unified
UC-GOV-21 — Communicate and report risk and control information
Establish channels, responsibilities, and cadences to communicate risk, control, and performance information internally at all levels — including objectives and internal control responsibilities — and with external stakeholders, business partners, and the technology function. Leverage information systems to capture, process, and deliver this reporting, and report on risk, culture, and performance to stakeholders at defined intervals and on significant events.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Governance, Policy & Oversight
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-GOV-21
- title
- Communicate and report risk and control information
- statement
- Establish channels, responsibilities, and cadences to communicate risk, control, and performance information internally at all levels — including objectives and internal control responsibilities — and with external stakeholders, business partners, and the technology function. Leverage information systems to capture, process, and deliver this reporting, and report on risk, culture, and performance to stakeholders at defined intervals and on significant events.
- domain
- Governance, Policy & Oversight
- control_type
- preventive
- control_category
- administrative
- members
- framework
- soc2
- control_id
- CC2.2
- coverage
- full
- relationship
- superset_of
- framework
- soc2
- control_id
- CC2.3
- coverage
- full
- relationship
- superset_of
- framework
- coso-erm
- control_id
- E18
- coverage
- full
- relationship
- superset_of
- framework
- coso-erm
- control_id
- E19
- coverage
- full
- relationship
- superset_of
- framework
- coso-erm
- control_id
- E20
- coverage
- full
- relationship
- superset_of
- framework
- cobit-2019
- control_id
- EDM05
- coverage
- partial
- delta
- evaluating stakeholder engagement/reporting requirements and monitoring engagement effectiveness at the governance layer, beyond performing communication and reporting
- relationship
- intersects_with
- framework
- cobit-2019
- control_id
- APO08
- coverage
- partial
- delta
- active business-IT relationship and demand management beyond communication
- relationship
- intersects_with
- framework
- coso-ic
- control_id
- P14
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-GOV-21 — Communicate and report risk and control information maps_to CC2.3 — The entity communicates with external parties regarding matters affecting the functioning of internal control.
- framework
- soc2
- control_id
- CC2.3
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-21 — Communicate and report risk and control information maps_to E19 — Communicates Risk Information
- framework
- coso-erm
- control_id
- E19
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Risk Appetite Definition & Board Reporting oversees UC-GOV-21 — Communicate and report risk and control information
- Risk & Control Self-Assessment (RCSA) Program operates UC-GOV-21 — Communicate and report risk and control information
- SOC 2 Reporting and Management Assertion operates UC-GOV-21 — Communicate and report risk and control information
- UC-GOV-21 — Communicate and report risk and control information mitigates Stakeholder trust and social-license erosion
- strength
- related
- rationale
- Reporting to external stakeholders on risk and performance sustains stakeholder relationships and trust.
- UC-GOV-21 — Communicate and report risk and control information maps_to E18 — Leverages Information and Technology
- framework
- coso-erm
- control_id
- E18
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- SOC 2 Trust Services Readiness tests UC-GOV-21 — Communicate and report risk and control information
- SOC 2 Type II Interim Testing tests UC-GOV-21 — Communicate and report risk and control information
- UC-GOV-21 — Communicate and report risk and control information maps_to P14 — The organization internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control.
- framework
- coso-ic
- control_id
- P14
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2013
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Quarterly Board & Audit-Committee GRC Reporting oversees UC-GOV-21 — Communicate and report risk and control information
- UC-GOV-21 — Communicate and report risk and control information maps_to CC2.2 — The entity internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control.
- framework
- soc2
- control_id
- CC2.2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-21 — Communicate and report risk and control information maps_to E20 — Reports on Risk, Culture, and Performance
- framework
- coso-erm
- control_id
- E20
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-21 — Communicate and report risk and control information maps_to EDM05 — Ensured Stakeholder Engagement
- framework
- cobit-2019
- control_id
- EDM05
- coverage
- partial
- delta
- evaluating stakeholder engagement/reporting requirements and monitoring engagement effectiveness at the governance layer, beyond performing communication and reporting
- relationship
- intersects_with
- source_version
- 2019
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Year-End Deficiency Aggregation & Severity Evaluation oversees UC-GOV-21 — Communicate and report risk and control information
- Risk Communication, Reporting & Performance Review operates UC-GOV-21 — Communicate and report risk and control information
- Quarterly 302/906 Sub-Certification Cascade operates UC-GOV-21 — Communicate and report risk and control information
- Deficiency Evaluation & Committee operates UC-GOV-21 — Communicate and report risk and control information
- Domain Oversight and Management Review oversees UC-GOV-21 — Communicate and report risk and control information
- ESG-Related Risk Materiality & Integration oversees UC-GOV-21 — Communicate and report risk and control information
- UC-GOV-21 — Communicate and report risk and control information maps_to APO08 — Managed Relationships
- framework
- cobit-2019
- control_id
- APO08
- coverage
- partial
- delta
- active business-IT relationship and demand management beyond communication
- relationship
- intersects_with
- source_version
- 2019
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-21 — Communicate and report risk and control information mitigates Money laundering, sanctions and financial-crime program failures
- strength
- related
- rationale
- Management Assessment & Assertion operates UC-GOV-21 — Communicate and report risk and control information