TPR-215Third-Party & Supply Chain Risk

Handling CUECs: Turning Complementary User Entity Controls Into Your Own Obligations

Every SOC report hands you controls you're expected to run. Turn complementary user entity controls into your own obligations, with owners and evidence.

6 lessons About 3 hours 2 ALCs Certificate on completion

What you'll be able to do

  • Find every complementary user entity control in your vendors' reports
  • Map each one to an internal control
  • Assign an owner and the evidence that proves it runs
  • Close the gaps auditors find when CUECs are ignored
You finish with

A CUEC register for your critical vendors

What's in it. Every complementary control from your critical vendors, mapped to an internal control, an owner and evidence.

You build it lesson by lesson, using your own organization, and submit it for your certificate. It's yours to keep and adapt.

Who it's for

Vendor risk, GRC and IT teams that rely on SOC reports from critical vendors.

What's inside

  1. Part 1Where the requirement comes from 18 min
  2. Part 2How small teams and enterprises meet it 17 min
  3. Part 3The method, step by step 20 min
  4. Part 4Hands-on lab: small team choose one 60 min
  5. Part 5Hands-on lab: enterprise choose one 120 min
  6. Part 6Finish and submit your deliverable 16 min

Built for your size

The requirement is the same everywhere. How you meet it depends on who you have. You pick the lab that matches your organization.

Small team or early-stageThree vendors, fifteen CUECs, mostly about access.
EnterpriseHundreds of CUECs feeding the control library and the risk register.

How you earn the certificate

Submit your finished deliverable, which is scored against a published rubric, and pass a short scenario quiz. Your certificate goes to your wallet and can be checked by anyone on the public register.

Ready to build a CUEC register for your critical vendors?6 lessons, about 3 hours. Start whenever you're ready.
Join and enroll