A cross-framework control mapping reference I maintain — 18 major security, privacy, and AI-governance frameworks reduced to a single unified control taxonomy of 99 controls across 12 domains. The principle: build the control once, map it to every framework it satisfies — the same approach that keeps OneLabs itself auditable as it grows.
Grouped by the governance domain each framework primarily addresses — privacy, security operations, AI governance, IT service management, or product/supply-chain security.
Which control areas are shared across which frameworks. Implementing one control area once — e.g. Access Controls & IAM — can satisfy the equivalent requirement in up to 14 frameworks simultaneously, which is the core efficiency case for an integrated control programme.
| Control Area | CRA | DPDPA | GDPR | HIPAA | GLBA | SOX | ISO 27001 | NIST CSF | PCI DSS | E8 | NIS2 | AI Act | ISO 42001 | AI RMF | SOC 2 | CIS v8 | ITIL 4 | COBIT |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Access Controls & IAM | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | – | – | – | ✓ | ✓ | ✓ | ✓ |
| Encryption (at rest & transit) | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | – | ✓ | – | – | – | ✓ | ✓ | ✓ | ✓ |
| Incident Response & Notification | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | – | ✓ | ✓ | – | ✓ | ✓ | ✓ | ✓ | ✓ |
| Audit Logging & Trails | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | – | ✓ | ✓ | – | – | ✓ | ✓ | ✓ | ✓ |
| Risk Assessment | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | – | ✓ | ✓ | ✓ | ✓ | ✓ | – | ✓ | ✓ |
| Vendor/Third-Party Management | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | – | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Data Classification | – | ✓ | ✓ | ✓ | ✓ | – | ✓ | ✓ | ✓ | – | ✓ | – | ✓ | – | ✓ | ✓ | – | ✓ |
| Privacy Notice / Transparency | – | ✓ | ✓ | ✓ | ✓ | – | – | – | – | – | – | ✓ | – | – | ✓ | – | – | ✓ |
| Data Subject Rights | – | ✓ | ✓ | ✓ | ✓ | – | – | – | – | – | – | – | – | – | ✓ | – | – | ✓ |
| Vulnerability Management | ✓ | – | ✓ | ✓ | – | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | – | – | – | ✓ | ✓ | ✓ | ✓ |
| Security by Design | ✓ | – | ✓ | ✓ | – | – | ✓ | ✓ | ✓ | – | ✓ | ✓ | ✓ | ✓ | – | ✓ | ✓ | ✓ |
| SBOM / Software Inventory | ✓ | – | – | – | – | – | – | ✓ | ✓ | – | – | – | – | – | – | ✓ | ✓ | ✓ |
| Financial Control Testing | – | – | – | – | – | ✓ | – | – | – | – | – | – | – | – | – | – | – | ✓ |
| BAA / DPA Agreements | – | ✓ | ✓ | ✓ | – | – | ✓ | ✓ | ✓ | – | ✓ | – | – | – | ✓ | ✓ | – | ✓ |
| Breach Notification to Regulator | ✓ | ✓ | ✓ | ✓ | ✓ | – | – | – | ✓ | – | ✓ | ✓ | – | – | – | – | – | ✓ |
| Application Control & Patching | ✓ | – | – | – | – | – | ✓ | ✓ | ✓ | ✓ | ✓ | – | – | – | ✓ | ✓ | ✓ | ✓ |
| Backups & Recovery | ✓ | – | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | – | ✓ | ✓ | – | – | – | ✓ | ✓ | ✓ | ✓ |
| AI Governance & Risk Management | – | – | ✓ | – | – | – | ✓ | ✓ | – | – | – | ✓ | ✓ | ✓ | – | – | – | ✓ |
| AI Transparency & Human Oversight | – | ✓ | ✓ | – | – | – | – | – | – | – | – | ✓ | ✓ | ✓ | – | – | – | ✓ |
| Model Security & Monitoring | ✓ | – | ✓ | – | – | – | ✓ | ✓ | – | – | – | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
Most organisations must comply with several of these frameworks at once — a healthcare vendor might face HIPAA, SOC 2, and NIST CSF simultaneously; a fintech might face GLBA, PCI DSS, and SOX. Mapping each control to every framework it satisfies — rather than running a separate compliance exercise per framework — reduces audit fatigue, cuts implementation cost, and prevents controls from drifting out of sync with each other over time. I maintain this matrix as a working reference for exactly that kind of multi-framework GRC work, and keep it current as frameworks evolve (e.g. NIST CSF 2.0, PCI DSS v4.0.1, the EU AI Act's phased obligations through 2027).