Risk Assessment
Complete guide to CC3 Risk Assessment controls. Plain-English explanations, AICPA text, risk levels, and evidence tips for each control.
Risk Assessment Objectives
Plain English
You have defined your security objectives and do a formal risk assessment to identify what could prevent you from achieving them. This isn't just a list — it must be documented.
View official AICPA language
The entity specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to objectives.
What auditors look for
Formal risk assessment document, risk register with likelihood and impact ratings, risk assessment meeting minutes
Risk Identification and Analysis
Plain English
You systematically identify, analyze, and prioritize security risks. You consider both the likelihood of a risk occurring and the impact if it does.
View official AICPA language
The entity identifies risks to the achievement of its objectives across the entity and analyzes risks as a basis for determining how the risks should be managed.
What auditors look for
Risk register showing identified risks, likelihood/impact ratings, and assigned owners. Evidence of annual (or more frequent) reviews.
Fraud Risk Assessment
Plain English
Your risk assessment specifically considers fraud risks — both internal (employee fraud) and external (customer fraud, social engineering). This must be documented.
View official AICPA language
The entity considers the potential for fraud in assessing risks to the achievement of objectives.
What auditors look for
Risk register entries specifically labeled as fraud risks, fraud risk assessment section in your annual risk review
Change Management Risk
Plain English
When significant changes occur (new product features, new vendors, reorg, new tech stack), you re-assess the risks those changes introduce to your control environment.
View official AICPA language
The entity identifies and assesses changes that could significantly impact the system of internal control.
What auditors look for
Change risk assessment process documentation, examples of risk re-assessments triggered by significant changes
Track all 4 controls in your free checklist
Assign owners, collect evidence, and get your readiness score — no credit card required.
Start Free Today