This objective confirms that your organization is not only documenting risk responses but actively carrying them out. Whether the decision was to mitigate, accept, transfer, or avoid a risk, this control verifies that those actions are being followed and tracked—especially for risks related to Controlled Unclassified Information (CUI).