The people responsible for controls are evaluated on whether those controls actually operate. Annual performance reviews reference security responsibilities. When a control fails or evidence is missing, the owner is held accountable through a documented process. This is the criterion that connects your RACI matrix to actual accountability, assigning ownership is not enough if there are never consequences for non-performance.
These are typical controls and implementation steps. Your systems and environment may differ.
Typical Control Performance reviews referencing security responsibilities
Implementation Steps
Include security responsibilities in job descriptions for roles with control ownership, auditors will ask to see that responsibilities are formally documented
Annual performance reviews must reference whether security responsibilities were fulfilled; this does not require a separate security review, just that it is included in the standard review process
Document the review process in a Performance Review Policy; confirm it applies to all staff, not just technical roles
For GRC tool continuous monitoring deficiencies (controls marked failing), ensure there is a documented remediation owner and timeline, the GRC alert alone is not accountability
Confirm annual reviews are conducted and documented for all staff; retain the review summary (not detailed scores) as evidence
For staff owning security controls (e.g., the person responsible for patch management), their review should reference whether the control was maintained
When a control has failed during the period, document the gap, the owner, and the corrective action, this demonstrates accountability rather than just acknowledging the failure
Tools / systems
HR review process (any HRIS)
Performance Review Policy document
Jira (corrective action records)
GRC platform (e.g., Vanta, Drata, your GRC platform, Scrut)
Evidence artifacts
Performance Review Policy with effective date
Evidence that reviews were conducted (completion log or HR confirmation); auditors do not need to see review content
Corrective action records for any control failures during the period, with named owner