How many controls should one risk have, and is a one-to-one mapping ever correct?
A risk should almost always map to more than one control, because a single control is rarely able to prevent, detect and correct the same risk at once, and most risks materialise through more than one failure path. A one-to-one mapping is not impossible, but it is uncommon enough that it should be treated as a prompt to check the work rather than accepted at face value.
Published
Maximilian Bazzi, Founder and CEOWhy cardinality is a modelling question, not a counting exercise
A control library records which controls address which risks, and it is tempting to treat that as a straightforward one-to-many or many-to-many mapping exercise. The more useful question is not how many controls a risk has, but whether the controls mapped to it actually cover the ways the risk can materialise. A risk with three distinct failure paths and one mapped control is under-controlled regardless of what the control library's summary statistics say.
Why one-to-one mappings are usually a modelling failure
A single control is rarely able to prevent, detect and correct the same risk at once, because those are different functions operating at different points in time relative to the failure: before it happens, while it is happening, and after it has happened. A control library that shows a risk with exactly one mapped control has usually stopped mapping after the first control was found, not concluded, after genuine analysis, that one control is sufficient across all three functions. This matters because the gap is invisible in a simple coverage report: the risk shows as controlled, and the report does not distinguish a risk with one control from a risk with five.
What the mapping should actually reflect
A defensible mapping reflects the risk's actual failure paths. Preventive controls reduce the likelihood of the risk materialising. Detective controls identify that it has materialised, or is in the process of doing so, quickly enough to act. Corrective controls limit or reverse the harm once it has. A risk that can fail through more than one route, for example a third-party outage caused either by the supplier's own failure or by a communication breakdown in escalation, needs controls addressing each route, not one control positioned to catch only the more obvious of the two.
Where teams commonly run into difficulty
Two patterns repeat. The first is exactly the one-to-one case above, where mapping stops at the first plausible control. The second is the opposite failure: risks accumulate controls over time as different teams add their own without checking what already exists, producing a high control count that looks thorough but includes duplication and controls that no longer map to a real failure path. Neither a low count nor a high count is, on its own, evidence of a well-modelled risk. What matters is whether the mapped controls, taken together, cover the risk's actual failure paths without unnecessary duplication.
How Bazzi Consulting helps
We build the control library against the actual failure paths behind each risk, rather than against a template ratio of controls per risk, so coverage reports reflect genuine mitigation rather than mapping convenience. See risk and resilience advisory.