unified
UC-ACCESS-21 — Manage subservice organizations supporting the system
Subservice organizations relevant to user entities' control objectives are identified, contractually bound to security and processing commitments, and monitored through review of their independent assurance reports, complementary user-entity controls, and performance. Identified issues are tracked to resolution.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Third-Party / Supply-Chain Risk
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-ACCESS-21
- title
- Manage subservice organizations supporting the system
- statement
- Subservice organizations relevant to user entities' control objectives are identified, contractually bound to security and processing commitments, and monitored through review of their independent assurance reports, complementary user-entity controls, and performance. Identified issues are tracked to resolution.
- domain
- Third-Party / Supply-Chain Risk
- control_type
- preventive
- control_category
- administrative
- members
- framework
- soc1
- control_id
- SOC1-12
- coverage
- full
- relationship
- equal
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-ACCESS-21 — Manage subservice organizations supporting the system maps_to SOC1-12 — Vendor / subservice organization management — controls provide reasonable assurance that subservice organizations relevant to user entities' ICFR are appropriately managed and monitored.
- framework
- soc1
- control_id
- SOC1-12
- coverage
- full
- relationship
- equal
- delta
- Not provided
- source_version
- SSAE 18 (current AICPA SOC suite)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Subservice Organization & Third-Party Personnel Oversight operates UC-ACCESS-21 — Manage subservice organizations supporting the system
- System ITGC Operation operates UC-ACCESS-21 — Manage subservice organizations supporting the system
- GCP Physical and Environmental Subservice Reliance oversees UC-ACCESS-21 — Manage subservice organizations supporting the system
- UC-ACCESS-21 — Manage subservice organizations supporting the system mitigates Critical vendor failure, insolvency or concentration
- strength
- related
- rationale
- Monitoring critical subservice-org performance and assurance gives early warning of a deteriorating dependency, reducing failure impact.
- SOC Report, Subservice & CUEC Review operates UC-ACCESS-21 — Manage subservice organizations supporting the system
- UC-ACCESS-21 — Manage subservice organizations supporting the system mitigates Third-party compliance failure creating vicarious liability
- strength
- related
- rationale
- Managing subservice (fourth-party) orgs and reviewing their assurance reports reduces the N-tier opacity that drives vicarious-liability exposure.
- UC-ACCESS-21 — Manage subservice organizations supporting the system mitigates Weak supplier security requirements and monitoring
- strength
- primary
- rationale
- Identifying, contractually binding, and monitoring subservice orgs via their assurance reports and CUECs directly closes the unmonitored, unbound third-party gap this risk describes.
- Vendor Risk Assessment and Disposition oversees UC-ACCESS-21 — Manage subservice organizations supporting the system
- Third-Party Vendor Risk Lifecycle oversees UC-ACCESS-21 — Manage subservice organizations supporting the system
- Vendor SOC 1/SOC 2 Report Review & CUEC Mapping oversees UC-ACCESS-21 — Manage subservice organizations supporting the system
- UC-ACCESS-21 — Manage subservice organizations supporting the system mitigates Vendor/outsourcing service non-performance and disputes
- strength
- primary
- rationale
- Monitoring subservice-org performance against commitments and tracking identified issues to resolution directly detects and remediates service non-performance.