Risk identification and analysis
Summary
The entity identifies risks to the achievement of its objectives across the entity and analyses risks as a basis for determining how the risks should be managed.
risk assessmentrisk analysis
Read the full official text: https://www.aicpa-cima.com/resources/download/2022-trust-services-criteria
Track SOC 2 criterion CC3.2 as evidence
eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.
Start free trial