Frameworks

Manage multiple frameworks in one platform.

Most organisations end up with more than one framework. The requirements differ, but the underlying controls overlap heavily. Compliancy maps one control to every framework it satisfies, so the same access review or encryption evidence is recorded once.

Core frameworks

SOC 2

Compliancy helps organisations prepare for a SOC 2 examination by mapping Trust Services Criteria to controls, linking policies, owners and evidence, and tracking readiness over the observation period.

ISO 27001

Compliancy supports an ISO/IEC 27001 information security management system by holding scope, risk assessment and treatment, Annex A control decisions, policies and evidence in one connected structure.

ISO 42001

Compliancy supports an ISO/IEC 42001 AI management system by holding AI risk assessments, model governance records, human oversight procedures, and the technical documentation EU AI Act high-risk obligations require.

GDPR

Compliancy helps organisations manage GDPR obligations by holding records of processing activities, lawful bases, data subject request handling, DPIAs, processor agreements and the technical and organisational measures that protect personal data.

HIPAA

Compliancy helps covered entities and business associates manage HIPAA obligations by tracking Security Rule safeguards, risk analysis, workforce policies, business associate agreements and supporting evidence.

CCPA / CPRA

Compliancy helps organisations manage California privacy obligations under the CCPA as amended by the CPRA, including consumer rights requests, disclosures, retention decisions, service provider contracts and security measures.

Missing a framework?

Or have questions about your compliance strategy?

Book a consultation

One control, several frameworks.

The tags on each control show every framework it currently satisfies.

Reporting

One overview across every framework.

Two frameworks shouldn't mean twice the work.