{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Risk Assessment & Management","type":"detective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-RISK-12","description":"A documented fraud risk assessment considers fraudulent reporting, asset misappropriation, and corruption, evaluating incentives, pressures, opportunities, and rationalizations, and explicitly addresses the risk of management override of controls. Specific anti-override controls operate, including review of journal entries and significant estimates at an appropriate level of precision. The assessment and mitigating controls are refreshed at least annually with documented results.","details":{"control_category":"administrative","control_type":"detective","domain":"Risk Assessment & Management","guidance":[],"members":[{"control_id":"CC3.3","coverage":"full","framework":"soc2","relationship":"superset_of"},{"control_id":"P8","coverage":"full","framework":"coso-ic","relationship":"superset_of"},{"control_id":"ELC-MGMT-OVR","coverage":"full","framework":"sox","relationship":"superset_of"}],"statement":"A documented fraud risk assessment considers fraudulent reporting, asset misappropriation, and corruption, evaluating incentives, pressures, opportunities, and rationalizations, and explicitly addresses the risk of management override of controls. Specific anti-override controls operate, including review of journal entries and significant estimates at an appropriate level of precision. The assessment and mitigating controls are refreshed at least annually with documented results.","title":"Assess and mitigate fraud risk including management override","unified_id":"UC-RISK-12"},"id":"uc:UC-RISK-12","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-RISK-12","sourceIds":["coso-ic","soc2","sox"],"sourceUrl":null,"title":"UC-RISK-12 — Assess and mitigate fraud risk including management override","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8846a3876f3031f025badfe8e50998bdfeb21e5875852c8e41a301de7d4ac2cc","properties":{"rationale":"Fraud risk assessment plus anti-override controls (journal-entry and significant-estimate review) directly detect and deter employee embezzlement, forgery and unauthorized disbursements.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-12-210e108b.json","sourceId":"uc:UC-RISK-12","targetDetailPath":"/data/v1/records/risk-fraud-internal-misappropriation-d235cd10.json","targetId":"risk:fraud-internal-misappropriation","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a4da889c3e8d9a23cacd902b671a9a5be1365ce9c64cb898768e45d8f0589034","properties":{"control_id":"P8","coverage":"full","delta":null,"framework":"coso-ic","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2013"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-12-210e108b.json","sourceId":"uc:UC-RISK-12","targetDetailPath":"/data/v1/records/ctrl-coso-ic-p8-e85b1bf7.json","targetId":"ctrl:coso-ic:P8","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a69d357cd19c13d44567d4318ca1862b4b8b09a41535dbfdc7fea1093ab236f5","properties":{"rationale":"Journal-entry and precision estimate review detect the mismarking and fictitious bookings used to conceal unauthorized/rogue positions (complements trading-limit controls).","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-12-210e108b.json","sourceId":"uc:UC-RISK-12","targetDetailPath":"/data/v1/records/risk-fraud-unauthorized-trading-activity-e5d9d4b9.json","targetId":"risk:fraud-unauthorized-trading-activity","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bc7fee09d5235e76437b44f81717b2b4cf31f6ef9114448f4a5b4bb6a617b765","properties":{"control_id":"ELC-MGMT-OVR","coverage":"full","delta":null,"framework":"sox","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SOX §302/§404 (2002), PCAOB AS 2201"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-12-210e108b.json","sourceId":"uc:UC-RISK-12","targetDetailPath":"/data/v1/records/ctrl-sox-elc-mgmt-ovr-cd342100.json","targetId":"ctrl:sox:ELC-MGMT-OVR","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c29c8423d2c4d92550313926b5cb1d1a71673a0f131d84a3c3fc11b42876ff67","properties":{},"sourceDetailPath":"/data/v1/records/wf-a15-e859f6b8.json","sourceId":"wf:A15","targetDetailPath":"/data/v1/records/uc-uc-risk-12-210e108b.json","targetId":"uc:UC-RISK-12","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c7cf1c0bf23d8d13177655b0fbe3a61a49f27bd89e1ea10b86c89d71117aa063","properties":{},"sourceDetailPath":"/data/v1/records/wf-s10-d9231db2.json","sourceId":"wf:S10","targetDetailPath":"/data/v1/records/uc-uc-risk-12-210e108b.json","targetId":"uc:UC-RISK-12","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ea943c0a016fd53ff5a51c77514c247b92c3e81bb00f580878b9a66411e142a1","properties":{"control_id":"CC3.3","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-12-210e108b.json","sourceId":"uc:UC-RISK-12","targetDetailPath":"/data/v1/records/ctrl-soc2-cc3-3-ae6eeb77.json","targetId":"ctrl:soc2:CC3.3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f9bd9bbad267b896fe4c0e1a8a041ec566590c53f7c85ef897ecf0172e2586dd","properties":{},"sourceDetailPath":"/data/v1/records/wf-s1-ee2f3289.json","sourceId":"wf:S1","targetDetailPath":"/data/v1/records/uc-uc-risk-12-210e108b.json","targetId":"uc:UC-RISK-12","type":"oversees"}],"schemaVersion":1}
