Skip to content

Platform · Control library and framework mapping

One control library, mapped across your frameworks, with the gaps left visible.

The control library holds more than 2,800 control objectives across more than 50 framework packs, from BSA/AML and sanctions to PCI DSS and information security, and shows where an objective in one framework maps to objectives in another. Where no mapping exists, the objective is shown as unmapped. A document request list tells you, piece by piece, what evidence you hold and what you still need.

The problem it removes

The same control, documented three times, and a crosswalk nobody trusts

  • Your bank partner asks for SOC 2, a card program asks for PCI, and your examiner asks about the AML program. Each request starts a new spreadsheet.
  • Crosswalks bought or copied from elsewhere mark everything as covered, so the objective with no matching control is the one nobody sees.
  • Before an audit, the question "what evidence do we still need" takes a week of email to answer.

What you see

Coverage by framework, and the unmapped ones named

For each framework pack, you see how many objectives are mapped across to other frameworks and which aren't. Objectives without a crosswalk are listed as unmapped rather than counted as covered.

Control EV-07 · Access to production systems reviewed quarterlySample data
FrameworkObjectiveMapping
NYDFS cybersecurity23 NYCRR 500.7Mapped
PCI DSS7.2.4Mapped
GLBA Safeguards Rule16 CFR 314.4(c)(1)Unmapped no crosswalk
Evidence requestedStatus
Q2 access review sign-offHeld uploaded 2026-07-08
List of users with production accessHeld export 2026-07-01
Q3 access review sign-offNeeded

Illustrative example with invented data. The framework references are real; the control and the evidence aren't.

How it works

Choose, map, request, review

  1. Choose your frameworks. Pick the packs you answer to. Each objective ties back to the requirements in your regulatory inventory.
  2. Map. The crosswalk between frameworks is written down, not inferred. A mapping either exists or the objective is marked unmapped. No model creates a mapping.
  3. Request evidence. A document request list names each piece of evidence each control needs and marks it held or needed as your exports and files come in.
  4. Review. A practitioner reviews the mappings that matter to your engagement and the evidence against them before any control is tested or any report is signed.

Inside an engagement, a control tested once can stand as evidence for every framework it maps to. That reuse is done by the practitioner running the engagement.

Guardrails

What it will never do

  • Reusing one test across frameworks isn't a feature you switch on alone. It happens inside an engagement, under a practitioner.
  • It doesn't hide an unmapped objective to make coverage look complete. Every one is listed.

Where it shows up

The work this part does for you

Plain English

What this is, and how anyone does it

Reference articles from our library, cited to the published rules and standards. No sales copy.

Connected parts

What it works with

See the whole platform

Talk to a practitioner

Book a 15-minute chat with our founder.

A real conversation with a senior compliance leader, to see if there's a fit. Not a sales call, not a demo, no pressure.