{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Third-Party / Supply-Chain Risk","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-21","description":"Subservice organizations relevant to user entities' control objectives are identified, contractually bound to security and processing commitments, and monitored through review of their independent assurance reports, complementary user-entity controls, and performance. Identified issues are tracked to resolution.","details":{"control_category":"administrative","control_type":"preventive","domain":"Third-Party / Supply-Chain Risk","guidance":[],"members":[{"control_id":"SOC1-12","coverage":"full","framework":"soc1","relationship":"equal"}],"statement":"Subservice organizations relevant to user entities' control objectives are identified, contractually bound to security and processing commitments, and monitored through review of their independent assurance reports, complementary user-entity controls, and performance. Identified issues are tracked to resolution.","title":"Manage subservice organizations supporting the system","unified_id":"UC-ACCESS-21"},"id":"uc:UC-ACCESS-21","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-21","sourceIds":["soc1"],"sourceUrl":null,"title":"UC-ACCESS-21 — Manage subservice organizations supporting the system","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1453ec0d0a9b31e2eb4d51ab3c43a632bc169a42bdb8336f101fea32af775363","properties":{"control_id":"SOC1-12","coverage":"full","delta":null,"framework":"soc1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"equal","source_version":"SSAE 18 (current AICPA SOC suite)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-21-14f45683.json","sourceId":"uc:UC-ACCESS-21","targetDetailPath":"/data/v1/records/ctrl-soc1-soc1-12-05ba06e4.json","targetId":"ctrl:soc1:SOC1-12","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:655a4dbde047661949b09ea891bf5bb39b0271c054f57adb428792555462aca6","properties":{},"sourceDetailPath":"/data/v1/records/wf-g24-104b8991.json","sourceId":"wf:G24","targetDetailPath":"/data/v1/records/uc-uc-access-21-14f45683.json","targetId":"uc:UC-ACCESS-21","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:76a4e1c2a4f383ce40ca8095cb9fda7bd0453ecfd99af9a3490c6b1b842625af","properties":{},"sourceDetailPath":"/data/v1/records/wf-d40-de759eff.json","sourceId":"wf:D40","targetDetailPath":"/data/v1/records/uc-uc-access-21-14f45683.json","targetId":"uc:UC-ACCESS-21","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7cb4621e282fb8493f21c6f44baa80e4a8767e56374ab0e90f7848b6eaefe762","properties":{},"sourceDetailPath":"/data/v1/records/wf-d32-3114234e.json","sourceId":"wf:D32","targetDetailPath":"/data/v1/records/uc-uc-access-21-14f45683.json","targetId":"uc:UC-ACCESS-21","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8aa481877a788d7863fea791d7cbf6befa77c3757189e083d3cfb4460dfe706e","properties":{"rationale":"Monitoring critical subservice-org performance and assurance gives early warning of a deteriorating dependency, reducing failure impact.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-21-14f45683.json","sourceId":"uc:UC-ACCESS-21","targetDetailPath":"/data/v1/records/risk-tprm-critical-vendor-failure-cb39c2bc.json","targetId":"risk:tprm-critical-vendor-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9fa29ccebc41285b7d7e131549969223866feaf6f861f1d6a7a5cc046b8a7cd9","properties":{},"sourceDetailPath":"/data/v1/records/wf-g40-988cd40b.json","sourceId":"wf:G40","targetDetailPath":"/data/v1/records/uc-uc-access-21-14f45683.json","targetId":"uc:UC-ACCESS-21","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:af910a9af8c30042de1c8f34c929a5e7453706e1ba5b60bf791f0dd6b71c2e91","properties":{"rationale":"Managing subservice (fourth-party) orgs and reviewing their assurance reports reduces the N-tier opacity that drives vicarious-liability exposure.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-21-14f45683.json","sourceId":"uc:UC-ACCESS-21","targetDetailPath":"/data/v1/records/risk-tprm-vendor-compliance-vicarious-liability-0215657c.json","targetId":"risk:tprm-vendor-compliance-vicarious-liability","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b6cdcd8fe386d6c033b5cf3e139295c50ec3fb0139ce7f5fe959466897e63102","properties":{"rationale":"Identifying, contractually binding, and monitoring subservice orgs via their assurance reports and CUECs directly closes the unmonitored, unbound third-party gap this risk describes.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-21-14f45683.json","sourceId":"uc:UC-ACCESS-21","targetDetailPath":"/data/v1/records/risk-tprm-weak-supplier-oversight-1baaa012.json","targetId":"risk:tprm-weak-supplier-oversight","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bf4c143c58a1b72925f975d8166a806c340c17b07e1a326580e29b6ae1452329","properties":{},"sourceDetailPath":"/data/v1/records/wf-d56-387bb72b.json","sourceId":"wf:D56","targetDetailPath":"/data/v1/records/uc-uc-access-21-14f45683.json","targetId":"uc:UC-ACCESS-21","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e4108943d1f1c15ca0c7275f293b222e822ff203fb4d6b95d07e4f3526081a78","properties":{},"sourceDetailPath":"/data/v1/records/wf-g13-0f34ff59.json","sourceId":"wf:G13","targetDetailPath":"/data/v1/records/uc-uc-access-21-14f45683.json","targetId":"uc:UC-ACCESS-21","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ea36e63f05373b1cc6c2191a77e284fd94ba2350bf917b8770ecedea4803659f","properties":{},"sourceDetailPath":"/data/v1/records/wf-c11-f590792c.json","sourceId":"wf:C11","targetDetailPath":"/data/v1/records/uc-uc-access-21-14f45683.json","targetId":"uc:UC-ACCESS-21","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f479ce0b4244aed02d135f5f4f2c664d09b05759e1b2aea66292db7cd8b0f346","properties":{"rationale":"Monitoring subservice-org performance against commitments and tracking identified issues to resolution directly detects and remediates service non-performance.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-21-14f45683.json","sourceId":"uc:UC-ACCESS-21","targetDetailPath":"/data/v1/records/risk-tprm-vendor-service-nonperformance-081f2fb9.json","targetId":"risk:tprm-vendor-service-nonperformance","type":"mitigates"}],"schemaVersion":1}
