modern auditing

Notes

904 controls, 280 obligations

We mapped 22 frameworks control by control. They collapse into 280 unified controls — a 3.2-to-1 reduction. That ratio is the whole argument for how compliance programmes should be structured, and most of them are structured the other way.

28 July 2026 · Rich Penfil


A company subject to SOX, SOC 2, ISO 27001 and a privacy regime does not have four control environments. It has four descriptions of a largely overlapping set of expectations about who has access to what, how changes get approved, whether anyone is watching, and what happens when something breaks.

Everyone in compliance knows this. Very few programmes are built as though it were true.

We maintain a map of 22 frameworks — COSO, the IIA Standards, ISO 27001 and 42001, ISO 31000, NIST 800-53 and CSF 2.0, COBIT, SOC 1 and SOC 2, SOX, GDPR, CCPA, HIPAA, PCI DSS, NYDFS Part 500, DORA, NIS2 and the EU AI Act among them — mapped requirement by requirement rather than topic by topic. As of this week it holds 904 individual framework controls.

Those 904 collapse into 280 unified controls.

The ratio is the argument

3.2 to 1. That is the arithmetic behind “test once, satisfy many”, and it is the largest single saving available in most compliance programmes — larger than any tooling decision, and available without buying anything.

It also explains why framework sprawl is survivable at all. Adding a fifth framework to a well-unified programme is mostly an evidence-and-mapping exercise, because 70–80% of what it asks for is already being done and tested. Adding a fifth framework to a programme running four separate control sets is a fifth programme.

Here is the coverage, framework by framework, with how many of our 138 published workflow templates touch each one:

Framework Controls Templates touching it
NIST SP 800-53 Rev 5 295 70
NIST CSF 2.0 106 34
ISO/IEC 27001:2022 Annex A 93 43
IIA 2024 Global Standards 68 13
SOC 2 Trust Services Criteria 61 21
COBIT 2019 40 13
ISO/IEC 42001:2023 38 6
ISO 31000:2018 22 9
SOX 404 / PCAOB AS 2201 21 19
COSO ERM (2017) 20 15

The long tail — NYDFS, GDPR, HIPAA, the EU AI Act, NIS2, PCI DSS, SOC 1, CCPA, DORA — accounts for another 104 controls between them.

Where unification actually goes wrong

Two failure modes, and the second is worse because it is invisible.

Mapping by topic instead of by requirement. ISO 27001 A.9 and the NIST 800-53 AC family are both “about access”. They are not the same obligation, and a mapping that treats them as equivalent produces a test that satisfies neither. The tell is a crosswalk whose entries are all “related” — that is a topic index wearing a crosswalk’s clothes.

Writing the unified control to the loosest requirement. If SOC 2 wants quarterly access review and another framework accepts annual, and your unified control says annual, you have a crosswalk that looks complete and satisfies one of the two. Nobody finds out until an assessor asks. The unified control must always be written to the strictest requirement in its mapping set, which sometimes means the unification makes your programme more expensive in one place in order to make it much cheaper overall.

That second one is why I am sceptical of crosswalks sold as content. A mapping you cannot interrogate — where you cannot see whether coverage is full, partial or merely thematic, and disagree with a specific line — is not doing the work. It is doing the appearance of the work.

What to do with this

If you are running more than two frameworks, the diagnostic is quick. Count the controls in your programme. If the number is closer to the sum of your frameworks’ requirements than to a third of it, you are paying for the arithmetic you have not done.

The map is open, the mappings are explicit and directional, and you are welcome to disagree with any of them.

In practice

Unified controls only pay off if a single test can produce evidence against every obligation it maps to — which means the test result has to be a structured record linked to controls, not a document filed under one framework’s folder. That is a data-model property, and it is what CoworkCanvas is built around.


Evidence

This note is built on: the enterprise compliance map (controlsmap.com) — 22 frameworks, 904 framework controls, 280 unified controls, 167 risks, counted 2026-07-29; the workflow template library (workflow-library.com) — 138 templates and their framework references. Nothing here is second-hand summary — if a figure appears above, it was counted from one of these.