← ArticlesRisk Controls and Defence in DepthProject Delivery · RiskLesson 3/7← PrevNext →
GuidePublished 13 Aug 202611 min readBy Kevin Joginrisk controlsdefence in depthbarrierscontrol effectiveness

Project Delivery · Project Risk Management

Risk Controls and Defence in Depth

A control-design guide covering preventive, detective, corrective and directive controls, barrier independence and effectiveness evidence.

12 min read Handbook guide Reviewed 2026-08-13 De-identified examples

Executive summary

A control-design guide covering preventive, detective, corrective and directive controls, barrier independence and effectiveness evidence. The method is intended to improve decisions, not merely complete documentation. Apply it proportionately, preserve the evidence behind judgement and connect every action to an accountable owner.

Learning outcomes

  • Define the undesired event
  • Map existing controls
  • Classify control purpose
  • Test independence and effectiveness
  • Assign assurance and improvement actions
  1. Define the undesired event
  2. Map existing controls
  3. Classify control purpose
  4. Test independence and effectiveness
  5. Assign assurance and improvement actions

Why Addressing Risk Is Where Strategy Becomes Action

Identification tells you what you face. Assessment tells you which risks matter most. Appetite tells you how much exposure is tolerable. But none of these steps actually changes anything. Addressing risk is where the organisation takes action — where analytical insight is converted into tangible controls that constrain threats, exploit opportunities, and shape the uncertainty landscape in the organisation's favour.

The Orange Book frames this with precision: the purpose of addressing risk is to turn uncertainty to the organisation's benefit by constraining threats and taking advantage of opportunities. Every action taken to address a risk constitutes what the Orange Book calls "internal control" — a term that encompasses far more than the financial controls traditionally associated with that phrase.

For project managers delivering complex defence and heavy engineering programmes, risk response design is where technical expertise, commercial judgement, and management skill converge. Choosing the right response strategy — and implementing the right type of control — is the difference between a programme that navigates uncertainty successfully and one that is overwhelmed by it.

What the Orange Book Establishes: The Five Response Options

The 4Ts Plus Opportunity

The Orange Book presents five approaches to addressing risk. The first four — the "4Ts" — represent the primary response strategies. The fifth —Take the Opportunity — is an overlay that applies alongside any of the four primary strategies.

Response 1: TOLERATE

The exposure may be tolerable without further action. Even if not ideal, the ability to do anything about some risks may be limited, or the cost of action may be disproportionate to the potential benefit. Tolerating a risk is a deliberate decision, not a default — and it may be supplemented by contingency planning for handling impacts if the risk materialises. Defence engineering example: A naval shipbuilding programme identifies the risk that the Australian Dollar may fluctuate against the US Dollar during the import of specialist fire control electronics. The inherent currency exposure of ±3% falls within the programme's financial contingency budget. The programme tolerates the risk, accepting that currency movements may slightly increase or decrease costs within the contingency envelope, rather than purchasing forward contracts for every import transaction.

Response 2: TREAT

By far the greatest number of risks will be addressed through treatment. The organisation continues the activity giving rise to the risk but applies controls to constrain it to an acceptable level. Treatment is the workhorse response strategy, and the Orange Book further classifies treatments into four distinct control types (see below).

Defence engineering example: The risk of weld defects in pressure vessel fabrication is treated through a combination of welder qualification requirements (AS/NZS 1554.1), procedural controls (welding procedure specifications), and inspection regimes (radiographic testing of all critical joints, plus statistical sampling of non-critical joints).

Response 3: TRANSFER

Transfer shifts the risk to a third party better placed to manage it. This includes conventional insurance, contracting arrangements, and outsourcing. Transfer is particularly effective for financial risks and risks to assets. However, the Orange Book includes a critical warning:

Defence engineering example: A prime contractor transfers the risk of specialised composite armour manufacturing to a Tier-2 subcontractor with deep expertise in advanced material processing. The subcontractor accepts schedule and quality risk for composite panel delivery under a fixed-price, performance-specified subcontract. However, the prime contractor retains the reputational risk — if the armour fails in service, the customer and the public will hold the prime responsible, not the subcontractor.

Response 4: TERMINATE

Terminate means ceasing the activity that generates the risk. The Orange Book notes that this option is "severely limited in government" compared to the private sector, because many government activities exist precisely because the associated risks are too great for any other entity to bear.

