CC9.1
Risk Mitigation
SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified August 2026
Objective
Identify risks that could disrupt objectives and select mitigation activities, including insurance, diversification, acceptance, or changes to operations.
Points of focus
- Connect each material risk to a named response and owner
- Consider mitigation choices beyond preventive security controls
- Track residual risk after the selected response operates
Implementation notes
Tie product, infrastructure, financial, and dependency risks to concrete response tickets; require an accountable executive to approve residual exposure and revisit it after architecture or customer-volume changes. Operationalize connect each material risk to a named response and owner in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain risk register showing response, owner, due date, and residual rating with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that high risks remain listed with no funded treatment or explicit acceptance Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample risk register showing response, owner, due date, and residual rating with dates and named reviewers. Be ready to walk through how you detect and correct: high risks remain listed with no funded treatment or explicit acceptance
Evidence auditors typically request:
- Risk register showing response, owner, due date, and residual rating
- Executive risk acceptance or mitigation approval records
- Business continuity, insurance, or concentration-risk review artifacts
Common gaps
- High risks remain listed with no funded treatment or explicit acceptance
- Insurance is cited as mitigation without checking exclusions against the SaaS loss scenario
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| SOC 2 | CC9.1 | This control |
| ISO 27001 | A.5.29, A.5.30 | ISO business continuity and ICT readiness themes support mitigation planning. |
| HIPAA | §164.308(a)(1) | HIPAA risk analysis informs which residual risks are reasonable to accept. |
| GDPR | Article 32 | GDPR accountability expects documented risk treatment for personal-data processing. |
Primary sources
- AICPA Trust Services Criteria: AICPA TSP Section 100 — 2017 Trust Services Criteria with 2022 Revised Points of Focus