Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon

Browse

33 controls

CC5.1Selects and develops control activities that mitigate risksSOC 2Control Activities

Official Requirement

COSO Principle 10: The entity selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels.

Source: AICPA Trust Services Criteria (2017), incorporating COSO principles

In Plain English

The controls you have chosen are actually matched to your risks. If your top risk is unauthorized access to production databases, your controls address that specific scenario, not just generic IT hygiene. This criterion asks whether there is a traceable line from your risk register to your control set. Controls that exist but do not address any documented risk are evidence of a checkbox program, not a real one.

Help us build what matters.

Vote for the next framework, subscribe for updates, and let us know if you'd contribute.

The Trust Services Criteria referenced in this tool are published by the American Institute of Certified Public Accountants (AICPA) and incorporate principles from the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Criteria descriptions are reproduced for reference purposes. All implementation guidance, evidence recommendations, and control language are original work by Truvo Cyber. ISO 27001 and ISO 42001 are standards published by the International Organization for Standardization (ISO). Framework and standard names are the property of their respective owners. This tool is not affiliated with, endorsed by, or certified by AICPA, COSO, or ISO.

© 2026 Truvo Cyber. All rights reserved.

On-premises implementation and evidence

Risk-to-control mapping in the risk register

Implementation steps

  1. In your risk register, add a column for 'Mitigating Controls' and populate it with specific control references (e.g., control IDs from your GRC platform or your internal control library)
  2. When a new risk is added, immediately identify whether existing controls already address it (and the control is sufficient) or whether a new control needs to be designed
  3. Document the control selection rationale: why this control was chosen over alternatives, and how it specifically addresses the threat scenario

Tools / systems

Evidence artifacts

Evidence frequency: Annual; updated per new risk identification