In project management, termination is most relevant when the cost-benefit relationship of a project deteriorates to the point where continuation cannot be justified. This is the kill-the-project option — painful but sometimes essential.

Defence engineering example: A technology demonstrator programme for a novel directed-energy weapon encounters fundamental physics constraints that make the specified power output unachievable within the programme's budget envelope. The risk that the system will never meet specification is assessed as almost certain. The programme is terminated, and the technology insights are captured for potential future application when enabling technologies mature.

The Fifth Option: TAKE THE OPPORTUNITY

This option overlays all four primary strategies. The Orange Book identifies two aspects:

Aspect 1: Exploiting positive impact alongside threat mitigation. When mitigating a threat, are the relevant controls good enough to justify increasing the stakes to gain even greater advantages? If a major capital investment has excellent risk controls, the organisation might invest more to capture larger benefits. Aspect 2: Exploiting circumstances that offer positive opportunities. Even without generating threats, circumstances may present advantageous uncertainties. A drop in raw material prices frees up budget that can be redeployed to accelerate other programme elements. Defence engineering example: A shipbuilding programme's steel supplier offers an early delivery of hull plate at a 7% discount due to a temporary production gap in their schedule. This creates an opportunity — accepting early delivery reduces supply chain risk (positive) while saving cost (positive), but requires the programme to fund early material storage (cost) and manage potential storage degradation (risk). The programme takes the opportunity because the benefits outweigh the costs, and storage controls are adequate to manage the degradation risk.

The Four Types of Internal Control

When the "Treat" response is selected, the Orange Book further classifies controls into four types based on their purpose and timing:

Preventive Controls

Purpose: Limit the possibility of an undesirable outcome being realised. Timing: Before the risk event. Principle: The more important it is that an undesirable outcome should not arise, the more important it becomes to implement appropriate preventive controls.

Mechanism Defence Engineering Example
Separation of duty The engineer who designs the weld joint specification is not the same person who inspects the completed weld — preventing self-certification
Authorisation controls Only personnel with current explosive handling certification are permitted to work in the ordnance filling facility
Qualification requirements All NDT inspectors must hold current recognised Level II nondestructive-testing certification in the relevant test method before performing production inspections
Design reviews Independent design review panels assess structural calculations before manufacturing release, preventing design errors from reaching the shop floor

Corrective Controls

Purpose: Correct undesirable outcomes that have already been realised — providing recovery routes against loss or damage. Timing: After the risk event.

Mechanism Defence Engineering Example
Contract terms Contract includes liquidated damages clause allowing recovery of costs if subcontractor delivers components beyond the agreed tolerance window
Insurance Comprehensive property insurance covers the replacement cost of production facility equipment damaged by fire, flood, or severe weather
Contingency plans Business continuity plan enables production to transfer to an alternate facility within 72 hours if the primary site becomes unavailable
Warranty provisions Component supplier warranties allow free replacement of items that fail within the specified service life under normal operating conditions

Directive Controls

Purpose: Ensure that a particular outcome is achieved. Particularly important when an undesirable event must be avoided — typically associated with health and safety or security. Timing: Continuous — prescribing required behaviours.

Mechanism Defence Engineering Example
Mandatory PPE requirements All personnel in the blast chamber must wear hearing protection, safety glasses, and flame-retardant coveralls
Mandatory training All confined space entry requires completion of the AS 2865 training programme before unsupervised work is permitted
Safety interlocks CNC plasma cutting machine will not operate unless the extraction ventilation system is confirmed active
Security protocols Classified documents must be stored in approved security containers when not in active use; removal from the controlled area requires signed register entries

Detective Controls

Purpose: Identify occasions where undesirable outcomes have already been realised. By definition, these operate after the event and are only appropriate when it is possible to accept the loss or damage incurred. Timing: After the risk event, or during periodic review.

Mechanism Defence Engineering Example
Stock/asset checks Monthly tooling inventory reconciliation detects whether specialised fixtures have been removed without authorisation or damaged without reporting
Reconciliation Monthly comparison of material requisitions against production output detects unexplained material consumption variances (potential waste, theft, or measurement error)
Post-implementation reviews Lessons-learned review after completion of each hull module identifies systemic quality issues, schedule drivers, and process improvement opportunities for subsequent modules
Monitoring activities Continuous vibration monitoring on critical CNC spindle bearings detects degradation trends before catastrophic failure occurs

Proportionality: The Golden Rule of Control Design

The Orange Book establishes a principle that is often overlooked in risk-averse environments:

Every control has a cost — financial cost, operational friction, time delay, complexity. Over-controlling low-severity risks wastes resources and creates bureaucratic drag that impedes the organisation's ability to deliver. The Orange Book's guidance is clear: the purpose of control is to constrain risk, not to eliminate it.

