Compliance framework management in one place: adopt SOC 2, ISO 27001, ISO 14001 or ISO 45001 ready-made, write each control once, map it to every requirement it meets, and see which requirements still have a gap.
SOC 2 CC7.3 has no control yet, so it shows up as a gap.
Access reviews, incident response and policy approval show up in more than one standard. A spreadsheet makes you write them down for each.
One tab per standard, one row per requirement, and control names copied between tabs. Change a control and every tab that mentions it is out of date.
A quarterly access review counts for SOC 2 and for ISO 27001. Described separately for each, the two descriptions drift apart.
Which requirements have no control at all? Answering means reading the whole matrix, row by row, before every audit.
Describe what your organization actually does once, and let each framework show what it covers.
Add SOC 2, ISO/IEC 27001, ISO 14001 or ISO 45001 with the full requirement tree, or build your own from an insurer’s or your group’s requirements.
A control is something you actually do, like a quarterly access review. Map it to every requirement it meets, in any framework. 21RISK suggests controls when you adopt a framework, already mapped.
Coverage per framework and per section shows which requirements have a control and which have none yet, so you know where to start.
SOC 2, ISO/IEC 27001, ISO 14001 and ISO 45001 with the full requirement tree, plus suggested controls. Everything stays editable.
Mark a requirement or a section as not applicable, with the reason on record. It leaves the coverage count.
Give each control an owner, and let the board's User Access decide who sees and who edits, by user or by group.
SOC 2 (Trust Services Criteria 2017), ISO/IEC 27001:2022, ISO 14001:2015 and ISO 45001:2018, each with its full requirement tree. Everything stays editable after you add it, and you can build your own framework from scratch, for example from an insurer’s requirements or a group policy.
Yes, that is the point. Map a control to requirements in as many frameworks as it meets. When you adopt a second framework, the suggested controls you already have are linked to its requirements instead of being created again.
Mark it, or a whole section, as not applicable and give the reason. It stays on record with that reason and no longer counts toward the framework’s coverage.
No. Coverage tells you that every applicable requirement has a control. Whether each control works is still for your audit to show, which is why 21RISK says “have a control”, not “compliant”.
Frameworks and Controls is a board, so it works like the rest of 21RISK. It sits under Boards in the sidebar, and under Settings › User Access you decide who can see it and who can edit it, by user or by group. Give your IT, EHS or quality team the access they need.
Compliance standards are checklists your sites answer in audits. Frameworks and Controls describes what your organization does once, centrally, and which requirements of each standard that covers. Next, you will be able to link actions, findings, reports and safety walks to a control, so each control shows the work behind it.
Frameworks and controls on the same platform as your sites, audits and findings.