QuartzIQ
    Use Case

    Regulations & Standards Library

    Hold the regulations and standards you answer to in one library, mapped once onto the controls that already satisfy them, so a new text is a mapping exercise over existing coverage rather than a programme of its own.

    One library of the regulations and standards you answer to, mapped onto the controls that already satisfy them, so a new text is a mapping exercise rather than a programme.

    Book a Demo

    The Challenge

    Common challenges faced by organizations

    Every new regulation starts over

    Each new text begins a fresh mapping exercise across controls that already exist and already satisfy most of it.

    Obligations sit away from the controls that meet them

    Framework, assessment, testing and audit are owned by different teams, which is why they drift apart and why coverage cannot be shown on demand.

    Regulatory reporting is assembled by hand

    Returns are built from exports each period, so the effort recurs and the numbers cannot be traced back to anything.

    Nobody can show current coverage

    Answering a supervisor means reconstructing the position from several systems rather than reading it.

    How QuartzIQ Solves This

    Streamline your regulations & standards library with powerful automation

    Regulations and standards held in one library

    The texts you answer to are inventoried in one place, versioned as they change, rather than tracked in parallel by each team.

    Mapped once onto existing controls

    Requirements attach to the controls that already evidence them, so a new obligation inherits the coverage it already has.

    One control, several frameworks

    A control documented once can evidence more than one obligation, so overlap between texts is reused instead of rebuilt.

    Coverage readable per perimeter

    What each regulation requires and what actually covers it can be read on the perimeter it applies to.

    What the library holds

    Regulations, standards and laws by domain and by industry, across the jurisdictions you answer to.

    Information security & cyber

    Cross-industry security frameworks, and the certifications customers and auditors ask for first.

    • ISO/IEC 27001

      Information security management systems

      International
    • ISO/IEC 27002

      Information security controls

      International
    • ISO/IEC 27017 & 27018

      Cloud security and personal data in the cloud

      International
    • NIST Cybersecurity Framework 2.0

      Govern, identify, protect, detect, respond, recover

      United States
    • NIST SP 800-53

      Security and privacy controls

      United States
    • CIS Critical Security Controls

      Prioritised cyber defence safeguards

      International
    • SOC 2

      AICPA Trust Services Criteria

      United States
    • NIS2 Directive

      Cybersecurity of essential and important entities

      EU
    • Cyber Resilience Act

      Security requirements for products with digital elements

      EU
    • Cyber Essentials

      Baseline technical controls

      United Kingdom

    Privacy & data protection

    Personal data laws across the jurisdictions you operate in, and the standards that operationalise them.

    • GDPR

      General Data Protection Regulation

      EU
    • UK GDPR & Data Protection Act 2018

      Post-Brexit data protection regime

      United Kingdom
    • Law 25

      Modernised protection of personal information in the private sector

      Québec
    • PIPEDA

      Federal private-sector privacy law

      Canada
    • CCPA / CPRA

      California consumer privacy rights

      United States
    • LGPD

      Brazilian General Data Protection Law

      Brazil
    • ePrivacy Directive

      Confidentiality of communications and cookies

      EU
    • ISO/IEC 27701

      Privacy information management

      International

    Operational resilience & continuity

    Rules on staying up through disruption, and on the third parties your critical services depend on.

    • DORA

      Digital Operational Resilience Act

      EU
    • ISO 22301

      Business continuity management systems

      International
    • OSFI Guideline E-21

      Operational risk management and resilience

      Canada
    • OSFI Guideline B-10

      Third-party risk management

      Canada
    • PRA SS1/21

      Operational resilience: impact tolerances for important business services

      United Kingdom
    • BCBS Principles for Operational Resilience

      Basel Committee principles

      International
    • EBA Guidelines on outsourcing

      Outsourcing arrangements

      EU

    AI & model risk

    The emerging body of AI law, and the model risk guidance that preceded it.

