Introduction: The Shift from Risk to Action
Once an organization understands what it’s trying to achieve and what abuse-related uncertainties threaten those aims, the next step is to decide how it will manage those risks. This is the work of selecting and evaluating controls — a process that lies at the heart of the Jigsaw system.
Too often, organizations adopt controls because they’re mandated, borrowed from others, or inherited from the past. But in a system like Jigsaw, which uses Enterprise Risk Management (ERM) to reduce uncertainty around core objectives, controls must be chosen deliberately — with purpose, context, and function in mind.
This is critical because sexual abuse almost always occurs not in the absence of controls, but in the presence of ones that failed: sometimes because they were misunderstood, misapplied, or simply mismatched to the risk. That’s why in Jigsaw, control selection begins with risk clarity and ends with fit-for-purpose performance.
Why Controls Come After the Why
Though it may sound obvious that controls come after deciding what risks an organization needs to manage (its ‘why’), as noted above, that’s not how sexual abuse risk is typically managed today.
The Why stage of Jigsaw, however, clarifies:
- What matters most to your organization (your Swans)
- Where and how abuse-related risks could disrupt or undermine those aims (your SAM Risk Sets and existential SAM risks)
- What your operating model looks like (your people, places, practices, and culture)
Once the risks are visible, the next questions are:
- What types of controls do we need to manage these risks?
- Where in our system do those controls need to be applied?
- How can we ensure they actually work?
This isn’t about choosing from a generic list. It’s about designing a system of risk responses tailored to your specific context and mission.
What a Control Is
A control is any deliberate structure, behavior, decision, or system that reduces uncertainty around the achievement of a Swan or protection goal. In Jigsaw, controls are classified by function:
- Preventive: Reduce the likelihood of abuse occurring
- Detective: Alert you to something you need to know
- Responsive: Enable timely, safe, and effective intervention
- Adaptive: Support learning and improvement over time
Controls are the link between what you’re worried about and what you’re doing about it.
Matching Controls to Risk
Each risk identified in a SAM Risk Set and each existential SAM risk requires a response — usually multiple, layered controls. Some risks relate to people, others to behavior, visibility, or system function. Existential risks in particular demand cross-functional, deeply embedded responses linked to leadership and oversight.
| Type of Uncertainty | Control Focus |
| About people | Intake, training, onboarding, and culture-setting |
| About behavior | Reporting systems, peer checks, feedback routines |
| About time/place | Supervision, environment design, structured transitions |
| About detection | Monitoring, documentation, escalation protocols |
| About response | Team roles, audits, consultation, reviews |
| About learning | Feedback loops, system updating, review cycles |
Example:
If a risk is “mentoring sessions occur behind closed doors without visibility,” relevant controls might include supervision protocols, environment design, and scheduling structures — all designed to reduce behavioral and visibility uncertainty.
The Leadership Act of Choosing Controls
Choosing controls is not merely technical. It’s a leadership act. It signals ownership of the organization’s protection system and a commitment to match risks with solutions.
Too often, controls fail because they were:
- Generic or borrowed
- Misaligned with culture or capacity
- Understood by some but not all
- Never reviewed or adapted
Jigsaw ensures each control is selected, structured, and supported in ways that match the risk, the context, and the people involved.
From Choosing to Evaluating
Once controls are selected, the next question is: Are they fit for purpose?
That is — do they work? Not, will they work? Do they work?
Fit-for-purpose controls are those that:
- Address the specific risk or uncertainty they were chosen for
- Function in the real environment of the organization
- Are understood, trusted, and used by the people involved
- Are aligned with the mission and therefore sustainable over time
This is the core test of prevention: not whether a control exists, but whether it works as intended, under pressure, and over time.
The Three-Lens Model for Fit-for-Purpose
Jigsaw uses three lenses to assess control effectiveness. Together, they ensure each control aligns with risk, fits the organization, and functions for real people.
1. Strategic Fit (Your Why)
Does the control support the organization’s mission, reduce critical risks, and protect what matters most?
2. Operational Fit (Effectiveness)
Can the control be implemented effectively given the organization’s structure, capacity, and risk profile?
3. Experiential Fit (Human/System)
Is the control understood, trusted, consistently applied, and capable of evolving?
