unified
UC-RISK-11 — Assess changes that could significantly affect risk and control
The organization identifies and assesses internal and external changes - new business models, leadership, systems, regulations, and operating environment - that could significantly affect its risk profile or system of internal control. Risk assessments and responses are updated dynamically as changes and emerging risks are detected. Change-triggered assessments and resulting updates are documented.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Risk Assessment & Management
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-RISK-11
- title
- Assess changes that could significantly affect risk and control
- statement
- The organization identifies and assesses internal and external changes - new business models, leadership, systems, regulations, and operating environment - that could significantly affect its risk profile or system of internal control. Risk assessments and responses are updated dynamically as changes and emerging risks are detected. Change-triggered assessments and resulting updates are documented.
- domain
- Risk Assessment & Management
- control_type
- preventive
- control_category
- administrative
- members
- framework
- soc2
- control_id
- CC3.4
- coverage
- full
- relationship
- superset_of
- framework
- coso-ic
- control_id
- P9
- coverage
- full
- relationship
- superset_of
- framework
- coso-erm
- control_id
- E15
- coverage
- full
- relationship
- superset_of
- framework
- iso-31000
- control_id
- 31000-P5
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-RISK-11 — Assess changes that could significantly affect risk and control mitigates Geopolitical, macroeconomic and sovereign risk
- strength
- related
- rationale
- Control assesses changes in the external operating environment; detecting geopolitical/macro shifts early enables risk-response updates that blunt operational impact.
- UC-RISK-11 — Assess changes that could significantly affect risk and control maps_to P9 — The organization identifies and assesses changes that could significantly impact the system of internal control.
- framework
- coso-ic
- control_id
- P9
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2013
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-RISK-11 — Assess changes that could significantly affect risk and control maps_to E15 — Assesses Substantial Change
- framework
- coso-erm
- control_id
- E15
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-RISK-11 — Assess changes that could significantly affect risk and control maps_to CC3.4 — The entity identifies and assesses changes that could significantly impact the system of internal control.
- framework
- soc2
- control_id
- CC3.4
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-RISK-11 — Assess changes that could significantly affect risk and control maps_to 31000-P5 — Dynamic
- framework
- iso-31000
- control_id
- 31000-P5
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2018
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Regulatory Change Intake & Impact Assessment operates UC-RISK-11 — Assess changes that could significantly affect risk and control
- Enterprise Risk Treatment Operations Cycle operates UC-RISK-11 — Assess changes that could significantly affect risk and control
- SOX Scoping Decision oversees UC-RISK-11 — Assess changes that could significantly affect risk and control
- EU AI Act Obligation Impact Analysis oversees UC-RISK-11 — Assess changes that could significantly affect risk and control
- SOC 2 Trust Services Readiness tests UC-RISK-11 — Assess changes that could significantly affect risk and control
- UC-RISK-11 — Assess changes that could significantly affect risk and control mitigates Adverse regulatory or policy change
- strength
- related
- rationale
- Control explicitly assesses regulatory changes for risk impact; early detection of adverse law/policy change enables timely, less costly adaptation.
- Regulatory Impact Analysis & Obligation Mapping oversees UC-RISK-11 — Assess changes that could significantly affect risk and control
- UC-RISK-11 — Assess changes that could significantly affect risk and control mitigates Innovation shortfall and emerging-technology adoption risk
- strength
- related
- rationale
- Control assesses new systems/technologies for risk impact; flagging undiligenced emerging-tech adoption enables diligence reducing implementation and ethical exposure.
- Emerging Risk & Horizon Scan operates UC-RISK-11 — Assess changes that could significantly affect risk and control
- UC-RISK-11 — Assess changes that could significantly affect risk and control mitigates Competitive disruption and business-model obsolescence
- strength
- related
- rationale
- Control assesses new business models and emerging risks; early detection of disruptive industry/technology shifts enables response before the model is obsoleted.
- Regulatory Horizon Scanning & Triage oversees UC-RISK-11 — Assess changes that could significantly affect risk and control