Detectability
Detectability refers to how likely it is that a problem, such as a failure or fault, will be caught before it causes harm or affects a system or process. A higher detectability means an issue is more likely to be identified in time; lower detectability means it may go unnoticed until damage occurs. In a governance, risk, and compliance context, detectability is often considered when evaluating how well controls or monitoring activities can surface an issue before it produces an impact.
In risk and reliability analysis, detectability is commonly defined as the probability or ability to detect a failure mode before it propagates to affect the system or process. It is frequently treated as one of the dimensions of failure mode assessment, alongside the likelihood of occurrence and the severity of consequence, and lower detectability typically corresponds to greater risk exposure because an undetected condition cannot be treated in time. The term originates in engineering and signal-detection disciplines, where detectability is characterized in relation to the probability of detection and, in some formulations, the probability of false alarm; in systems and discrete-event contexts it may instead denote the ability to estimate a system's current and future states from available observations. Precise operationalization (for example, the scoring scales used in failure mode analyses or the statistical thresholds used in detection theory) varies by methodology and application domain and should be verified against the specific framework in use.
Why it matters
Detectability is central to understanding whether an organization's controls and monitoring activities can surface a problem in time to act on it. Two risks with the same likelihood of occurrence and the same potential severity can carry very different levels of exposure depending on how readily each can be detected: a failure mode that is difficult to detect may go unnoticed until it has already produced an impact, whereas a highly detectable condition offers an opportunity for timely treatment. For this reason, detectability is frequently treated as a distinct dimension of failure mode assessment, sitting alongside the likelihood of occurrence and the severity of consequence.
In a governance, risk, and compliance setting, detectability helps distinguish the design of a control from its ability to actually catch an issue. A control may exist on paper, but if the monitoring around it cannot reliably identify a fault before it propagates, residual exposure remains higher than it appears. Lower detectability typically corresponds to greater risk exposure, because an undetected condition cannot be addressed before it causes harm. Conversely, investment in detection capability can reduce exposure even where the underlying likelihood of a failure cannot easily be changed.
Because the concept originates in engineering, reliability, and signal-detection disciplines, its precise meaning and measurement depend heavily on the methodology in use. In failure mode analyses it is often scored on defined scales, while in detection theory it is characterized statistically in relation to the probability of detection and, in some formulations, the probability of false alarm. Practitioners applying detectability to GRC problems should confirm how the term is operationalized within their chosen framework rather than assuming a single universal definition.
Who it's relevant to
Inside Detectability
Common questions
Answers to the questions practitioners most commonly ask about Detectability.

