ControlsMap catalog
Frameworks and guidance
Read the source requirements and their mappings to unified controls. Each page links to the corresponding view in the interactive map.
- Framework
AIUC-1 (Jul 2026)
AIUC-1 — AI agent security, safety and reliability standard (requirement level)
- Regulation
CCPA/CPRA
CCPA/CPRA — California Consumer Privacy
- Framework
COBIT 2019
COBIT 2019 Governance & Management Objectives
- Framework
COSO ERM 2017
COSO ERM – Integrating with Strategy and Performance (2017)
- Framework
COSO IC 2013
COSO Internal Control – Integrated Framework (2013)
- Regulation
EU AI Act
EU AI Act — principal obligation areas (Chapters II, III, V and IX)
- Regulation
EU DORA
EU DORA — Digital Operational Resilience Act
- Regulation
EU GDPR
EU GDPR — General Data Protection Regulation
- Regulation
EU NIS2
EU NIS2 Directive
- Regulation
HIPAA
HIPAA — Security, Privacy & Breach Notification
- Regulation
IIA 2024 Standards
IIA 2024 Global Internal Audit Standards
- Framework
ISO 31000:2018
ISO 31000:2018 Risk Management (principles/framework/process)
- Framework
ISO/IEC 27001:2022
ISO/IEC 27001:2022 Annex A
- Framework
ISO/IEC 42001:2023 (AI)
ISO/IEC 42001:2023 Annex A (AI Management System)
- Guidance
NIST Agent Identity (draft, Feb 2026)
NIST NCCoE: Software and AI Agent Identity and Authorization
- Framework
NIST CSF 2.0
NIST Cybersecurity Framework 2.0
- Framework
NIST SP 800-53 Rev5
NIST SP 800-53 Rev 5 — Security and Privacy Controls
- Guidance
NIST TEVV-Athlon (draft, Aug 2026)
NIST AI 200-2: TEVV-Athlon Framework for Evaluating AI Systems
- Regulation
NYDFS Part 500
NYDFS Part 500 — NY Cybersecurity Regulation
- Regulation
PCI DSS v4.0.1
PCI DSS v4.0.1
- Framework
SOC 1
SOC 1 (SSAE 18 / ISAE 3402) — service-org ICFR control objectives
- Framework
SOC 2 (TSC)
AICPA SOC 2 Trust Services Criteria (2017, rev. 2022)
- Regulation
SOX / PCAOB (ICFR)
SOX 404 / PCAOB AS 2201 — ICFR control taxonomy
- Guidance
The Role of the Internal Audit Function in Enterprise Risk Management
The Role of the Internal Audit Function in Enterprise Risk Management
- Guidance
Three Lines Model: Assurance and Advice in Support of Effective Governance
Three Lines Model: Assurance and Advice in Support of Effective Governance