{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Risk Assessment & Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-RISK-11","description":"The organization identifies and assesses internal and external changes - new business models, leadership, systems, regulations, and operating environment - that could significantly affect its risk profile or system of internal control. Risk assessments and responses are updated dynamically as changes and emerging risks are detected. Change-triggered assessments and resulting updates are documented.","details":{"control_category":"administrative","control_type":"preventive","domain":"Risk Assessment & Management","guidance":[],"members":[{"control_id":"CC3.4","coverage":"full","framework":"soc2","relationship":"superset_of"},{"control_id":"P9","coverage":"full","framework":"coso-ic","relationship":"superset_of"},{"control_id":"E15","coverage":"full","framework":"coso-erm","relationship":"superset_of"},{"control_id":"31000-P5","coverage":"full","framework":"iso-31000","relationship":"superset_of"}],"statement":"The organization identifies and assesses internal and external changes - new business models, leadership, systems, regulations, and operating environment - that could significantly affect its risk profile or system of internal control. Risk assessments and responses are updated dynamically as changes and emerging risks are detected. Change-triggered assessments and resulting updates are documented.","title":"Assess changes that could significantly affect risk and control","unified_id":"UC-RISK-11"},"id":"uc:UC-RISK-11","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-RISK-11","sourceIds":["coso-erm","coso-ic","iso-31000","soc2"],"sourceUrl":null,"title":"UC-RISK-11 — Assess changes that could significantly affect risk and control","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:05da61c8ac5e2aa3719994605926d4cffefd674a114a63377a138d4262fa632c","properties":{"rationale":"Control assesses changes in the external operating environment; detecting geopolitical/macro shifts early enables risk-response updates that blunt operational impact.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-11-3f5d23ea.json","sourceId":"uc:UC-RISK-11","targetDetailPath":"/data/v1/records/risk-strategic-geopolitical-4e7aba30.json","targetId":"risk:strategic-geopolitical","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0be2c34465b299c94ca6af1affeb773f61d4e88ba0a1046a45cab8dd13a7a1aa","properties":{"control_id":"P9","coverage":"full","delta":null,"framework":"coso-ic","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2013"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-11-3f5d23ea.json","sourceId":"uc:UC-RISK-11","targetDetailPath":"/data/v1/records/ctrl-coso-ic-p9-8a96cb71.json","targetId":"ctrl:coso-ic:P9","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:108a3809a1bac8bc7cb9df10dcb04af91bb4cceb5fd8086da8cbfc0011a122c9","properties":{"control_id":"E15","coverage":"full","delta":null,"framework":"coso-erm","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-11-3f5d23ea.json","sourceId":"uc:UC-RISK-11","targetDetailPath":"/data/v1/records/ctrl-coso-erm-e15-7207b4fa.json","targetId":"ctrl:coso-erm:E15","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3c83d27d46c0508a1f21ca605e37869a18ecca86c2ddd41df9af37c3a25f6409","properties":{"control_id":"CC3.4","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-11-3f5d23ea.json","sourceId":"uc:UC-RISK-11","targetDetailPath":"/data/v1/records/ctrl-soc2-cc3-4-a6d03c70.json","targetId":"ctrl:soc2:CC3.4","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:442b214a3a15689767f0084c623fab429ea634cf1bc61a3b1a28a625c312b729","properties":{"control_id":"31000-P5","coverage":"full","delta":null,"framework":"iso-31000","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2018"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-11-3f5d23ea.json","sourceId":"uc:UC-RISK-11","targetDetailPath":"/data/v1/records/ctrl-iso-31000-31000-p5-f7cd76e5.json","targetId":"ctrl:iso-31000:31000-P5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