CC3.2: Identifying and analyzing risks
At least once a year the company lists the threats to its systems and data (including from vendors), rates their likelihood and impact, and decides how to treat each one.
Category: Security (common criteria, required in every SOC 2 report) · Series: CC3 (Risk assessment) · TSC 2017 (2022 points of focus)
That summary is Policyseed’s own paraphrase, written to be read next to the policy sections below. The authoritative wording is the AICPA’s Trust Services Criteria, which the CPA firm tests your controls against during the examination.
Policies that address CC3.2
The Policyseed crosswalk points CC3.2 at 2 policies. Each link opens the full sample text at the section an auditor would read. Section 4 holds the statements management commits to; section 5 holds the procedures that produce evidence.
- P16 Vendor and Third-Party Risk Management Policy, section 5 (Procedures). Owner: Security Owner.
- P17 Risk Assessment and Management Policy, section 5 (Procedures). Owner: Security Owner.
Evidence examples for CC3.2
Artifacts a company of 5 to 200 people can realistically produce. The Audit Kit’s evidence checklist lists them per policy with an owner column so each one has a name against it before the examination.
- Completed annual risk register with likelihood, impact, treatment and owner columns
- Vendor risk assessment records for critical vendors (SOC 2 report review notes or security questionnaire)
- Meeting notes or ticket showing leadership approval of the risk treatment plan
Related criteria in CC3 (Risk assessment)
Previous: CC3.1 Objectives for risk assessment. Next: CC3.3 Fraud risk. All 38 criteria are listed on the template index.
Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.