    • EU AI Act

      Risk-based regulation of AI systems

      EU
    • ISO/IEC 42001

      AI management systems

      International
    • ISO/IEC 23894

      AI risk management guidance

      International
    • NIST AI RMF

      AI Risk Management Framework

      United States
    • OSFI Guideline E-23

      Model risk management, including AI

      Canada
    • SR 11-7

      Federal Reserve guidance on model risk management

      United States

    Governance, risk & internal control

    The frameworks the risk, compliance and audit functions are themselves built on.

    • COSO Internal Control

      Integrated Framework

      International
    • COSO ERM

      Enterprise risk management

      International
    • ISO 31000

      Risk management guidelines

      International
    • ISO 37301

      Compliance management systems

      International
    • Sarbanes-Oxley Act

      Internal control over financial reporting (s.302, s.404)

      United States
    • NI 52-109

      Certification of disclosure in issuers’ filings

      Canada
    • COBIT 2019

      Governance of enterprise IT

      International
    • IIA Global Internal Audit Standards

      Professional standards for internal audit

      International
    • IIA Three Lines Model

      Roles across management, oversight and assurance

      International

    Banking & capital markets

    Prudential and supervisory texts for banks, investment firms and market participants.

    • Basel III / CRR & CRD

      Capital, liquidity and governance requirements

      EU
    • BCBS 239

      Risk data aggregation and risk reporting

      International
    • Arrêté du 3 novembre 2014

      Internal control of banking-sector firms

      France
    • EBA Guidelines on internal governance

      Governance arrangements and internal control

      EU
    • MiFID II / MiFIR

      Markets in financial instruments

      EU
    • OSFI Guideline B-13

      Technology and cyber risk management

      Canada
    • OSFI Corporate Governance Guideline

      Board and senior management expectations

      Canada
    • NYDFS 23 NYCRR 500

      Cybersecurity requirements for financial services

      United States
    • FFIEC IT Examination Handbook

      IT examination guidance for US institutions

      United States
    • Gramm-Leach-Bliley Act

      Safeguards Rule and financial privacy

      United States
    • SM&CR

      Senior Managers and Certification Regime

      United Kingdom

    Insurance

    Solvency, own-risk assessment and conduct rules for insurers and intermediaries.

    • Solvency II

      Prudential regime, including the system of governance

      EU
    • IAIS Insurance Core Principles

      Global supervisory standards

      International
    • ORSA

      Own Risk and Solvency Assessment

      International
    • OSFI Guideline E-19

      Own Risk and Solvency Assessment

      Canada
    • Insurance Distribution Directive

      Distribution and conduct rules

      EU
    • NAIC Insurance Data Security Model Law

      Information security programme for licensees

      United States

    Financial crime & anti-corruption

    Anti-money laundering, sanctions and anti-bribery obligations, most of which apply well beyond financial services.

    • FATF Recommendations

      International AML/CFT standards

      International
    • EU AML package (AMLR, AMLD6)

      Anti-money laundering rulebook and AMLA

      EU
    • PCMLTFA

      Proceeds of Crime (Money Laundering) and Terrorist Financing Act

      Canada
    • Bank Secrecy Act

      AML programme and reporting

      United States
    • OFAC sanctions

      Economic and trade sanctions compliance

      United States
    • Sapin II

      Anti-corruption programme requirements

      France
    • UK Bribery Act

      Adequate procedures to prevent bribery

      United Kingdom
    • FCPA

      Foreign Corrupt Practices Act

      United States
    • ISO 37001

      Anti-bribery management systems

      International

    Payments & digital assets

    Card, payment and crypto-asset rules for issuers, processors and payment service providers.

    • PCI DSS

      Payment Card Industry Data Security Standard

      International
    • PSD2

      Payment Services Directive, including strong customer authentication

      EU
    • MiCA

      Markets in Crypto-Assets Regulation

      EU
    • Retail Payment Activities Act

      Operational risk and fund safeguarding for PSPs

      Canada
    • SWIFT Customer Security Programme

      Customer Security Controls Framework

      International

    Healthcare & life sciences

    Health information privacy, hosting and the quality rules regulated products are made under.

