Field Notes
When alert thresholds hide overdue attestations
How quiet threshold choices in risk control monitoring applications can mask attestations that are already late.
During application audits of risk control monitoring applications, we often find alert rules that look strict until you ask what “due soon” means. A threshold set to fire only after thirty days past due will never interrupt a twenty-nine-day backlog. Operators then report green dashboards while attestations age just under the wire.
What to sample
Pull a period where business volume was normal, not a holiday lull. Compare the application’s “open past due” count with a manual age analysis of the same queue. If the manual age curve peaks just below the alert threshold, the rule is teaching the organisation how to stay invisible.
What to write in the finding
Name the threshold, the sample window, and how many items sat in the quiet band. Avoid blaming operators who learned to work inside the rule. The remediation is usually a threshold change plus a second-line review of items that previously hid in that band — not a training slide.
Related engagement
This pattern often surfaces in a Full Application Control Audit or a focused Monitoring Gap Assessment.