Unified control
A single control definition satisfying requirements from several frameworks at once, so one test produces evidence for many obligations.
Framework sprawl is arithmetic before it is a strategy problem. An organisation subject to SOX, SOC 2, ISO 27001 and a privacy regime is not facing four control environments; it is facing four descriptions of substantially overlapping expectations about access, change, monitoring and incident response.
Unified controls collapse the overlap. One control — “privileged access is reviewed quarterly and exceptions remediated” — is defined once, tested once, and mapped to every framework requirement it satisfies.
The scale of the reduction is worth stating concretely. Across the 22 frameworks in the compliance map, 904 individual framework controls collapse to 280 unified controls: roughly a 3.2-to-1 reduction. That ratio is the single largest available saving in most compliance programmes, and it is available without buying anything.
The discipline it demands is that the unified control must be written to the strictest requirement among those it maps to. Written to the loosest, it produces a crosswalk that looks complete and satisfies nothing — which is the common failure, and worse than not unifying at all because it conceals the gap.
Related