TPRM glossary

Compensating control, when the required control will not fit

A compensating control is an alternative safeguard put in place when the control a standard or contract requires cannot be implemented. It must address the same risk to a comparable standard, be documented with the reason the original was infeasible, and be approved and reviewed rather than assumed to hold indefinitely. Also called Alternative control, Mitigating control.

Compensating controls in third-party risk

Most compensating controls a risk team meets arrive inside a vendor's answer to a security questionnaire: the vendor cannot do the thing the control asks for, and offers something else instead. Small vendors cannot always segregate duties across a four-person engineering team. A legacy system may not support multi-factor authentication.

The answer is not automatically a failure, and treating it as one trains vendors to write "yes" where the honest answer is "no, but". What makes a compensating control acceptable is that it addresses the same risk, not that it exists. Compensating for absent MFA with quarterly password rotation does not, because the risk is credential replay and rotation barely touches it. Compensating with hardware-key access from managed devices on a restricted network does.

How to assess a compensating control

Four questions, and the fourth is the one that gets skipped. What risk did the original control address? Does the alternative address that same risk, to a comparable standard? Who approved the exception, and against what risk appetite? And when does it expire?

An exception without an expiry date is a permanent change to your control baseline, agreed by someone who thought they were agreeing to a temporary one. Record them in the risk register with an owner and a review date, and re-test at renewal — the constraint that justified the exception is often gone, and nobody has revisited it because nothing forced them to.

Common questions

Is a compensating control the same as an exception?
Related but not identical. An exception is the decision to accept that a required control is not in place. A compensating control is what you put there instead. An exception with no compensating control is straightforward risk acceptance; a compensating control without a recorded exception is an undocumented change to your control baseline.
Do compensating controls satisfy auditors?
They can, where the framework allows them and the reasoning is documented. PCI DSS sets this out most explicitly, requiring a written worksheet showing the constraint, the alternative and how it meets the intent of the original requirement. ISO 27001 and SOC 2 assess the control objective rather than a prescribed control, so a well-evidenced alternative is judged on whether the objective is met.
How long should a compensating control last?
Until the constraint that made the original control infeasible is gone. In practice, set a review date no further out than the next assessment cycle and treat the exception as expiring on that date rather than continuing by default. Exceptions that renew silently are how a temporary workaround becomes the architecture.

Definitions are the easy part. Evidence is not.

See what your vendors actually expose — scored, monitored and evidenced in one place.