Green Lights With No Bulb Behind Them

Kamarin Lee · August 26, 2026 · Updated September 14, 2026

A control that has never failed is not protection. It is a green light with no bulb behind it, and you cannot tell the two apart by looking.

Private capital often relies on records produced by different parties for different purposes. A track record may arrive as a spreadsheet. The terms that govern it may live in a PDF. Interviews and reference calls add evidence of their own. Audited statements, administrators, questionnaires, and references are all useful. None of those labels, by itself, tells an investor exactly what work was performed.

Each control can answer a narrower question than the person reading it believes. That is the complication, and it does not require anyone to behave badly.

So the question worth asking about any control is not whether it passed. It is whether it has ever been seen to fail.

Four controls, and what each one actually answers

The audit addresses the financial statements. It does not turn an estimate into a market price. Fair value is an accounting estimate that can carry substantial measurement uncertainty. Auditing standards require work on the methods, data, and significant assumptions behind that estimate. They also permit an auditor to develop an independent expectation. That is more than a check for policy consistency. It still does not guarantee that an illiquid position will trade at the reported amount.12

An administrator's independence does not define the scope of its valuation work. An administrator may calculate a net asset value, carry out an agreed valuation procedure, or perform a broader service. The SEC's Form ADV guidance distinguishes the party that performs a valuation procedure from the adviser that considers itself ultimately responsible. The useful questions are which procedure was performed, which inputs were tested, and who owned the final judgment.3

The questionnaire organizes claims. It does not verify each answer. The Institutional Limited Partners Association describes its due diligence questionnaire as a way to standardize inquiry and guide further engagement. Its own disclaimer says the document is not a substitute for an LP's determination of what information it needs. A completed questionnaire is useful evidence of what was represented. Corroboration is a separate step.4

A reference list has a sampling rule, whether or not the reader can see it. A few names selected for a call are not the same evidence as a defined population. ILPA asks for a broad cross-section of general references and, in specified categories, a list covering the full stated population. The reader should record who selected the names, the denominator, and what could not be reached.4

The gap between a control's stated scope and the conclusion a reader draws is where false assurance begins.

Why this is structural, not carelessness

A control can inherit the blind spot of whoever wrote it. That is why adding more controls does not automatically close the gap.

Controls are usually designed against known objectives and known risks. That is sensible, but it creates a boundary. NIST distinguishes examining a control, interviewing the people around it, and testing it under specified conditions. The GAO framework likewise separates design, implementation, operation, and monitoring. A document that shows a control exists is therefore not the same as evidence that the control produced its intended result.56

So controls accumulate. The file thickens and the green boxes multiply. Unless the assessment method and observed result improve with the count, the added volume can create confidence without adding equivalent evidence.

This is not primarily an incentive problem. No one has to game the measure. A control can fail because its test never reaches the property named in its label.

A harder test

A review is not the same as a test. NIST defines testing as exercising an assessment object under specified conditions and comparing actual behavior with expected behavior. For a control that is supposed to reject a bad input, a deliberately broken case is direct evidence. If the control accepts it, the test has found a mismatch between the control's name and its behavior.5

The test record should name the invalid input, expected rejection, observed response, and time. Repeatable evidence matters more than the label attached to the control.

What to count instead

The number of controls is the wrong target. Verification is not free. Every added control creates review, maintenance, and interpretation work. A file with two hundred checks is not necessarily twice as safe as one with a hundred. Count alone says nothing about whether the controls cover the material risks or work as intended.

Three properties are worth more than the count.

Controls that have been observed to fail. Not could fail. Have failed, on a real case, with the failure and its date written down where the next reader will find it.

Disagreement surfaced rather than averaged. When two sources give different answers about the same fact, that disagreement is the most valuable signal in the file, and the strongest instinct is to reconcile it quietly before anyone notices.

Absences that are counted. A control that skips something must state the skipped population and its count. Otherwise, the record cannot distinguish an excluded category from an unexamined one.

The uncomfortable part

Rigor can hide failure when readers treat the size of the file as the result. Documentation is useful when it exposes who did what, when, against which population, and which checks failed. It is misleading when its volume becomes a proxy for evidence.

The measure of a verification process is not how many of its controls passed. It is how many have ever been seen to fail, and what happened the last time two of them disagreed.

Limits

This essay does not report a representative study of private funds or estimate how often these gaps occur, compare providers, or measure their effect on investment outcomes. Its narrower claim is that a control label is insufficient without the objective, population, method, failure behavior, and observed result.

Sources and notes

  1. PCAOB, AS 2501: Auditing Accounting Estimates, Including Fair Value Measurements. The standard covers risk assessment and testing of methods, data, and significant assumptions.
  2. SEC, private-fund auditor enforcement release, March 29, 2023. The matter describes failures to obtain sufficient evidence about fair-value methods, models, and alternative assumptions.
  3. SEC, Form ADV and IARD frequently asked questions. The October 26, 2023 response for Schedule D question 27 distinguishes performance of a valuation procedure from ultimate responsibility.
  4. Institutional Limited Partners Association, Due Diligence Questionnaire 2.0. See the overview, disclaimer, and Appendix C reference templates.
  5. NIST SP 800-53A Revision 5. The framework distinguishes examination, interview, and testing methods for control assessment.
  6. U.S. Government Accountability Office, 2025 Green Book. The framework addresses the design, implementation, operation, and monitoring of internal control.