904 controls, 280 obligations
We mapped 22 frameworks control by control. They collapse into 280 unified controls — a 3.2-to-1 reduction. That ratio is the whole argument for how compliance programmes should be structured, and most of them are structured the other way.
A company subject to SOX, SOC 2, ISO 27001 and a privacy regime does not have four control environments. It has four descriptions of a largely overlapping set of expectations about who has access to what, how changes get approved, whether anyone is watching, and what happens when something breaks.
Everyone in compliance knows this. Very few programmes are built as though it were true.
We maintain a map of 22 frameworks — COSO, the IIA Standards, ISO 27001 and 42001, ISO 31000, NIST 800-53 and CSF 2.0, COBIT, SOC 1 and SOC 2, SOX, GDPR, CCPA, HIPAA, PCI DSS, NYDFS Part 500, DORA, NIS2 and the EU AI Act among them — mapped requirement by requirement rather than topic by topic. As of this week it holds 904 individual framework controls.
Those 904 collapse into 280 unified controls.
The ratio is the argument
3.2 to 1. That is the arithmetic behind “test once, satisfy many”, and it is the largest single saving available in most compliance programmes — larger than any tooling decision, and available without buying anything.
It also explains why framework sprawl is survivable at all. Adding a fifth framework to a well-unified programme is mostly an evidence-and-mapping exercise, because 70–80% of what it asks for is already being done and tested. Adding a fifth framework to a programme running four separate control sets is a fifth programme.
Here is the coverage, framework by framework, with how many of our 138 published workflow templates touch each one:
| Framework | Controls | Templates touching it |
|---|---|---|
| NIST SP 800-53 Rev 5 | 295 | 70 |
| NIST CSF 2.0 | 106 | 34 |
| ISO/IEC 27001:2022 Annex A | 93 | 43 |
| IIA 2024 Global Standards | 68 | 13 |
| SOC 2 Trust Services Criteria | 61 | 21 |
| COBIT 2019 | 40 | 13 |
| ISO/IEC 42001:2023 | 38 | 6 |
| ISO 31000:2018 | 22 | 9 |
| SOX 404 / PCAOB AS 2201 | 21 | 19 |
| COSO ERM (2017) | 20 | 15 |
The long tail — NYDFS, GDPR, HIPAA, the EU AI Act, NIS2, PCI DSS, SOC 1, CCPA, DORA — accounts for another 104 controls between them.
Where unification actually goes wrong
Two failure modes, and the second is worse because it is invisible.
Mapping by topic instead of by requirement. ISO 27001 A.9 and the NIST 800-53 AC family are both “about access”. They are not the same obligation, and a mapping that treats them as equivalent produces a test that satisfies neither. The tell is a crosswalk whose entries are all “related” — that is a topic index wearing a crosswalk’s clothes.
Writing the unified control to the loosest requirement. If SOC 2 wants quarterly access review and another framework accepts annual, and your unified control says annual, you have a crosswalk that looks complete and satisfies one of the two. Nobody finds out until an assessor asks. The unified control must always be written to the strictest requirement in its mapping set, which sometimes means the unification makes your programme more expensive in one place in order to make it much cheaper overall.
That second one is why I am sceptical of crosswalks sold as content. A mapping you cannot interrogate — where you cannot see whether coverage is full, partial or merely thematic, and disagree with a specific line — is not doing the work. It is doing the appearance of the work.
What to do with this
If you are running more than two frameworks, the diagnostic is quick. Count the controls in your programme. If the number is closer to the sum of your frameworks’ requirements than to a third of it, you are paying for the arithmetic you have not done.
The map is open, the mappings are explicit and directional, and you are welcome to disagree with any of them.
In practice
Unified controls only pay off if a single test can produce evidence against every obligation it maps to — which means the test result has to be a structured record linked to controls, not a document filed under one framework’s folder. That is a data-model property, and it is what CoworkCanvas is built around.
Evidence