4566ad6d964c2a80bd3ecb5f71f239b6d93d13d118be9f08e0ead1d452ffd81f","properties":{},"sourceDetailPath":"/data/v1/records/wf-r18-45ff4c37.json","sourceId":"wf:R18","targetDetailPath":"/data/v1/records/uc-uc-risk-11-3f5d23ea.json","targetId":"uc:UC-RISK-11","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:57702ef5e30ad07f33e36fec45854fda67abedb1a4c657f08a11ef16ea7b7a6f","properties":{},"sourceDetailPath":"/data/v1/records/wf-g22-87bce2d6.json","sourceId":"wf:G22","targetDetailPath":"/data/v1/records/uc-uc-risk-11-3f5d23ea.json","targetId":"uc:UC-RISK-11","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6b4a66550e01e8e2854f3b3d4aa96fa61b43572582716db62677d15e06e61337","properties":{},"sourceDetailPath":"/data/v1/records/wf-s7-e8f6281e.json","sourceId":"wf:S7","targetDetailPath":"/data/v1/records/uc-uc-risk-11-3f5d23ea.json","targetId":"uc:UC-RISK-11","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7440e568ab6699c38ac87ca174d8e8d042726f22c06bddc7d5cf228871944052","properties":{},"sourceDetailPath":"/data/v1/records/wf-r2-e4fb6250.json","sourceId":"wf:R2","targetDetailPath":"/data/v1/records/uc-uc-risk-11-3f5d23ea.json","targetId":"uc:UC-RISK-11","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7baae2a1e9851de38a5e8cd33e2cc9029d8ae59d389fc6c959495347b81aaf24","properties":{},"sourceDetailPath":"/data/v1/records/wf-a15-e859f6b8.json","sourceId":"wf:A15","targetDetailPath":"/data/v1/records/uc-uc-risk-11-3f5d23ea.json","targetId":"uc:UC-RISK-11","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:90878588df00f7d57db2d579ea31b5def525f8d552d2053df6dcd6a98660c2f3","properties":{"rationale":"Control explicitly assesses regulatory changes for risk impact; early detection of adverse law/policy change enables timely, less costly adaptation.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-11-3f5d23ea.json","sourceId":"uc:UC-RISK-11","targetDetailPath":"/data/v1/records/risk-compliance-regulatory-policy-change-9429f25b.json","targetId":"risk:compliance-regulatory-policy-change","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:987fcce26b6c52285e55cfebe60d060829208eb00c36446c6a988c9f8fdd0b3b","properties":{},"sourceDetailPath":"/data/v1/records/wf-r4-097c6fc4.json","sourceId":"wf:R4","targetDetailPath":"/data/v1/records/uc-uc-risk-11-3f5d23ea.json","targetId":"uc:UC-RISK-11","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c2bc58a06e1fd8882b07486282a6f880649a3f9e7e698b478d6a469c2bcc089e","properties":{"rationale":"Control assesses new systems/technologies for risk impact; flagging undiligenced emerging-tech adoption enables diligence reducing implementation and ethical exposure.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-11-3f5d23ea.json","sourceId":"uc:UC-RISK-11","targetDetailPath":"/data/v1/records/risk-strategic-innovation-emerging-tech-025a931b.json","targetId":"risk:strategic-innovation-emerging-tech","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c98795445743c24d23cfc5538bdae5421e3069dd02f7ea4b103338935c0afa52","properties":{},"sourceDetailPath":"/data/v1/records/wf-g36-fad03f41.json","sourceId":"wf:G36","targetDetailPath":"/data/v1/records/uc-uc-risk-11-3f5d23ea.json","targetId":"uc:UC-RISK-11","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e765cd097bbd92adeec23f4e2988d0b58ae3814132d8fd4cd82fba1d62079072","properties":{"rationale":"Control assesses new business models and emerging risks; early detection of disruptive industry/technology shifts enables response before the model is obsoleted.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-11-3f5d23ea.json","sourceId":"uc:UC-RISK-11","targetDetailPath":"/data/v1/records/risk-strategic-disruption-substitution-516d480f.json","targetId":"risk:strategic-disruption-substitution","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ebc31354714cf1a2b7c85859dae6d75775d5e89ace1fa30f55439ab8fecf03f3","properties":{},"sourceDetailPath":"/data/v1/records/wf-r3-be0f2e9a.json","sourceId":"wf:R3","targetDetailPath":"/data/v1/records/uc-uc-risk-11-3f5d23ea.json","targetId":"uc:UC-RISK-11","type":"oversees"}],"schemaVersion":1}
