Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon

Browse

33 controls

CC3.3Considers potential for fraud in assessing risksSOC 2Risk Assessment

Official Requirement

COSO Principle 8: The entity considers the potential for fraud in assessing risks to the achievement of objectives.

Source: AICPA Trust Services Criteria (2017), incorporating COSO principles

In Plain English

Your risk assessment explicitly considers insider threat and fraud scenarios, not just external attackers. This means thinking about what a malicious or negligent employee could do with their access, unauthorized data export, financial fraud, sabotage of production systems. The fraud risk section does not need to be elaborate, but it must be explicitly addressed in the risk register.

Help us build what matters.

Vote for the next framework, subscribe for updates, and let us know if you'd contribute.

The Trust Services Criteria referenced in this tool are published by the American Institute of Certified Public Accountants (AICPA) and incorporate principles from the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Criteria descriptions are reproduced for reference purposes. All implementation guidance, evidence recommendations, and control language are original work by Truvo Cyber. ISO 27001 and ISO 42001 are standards published by the International Organization for Standardization (ISO). Framework and standard names are the property of their respective owners. This tool is not affiliated with, endorsed by, or certified by AICPA, COSO, or ISO.

© 2026 Truvo Cyber. All rights reserved.

On-premises implementation and evidence

Fraud risk scenarios documented in the risk register

Implementation steps

  1. Include a fraud risk section in the annual risk assessment; identify the roles with the highest fraud exposure (privileged system access, financial system access)
  2. Document the controls that reduce fraud risk: segregation of duties (no single person can both approve and execute a sensitive action), privileged access logging via your SIEM/monitoring platform, periodic access reviews
  3. Ensure that audit log tampering is a documented fraud risk, confirm that log integrity controls are in place (your SIEM/monitoring platform immutable logging, your IDS/network monitoring platform log forwarding to an isolated store)

Tools / systems

Evidence artifacts

Evidence frequency: Annual formal review; log configuration evidence pulled at audit window