A detective control identifies an undesired condition after it exists. IGA examples include finding orphaned accounts, reporting separation-of-duties violations, detecting access outside a peer baseline and flagging failed deprovisioning.
Detective controls require timely remediation and evidence. Where the risk demands it, they should support preventive controls that stop inappropriate access before assignment or use.