Product/ Safety/ Frameworks and controls
Frameworks and controls

Compliance framework management without the mapping spreadsheet

Compliance framework management in one place: adopt SOC 2, ISO 27001, ISO 14001 or ISO 45001 ready-made, write each control once, map it to every requirement it meets, and see which requirements still have a gap.

Coverage 5 of 6 requirements have a control · 2 controls, 2 frameworks

SOC 2 CC7.3 has no control yet, so it shows up as a gap.

The problem

Every standard gets its own spreadsheet

Access reviews, incident response and policy approval show up in more than one standard. A spreadsheet makes you write them down for each.

The mapping lives in a spreadsheet

One tab per standard, one row per requirement, and control names copied between tabs. Change a control and every tab that mentions it is out of date.

The same work, written up twice

A quarterly access review counts for SOC 2 and for ISO 27001. Described separately for each, the two descriptions drift apart.

Nobody can say where the gaps are

Which requirements have no control at all? Answering means reading the whole matrix, row by row, before every audit.

How it works

One control, every framework it counts for

Describe what your organization actually does once, and let each framework show what it covers.

  1. 01

    Start from a framework

    Add SOC 2, ISO/IEC 27001, ISO 14001 or ISO 45001 with the full requirement tree, or build your own from an insurer’s or your group’s requirements.

  2. 02

    Write each control once

    A control is something you actually do, like a quarterly access review. Map it to every requirement it meets, in any framework. 21RISK suggests controls when you adopt a framework, already mapped.

  3. 03

    See the gaps

    Coverage per framework and per section shows which requirements have a control and which have none yet, so you know where to start.

Frameworks and Controls 3 FRAMEWORKS
SOC 2 44 of 52 have a control
ISO/IEC 27001 86 of 112 have a control · 7 not applicable
ISO 14001 19 of 28 have a control
SOC 2 · CC7 System operations
CC7.1 Detecting configuration changes OPS-03
CC7.2 Monitoring system components OPS-04
CC7.3 Evaluating security events No control yet
CC7.4 Responding to security incidents OPS-05
Control · ACC-02 Access to production is reviewed every quarter Owner: Sara Holm
SOC 2 CC6.2CC6.3
ISO/IEC 27001 A.5.18
Features

What you get with frameworks and controls

TEMPLATES

Four frameworks, ready-made

SOC 2, ISO/IEC 27001, ISO 14001 and ISO 45001 with the full requirement tree, plus suggested controls. Everything stays editable.

NOT APPLICABLE

Exclusions with a reason

Mark a requirement or a section as not applicable, with the reason on record. It leaves the coverage count.

ACCESS

The people who do the work

Give each control an owner, and let the board's User Access decide who sees and who edits, by user or by group.

FAQ

Frequently asked questions

Which frameworks are ready-made?

SOC 2 (Trust Services Criteria 2017), ISO/IEC 27001:2022, ISO 14001:2015 and ISO 45001:2018, each with its full requirement tree. Everything stays editable after you add it, and you can build your own framework from scratch, for example from an insurer’s requirements or a group policy.

Can one control count for several frameworks?

Yes, that is the point. Map a control to requirements in as many frameworks as it meets. When you adopt a second framework, the suggested controls you already have are linked to its requirements instead of being created again.

What if a requirement does not apply to us?

Mark it, or a whole section, as not applicable and give the reason. It stays on record with that reason and no longer counts toward the framework’s coverage.

Does full coverage mean we are compliant?

No. Coverage tells you that every applicable requirement has a control. Whether each control works is still for your audit to show, which is why 21RISK says “have a control”, not “compliant”.

Who can see and edit it?

Frameworks and Controls is a board, so it works like the rest of 21RISK. It sits under Boards in the sidebar, and under Settings › User Access you decide who can see it and who can edit it, by user or by group. Give your IT, EHS or quality team the access they need.

How is this different from compliance standards?

Compliance standards are checklists your sites answer in audits. Frameworks and Controls describes what your organization does once, centrally, and which requirements of each standard that covers. Next, you will be able to link actions, findings, reports and safety walks to a control, so each control shows the work behind it.

Write each control once

Frameworks and controls on the same platform as your sites, audits and findings.