Hold the regulations and standards you answer to in one library, mapped once onto the controls that already satisfy them, so a new text is a mapping exercise over existing coverage rather than a programme of its own.
One library of the regulations and standards you answer to, mapped onto the controls that already satisfy them, so a new text is a mapping exercise rather than a programme.
Common challenges faced by organizations
Each new text begins a fresh mapping exercise across controls that already exist and already satisfy most of it.
Framework, assessment, testing and audit are owned by different teams, which is why they drift apart and why coverage cannot be shown on demand.
Returns are built from exports each period, so the effort recurs and the numbers cannot be traced back to anything.
Answering a supervisor means reconstructing the position from several systems rather than reading it.
Streamline your regulations & standards library with powerful automation
The texts you answer to are inventoried in one place, versioned as they change, rather than tracked in parallel by each team.
Requirements attach to the controls that already evidence them, so a new obligation inherits the coverage it already has.
A control documented once can evidence more than one obligation, so overlap between texts is reused instead of rebuilt.
What each regulation requires and what actually covers it can be read on the perimeter it applies to.
Regulations, standards and laws by domain and by industry, across the jurisdictions you answer to.
Cross-industry security frameworks, and the certifications customers and auditors ask for first.
ISO/IEC 27001
Information security management systems
ISO/IEC 27002
Information security controls
ISO/IEC 27017 & 27018
Cloud security and personal data in the cloud
NIST Cybersecurity Framework 2.0
Govern, identify, protect, detect, respond, recover
NIST SP 800-53
Security and privacy controls
CIS Critical Security Controls
Prioritised cyber defence safeguards
SOC 2
AICPA Trust Services Criteria
NIS2 Directive
Cybersecurity of essential and important entities
Cyber Resilience Act
Security requirements for products with digital elements
Cyber Essentials
Baseline technical controls
Personal data laws across the jurisdictions you operate in, and the standards that operationalise them.
GDPR
General Data Protection Regulation
UK GDPR & Data Protection Act 2018
Post-Brexit data protection regime
Law 25
Modernised protection of personal information in the private sector
PIPEDA
Federal private-sector privacy law
CCPA / CPRA
California consumer privacy rights
LGPD
Brazilian General Data Protection Law
ePrivacy Directive
Confidentiality of communications and cookies
ISO/IEC 27701
Privacy information management
Rules on staying up through disruption, and on the third parties your critical services depend on.
DORA
Digital Operational Resilience Act
ISO 22301
Business continuity management systems
OSFI Guideline E-21
Operational risk management and resilience
OSFI Guideline B-10
Third-party risk management
PRA SS1/21
Operational resilience: impact tolerances for important business services
BCBS Principles for Operational Resilience
Basel Committee principles
EBA Guidelines on outsourcing
Outsourcing arrangements
The emerging body of AI law, and the model risk guidance that preceded it.
EU AI Act
Risk-based regulation of AI systems
ISO/IEC 42001
AI management systems
ISO/IEC 23894
AI risk management guidance
NIST AI RMF
AI Risk Management Framework
OSFI Guideline E-23
Model risk management, including AI
SR 11-7
Federal Reserve guidance on model risk management
The frameworks the risk, compliance and audit functions are themselves built on.
COSO Internal Control
Integrated Framework
COSO ERM
Enterprise risk management
ISO 31000
Risk management guidelines
ISO 37301
Compliance management systems
Sarbanes-Oxley Act
Internal control over financial reporting (s.302, s.404)
NI 52-109
Certification of disclosure in issuers’ filings
COBIT 2019
Governance of enterprise IT
IIA Global Internal Audit Standards
Professional standards for internal audit
IIA Three Lines Model
Roles across management, oversight and assurance
Prudential and supervisory texts for banks, investment firms and market participants.
Basel III / CRR & CRD
Capital, liquidity and governance requirements
BCBS 239
Risk data aggregation and risk reporting
Arrêté du 3 novembre 2014
Internal control of banking-sector firms
EBA Guidelines on internal governance
Governance arrangements and internal control
MiFID II / MiFIR
Markets in financial instruments
OSFI Guideline B-13
Technology and cyber risk management
OSFI Corporate Governance Guideline
Board and senior management expectations
NYDFS 23 NYCRR 500
Cybersecurity requirements for financial services
FFIEC IT Examination Handbook
IT examination guidance for US institutions
Gramm-Leach-Bliley Act
Safeguards Rule and financial privacy
SM&CR
Senior Managers and Certification Regime
Solvency, own-risk assessment and conduct rules for insurers and intermediaries.
