unified
UC-RISK-12 — Assess and mitigate fraud risk including management override
A documented fraud risk assessment considers fraudulent reporting, asset misappropriation, and corruption, evaluating incentives, pressures, opportunities, and rationalizations, and explicitly addresses the risk of management override of controls. Specific anti-override controls operate, including review of journal entries and significant estimates at an appropriate level of precision. The assessment and mitigating controls are refreshed at least annually with documented results.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Risk Assessment & Management
- type
- detective
- category
- administrative
Details
- unified_id
- UC-RISK-12
- title
- Assess and mitigate fraud risk including management override
- statement
- A documented fraud risk assessment considers fraudulent reporting, asset misappropriation, and corruption, evaluating incentives, pressures, opportunities, and rationalizations, and explicitly addresses the risk of management override of controls. Specific anti-override controls operate, including review of journal entries and significant estimates at an appropriate level of precision. The assessment and mitigating controls are refreshed at least annually with documented results.
- domain
- Risk Assessment & Management
- control_type
- detective
- control_category
- administrative
- members
- framework
- soc2
- control_id
- CC3.3
- coverage
- full
- relationship
- superset_of
- framework
- coso-ic
- control_id
- P8
- coverage
- full
- relationship
- superset_of
- framework
- sox
- control_id
- ELC-MGMT-OVR
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-RISK-12 — Assess and mitigate fraud risk including management override mitigates Internal fraud — asset misappropriation, embezzlement, forgery
- strength
- primary
- rationale
- Fraud risk assessment plus anti-override controls (journal-entry and significant-estimate review) directly detect and deter employee embezzlement, forgery and unauthorized disbursements.
- UC-RISK-12 — Assess and mitigate fraud risk including management override maps_to P8 — The organization considers the potential for fraud in assessing risks to the achievement of objectives.
- framework
- coso-ic
- control_id
- P8
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2013
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-RISK-12 — Assess and mitigate fraud risk including management override mitigates Unauthorized activity — rogue trading, position mismarking, concealment
- strength
- related
- rationale
- Journal-entry and precision estimate review detect the mismarking and fictitious bookings used to conceal unauthorized/rogue positions (complements trading-limit controls).
- UC-RISK-12 — Assess and mitigate fraud risk including management override maps_to ELC-MGMT-OVR — Anti-fraud and management override controls — controls addressing the risk of management override of controls, including journal-entry review and review of significant estimates.
- framework
- sox
- control_id
- ELC-MGMT-OVR
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- SOX §302/§404 (2002), PCAOB AS 2201
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- SOC 2 Trust Services Readiness tests UC-RISK-12 — Assess and mitigate fraud risk including management override
- Fraud Risk Assessment & Anti-Override Control Review operates UC-RISK-12 — Assess and mitigate fraud risk including management override
- UC-RISK-12 — Assess and mitigate fraud risk including management override maps_to CC3.3 — The entity considers the potential for fraud in assessing risks to the achievement of objectives.
- framework
- soc2
- control_id
- CC3.3
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Annual ICFR Scoping & Risk Assessment oversees UC-RISK-12 — Assess and mitigate fraud risk including management override