Ask the Assessors - CMMC Edition! Join us Thursday, December 14th @ 1:00 PM (EST)

Services
Services
SOC & Attestations
SOC & Attestations
Payment Card Assessments
Payment Card Assessments
ISO Certifications
ISO Certifications
Privacy Assessments
Privacy Assessments
Federal Assessments
Federal Assessments
Healthcare Assessments
Healthcare Assessments
Penetration Testing
Penetration Testing
Cybersecurity Assessments
Cybersecurity Assessments
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
ESG & Sustainability
ESG & Sustainability
Industry Solutions
Industry Solutions
Cloud Computing & Data Centers
Cloud Computing & Data Centers
Financial Services & Fintech
Financial Services & Fintech
Healthcare
Healthcare
Payment Card Processing
Payment Card Processing
US Government
US Government
Higher Education & Research Laboratories
Higher Education & Research Laboratories
About Us
About Us
Leadership Team
Leadership Team
Careers
Careers
Corporate Social Responsibility
Corporate Social Responsibility
Strategic Partnerships
Strategic Partnerships

Formal Risk Assessment Before Our SOC 1?

SOC & Attestations

Do we have to go through a formal risk assessment before our SOC 1?

No, a formal or informal process for identifying relevant risks can be completed (ref paragraph .A18). Per the Standard:

“Because control objectives relate to the risks that controls seek to mitigate, … management’s thoughtful identification of the control objectives when designing, implementing, and documenting the service organization’s system may itself comprise an informal process for identifying relevant risks.”

The system description (narrative or body of the SOC report) will include a description of the risk assessment process at the service organization. Although the SOC 1 does not require a formal risk assessment process to be completed, other compliance, attestation, and certification initiatives may require a more formal risk assessment process to be performed, and management should take this into consideration when deciding the scope and formality of their risk assessment process.

About LAUREN EDMONDS

Lauren is a Principal at Schellman with over 10 years of attestation and compliance experience. Lauren has evaluated risks and controls for a number of industries including financial services, manufacturing, marketing, distribution and service-based organizations.