Platform · Control library and framework mapping
One control library, mapped across your frameworks, with the gaps left visible.
The control library holds more than 2,800 control objectives across more than 50 framework packs, from BSA/AML and sanctions to PCI DSS and information security, and shows where an objective in one framework maps to objectives in another. Where no mapping exists, the objective is shown as unmapped. A document request list tells you, piece by piece, what evidence you hold and what you still need.
The problem it removes
The same control, documented three times, and a crosswalk nobody trusts
- Your bank partner asks for SOC 2, a card program asks for PCI, and your examiner asks about the AML program. Each request starts a new spreadsheet.
- Crosswalks bought or copied from elsewhere mark everything as covered, so the objective with no matching control is the one nobody sees.
- Before an audit, the question "what evidence do we still need" takes a week of email to answer.
What you see
Coverage by framework, and the unmapped ones named
For each framework pack, you see how many objectives are mapped across to other frameworks and which aren't. Objectives without a crosswalk are listed as unmapped rather than counted as covered.
| Framework | Objective | Mapping |
|---|---|---|
| NYDFS cybersecurity | 23 NYCRR 500.7 | Mapped |
| PCI DSS | 7.2.4 | Mapped |
| GLBA Safeguards Rule | 16 CFR 314.4(c)(1) | Unmapped no crosswalk |
| Evidence requested | Status |
|---|---|
| Q2 access review sign-off | Held uploaded 2026-07-08 |
| List of users with production access | Held export 2026-07-01 |
| Q3 access review sign-off | Needed |
Illustrative example with invented data. The framework references are real; the control and the evidence aren't.
How it works
Choose, map, request, review
- Choose your frameworks. Pick the packs you answer to. Each objective ties back to the requirements in your regulatory inventory.
- Map. The crosswalk between frameworks is written down, not inferred. A mapping either exists or the objective is marked unmapped. No model creates a mapping.
- Request evidence. A document request list names each piece of evidence each control needs and marks it held or needed as your exports and files come in.
- Review. A practitioner reviews the mappings that matter to your engagement and the evidence against them before any control is tested or any report is signed.
Inside an engagement, a control tested once can stand as evidence for every framework it maps to. That reuse is done by the practitioner running the engagement.
Guardrails
What it will never do
- Reusing one test across frameworks isn't a feature you switch on alone. It happens inside an engagement, under a practitioner.
- It doesn't hide an unmapped objective to make coverage look complete. Every one is listed.
Where it shows up
The work this part does for you
Plain English
What this is, and how anyone does it
Reference articles from our library, cited to the published rules and standards. No sales copy.
- ReferenceControl Library and Framework Mapping (Crosswalks), ExplainedWhat a control library is, how frameworks are crosswalked, NIST CSF 2.0 informative references and NIST's mapping relationship types, SOC 2, COSO and PCI DSS v4.0.1 mappings, and the limits of testing once for several frameworks.
- ReferenceGRC (Governance, Risk and Compliance): Definition and FrameworksOCEG's definition and principled performance, the IIA Three Lines Model, the COSO frameworks, what GRC software holds, and the limits of a GRC program.
Connected parts
What it works with
Talk to a practitioner
Book a 15-minute chat with our founder.
A real conversation with a senior compliance leader, to see if there's a fit. Not a sales call, not a demo, no pressure.