unified
UC-RISK-13 — Monitor and review risk management performance
The organization performs ongoing and separate evaluations of risk management and internal control performance, periodically measuring the framework's effectiveness against its design and intended outcomes. Risk and business performance are reviewed together at defined intervals and results are reported to accountable management. Evaluation schedules, results, and review minutes are retained as evidence.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Risk Assessment & Management
- type
- detective
- category
- administrative
Details
- unified_id
- UC-RISK-13
- title
- Monitor and review risk management performance
- statement
- The organization performs ongoing and separate evaluations of risk management and internal control performance, periodically measuring the framework's effectiveness against its design and intended outcomes. Risk and business performance are reviewed together at defined intervals and results are reported to accountable management. Evaluation schedules, results, and review minutes are retained as evidence.
- domain
- Risk Assessment & Management
- control_type
- detective
- control_category
- administrative
- members
- framework
- soc2
- control_id
- CC4.1
- coverage
- full
- relationship
- superset_of
- framework
- iso-31000
- control_id
- 31000-PR7
- coverage
- full
- relationship
- superset_of
- framework
- iso-31000
- control_id
- 31000-FW5
- coverage
- full
- relationship
- superset_of
- framework
- coso-erm
- control_id
- E16
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- Risk Assessment and Treatment Review operates UC-RISK-13 — Monitor and review risk management performance
- UC-RISK-13 — Monitor and review risk management performance maps_to CC4.1 — The entity selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.
- framework
- soc2
- control_id
- CC4.1
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-RISK-13 — Monitor and review risk management performance mitigates Inadequate or absent risk assessment process
- strength
- related
- rationale
- Monitoring/reviewing the framework's own performance detects process decay, but is meta-monitoring of the program, not the operative assessment steps; ongoing risk monitoring itself sits in the register/reassessment controls.
- UC-RISK-13 — Monitor and review risk management performance maps_to E16 — Reviews Risk and Performance
- framework
- coso-erm
- control_id
- E16
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- SOC 2 Trust Services Readiness tests UC-RISK-13 — Monitor and review risk management performance
- UC-RISK-13 — Monitor and review risk management performance maps_to 31000-PR7 — Monitoring and review
- framework
- iso-31000
- control_id
- 31000-PR7
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2018
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Continuous Controls Monitoring (ISCM) Cycle oversees UC-RISK-13 — Monitor and review risk management performance
- Risk Communication, Reporting & Performance Review operates UC-RISK-13 — Monitor and review risk management performance
- Domain Oversight and Management Review oversees UC-RISK-13 — Monitor and review risk management performance
- Enterprise Risk Register Lifecycle oversees UC-RISK-13 — Monitor and review risk management performance
- Risk & Control Self-Assessment (RCSA) Program operates UC-RISK-13 — Monitor and review risk management performance
- Risk Appetite Definition & Board Reporting oversees UC-RISK-13 — Monitor and review risk management performance
- UC-RISK-13 — Monitor and review risk management performance mitigates Environmental footprint of AI training and infrastructure
- strength
- related
- rationale
- UC-RISK-13 — Monitor and review risk management performance maps_to 31000-FW5 — Evaluation
- framework
- iso-31000
- control_id
- 31000-FW5
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2018
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- CSF 2.0 Profile & Maturity Assessment oversees UC-RISK-13 — Monitor and review risk management performance
- UC-RISK-13 — Monitor and review risk management performance mitigates Product and service quality failure
- strength
- related
- rationale