Preventive control and detective control
Category
A preventive control stops an unwanted transaction before it occurs. A detective control identifies one after it has occurred. Both are standard categories in internal control frameworks. The distinction matters more for agent transactions than for human ones, because settlement is fast and often irreversible.
How it works
Preventive controls sit in the transaction path and can refuse. Approval requirements, budget limits, and counterparty allowlists are preventive when enforced at the moment of the attempt. Detective controls run afterward: reconciliations, exception reports, variance analysis, audit sampling. Most financial controls in general use are detective, because they were designed around a human-paced transaction cycle in which after-the-fact review was fast enough.
Example
Northwind's $40 overage. A preventive control refuses the request and no money moves. A detective control produces a March exception report showing a $40 overage — accurate, useful, and forty days too late to prevent anything.
Common questions
Are detective controls insufficient for agent transactions?
Not insufficient — incomplete. Detection remains necessary, particularly where information arrives late. The problem is relying on detection alone when the transaction cannot be reversed and the counterparty may not persist.
Which controls should be preventive?
Generally, those where the loss is unrecoverable. A single large erroneous transfer between known institutions can often be recovered by cooperation. Many small transfers to counterparties that no longer exist cannot.