CC9 Security Required

Risk Mitigation

Complete guide to CC9 Risk Mitigation controls. Plain-English explanations, AICPA text, risk levels, and evidence tips for each control.

2 Controls
1 Critical
1 High
CC9.1 high

Risk Mitigation

You have a Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) that address how you maintain or restore services after a major disruption.

View official AICPA language

The entity identifies, selects, and develops risk mitigation activities for risks arising from potential business disruptions.

What auditors look for

Business Continuity Plan document, DR runbooks, annual DR test results (RTO/RPO verification), backup configuration

CC9.2 critical

Vendor & Third-Party Risk Management

You maintain a vendor inventory, assess each vendor's security posture before and during the relationship, and have contractual protections (DPAs, security requirements) in vendor agreements.

View official AICPA language

The entity assesses and manages risks associated with vendors and business partners.

What auditors look for

Vendor inventory list, security questionnaires or SOC 2 reports collected from critical vendors, DPAs signed with each vendor

Track all 2 controls in your free checklist

Assign owners, collect evidence, and get your readiness score — no credit card required.

Start Free Today