This objective ensures your organization has formally documented and is actively using a risk assessment process to evaluate potential threats to Controlled Unclassified Information (CUI). Assessors will expect to see a defined, repeatable process in writing—and evidence that it’s been followed.