Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon

Browse

33 controls

CC3.2Identifies and analyzes risks to achievement of objectivesSOC 2Risk Assessment

Official Requirement

COSO Principle 7: The entity identifies risks to the achievement of its objectives across the entity and analyzes risks as a basis for determining how the risks should be managed.

Source: AICPA Trust Services Criteria (2017), incorporating COSO principles

In Plain English

You maintain a live risk register that identifies threats, estimates their likelihood and impact, and documents how each risk is being treated. This is not a one-time exercise done before a Type I audit. The register is updated when new threats emerge, when significant changes happen to the environment, and after security incidents. Auditors will look at both the register and whether it was acted upon.

Help us build what matters.

Vote for the next framework, subscribe for updates, and let us know if you'd contribute.

The Trust Services Criteria referenced in this tool are published by the American Institute of Certified Public Accountants (AICPA) and incorporate principles from the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Criteria descriptions are reproduced for reference purposes. All implementation guidance, evidence recommendations, and control language are original work by Truvo Cyber. ISO 27001 and ISO 42001 are standards published by the International Organization for Standardization (ISO). Framework and standard names are the property of their respective owners. This tool is not affiliated with, endorsed by, or certified by AICPA, COSO, or ISO.

© 2026 Truvo Cyber. All rights reserved.

On-premises implementation and evidence

Annual risk assessment with maintained risk register

Implementation steps

  1. Run an annual risk assessment using a structured methodology: identify assets, identify threats per asset, rate likelihood and impact, calculate inherent risk, apply existing controls, calculate residual risk
  2. Maintain the risk register in your GRC platform or a version-controlled spreadsheet, update it whenever the environment materially changes (new production system, new vendor with data access, significant infrastructure change)
  3. For each high and critical risk, create a remediation task in your ticketing system with an owner and target date
  4. Present the risk register to management or the board at least annually for review and sign-off

Tools / systems

Evidence artifacts

Evidence frequency: Annual assessment; register updated on material changes; management quarterly