unified
UC-RISK-06 — Perform periodic enterprise risk assessments
The organization performs an enterprise-wide risk assessment at least annually and upon significant change, identifying and analyzing risks to the achievement of objectives, including cybersecurity, privacy, and financial reporting risks. Assessments follow the documented methodology, address the design of the control environment and evolving threats and technologies, and are approved by management. Assessment reports, methodology references, and approvals are retained as evidence.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Risk Assessment & Management
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-RISK-06
- title
- Perform periodic enterprise risk assessments
- statement
- The organization performs an enterprise-wide risk assessment at least annually and upon significant change, identifying and analyzing risks to the achievement of objectives, including cybersecurity, privacy, and financial reporting risks. Assessments follow the documented methodology, address the design of the control environment and evolving threats and technologies, and are approved by management. Assessment reports, methodology references, and approvals are retained as evidence.
- domain
- Risk Assessment & Management
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- RA-3
- coverage
- full
- relationship
- superset_of
- framework
- soc2
- control_id
- CC3.2
- coverage
- full
- relationship
- superset_of
- framework
- coso-ic
- control_id
- P7
- coverage
- full
- relationship
- superset_of
- framework
- sox
- control_id
- ELC-RA
- coverage
- partial
- delta
- objective-setting, fraud, and change aspects covered by dedicated unified controls
- relationship
- intersects_with
- framework
- nydfs-500
- control_id
- 500.9
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- Enterprise Risk Treatment Operations Cycle operates UC-RISK-06 — Perform periodic enterprise risk assessments
- UC-RISK-06 — Perform periodic enterprise risk assessments maps_to ELC-RA — Risk Assessment — entity objective-setting, identification and analysis of risks to financial reporting, fraud risk assessment, and assessment of changes affecting internal control.
- framework
- sox
- control_id
- ELC-RA
- coverage
- partial
- delta
- objective-setting, fraud, and change aspects covered by dedicated unified controls
- relationship
- intersects_with
- source_version
- SOX §302/§404 (2002), PCAOB AS 2201
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-RISK-06 — Perform periodic enterprise risk assessments maps_to 500.9 — Risk assessment
- framework
- nydfs-500
- control_id
- 500.9
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 23 NYCRR 500, Second Amendment
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-RISK-06 — Perform periodic enterprise risk assessments maps_to P7 — The organization identifies risks to the achievement of its objectives across the entity and analyzes risks as a basis for determining how the risks should be managed.
- framework
- coso-ic
- control_id
- P7
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2013
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Annual ICFR Scoping & Risk Assessment oversees UC-RISK-06 — Perform periodic enterprise risk assessments
- UC-RISK-06 — Perform periodic enterprise risk assessments mitigates Attacks by capable, motivated threat actors
- strength
- related
- rationale
- NYDFS 500.9 member and explicit cyber scope make the assessment periodically surface evolving cyber threats for treatment, enabling context not the operative defense.
- SOC 2 Trust Services Readiness tests UC-RISK-06 — Perform periodic enterprise risk assessments
- Enterprise Risk Assessment & Portfolio Oversight Cycle oversees UC-RISK-06 — Perform periodic enterprise risk assessments
- UC-RISK-06 — Perform periodic enterprise risk assessments maps_to CC3.2 — The entity identifies risks to the achievement of its objectives across the entity and analyzes risks as a basis for determining how the risks should be managed.
- framework
- soc2
- control_id
- CC3.2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-RISK-06 — Perform periodic enterprise risk assessments mitigates Inadequate or absent risk assessment process
- strength
- primary
- rationale
- Performing periodic enterprise-wide risk assessments per a documented methodology directly operates the assessment process the risk describes as absent.
- UC-RISK-06 — Perform periodic enterprise risk assessments mitigates Liquidity, capital-structure and refinancing risk
- strength
- related
- rationale
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-RISK-06 — Perform periodic enterprise risk assessments
- UC-RISK-06 — Perform periodic enterprise risk assessments maps_to RA-3 — Risk Assessment
- framework
- nist-800-53
- control_id
- RA-3
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISMS Risk Assessment & Treatment Cycle oversees UC-RISK-06 — Perform periodic enterprise risk assessments