Every security measure in your security base displays an operations score, which reflects whether it is monitored over time through recurring controls. Recurring tasks are one of the two levers that feed this score, along with performance indicators.
🔎 To understand the difference between efficiency, operations, and performance for a measure, start with Understanding the efficiency, operations, and performance scores of a security measure. This article focuses specifically on the impact of your recurring tasks on this score.
How a recurring task moves the score
The operations score of a measure tracked by recurring tasks corresponds to its completion rate: the proportion of periods actually completed among those that were due.
Done / Done OK: the period counts as completed and moves the score up.
Done KO (control tasks): the period counts as completed for the completion rate, just like a Done OK. A failed control result therefore does not impact the operations score; it is tracked separately through the pass rate, specific to control tasks.
Not done: the period counts negatively against the score, permanently.
Not applicable: the period is excluded from the calculation altogether, it isn't factored into the score either way.
Rejected: until the entry is corrected and resubmitted, it is not counted as done.
⚠️ If an approver is configured on the recurring task, an entry pending approval is not yet counted as done. Only approved entries move the score forward.
Over what period the operations score is calculated
The score isn't recalculated over the measure's entire history. Depending on your organization's preference, it covers either the last 365 days (or since the task's start date if more recent), or only the last elapsed period.
Either way, one rule stays constant: the current period is never counted, since its due date hasn't been reached yet.
💡 In practice, if you complete your monthly task today, the measure's score will only move once that period is due, not immediately after you log it.
If no elapsed period is available yet
Two situations lead to the same outcome: your measure has no recurring task or indicator attached yet, or it has one but no period is due yet (or all periods are marked N/A). In both cases, the operations score defaults to 75%, flagged with a "Default" label next to it.
🔎 This default value is configurable for your organization. See the Tenacy preferences glossary (preferences Measure.default_performance and Measure.task_timerange) for details.
Where to check a measure's operations score
You can check the operations score's detail and evolution in two places:
From the Security base: open the relevant policy, then click a measure to display its efficiency and operations detail.
From the Policies module: open the policy, click the measured score icon, then click a requirement to browse its associated measures and their calculation detail.
Frequently asked questions
Why hasn't the operations score moved even though I completed my task today?
Because the current period is never factored into the calculation: only a period that has reached its due date can move the score.
Does a task marked "Not applicable" count against the score?
No, it's simply excluded from the calculation: it counts neither as done nor as not done.
My task is pending approval, is it counted in the score?
Not yet. If an approver is required, only approved entries are counted as done.
What's the difference between the logging rate and the completion rate?
The logging rate measures the share of periods that received a final answer of any kind: Done OK, Done KO, Not done, or Not applicable all count as "logged," both in the numerator and against a total that includes every period. The completion rate, which feeds the operations score, measures something else: among the periods the control genuinely applied to, the share that were actually done. For this calculation, Not applicable periods are removed entirely, counted neither as done nor as not done, and excluded from both the numerator and the denominator. The completion rate is therefore always lower than or equal to the logging rate.
Does a "Done KO" control bring the operations score down?
No. The operations score only measures whether the control was carried out on time, not whether it passed. A Done KO counts as a completion just like a Done OK. To track the share of controls that fail, look at the pass rate, a separate score specific to control tasks (number of Done OK over the total excluding N/A), which does not feed into the measure's operations score.
What impact do recurring tasks have on my measure's performance score?
Your recurring tasks don't act directly on the performance score: they feed the operations score (through the completion rate detailed above), which is then combined with efficiency to produce the performance score (performance = efficiency × operations). In practice, the more your recurring tasks are completed on time, the higher the operations score, and the more it pulls the measure's performance up, independently of its efficiency. For the full breakdown of this combination, see Understanding the efficiency, operations, and performance scores of a security measure.
Does the operations score take both recurring tasks and indicators into account?
Yes. If a measure only has recurring tasks, the operations score corresponds to their completion rate. If it only has performance indicators, it corresponds to the average of their achievement rates. If it has both, the operations score is the average of the two components: the recurring tasks' completion rate on one side, the average of the indicators' achievement on the other. Recurring tasks and indicators therefore carry equal weight in the score, regardless of how many of each you have: if a measure has just one recurring task but 3 indicators, that single task's completion rate carries as much weight in the operations score calculation as the average of the 3 indicators.
🔎 To go further: Completing a recurring task and Creating a recurring task.



