cc3.1-4-001

CC3.1 · D4 · f1

D4
Difficulty
4
Gaps
1
Red Herrings
63%
Avg Score

Task

You are a SOC 2 auditor evaluating Vertex AI Corp's risk management controls under Trust Services Criteria CC3.1. Review all provided evidence documents to assess whether the organization's risk identification, assessment, and management processes are operating effectively. Evaluate the completeness of risk coverage, timeliness of risk reviews, adequacy of risk treatment, and governance oversight. Identify any gaps or deficiencies, but be careful to distinguish genuine gaps from risks that have been properly managed through formal exception and governance processes.

Evidence

Findings

IDTypeSeverityFinding
F-001red_herringlowRISK-014 Critical Risk Accepted Without Mitigation
RISK-014 (cross-border data transfer non-compliance) is rated Critical (Likelihood 4, Impact 5, Rating 20) with a treatment strategy of 'Accept.' This appears to be an unmitigated Critical risk. Howev...
F-002gaphighThree Risks Overdue for Quarterly Review
The risk management policy (Section 7.2) requires quarterly review of all risks by their owners. Three risks in the register have not been reviewed within the required quarterly cycle: RISK-008 (Softw...
F-003gaphighTwo High-Rated Risks Without Assigned Owners
The risk management policy (Section 3.2) requires that each identified risk must have a designated Risk Owner responsible for implementing treatment plans, monitoring risk indicators, and reporting st...
F-004gapmediumAnnual Risk Assessment Missing Supply Chain and AI/ML Risk Categories
The 2025 Annual Risk Assessment Report covers 15 risk categories but notably omits two categories that are highly relevant for a company named 'Vertex AI Corp' that develops AI/ML products: (1) AI/ML ...
F-005gapmediumRisk Assessment Report Staleness Approaching End of Validity
The annual risk assessment was completed in March 2025 and by the end of Q4 2025, the assessment is 9 months old. The policy requires annual risk assessments (Section 4.1, 'typically in Q1'), and the ...

Results

ModelProviderScoreRecallPrec.F1GapsReported
Sonnet 4.6Anthropic73%100%57%73%4/47
Opus 4.7Anthropic62%100%44%62%4/49
GPT-5.5OpenAI50%75%38%50%3/48
GPT-4.1OpenAI80%100%67%80%4/46
Haiku 4.5Anthropic67%75%60%67%3/45
GPT-4oOpenAI44%50%40%44%2/45