A control assessment asks two questions: is the control designed to achieve its objective, and is it operating as designed. Design is read; operation must be sampled.
The evidence ladder
From weakest to strongest: somebody says the control runs; a document says it should run; a screenshot shows it ran once; a system export shows every instance in the period; you re-perform the control yourself and get the same result.
Aim at least two rungs up from an interview. Screenshots are the most common evidence and among the weakest — they show one moment, chosen by the person being assessed.
Sampling
For a control that runs many times — access reviews, change approvals, starter and leaver processing — pick a sample across the whole period rather than the most recent few, and include the awkward cases: emergency changes, contractors, transfers between teams, and anyone who left in a hurry.
What exceptions mean
One failure in twenty-five is not noise; it is a 4% failure rate in a control somebody is relying on. Record it, find out why, and separate "the control was skipped" from "the control does not work" — those have different fixes.
Writing it up
Say what you tested, over what period, how you chose the sample, what you found and what it means for the objective. An assessment that cannot be re-performed from its own write-up is an opinion.