Recovery Control Surface
The Recovery Control Surface defines how a workflow detects, reverses, repairs, escalates, compensates, or safely exits after error or harm. Recovery is separate from prevention because strong controls can still fail.
What question does it answer?
Once error or harm occurred, what recovery path existed?
What does recovery failure look like?
Failures include missing rollback, inability to identify affected users, no correction or notification mechanism, absent escalation, unrecoverable backups, no recurrence test, or taking a system offline without repairing the consequence already created.
External sanctions, litigation, or public pressure may force correction, but externally imposed repair is not evidence that the original workflow had an operational recovery surface.
What evidence should an audit inspect?
- containment and rollback procedures;
- affected-user, record, or system identification;
- correction, notification, and compensation paths;
- incident escalation and ownership;
- recovery action logs;
- recurrence tests and control updates; and
- proof that restored state is usable and complete.
What is the decision consequence of a gap?
A workflow may be stopped yet remain unrecovered. If affected scope and correction paths are unknown, the organization cannot establish that the incident’s downstream consequence has been contained or repaired.
Related Terms