Compliance Automation Toolby Agent Trust Cloud

Compliance control mapping

29 controls, 6 frameworks, one row each. 29 controls serve more than one framework. The compliance automation tool filters this map to the frameworks you pick, adds your status and the systems you run, and turns it into a gap list.

ControlSOC 2ISO 27001HIPAAISO 42001NIST AI RMFEU AI Act
SEC-POL Security policies approved and acknowledgedCC5.3A.5.1§164.316(a), §164.316(b)(1)–––
AI-POL AI policy–––5.2, A.2.2GOVERN 1.2–
ROLES Security and AI roles assignedCC1.3A.5.2§164.308(a)(2)5.3, A.3.2GOVERN 2.1–
RISK Risk assessment and treatmentCC3.1, CC3.26.1.2, 6.1.3, 8.2§164.308(a)(1)(ii)(A), §164.308(a)(1)(ii)(B)6.1.2, 6.1.3, 8.2GOVERN 1.3Art. 9
AI-IMPACT AI system impact assessment–––6.1.4, A.5.2, A.5.4MAP 1.1, MAP 5.1Art. 27
ASSETS Asset inventoryCC6.1A.5.9§164.310(d)(1)–––
AI-INV AI system and agent inventory–––A.4.2, A.4.3GOVERN 1.6–
ACCESS Least-privilege access, approved before it is grantedCC6.2, CC6.3A.5.15, A.5.18, A.8.2§164.308(a)(4), §164.312(a)(1)–––
MFA Unique accounts and multi-factor authenticationCC6.1A.5.17, A.8.5§164.312(a)(2)(i), §164.312(d)–––
OFFBOARD Access removed when people leaveCC6.2A.5.11, A.5.18§164.308(a)(3)(ii)(C)–––
ACCESS-REVIEW Periodic access reviewsCC6.3A.5.18§164.308(a)(4)(ii)(C)–––
ENCRYPT Encryption at rest and in transitCC6.1, CC6.7A.8.24§164.312(a)(2)(iv), §164.312(e)(1)–––
ENDPOINT Endpoint protectionCC6.8A.8.1, A.8.7§164.308(a)(5)(ii)(B)–––
VULN Vulnerability managementCC7.1A.8.8§164.308(a)(1)(ii)(B)–––
LOGGING Logging and monitoringCC7.2A.8.15, A.8.16§164.312(b), §164.308(a)(1)(ii)(D)–––
AI-MONITOR AI system event logs and monitoring–––A.6.2.6, A.6.2.8MEASURE 2.4, MANAGE 4.1Art. 12, Art. 72
INCIDENT Incident responseCC7.3, CC7.4A.5.24, A.5.25, A.5.26§164.308(a)(6)A.8.4MANAGE 4.3Art. 73
CHANGE Change managementCC8.1A.8.32––––
SDLC Secure developmentCC8.1A.8.25, A.8.28, A.8.31––––
BACKUP Backups and restore testsA1.2, A1.3A.8.13§164.308(a)(7)(ii)(A)–––
BCDR Business continuity and disaster recoveryA1.3, CC9.1A.5.29, A.5.30§164.308(a)(7)(ii)(B), §164.308(a)(7)(ii)(D)–––
VENDOR Vendor and AI supplier riskCC9.2A.5.19, A.5.20, A.5.22§164.308(b)(1)A.10.3GOVERN 6.1, MANAGE 3.1Art. 25
TRAINING Security and AI awareness trainingCC2.2A.6.3§164.308(a)(5)(i)7.2, 7.3GOVERN 2.2Art. 4
SCREENING Screening and confidentiality agreementsCC1.4A.6.1, A.6.2, A.6.6§164.308(a)(3)(ii)(B)–––
AI-DATA Data quality and provenance for AI–––A.7.4, A.7.5, A.7.6MAP 2.3Art. 10
AI-TEST AI testing, including security and misuse–––A.6.2.4MEASURE 2.5, MEASURE 2.7Art. 15
AI-OVERSIGHT Human oversight of AI decisions and actions–––A.9.4GOVERN 3.2Art. 14, Art. 26
AI-TRANSPARENCY Information for users about AI–––A.8.2MEASURE 2.9Art. 13, Art. 50
AUDIT Internal audit and management reviewCC4.19.2, 9.3§164.308(a)(8)9.2, 9.3GOVERN 1.5–

Frameworks and versions

References follow the official documents; control names and descriptions are our own. For SOC 2 detail see SOC 2 compliance automation; for the AI frameworks see AI regulatory compliance.

Filter this map to your frameworks

Sources

Questions

What is a control mapping (crosswalk)?

A table that links one control to the requirement it answers in each framework, so one piece of evidence can serve several audits.

Is this mapping official?

No. It is our own mapping to the official references named on this page. Auditors and certification bodies make their own judgement; use it as a starting point and record your reasoning.