner signs the retirement list.

Evidence that a control has stopped earning its place

Some signs can be measured rather than argued about:

  • Approvals that are always granted. If a sign-off step has approved every request for two years, it may be adding delay without adding judgement. Either the threshold is wrong or the step is no longer needed.
  • Checks that never find anything. An inspection that has not found a problem in hundreds of cycles may be checking for something that no longer happens, or may be checking the wrong thing.
  • Workarounds. When staff routinely find ways around a step, it usually means the step no longer fits the work. Find out why before deciding whether to enforce or remove it.
  • Duplicate records. The same information entered in two systems, or signed for twice, often marks a control added on top of an older one.

None of these proves a control is unnecessary. Each is a reason to ask the five questions.

Ask reviews to report surplus as well as gaps

Whoever reviews your controls, whether an external adviser, an auditor, an insurer’s surveyor or a manager doing an internal check, will usually be asked whether controls are adequate. That framing can only find gaps. Ask instead for a net view: where control is missing, and where it is more than the risk warrants. A review that is allowed to recommend withdrawal, without its author carrying all the blame if something later goes wrong, is the only kind that can ever shrink the pile.

Check obligations before removing anything

Some controls are not optional:

  • Legal requirements, such as work health and safety duties, food safety rules, licence conditions or record-keeping obligations.
  • Insurance conditions, such as alarm monitoring, security measures or inspection regimes that a policy requires.
  • Contract terms with customers, lenders or landlords.
  • Industry or certification standards you have committed to.

Note the source of each obligation against the control. Where a control exists because of an obligation, the question is not whether to remove it but whether it is still the best way to meet that obligation.

A worked example

This is an illustration. An equipment hire business rents excavators, telehandlers, generators and lighting towers to builders and civil contractors. Its business depends on turnaround: a machine that is back from hire but not yet released again earns nothing.

Over ten years, the hire-out process has grown to fourteen steps. The owner lists each step and asks what put it there:

  • A second signature on the pre-hire inspection followed a tip-over eight years ago. Since then, every machine has factory telematics that log faults and tilt alarms, and a single trained inspector uses a digital checklist with photos. The second signature adds about 15 minutes per hire. Retired, with a reinstatement trigger: any inspection-related incident.
  • A full credit check on every new account followed a bad debt. Credit risk on large accounts now sits with a finance partner, and small accounts pay by card at booking. Retired for card-paying accounts; retained for accounts on credit terms.
  • Branch staff watching geofence alerts followed a theft. The telematics provider now monitors alerts and calls the branch. Retired, after checking with the insurer that the policy conditions are still met by the provider’s monitoring.
  • Operator competency verification followed an injury on a client’s site. The owner confirms with an adviser that it supports the business’s safety duties. Retained, and simplified to a check of a recorded licence or ticket.
  • Three other steps cannot be traced to any reason at all. Two are retired; one is referred to the branch manager to find out why it exists.

Before the review, a hire-out took about 95 minutes of staff time. Afterwards it takes about 60. Across roughly 1,800 hires a year, that saves about 35 minutes each, or around 1,050 hours a year, worth about $57,750 at $55 an hour, and machines go back out on hire sooner. The business also adopts the one-in, one-out rule, so the next incident prompts a decision rather than an automatic extra step.

How this applies to a small Australian business

  • List every check, sign-off and rule in one important process.
  • Record when and why each was introduced, who owns it and what it costs.
  • Apply the five tests.
  • Put the burden of proof on keeping controls whose reasons have gone.
  • Give every retirement a reinstatement trigger.
  • Adopt one in, one out for new controls.
  • Check legal, insurance and contract obligations before removing anything.
  • Review one process a year rather than everything at once.

Signals worth watching

  • Steps in a process nobody can explain.
  • Two or more checks aimed at the same problem.
  • Controls added after incidents and never reviewed.
  • Staff working around a control because it no longer makes sense.
  • Approvals that are always granted.
  • Reviews that only ever recommend more control.

Common mistakes

  • Assuming that keeping a control is always the safe choice.
  • Never recording why a control was introduced.
  • Closing a risk but leaving its control in place forever.
  • Removing controls that meet a legal, insurance or contract obligation.
  • Retiring controls without a reinstatement trigger.
  • Adding controls after every incident without asking what they replace.

Frequently asked questions

Isn’t removing controls risky? It can be, which is why each retirement needs a reason, an owner’s signature and a trigger for bringing it back. Keeping unnecessary controls is also risky: they cost time, create workarounds and give false comfort.

Where should we start? With one process that matters for speed or customer experience, such as quoting, ordering, dispatch or onboarding a customer.

What if nobody knows why a control exists? That is useful information. Ask around for a short period; if nobody can explain it, retire it with a reinstatement trigger.

Should staff be involved? Yes. The people who perform a control usually know which steps add value and which are habit.

How often should we review? One process a year is a sensible pace for most small businesses, plus a quick check whenever a new control is proposed.

Does this apply to software and IT controls? Yes. Passwords that must change monthly, approval workflows in accounting software, duplicate backups and access restrictions all accumulate in the same way. Some, such as multi-factor authentication and tested backups, are basic protections worth keeping; others may have been overtaken by better tools. Check current guidance from the Australian Signals Directorate before removing security controls.

What about controls customers can see? Treat them with extra care. A customer may rely on a check you perform, such as a delivery sign-off or a test certificate, even if it no longer matters to you. Ask before removing it.

Questions to ask

  • Why does each step in this process exist?
  • Which controls address risks that have changed or disappeared?
  • Which controls duplicate each other?
  • What does each control cost us in our scarcest resource?
  • Which controls are required by law, insurers or contracts?
  • What would make us bring a retired control back?

Bringing it together

Controls are easy to add and almost never removed, so they accumulate, unowned and unpriced, long after their reasons have gone. Record when and why each was introduced, who owns it and what it costs. Test each against its origin, overlaps, changes in the environment, side effects and cost. Put the burden of proof on keeping rather than removing, give every retirement a reinstatement trigger, and require new controls to name what they replace. Check legal, insurance and contract obligations first. Done carefully, retiring controls makes a business faster without making it less safe.


Source: KEVOS notes, drawing on teaching material on risk treatment, control registers and the secondary risks created by risk responses. Examples and figures in this article are illustrations. This article is general information, not legal, safety or insurance advice.

Need practical engineering, manufacturing or process support? KEVOS can help move the work forward.