unified
UC-AUDIT-23 — Coordinate independent assurance reviews across providers
The organization plans and obtains independent reviews of its approach to managing and implementing information security - including people, processes, and technologies - at planned intervals, after significant changes, and where required by applicable law or regulation. Before relying on another provider's work, each reliance decision assesses and records the provider's independence and objectivity, competence and methodology rigor, evidence quality and reperformance capability, and recency against the covered risk's cadence, together with the resulting reliance level and rationale. Assurance activities are coordinated across internal and external providers to ensure coverage, minimize duplication, and support reliance on others' work. Material reliance limitations, assurance gaps, and duplication remain visible to management and the board. Results are reported to management and the board and drive corrective actions.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Compliance, Audit & Assurance
- type
- detective
- category
- administrative
Details
- unified_id
- UC-AUDIT-23
- title
- Coordinate independent assurance reviews across providers
- statement
- The organization plans and obtains independent reviews of its approach to managing and implementing information security - including people, processes, and technologies - at planned intervals, after significant changes, and where required by applicable law or regulation. Before relying on another provider's work, each reliance decision assesses and records the provider's independence and objectivity, competence and methodology rigor, evidence quality and reperformance capability, and recency against the covered risk's cadence, together with the resulting reliance level and rationale. Assurance activities are coordinated across internal and external providers to ensure coverage, minimize duplication, and support reliance on others' work. Material reliance limitations, assurance gaps, and duplication remain visible to management and the board. Results are reported to management and the board and drive corrective actions.
- domain
- Compliance, Audit & Assurance
- control_type
- detective
- control_category
- administrative
- members
- framework
- iso-27001
- control_id
- A.5.35
- coverage
- full
- relationship
- superset_of
- framework
- ccpa
- control_id
- CCPA-1798.185
- coverage
- partial
- delta
- risk-assessment submission obligations handled under risk management controls
- relationship
- intersects_with
- framework
- cobit-2019
- control_id
- MEA04
- coverage
- full
- relationship
- superset_of
- framework
- iia-2024
- control_id
- Std 9.5
- coverage
- full
- relationship
- superset_of
- guidance
- source
- iia-pos-2026-three-lines
- sourceTitle
- Three Lines Model: Assurance and Advice in Support of Effective Governance
- propositionId
- IIA-POS-TLM-03
- propositionTitle
- Assurance Coordination and Reliance
- sourcePages
- Three Lines pp. 15–16, 18–19
Source
No record-specific source URL is provided.
Connections
- UC-AUDIT-23 — Coordinate independent assurance reviews across providers mitigates Lack of independent audit and compliance review
- strength
- primary
- rationale
- Planning and obtaining independent reviews of information security at intervals and after change (ISO A.5.35) is the independent-review control this risk lacks.
- ISMS Internal Audit & Management Review operates UC-AUDIT-23 — Coordinate independent assurance reviews across providers
- Regulatory Exam & External Audit Management oversees UC-AUDIT-23 — Coordinate independent assurance reviews across providers
- SOC 2 Readiness & Evidence Collection oversees UC-AUDIT-23 — Coordinate independent assurance reviews across providers
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-AUDIT-23 — Coordinate independent assurance reviews across providers
- UC-AUDIT-23 — Coordinate independent assurance reviews across providers maps_to MEA04 — Managed Assurance
- framework
- cobit-2019
- control_id
- MEA04
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2019
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-AUDIT-23 — Coordinate independent assurance reviews across providers mitigates Public-safety harm from AI in critical infrastructure
- strength
- related
- rationale
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-AUDIT-23 — Coordinate independent assurance reviews across providers
- Cybersecurity Assurance Review operates UC-AUDIT-23 — Coordinate independent assurance reviews across providers
- UC-AUDIT-23 — Coordinate independent assurance reviews across providers maps_to CCPA-1798.185 — CPPA regulations: cybersecurity audits and risk assessments
- framework
- ccpa
- control_id
- CCPA-1798.185
- coverage
- partial
- delta
- risk-assessment submission obligations handled under risk management controls
- relationship
- intersects_with
- source_version
- CCPA (2018) as amended by CPRA (2020)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-AUDIT-23 — Coordinate independent assurance reviews across providers maps_to Std 9.5 — Coordination and Reliance
- framework
- iia-2024
- control_id
- Std 9.5
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2024 edition
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-AUDIT-23 — Coordinate independent assurance reviews across providers maps_to A.5.35 — Independent review of information security
- framework
- iso-27001
- control_id
- A.5.35
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-AUDIT-23 — Coordinate independent assurance reviews across providers informed_by IIA-POS-TLM-03 — Assurance Coordination and Reliance
- framework
- iia-pos-2026-three-lines
- control_id
- IIA-POS-TLM-03
- coverage
- guidance
- relationship
- informs
- delta
- Not provided
- source_version
- 2026
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- sourcePages
- Three Lines pp. 15–16, 18–19
- Combined Assurance Mapping tests UC-AUDIT-23 — Coordinate independent assurance reviews across providers