Governance, Risk & Compliance

Compliance Framework Mapping

A cross-framework control mapping reference I maintain — 18 major security, privacy, and AI-governance frameworks reduced to a single unified control taxonomy of 99 controls across 12 domains. The principle: build the control once, map it to every framework it satisfies — the same approach that keeps OneLabs itself auditable as it grows.

18
Frameworks Mapped
99
Unified Controls
12
Control Domains
6
Jurisdictions Covered
Framework Library

18 Frameworks, by Category

Grouped by the governance domain each framework primarily addresses — privacy, security operations, AI governance, IT service management, or product/supply-chain security.

Privacy & Data Protection
GDPR
General Data Protection Regulation
EU / EEA
Lawful basis, data subject rights, DPIA, 72-hour breach notice
DPDPA
Digital Personal Data Protection Act 2023
India
Consent, data minimisation, purpose limitation, breach notification
HIPAA
Health Insurance Portability and Accountability Act
USA — healthcare
Administrative, physical and technical PHI safeguards
GLBA
Gramm-Leach-Bliley Act / Safeguards Rule
USA — financial institutions
Information security programme, risk assessment, access controls
Security Management & Governance
ISO 27001
ISO/IEC 27001:2022 (≡ TCVN ISO/IEC 27001)
Global — certifiable ISMS
93 Annex A controls across 4 themes; Statement of Applicability
NIST CSF
NIST Cybersecurity Framework 2.0
USA origin, global use
Govern · Identify · Protect · Detect · Respond · Recover
PCI DSS
Payment Card Industry Data Security Standard v4.0.1
Global — cardholder data
12 Requirements; annual ROC/SAQ validation; quarterly ASV scans
Essential Eight
ACSC Essential Eight
Australia
8 mitigation strategies; Maturity Levels 0–3
NIS2
Network and Information Security Directive (EU) 2022/2555
EU — 18 essential/important sectors
Governance, technical measures, 24h/72h/1mo incident reporting
CIS v8
CIS Critical Security Controls v8.1
Global
18 Controls / 153 Safeguards across Implementation Groups
SOC 2
AICPA SOC 2 — Trust Services Criteria
USA origin, global
Common Criteria CC1–CC9; Type I (design) vs Type II (operating)
SOX
Sarbanes-Oxley Act (Sections 302, 404, 906)
USA — public companies
IT general controls, financial reporting integrity, change management
AI Governance
EU AI Act
EU Artificial Intelligence Act (Reg 2024/1689)
EU, extraterritorial
Risk classification, data governance, human oversight, transparency
ISO 42001
ISO/IEC 42001:2023 — AI Management System
Global — certifiable AIMS
AIMS clauses 4–10; Annex A AI controls; AI impact assessment
NIST AI RMF
NIST AI Risk Management Framework 1.0 + GenAI Profile
USA origin, global use
Govern · Map · Measure · Manage; GenAI-specific risks
IT Service & Enterprise Governance
ITIL 4
ITIL 4 — IT Service Management (AXELOS/PeopleCert)
Global — voluntary ITSM
Service Value System; 34 management practices
COBIT 2019
COBIT 2019 — Governance of Enterprise I&T (ISACA)
Global — governance framework
40 governance/management objectives; EDM–APO–BAI–DSS–MEA
Product & Supply Chain Security
CRA
EU Cyber Resilience Act
EU — products with digital elements
Security by design, vulnerability handling, incident reporting, SBOM
Unified Control Matrix

Control Overlap Map

Which control areas are shared across which frameworks. Implementing one control area once — e.g. Access Controls & IAM — can satisfy the equivalent requirement in up to 14 frameworks simultaneously, which is the core efficiency case for an integrated control programme.

Control Area CRA DPDPA GDPR HIPAA GLBA SOX ISO 27001 NIST CSF PCI DSS E8 NIS2 AI Act ISO 42001 AI RMF SOC 2 CIS v8 ITIL 4 COBIT
Access Controls & IAM
Encryption (at rest & transit)
Incident Response & Notification
Audit Logging & Trails
Risk Assessment
Vendor/Third-Party Management
Data Classification
Privacy Notice / Transparency
Data Subject Rights
Vulnerability Management
Security by Design
SBOM / Software Inventory
Financial Control Testing
BAA / DPA Agreements
Breach Notification to Regulator
Application Control & Patching
Backups & Recovery
AI Governance & Risk Management
AI Transparency & Human Oversight
Model Security & Monitoring
Approach

Why Map Frameworks This Way

Most organisations must comply with several of these frameworks at once — a healthcare vendor might face HIPAA, SOC 2, and NIST CSF simultaneously; a fintech might face GLBA, PCI DSS, and SOX. Mapping each control to every framework it satisfies — rather than running a separate compliance exercise per framework — reduces audit fatigue, cuts implementation cost, and prevents controls from drifting out of sync with each other over time. I maintain this matrix as a working reference for exactly that kind of multi-framework GRC work, and keep it current as frameworks evolve (e.g. NIST CSF 2.0, PCI DSS v4.0.1, the EU AI Act's phased obligations through 2027).