The SOC 2 risk assessment
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 2 min read · SOC 2
The risk assessment is not paperwork for the auditor — it is supposed to explain why you chose the controls you did. Write it so it actually does that.
Why it is mandatory
The SOC 2 Common Criteria (CC3) require a risk assessment: the organisation identifies risks to achieving its objectives and decides how to manage them. It is the connective tissue that explains why your control set looks the way it does — without it, your controls are a checklist with no rationale.
A credible, lightweight version
List the real risks to your service — outage, data breach, insider misuse, vendor failure, key-person dependency. Rate each on likelihood and impact, decide a treatment (mitigate, accept, transfer), and name the control or action that addresses it. A clear spreadsheet that a stranger could follow beats a 40-page document nobody updates.
Keep it alive
A risk assessment dated once, two years ago, is a classic exception. Review it at least annually and when something material changes — a new product line, a major vendor, an incident. Record the review date and what changed. The cadence is the control as much as the content.
Make it drive decisions
The test auditors apply is whether the assessment actually shaped your program: did the high risks get controls, did an accepted risk get signed off by someone with authority. Tie each significant risk to the control that addresses it, and the assessment stops being theatre. SentinelPanda keeps the risk register linked to controls and prompts the annual review.