unified
UC-RISK-10 — Maintain a risk register and report the portfolio view
A risk register records identified risks with analysis results, owners, treatment plans, and current status, and is updated on a defined cycle and upon significant change. Portfolio-level views aggregate risks across the entity and are reported to management and the board to support oversight and resource decisions. Register extracts and portfolio reports evidence operation.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Risk Assessment & Management
- type
- detective
- category
- administrative
Details
- unified_id
- UC-RISK-10
- title
- Maintain a risk register and report the portfolio view
- statement
- A risk register records identified risks with analysis results, owners, treatment plans, and current status, and is updated on a defined cycle and upon significant change. Portfolio-level views aggregate risks across the entity and are reported to management and the board to support oversight and resource decisions. Register extracts and portfolio reports evidence operation.
- domain
- Risk Assessment & Management
- control_type
- detective
- control_category
- administrative
- members
- framework
- iso-31000
- control_id
- 31000-PR8
- coverage
- full
- relationship
- superset_of
- framework
- coso-erm
- control_id
- E14
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- Risk Register Intake oversees UC-RISK-10 — Maintain a risk register and report the portfolio view
- UC-RISK-10 — Maintain a risk register and report the portfolio view mitigates Inadequate or absent risk assessment process
- strength
- primary
- rationale
- A maintained risk register with status and portfolio reporting is the ongoing risk monitoring the risk describes as missing.
- UC-RISK-10 — Maintain a risk register and report the portfolio view maps_to 31000-PR8 — Recording and reporting
- framework
- iso-31000
- control_id
- 31000-PR8
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2018
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Enterprise Risk Assessment & Portfolio Oversight Cycle oversees UC-RISK-10 — Maintain a risk register and report the portfolio view
- Risk & Control Self-Assessment (RCSA) Program operates UC-RISK-10 — Maintain a risk register and report the portfolio view
- UC-RISK-10 — Maintain a risk register and report the portfolio view mitigates Failed M&A, integration or divestiture
- strength
- related
- rationale
- ERM Risk Identification & Register Refresh operates UC-RISK-10 — Maintain a risk register and report the portfolio view
- Enterprise Risk Treatment Operations Cycle operates UC-RISK-10 — Maintain a risk register and report the portfolio view
- Quarterly Board & Audit-Committee GRC Reporting oversees UC-RISK-10 — Maintain a risk register and report the portfolio view
- ISMS Risk Assessment & Treatment Cycle oversees UC-RISK-10 — Maintain a risk register and report the portfolio view
- UC-RISK-10 — Maintain a risk register and report the portfolio view maps_to E14 — Develops Portfolio View
- framework
- coso-erm
- control_id
- E14
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Enterprise Risk Register Lifecycle oversees UC-RISK-10 — Maintain a risk register and report the portfolio view