CC3.3 CC3 · Risk Assessment · Security (Common Criteria)

CC3.3 — Fraud risk assessment

COSO Principle 8 — The entity considers the potential for fraud in assessing risks to the achievement of objectives.

Also written as CC 3.3, TSC CC3.3, SOC2 CC3.3, SOC 2 Type 2 CC3.3.

What SOC 2 CC3.3 requires

Fraud risk assessment is one of 4 criteria in the Risk Assessment (CC3) series of the Security (Common Criteria) category. COSO Principle 8 — The entity considers the potential for fraud in assessing risks to the achievement of objectives. CC3 evidence is your risk assessment itself — auditors check that it is current, that it considers fraud, and that identified risks visibly drive the controls tested elsewhere in the report.

Audit evidence assessors look for

When preparing for a SOC 2 audit against CC3.3, gather artefacts such as:

  • Fraud risk assessment records
  • Segregation-of-duties analysis
  • Anti-fraud controls documentation (approvals, reconciliations)
  • Whistleblower reports and investigation records

ISO 27001 mapping

CC3.3 has no clean one-to-one ISO 27001:2022 Annex A equivalent — it is largely a governance or reporting expectation that ISO 27001 handles through the management-system clauses (4–10) rather than an Annex A control. Treat it as its own requirement rather than assuming ISMS evidence covers it.

Map CC3.3 to ISO 27001 & NIST CSF →
Crosswalk this criterion in the Control Mapper & Gap Assessment.
Document the risk →
Record treatment for gaps against CC3.3 in the Risk Register.

Other Risk Assessment criteria

CC3.1 Objectives for risk assessment CC3.2 Risk identification and analysis CC3.4 Assessing significant change

All CC3 Risk Assessment criteria →

Frequently asked questions

Is CC3.3 required for a SOC 2 report?

Yes. CC3.3 sits in the Common Criteria, which apply to every SOC 2 engagement regardless of which additional categories you scope in — there is no SOC 2 report that omits them.

How does an auditor test CC3.3?

In a Type 1 report the auditor assesses design only — does a control exist at a point in time that would meet CC3.3 if it operated. In a Type 2 report they also test operating effectiveness by sampling evidence from across the review period, typically 3 to 12 months. That difference is why Type 2 evidence has to be continuous rather than assembled the week before fieldwork.

What happens if CC3.3 fails testing?

A control that fails becomes an exception, which the auditor describes in the report along with management's response. Exceptions do not automatically make a report "failed" — a SOC 2 report is an opinion, not a pass/fail certificate — but a qualified opinion is what customers notice, so remediate and re-test before fieldwork closes where you can.