This objective ensures your organization has formally documented the risks related to how Controlled Unclassified Information (CUI) is processed, stored, and transmitted. Assessors will expect to see evidence that risks were identified, evaluated, and tied to specific systems or workflows.