CC3 Security Required

Risk Assessment

Complete guide to CC3 Risk Assessment controls. Plain-English explanations, AICPA text, risk levels, and evidence tips for each control.

4 Controls
0 Critical
2 High
CC3.1 high

Risk Assessment Objectives

You have defined your security objectives and do a formal risk assessment to identify what could prevent you from achieving them. This isn't just a list — it must be documented.

View official AICPA language

The entity specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to objectives.

What auditors look for

Formal risk assessment document, risk register with likelihood and impact ratings, risk assessment meeting minutes

CC3.2 high

Risk Identification and Analysis

You systematically identify, analyze, and prioritize security risks. You consider both the likelihood of a risk occurring and the impact if it does.

View official AICPA language

The entity identifies risks to the achievement of its objectives across the entity and analyzes risks as a basis for determining how the risks should be managed.

What auditors look for

Risk register showing identified risks, likelihood/impact ratings, and assigned owners. Evidence of annual (or more frequent) reviews.

CC3.3 medium

Fraud Risk Assessment

Your risk assessment specifically considers fraud risks — both internal (employee fraud) and external (customer fraud, social engineering). This must be documented.

View official AICPA language

The entity considers the potential for fraud in assessing risks to the achievement of objectives.

What auditors look for

Risk register entries specifically labeled as fraud risks, fraud risk assessment section in your annual risk review

CC3.4 medium

Change Management Risk

When significant changes occur (new product features, new vendors, reorg, new tech stack), you re-assess the risks those changes introduce to your control environment.

View official AICPA language

The entity identifies and assesses changes that could significantly impact the system of internal control.

What auditors look for

Change risk assessment process documentation, examples of risk re-assessments triggered by significant changes

Track all 4 controls in your free checklist

Assign owners, collect evidence, and get your readiness score — no credit card required.

Start Free Today