For defence engineering, this is the constant tension between quality assurance rigour and production throughput. Inspecting every weld on a non-critical bracket to the same standard as a primary structural member is disproportionate control — it consumes NDT capacity that would be better deployed on higher-consequence joints.

The treatment plan structure from the course material reinforces this principle by requiring a cost/benefit assessment and resource requirement for each proposed treatment option. This forces the question: is the cost of this control justified by the reduction in risk it achieves?

Selecting the Right Response: A Decision Framework

When choosing between the 4Ts for a given risk, the decision should be guided by:

Decision Factor Favours Tolerate Favours Treat Favours Transfer Favours Terminate
Residual risk after control Already within appetite Can be brought within appetite Transferable to more capable party Cannot be controlled to acceptable level
Cost of control vs exposure Control cost exceeds exposure Control cost is proportionate Third party can control more efficiently Activity cost exceeds total benefit
Organisational capability No action feasible Organisation has relevant expertise Third party has superior expertise No capability exists
Strategic importance Low-priority activity Core activity, must continue Support activity, not core Activity no longer aligned with strategy

Common Pitfalls in Addressing Risk

Defaulting to "treat" for everything. Not every risk needs active treatment. Some should be tolerated (within appetite), transferred (to more capable parties), or terminated (when the activity no longer justifies the risk). Over-reliance on treatment leads to bloated control environments. Forgetting that transfer doesn't eliminate risk. Reputational risk, in particular, cannot be transferred. Contracting out service delivery transfers operational risk to the contractor, but the organisation retains the reputational consequences of contractor failure. Ignoring the opportunity dimension. The Orange Book explicitly requires that opportunity be considered alongside every risk response. Organisations that focus solely on threat mitigation miss positive uncertainties that could enhance programme outcomes. Disproportionate control. Applying heavy controls to low-impact risks creates operational friction and diverts resources from higher-priority risks. Control must be proportionate to the risk being managed. No contingency planning for tolerated risks. Tolerating a risk does not mean ignoring it. Toleration should be accompanied by contingency plans for managing the impact if the risk materialises — otherwise, toleration becomes complacency. Confusing detective and preventive controls. Detective controls identify problems after they occur; preventive controls stop them from occurring. An inspection regime that only finds defects after assembly is complete is detective, not preventive. If the goal is to prevent defects from entering the assembly, preventive controls (qualification, procedure, design review) must be in place earlier in the process.

Key Takeaways

Practitioner completion checks

Use these checks before closing the analysis or taking the decision forward. Scale the evidence to the consequence, uncertainty and reversibility of the decision.

Check 01Define the undesired event is defined, owned, evidenced and linked to the relevant project decision.
Check 02Map existing controls is defined, owned, evidenced and linked to the relevant project decision.
Check 03Classify control purpose is defined, owned, evidenced and linked to the relevant project decision.
Check 04Test independence and effectiveness is defined, owned, evidenced and linked to the relevant project decision.
Check 05Assign assurance and improvement actions is defined, owned, evidenced and linked to the relevant project decision.
How much detail is enough?

Use the least complex method that can support a defensible decision. Increase rigour when consequences are high, uncertainty is material, interfaces are complex, evidence is weak or the decision is difficult to reverse.

What should the decision record contain?

Record the objective, scope, inputs, assumptions, method, uncertainties, options, judgement, owner, approval, actions, residual exposure and the trigger or date for review.

When should the work be repeated?

Repeat it when a key assumption changes, new evidence appears, exposure crosses a threshold, a response fails, scope or interfaces change, or the next governance decision requires refreshed information.

Current authoritative reference points

Use the current published documents and the requirements adopted for the project's jurisdiction and contract. Links below support currency checking; they do not reproduce copyrighted standards.

Continue learning

Project Risk Treatment and Action PlansGuide · RiskNEXT LESSON →Risk Triggers, Contingencies and Early WarningGuide · RiskThreat and Opportunity Response StrategiesGuide · RiskRisk Monitoring, Reporting and ControlGuide · Risk