Recovery Control Surface

The Recovery Control Surface defines how a workflow detects, reverses, repairs, escalates, compensates, or safely exits after error or harm. Recovery is separate from prevention because strong controls can still fail.

What question does it answer?

Once error or harm occurred, what recovery path existed?

What does recovery failure look like?

Failures include missing rollback, inability to identify affected users, no correction or notification mechanism, absent escalation, unrecoverable backups, no recurrence test, or taking a system offline without repairing the consequence already created.

External sanctions, litigation, or public pressure may force correction, but externally imposed repair is not evidence that the original workflow had an operational recovery surface.

What evidence should an audit inspect?

What is the decision consequence of a gap?

A workflow may be stopped yet remain unrecovered. If affected scope and correction paths are unknown, the organization cannot establish that the incident’s downstream consequence has been contained or repaired.