    • HIPAA

      Privacy, Security and Breach Notification Rules

      United States
    • HITECH Act

      Health IT and breach enforcement

      United States
    • PHIPA

      Personal Health Information Protection Act

      Ontario
    • HDS

      Health data hosting certification

      France
    • HITRUST CSF

      Health-sector security framework

      United States
    • 21 CFR Part 11

      Electronic records and signatures (FDA)

      United States
    • EU GMP Annex 11

      Computerised systems

      EU
    • ISO 13485

      Medical devices quality management

      International
    • EU MDR

      Medical Device Regulation

      EU

    Energy, utilities & critical infrastructure

    Security and resilience obligations for operators whose failure is felt outside their own walls.

    • NERC CIP

      Critical infrastructure protection for the bulk electric system

      United States
    • IEC 62443

      Industrial automation and control systems security

      International
    • CER Directive

      Resilience of critical entities

      EU
    • TSA Security Directives

      Pipeline and rail cybersecurity

      United States
    • Loi de programmation militaire

      Security obligations of operators of vital importance

      France
    • KRITIS / BSI Act

      Critical infrastructure security

      Germany

    Public sector & defence

    The authorisation and assurance regimes for selling into government and its supply chain.

    • FedRAMP

      Federal cloud service authorisation

      United States
    • FISMA

      Federal information security

      United States
    • NIST SP 800-171

      Protecting controlled unclassified information

      United States
    • CMMC 2.0

      Cybersecurity Maturity Model Certification

      United States
    • ITSG-33

      IT security risk management lifecycle

      Canada
    • SecNumCloud

      ANSSI trusted cloud qualification

      France
    • RGS

      Référentiel général de sécurité

      France

    ESG & sustainability

    Sustainability reporting, climate risk and supply-chain due diligence.

    • CSRD & ESRS

      Corporate sustainability reporting

      EU
    • ISSB IFRS S1 & S2

      Sustainability and climate-related disclosures

      International
    • TCFD

      Climate-related financial disclosures

      International
    • EU Taxonomy

      Classification of sustainable activities

      EU
    • SFDR

      Sustainability disclosures in financial services

      EU
    • CSDDD

      Corporate sustainability due diligence

      EU
    • Loi sur le devoir de vigilance

      Duty of vigilance for large companies

      France
    • OSFI Guideline B-15

      Climate risk management

      Canada
    • Fighting Against Forced Labour and Child Labour in Supply Chains Act

      Supply-chain reporting (S-211)

      Canada
    • GRI Standards

      Sustainability reporting standards

      International
    • ISO 14001

      Environmental management systems

      International

    Conduct & consumer protection

    How customers are treated, what they are told, and what they can access.

    • FCA Consumer Duty

      Good outcomes for retail customers

      United Kingdom
    • UDAAP

      Unfair, deceptive or abusive acts or practices

      United States
    • Financial Consumer Protection Framework

      Bank Act consumer provisions

      Canada
    • Digital Services Act

      Obligations of online intermediaries and platforms

      EU
    • European Accessibility Act

      Accessibility of products and services

      EU

    Quality & management systems

    The ISO management system family, which shares one structure and so maps onto the same controls.

    • ISO 9001

      Quality management systems

      International
    • ISO/IEC 20000-1

      IT service management

      International
    • ISO 45001

      Occupational health and safety

      International
    • ISO 28000

      Supply chain security management

      International

    Examples, not a closed list: any text you answer to can be added to the library and mapped onto the controls that meet it.

    Key Benefits

    Advantages of implementing our solution

    A new text is a mapping, not a programme

    Most of what a new regulation asks for is already running; the work is showing which controls answer it.

    Answers without reconstruction

    Supervisory questions are answered from the framework rather than by assembling exports from several systems.

    Evidence that traces back

    Every claim of coverage points at the control that produces the evidence, and at the perimeter that owns it.

    Ready to modernize your regulations & standards library?

    Schedule a personalized demo to see how our solution can address your specific needs.

    Book a Demo

    Security and compliance

    • SOC 2 Type IIAudited by Sensiba LLP.
    • ISO/IEC 27001Certified by Sensiba LLP, an ANAB-accredited certification body.
    • GDPRCompliant with the EU General Data Protection Regulation.
    • PIPEDAReady for Canada's Personal Information Protection and Electronic Documents Act.

    Reports available upon request