cc3.1-5-001

CC3.1 · D5 · f1

D5
Difficulty
5
Gaps
0
Red Herrings
23%
Avg Score

Task

You are a SOC 2 auditor evaluating Zenith Cloud's risk identification and assessment process for the Q4 2025 observation period (October 1 — December 31, 2025). Review the risk management policy, risk register, Security Governance Committee meeting minutes, and any supporting documentation. Assess whether CC3.1 requirements for risk identification and assessment are met. Identify any gaps, considering the adequacy of the risk assessment process, governance oversight, and whether the risk register accurately reflects the organization's risk posture.

Evidence

Findings

IDTypeSeverityFinding
F-001gapmediumRisk rating downgrades without documented justification in the register
Two risks were downgraded from High to Medium during Q4 2025: ZC-RISK-002 (cloud misconfiguration) and ZC-RISK-015 (phishing attack). The risk register's change_justification field is blank for ZC-RIS...
F-002gapmediumRisk register comprehensive update approaching staleness
The risk policy Section 4.2 requires a comprehensive risk assessment 'conducted annually, typically in Q1.' The risk register shows the last comprehensive review was February 15, 2025 — 10 months prio...
F-003gapmediumSGC reviewed only top 10 of 22 risks
The risk register contains 22 risks. The SGC Q4 meeting minutes show the committee reviewed only the 'top 10 risks by residual risk rating.' Twelve risks received no governance committee review during...
F-004gapmediumRisk matrix may understate catastrophic-impact risks
ZC-RISK-007 (insider threat — malicious data exfiltration) has likelihood=2 and impact=5. Per the 5x5 matrix in the risk policy, this maps to 'Medium.' However, impact=5 is defined as 'Catastrophic — ...
F-005gaplowNo formal emerging risk assessment conducted
The risk policy Section 7 describes an emerging risk identification process that includes 'quarterly threat landscape briefings,' 'industry peer benchmarking,' 'technology horizon scanning,' and 'regu...

Results

ModelProviderScoreRecallPrec.F1GapsReported
Sonnet 4.6Anthropic55%60%50%55%3/56
Opus 4.7Anthropic40%60%30%40%3/510
GPT-5.5OpenAI33%40%29%33%2/57
GPT-4.1OpenAI0%0%0%0%0/510
Haiku 4.5Anthropic12%60%7%12%3/546
GPT-4oOpenAI0%0%0%0%0/55