unified
UC-RISK-10 — Maintain a risk register and report the portfolio view
A risk register records identified risks with analysis results, owners, treatment plans, and current status, and is updated on a defined cycle and upon significant change. Portfolio-level views aggregate risks across the entity and are reported to management and the board to support oversight and resource decisions. Register extracts and portfolio reports evidence operation.
In catalog since 2026-09-17T22:28:00Z · Last changed 2026-09-17T22:28:00Z (f368a6cce277)
Record JSON · Open in map · Data retrieval guide
Catalog revision: 791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4. A connection does not establish full coverage.
Attributes
- domain
- Risk Assessment & Management
- type
- detective
- category
- administrative
Details
- unified_id
- UC-RISK-10
- title
- Maintain a risk register and report the portfolio view
- statement
- A risk register records identified risks with analysis results, owners, treatment plans, and current status, and is updated on a defined cycle and upon significant change. Portfolio-level views aggregate risks across the entity and are reported to management and the board to support oversight and resource decisions. Register extracts and portfolio reports evidence operation.
- domain
- Risk Assessment & Management
- control_type
- detective
- control_category
- administrative
- members
- framework
- iso-31000
- control_id
- 31000-PR8
- coverage
- full
- relationship
- superset_of
- framework
- coso-erm
- control_id
- E14
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- Risk Register Intake oversees UC-RISK-10 — Maintain a risk register and report the portfolio view
- UC-RISK-10 — Maintain a risk register and report the portfolio view mitigates Inadequate or absent risk assessment process
- strength
- primary
- rationale
- A maintained risk register with status and portfolio reporting is the ongoing risk monitoring the risk describes as missing.
- UC-RISK-10 — Maintain a risk register and report the portfolio view maps_to 31000-PR8 — Recording and reporting
- framework
- iso-31000
- control_id
- 31000-PR8
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2018
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Enterprise Risk Assessment & Portfolio Oversight Cycle oversees UC-RISK-10 — Maintain a risk register and report the portfolio view
- Risk & Control Self-Assessment (RCSA) Program operates UC-RISK-10 — Maintain a risk register and report the portfolio view
- UC-RISK-10 — Maintain a risk register and report the portfolio view mitigates Failed M&A, integration or divestiture
- strength
- related
- rationale
- ERM Risk Identification & Register Refresh operates UC-RISK-10 — Maintain a risk register and report the portfolio view
- Enterprise Risk Treatment Operations Cycle operates UC-RISK-10 — Maintain a risk register and report the portfolio view
- Quarterly Board & Audit-Committee GRC Reporting oversees UC-RISK-10 — Maintain a risk register and report the portfolio view
- ISMS Risk Assessment & Treatment Cycle oversees UC-RISK-10 — Maintain a risk register and report the portfolio view
- UC-RISK-10 — Maintain a risk register and report the portfolio view maps_to E14 — Develops Portfolio View
- framework
- coso-erm
- control_id
- E14
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Enterprise Risk Register Lifecycle oversees UC-RISK-10 — Maintain a risk register and report the portfolio view