We're introducing Frameworks and Controls: one place to keep the standards you work towards and the controls you run to meet them. Write a control once, map it to every requirement it meets, in any framework, and see at a glance where the gaps are.
SOC 2 CC7.3 has no control yet, so it shows up as a gap.
Add SOC 2, ISO/IEC 27001, ISO 14001 or ISO 45001 ready-made, with the full requirement tree, or build your own from an insurer's or your group's requirements. Everything stays editable, and a requirement that doesn't apply to you can be marked not applicable, with the reason on record.
A control is something your organization actually does, like "Access is reviewed every quarter". Map it to every requirement it meets, across frameworks: one access review can cover SOC 2 and ISO 27001 at the same time. When you adopt a framework, 21RISK suggests controls for it, already mapped.
Coverage shows which requirements have a control and which don't, for each framework and each section, so you know where to focus before the next audit.
Frameworks and Controls is a board, so it works like the rest of 21RISK. You'll find it under Boards in the sidebar, and under Settings → User Access you decide who can see it and who can edit it: give your IT, EHS or quality team the access they need, by user or by group.
Next, you'll be able to link your work in 21RISK to controls: actions, findings, reports and safety walks. Each control will then show the work behind it, ready for the next audit.
Ready to try it? Open Frameworks and Controls and add your first framework.