CC9.1: Mitigating business disruption risk
The company identifies what could disrupt the business, decides how to reduce or accept each risk, and maintains plans (including backups and recovery) to keep operating or recover.
Category: Security (common criteria, required in every SOC 2 report) · Series: CC9 (Risk mitigation) · TSC 2017 (2022 points of focus)
That summary is Policyseed’s own paraphrase, written to be read next to the policy sections below. The authoritative wording is the AICPA’s Trust Services Criteria, which the CPA firm tests your controls against during the examination.
Policies that address CC9.1
The Policyseed crosswalk points CC9.1 at 3 policies. Each link opens the full sample text at the section an auditor would read. Section 4 holds the statements management commits to; section 5 holds the procedures that produce evidence.
- P14 Business Continuity and Disaster Recovery Policy, section 4 (Policy Statements). Owner: Engineering Lead.
- P15 Backup and Recovery Policy, section 4 (Policy Statements). Owner: Engineering Lead.
- P17 Risk Assessment and Management Policy, section 4 (Policy Statements). Owner: Security Owner.
Evidence examples for CC9.1
Artifacts a company of 5 to 200 people can realistically produce. The Audit Kit’s evidence checklist lists them per policy with an owner column so each one has a name against it before the examination.
- Business continuity and disaster recovery plan with recovery time and recovery point objectives per system
- Risk register entries for availability and disruption risks with treatments
- Cyber insurance policy summary or documented decision not to carry it
Related criteria in CC9 (Risk mitigation)
Previous: CC8.1 Change management. Next: CC9.2 Vendor and business partner risk. All 38 criteria are listed on the template index.
Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.