Solvency II
Prudential regime, including the system of governance
IAIS Insurance Core Principles
Global supervisory standards
ORSA
Own Risk and Solvency Assessment
OSFI Guideline E-19
Own Risk and Solvency Assessment
Insurance Distribution Directive
Distribution and conduct rules
NAIC Insurance Data Security Model Law
Information security programme for licensees
Anti-money laundering, sanctions and anti-bribery obligations, most of which apply well beyond financial services.
FATF Recommendations
International AML/CFT standards
EU AML package (AMLR, AMLD6)
Anti-money laundering rulebook and AMLA
PCMLTFA
Proceeds of Crime (Money Laundering) and Terrorist Financing Act
Bank Secrecy Act
AML programme and reporting
OFAC sanctions
Economic and trade sanctions compliance
Sapin II
Anti-corruption programme requirements
UK Bribery Act
Adequate procedures to prevent bribery
FCPA
Foreign Corrupt Practices Act
ISO 37001
Anti-bribery management systems
Card, payment and crypto-asset rules for issuers, processors and payment service providers.
PCI DSS
Payment Card Industry Data Security Standard
PSD2
Payment Services Directive, including strong customer authentication
MiCA
Markets in Crypto-Assets Regulation
Retail Payment Activities Act
Operational risk and fund safeguarding for PSPs
SWIFT Customer Security Programme
Customer Security Controls Framework
Health information privacy, hosting and the quality rules regulated products are made under.
HIPAA
Privacy, Security and Breach Notification Rules
HITECH Act
Health IT and breach enforcement
PHIPA
Personal Health Information Protection Act
HDS
Health data hosting certification
HITRUST CSF
Health-sector security framework
21 CFR Part 11
Electronic records and signatures (FDA)
EU GMP Annex 11
Computerised systems
ISO 13485
Medical devices quality management
EU MDR
Medical Device Regulation
Security and resilience obligations for operators whose failure is felt outside their own walls.
NERC CIP
Critical infrastructure protection for the bulk electric system
IEC 62443
Industrial automation and control systems security
CER Directive
Resilience of critical entities
TSA Security Directives
Pipeline and rail cybersecurity
Loi de programmation militaire
Security obligations of operators of vital importance
KRITIS / BSI Act
Critical infrastructure security
The authorisation and assurance regimes for selling into government and its supply chain.
FedRAMP
Federal cloud service authorisation
FISMA
Federal information security
NIST SP 800-171
Protecting controlled unclassified information
CMMC 2.0
Cybersecurity Maturity Model Certification
ITSG-33
IT security risk management lifecycle
SecNumCloud
ANSSI trusted cloud qualification
RGS
Référentiel général de sécurité
Sustainability reporting, climate risk and supply-chain due diligence.
CSRD & ESRS
Corporate sustainability reporting
ISSB IFRS S1 & S2
Sustainability and climate-related disclosures
TCFD
Climate-related financial disclosures
EU Taxonomy
Classification of sustainable activities
SFDR
Sustainability disclosures in financial services
CSDDD
Corporate sustainability due diligence
Loi sur le devoir de vigilance
Duty of vigilance for large companies
OSFI Guideline B-15
Climate risk management
Fighting Against Forced Labour and Child Labour in Supply Chains Act
Supply-chain reporting (S-211)
GRI Standards
Sustainability reporting standards
ISO 14001
Environmental management systems
How customers are treated, what they are told, and what they can access.
FCA Consumer Duty
Good outcomes for retail customers
UDAAP
Unfair, deceptive or abusive acts or practices
Financial Consumer Protection Framework
Bank Act consumer provisions
Digital Services Act
Obligations of online intermediaries and platforms
European Accessibility Act
Accessibility of products and services
The ISO management system family, which shares one structure and so maps onto the same controls.
ISO 9001
Quality management systems
ISO/IEC 20000-1
IT service management
ISO 45001
Occupational health and safety
ISO 28000
Supply chain security management
Examples, not a closed list: any text you answer to can be added to the library and mapped onto the controls that meet it.
Advantages of implementing our solution
Most of what a new regulation asks for is already running; the work is showing which controls answer it.
Supervisory questions are answered from the framework rather than by assembling exports from several systems.
Every claim of coverage points at the control that produces the evidence, and at the perimeter that owns it.
Schedule a personalized demo to see how our solution can address your specific needs.
Security and compliance
Reports available upon request