Compensating control
A measure that holds the line on a risk while a gap remains open (for example, human review of a model's outputs until a stale evaluation is re-run). A sound compensating control names three things: the exact boundary of the risk it covers, the trigger that forces human escalation, and who signs off and how often. Named in a flag so that a disclosed gap comes with an interim safeguard rather than an open exposure.
Defined in 2 GAGE programs, which carry 4 distinct definitions of it. The wording above is taught in AI Governance: Applied Mastery.
How each discipline defines it
The same term does different work depending on who is using it. These are the definitions as each program teaches them, unedited.
A measure that holds the line on a risk while a gap remains open (for example, human review of a model's outputs until a stale evaluation is re-run). A sound compensating control names three things: the exact boundary of the risk it covers, the trigger that forces human escalation, and who signs off and how often. Named in a flag so that a disclosed gap comes with an interim safeguard rather than an open exposure.
A structural or runtime control built at a boundary you do control specifically to offset residual risk from a safeguard you cannot verify or modify directly, such as a vendor agent's undisclosed internal safeguards (Section 3M). A compensating control does not require trusting the unverifiable part; it bounds the consequence if that part fails.
A mitigation applied at one component (for example, narrower tool permissions) to reduce the risk created by an unresolved gap at another component (for example, a protocol with no provenance check). Reduces exposure without claiming to fix the root cause.
A control an organization operates on its own side of a boundary with a third-party agent or system, added specifically to close a gap the third party's own controls do not cover, used when a vendor cannot or will not meet a required control depth directly.
Where it is taught
The exact lessons this term appears in. The first 7 topics of every program are free with a free account.
- The Parts That Make an Agent Act · The Agent, Deconstructed, Agentic AI Governance: Applied Mastery
- The Control Typology · Technical Controls and Threat Modeling, Agentic AI Governance: Applied Mastery
- Multi-Agent Controls · Multi-Agent Governance, Agentic AI Governance: Applied Mastery
- Assembling the dossier: every artifact, every decision, one evidence file · The Capstone: The Board Audit and Viva, AI Governance: Applied Mastery
Terms it appears with
Not an alphabetical neighbourhood: these are the terms taught in the same lessons, ranked by how often they appear together.