The enterprise compliance map
Every framework, unified control, risk and workflow in one interactive graph — including the crosswalk that collapses 904 framework controls into 280.
The map holds four layers and the relationships between them:
- Standards and frameworks — 22 of them, from COSO and the IIA Standards through ISO 27001, SOC 2, NIST 800-53 and CSF 2.0, to GDPR, DORA, NIS2, the EU AI Act and ISO 42001. 904 individual controls in total.
- Unified controls — 280 harmonised definitions that the framework controls map onto. This is the layer that makes “test once, satisfy many” concrete rather than aspirational.
- Risks — 167, linked to the controls that address them, so coverage gaps are visible rather than argued about.
- Workflows — the 138 published templates, attached to the controls they operate.
What it is useful for
Three things, in ascending order of value.
The obvious use is lookup: what does ISO 27001 A.8.16 correspond to in NIST 800-53, and which of our controls already covers both.
The better use is scoping a new obligation. When a framework lands — a customer demanding SOC 2, a regulator bringing DORA into scope — the question is what genuinely new work it creates. The map answers that by showing which of its requirements already have a unified control behind them and which do not. In most cases the honest answer is that 70–80% is already covered and the programme is an evidence exercise rather than a build.
The best use is arguing with it. The mappings are explicit and directional, which means you can disagree with a specific one. A crosswalk you cannot disagree with is a topic index.
The 3.2-to-1 number
904 framework controls reduce to 280 unified controls. That ratio is the arithmetic behind every multi-framework compliance strategy, and it is worth checking against your own environment rather than taking on faith — if your programme is running four frameworks as four programmes, the gap between 904 and 280 is roughly the size of the waste.