If any one of these fails, the control becomes fragile:
- Strategic misalignment ➝ neglect
- Operational failure ➝ breakdown
- Experiential failure ➝ inconsistency and mistrust
The Operational Criteria
These seven criteria evaluate whether a control works in practice — not just on paper:
- Operational Safety & Security: Does it reduce actual exposure to abuse?
- Behavioral Alignment: Does it support the behaviors the organization expects?
- Supervision & Oversight: Is it actively monitored?
- Information & Communication: Do people understand what, why, and how?
- Resources & Capacity: Is it doable with current people, time, and tools?
- Alignment with Objectives: Does it reinforce, not distract from, the mission?
- Cultural & Contextual Fit: Does it make sense for your setting and people?
The Universal Criteria
These seven criteria examine how controls are experienced and used by the people they touch:
- Clarity: Is the control easy to understand and remember?
- Ownership: Do people take responsibility for applying it?
- Confidence: Are they equipped and supported to use it?
- Fit: Is it doable and realistic in their role or setting?
- Alignment: Does it reinforce the organization’s culture and values?
- Consistency: Is it applied the same way across people and programs?
- Adaptiveness: Can it evolve as the organization learns?
A Practical Example: Choosing and Connecting a Control
Let’s look at how this works in practice.
Scenario:
A team identifies a risk in their SAM Risk Set:
“During youth mentoring sessions, staff and volunteers are sometimes left alone with young people in closed rooms without visibility or active supervision.”
Step 1: Ask the Right Questions
• What kind of risk is this?
→ Risk of inappropriate one-to-one time without oversight.
• What type of uncertainty does it reflect?
→ Uncertainty about behavior, visibility, and response capacity.
• What kind of control might reduce that uncertainty?
→ Supervision protocols, behavior expectations, and environment design.
• What kind of support does this control require?
→ Staff buy-in, physical layout changes, scheduling clarity.
• Who needs to be involved in choosing/designing it?
→ Program managers, frontline staff, facilities team.
Step 2: Choose the Control Type
The team identifies two relevant control types:
- Behavior requirement — supervision to ensure visibility and accountability
- Space Design — to reduce the opportunity for isolation
Step 3: Define the Control Goal
- Goal: Ensure that all one-to-one mentoring sessions take place in visible and structured spaces.
- Success: No sessions occur in isolated, closed-door rooms. Staff and youth both report clarity and comfort.
- Failure: Private meetings continue to occur in unmonitored spaces, often without anyone noticing until after the fact.
Step 4: Assign Ownership and Review Frequency
- Responsible Person: Program Coordinator
- Review: Monthly walkthrough + quarterly check-in on supervision plans
Step 5: Connect to the System
- The control is recorded under “Behavior requirement” in the system
- Supporting policies are updated to include space and scheduling standards
- The control is evaluated using the three-lens fit-for-purpose criteria:
| Fit-for-Purpose Lens | Evaluation Questions |
| Strategic Fit | Does this supervision protocol help us protect the Swans (e.g., safe mentoring relationships)? |
| Operational Fit | Is the protocol realistic to implement in our physical spaces with available staff? |
| Experiential Fit | Do staff understand the expectations, trust the system, and apply it consistently? |
This creates a full arc — from risk identification to system response, and from control design to performance evaluation. It ensures the control doesn’t just exist but works, strengthens over time, and protects what matters most.
How the Criteria Work Together
The three sets of criteria — strategic, operational, and experiential — work as a unified framework:
- Strategic Fit: Does it matter?
- Operational Fit: Does it work?
- Experiential Fit: Does it last?
Used together, they help teams:
- Design better controls
- Evaluate existing ones
- Strengthen weak ones
- Retire broken ones
- Communicate performance to stakeholders
A System That Strengthens Over Time
This approach turns control selection and evaluation into a dynamic loop:
- Identify the objectives and risks that matter most
- Select layered controls that target those risks
- Use the three-lens criteria to evaluate their effectiveness
- Adapt controls over time as the system learns
This is what it means to manage sexual abuse risk using ERM: not adopting what’s mandated, borrowed from others, inherited from the past, or reacting to incidents, but reducing uncertainty in pursuit of what matters most.
In Jigsaw, this isn’t optional — it’s essential. Because an effective protection system isn’t a static toolkit. It’s a living system, built to evolve as the organization grows, learns, and faces new challenges.
And that’s how you know, and can prove it’s working.
