Risk Mitigation
Complete guide to CC9 Risk Mitigation controls. Plain-English explanations, AICPA text, risk levels, and evidence tips for each control.
Risk Mitigation
Plain English
You have a Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) that address how you maintain or restore services after a major disruption.
View official AICPA language
The entity identifies, selects, and develops risk mitigation activities for risks arising from potential business disruptions.
What auditors look for
Business Continuity Plan document, DR runbooks, annual DR test results (RTO/RPO verification), backup configuration
Vendor & Third-Party Risk Management
Plain English
You maintain a vendor inventory, assess each vendor's security posture before and during the relationship, and have contractual protections (DPAs, security requirements) in vendor agreements.
View official AICPA language
The entity assesses and manages risks associated with vendors and business partners.
What auditors look for
Vendor inventory list, security questionnaires or SOC 2 reports collected from critical vendors, DPAs signed with each vendor
Track all 2 controls in your free checklist
Assign owners, collect evidence, and get your readiness score — no credit card required.
Start Free Today