COSO Principle 8 — The entity considers the potential for fraud in assessing risks to the achievement of objectives.
Also written as CC 3.3, TSC CC3.3, SOC2 CC3.3, SOC 2 Type 2 CC3.3.
Fraud risk assessment is one of 4 criteria in the Risk Assessment (CC3) series of the Security (Common Criteria) category. COSO Principle 8 — The entity considers the potential for fraud in assessing risks to the achievement of objectives. CC3 evidence is your risk assessment itself — auditors check that it is current, that it considers fraud, and that identified risks visibly drive the controls tested elsewhere in the report.
When preparing for a SOC 2 audit against CC3.3, gather artefacts such as:
CC3.3 has no clean one-to-one ISO 27001:2022 Annex A equivalent — it is largely a governance or reporting expectation that ISO 27001 handles through the management-system clauses (4–10) rather than an Annex A control. Treat it as its own requirement rather than assuming ISMS evidence covers it.
All CC3 Risk Assessment criteria →
Yes. CC3.3 sits in the Common Criteria, which apply to every SOC 2 engagement regardless of which additional categories you scope in — there is no SOC 2 report that omits them.
In a Type 1 report the auditor assesses design only — does a control exist at a point in time that would meet CC3.3 if it operated. In a Type 2 report they also test operating effectiveness by sampling evidence from across the review period, typically 3 to 12 months. That difference is why Type 2 evidence has to be continuous rather than assembled the week before fieldwork.
A control that fails becomes an exception, which the auditor describes in the report along with management's response. Exceptions do not automatically make a report "failed" — a SOC 2 report is an opinion, not a pass/fail certificate — but a qualified opinion is what customers notice, so remediate and re-test before fieldwork closes where you can.