← Kelroy James
Same Control, Two Vocabularies
Translation aidDefence logistics → GRCPublic frameworks only

Same control, two vocabularies

Nine things military logisticians do every week, described in the language a civilian assurance function would use for them. The environment changes. The control logic does not.

Just over half of UK veterans say they have at some point taken a job below the level of their last military role, and one of the two most cited reasons is that the employer did not recognise their transferable skills. I do not think that is mainly an employer problem. It is a translation problem, and it runs in both directions: the individual cannot name what they did, and the recruiter has no way to price it.

This table is my attempt at one direction of that translation. The left column is what the work is called on a unit. The middle is what the control is actually doing. The right is what the same activity is called in an assurance, audit or risk function, with the published frameworks where it lives.

It is deliberately generic. Nothing here describes any particular organisation's procedures, and everything on the right can be checked against a public standard. If you have done the thing on the left, you have operated the control on the right. The vocabulary is the only thing you are missing.

The mapping

Nine controls
What it is called on a unit What the control is doing What an assurance function calls it
On a unit

Logistics inspection

A scheduled, tiered inspection against a published standard, conducted by a body outside the unit being inspected.

The control

Independent testing of whether declared compliance matches observed practice, producing evidence a higher authority relies on, with findings tracked to closure.

In assurance

Second and third line assurance

Internal audit and independent control testing, with a defined finding lifecycle.

IIA Three LinesISO 19011
On a unit

Stores accounting and stocktaking

Maintaining the account, counting physical holdings on a cycle, and investigating why the count and the record disagree.

The control

Periodic verification that the recorded asset state matches the physical one, with variances investigated rather than adjusted away.

In assurance

Asset accountability and reconciliation

Inventory integrity, existence testing, variance investigation and inventory of assets.

ISO/IEC 27001 A.5.9COSO control activities
On a unit

Supersession and handover

Formal transfer of an account between two named individuals, with a certificate signed by both and retained.

The control

Accountability passes explicitly rather than by assumption, and at least two people are on record for the state of the account at the point of transfer.

In assurance

Custody transfer and segregation of duties

Documented handover of control ownership; dual authorisation at the point of change.

ISO/IEC 27001 A.5.3COSO
On a unit

Dangerous goods and transport safety

Classifying, documenting and moving regulated cargo under statutory requirements, with named competent persons.

The control

Legal obligations attach to the movement itself, and the evidence of compliance is created by the people doing the moving.

In assurance

Statutory compliance and chain of custody

Regulated goods handling, competent person regimes and traceable custody records.

CDG / ADRISO 9001 clause 8
On a unit

Supervising contractors

Overseeing external parties working on your equipment or in your space, to your standard, on your timeline.

The control

Risk that sits outside the organisation is managed through what the contract requires and what the supervision actually verifies.

In assurance

Third-party risk and contract governance

Supplier relationship security, performance monitoring and right-to-audit provisions.

ISO/IEC 27001 A.5.19–A.5.22NCSC supply chain
On a unit

Technical publication and data control

Ensuring the version of the document in use is the current one, and that controlled information reaches only those entitled to it.

The control

Configuration and classification are the same discipline applied to information: the right version, to the right people, with a record of who holds it.

In assurance

Information classification and access control

Classification schemes, document control, need-to-know access, and export control where technical data is involved.

ISO/IEC 27001 A.5.12ECJU code of practice
On a unit

Write-off and exception authority

Losses and discrepancies above a threshold cannot be cleared locally, and must be authorised at a defined level.

The control

Materiality decides who is allowed to make the decision, and the escalation itself creates the audit trail.

In assurance

Delegated authority and exception reporting

Authority matrices, materiality thresholds and escalation routes for exceptions.

COSOScheme of delegation
On a unit

Remedial action tracking

Findings from an inspection are assigned an owner and a date, and are followed up until they are closed.

The control

A finding that is recorded but never closed is not a control. Closure has to be evidenced by someone other than the person who caused it.

In assurance

Corrective action and finding closure

Root cause analysis, corrective and preventive action, and management review of open findings.

ISO 19011ISO 9001 clause 10
On a unit

Sustaining output under disruption

Keeping a platform supported when the supply chain, the schedule or the manning does not do what the plan assumed.

The control

Continuity is tested by the disruption, not by the plan. What matters is what degraded gracefully and what stopped.

In assurance

Operational resilience and continuity

Business continuity management, impact tolerance and single-point-of-failure analysis.

ISO 22301Operational resilience

What this table is not

It is a translation aid for people describing their own experience. It is not a compliance mapping, and no organisation should treat a row here as evidence that a requirement has been met. The frameworks named are pointers to where the equivalent control is written down, not claims of conformity.

It also runs one way. Knowing that a handover certificate is a custody transfer control does not mean a logistician can walk into an internal audit function, any more than an auditor could run a stores account. What it means is that the underlying reasoning transfers, and that the training gap is usually narrower than either side assumes.

And a caution I would apply to my own argument: naming a control is not evidence that it worked. A record is not the reality it describes. The value of this table is in helping someone ask better questions about their own experience, not in letting them assert more.

How to use it

Recognition before retraining
FIRST

Record what you did

Scope, scale, complexity, decision-making authority and consequence of failure. Not the job title, and not the course you attended. What you were accountable for, and what happened if it went wrong.

THEN

Find the reference point

Map that against a published standard, control model or competency framework. The right column is a starting set. The point is to find the language your target sector already uses, not to adopt mine.

ONLY THEN

Choose the training

Identify the gaps that are genuinely gaps, as opposed to gaps in vocabulary, and close those. A qualification should open a door. It should not shrink the room behind it.