Compliance control mapping
29 controls, 6 frameworks, one row each. 29 controls serve more than one framework. The compliance automation tool filters this map to the frameworks you pick, adds your status and the systems you run, and turns it into a gap list.
| Control | SOC 2 | ISO 27001 | HIPAA | ISO 42001 | NIST AI RMF | EU AI Act |
|---|---|---|---|---|---|---|
| SEC-POL Security policies approved and acknowledged | CC5.3 | A.5.1 | §164.316(a), §164.316(b)(1) | – | – | – |
| AI-POL AI policy | – | – | – | 5.2, A.2.2 | GOVERN 1.2 | – |
| ROLES Security and AI roles assigned | CC1.3 | A.5.2 | §164.308(a)(2) | 5.3, A.3.2 | GOVERN 2.1 | – |
| RISK Risk assessment and treatment | CC3.1, CC3.2 | 6.1.2, 6.1.3, 8.2 | §164.308(a)(1)(ii)(A), §164.308(a)(1)(ii)(B) | 6.1.2, 6.1.3, 8.2 | GOVERN 1.3 | Art. 9 |
| AI-IMPACT AI system impact assessment | – | – | – | 6.1.4, A.5.2, A.5.4 | MAP 1.1, MAP 5.1 | Art. 27 |
| ASSETS Asset inventory | CC6.1 | A.5.9 | §164.310(d)(1) | – | – | – |
| AI-INV AI system and agent inventory | – | – | – | A.4.2, A.4.3 | GOVERN 1.6 | – |
| ACCESS Least-privilege access, approved before it is granted | CC6.2, CC6.3 | A.5.15, A.5.18, A.8.2 | §164.308(a)(4), §164.312(a)(1) | – | – | – |
| MFA Unique accounts and multi-factor authentication | CC6.1 | A.5.17, A.8.5 | §164.312(a)(2)(i), §164.312(d) | – | – | – |
| OFFBOARD Access removed when people leave | CC6.2 | A.5.11, A.5.18 | §164.308(a)(3)(ii)(C) | – | – | – |
| ACCESS-REVIEW Periodic access reviews | CC6.3 | A.5.18 | §164.308(a)(4)(ii)(C) | – | – | – |
| ENCRYPT Encryption at rest and in transit | CC6.1, CC6.7 | A.8.24 | §164.312(a)(2)(iv), §164.312(e)(1) | – | – | – |
| ENDPOINT Endpoint protection | CC6.8 | A.8.1, A.8.7 | §164.308(a)(5)(ii)(B) | – | – | – |
| VULN Vulnerability management | CC7.1 | A.8.8 | §164.308(a)(1)(ii)(B) | – | – | – |
| LOGGING Logging and monitoring | CC7.2 | A.8.15, A.8.16 | §164.312(b), §164.308(a)(1)(ii)(D) | – | – | – |
| AI-MONITOR AI system event logs and monitoring | – | – | – | A.6.2.6, A.6.2.8 | MEASURE 2.4, MANAGE 4.1 | Art. 12, Art. 72 |
| INCIDENT Incident response | CC7.3, CC7.4 | A.5.24, A.5.25, A.5.26 | §164.308(a)(6) | A.8.4 | MANAGE 4.3 | Art. 73 |
| CHANGE Change management | CC8.1 | A.8.32 | – | – | – | – |
| SDLC Secure development | CC8.1 | A.8.25, A.8.28, A.8.31 | – | – | – | – |
| BACKUP Backups and restore tests | A1.2, A1.3 | A.8.13 | §164.308(a)(7)(ii)(A) | – | – | – |
| BCDR Business continuity and disaster recovery | A1.3, CC9.1 | A.5.29, A.5.30 | §164.308(a)(7)(ii)(B), §164.308(a)(7)(ii)(D) | – | – | – |
| VENDOR Vendor and AI supplier risk | CC9.2 | A.5.19, A.5.20, A.5.22 | §164.308(b)(1) | A.10.3 | GOVERN 6.1, MANAGE 3.1 | Art. 25 |
| TRAINING Security and AI awareness training | CC2.2 | A.6.3 | §164.308(a)(5)(i) | 7.2, 7.3 | GOVERN 2.2 | Art. 4 |
| SCREENING Screening and confidentiality agreements | CC1.4 | A.6.1, A.6.2, A.6.6 | §164.308(a)(3)(ii)(B) | – | – | – |
| AI-DATA Data quality and provenance for AI | – | – | – | A.7.4, A.7.5, A.7.6 | MAP 2.3 | Art. 10 |
| AI-TEST AI testing, including security and misuse | – | – | – | A.6.2.4 | MEASURE 2.5, MEASURE 2.7 | Art. 15 |
| AI-OVERSIGHT Human oversight of AI decisions and actions | – | – | – | A.9.4 | GOVERN 3.2 | Art. 14, Art. 26 |
| AI-TRANSPARENCY Information for users about AI | – | – | – | A.8.2 | MEASURE 2.9 | Art. 13, Art. 50 |
| AUDIT Internal audit and management review | CC4.1 | 9.2, 9.3 | §164.308(a)(8) | 9.2, 9.3 | GOVERN 1.5 | – |
Frameworks and versions
- SOC 2: AICPA Trust Services Criteria (2017, revised points of focus 2022).
- ISO 27001: ISO/IEC 27001:2022 information security management systems (clauses and Annex A).
- HIPAA: HIPAA Security Rule, 45 CFR Part 164 Subpart C.
- ISO 42001: ISO/IEC 42001:2023 AI management system (clauses and Annex A).
- NIST AI RMF: NIST AI Risk Management Framework 1.0 (NIST AI 100-1).
- EU AI Act: Regulation (EU) 2024/1689 (the AI Act), articles.
References follow the official documents; control names and descriptions are our own. For SOC 2 detail see SOC 2 compliance automation; for the AI frameworks see AI regulatory compliance.
Sources
- AICPA & CIMA, SOC 2: SOC for Service Organizations: Trust Services Criteria
- ISO/IEC 27001:2022 Information security management systems (ISO)
- 45 CFR Part 164 Subpart C, the HIPAA Security Rule (eCFR)
- ISO/IEC 42001:2023 Artificial intelligence management system (ISO)
- NIST AI Risk Management Framework (released 26 January 2023)
- Regulation (EU) 2024/1689, the AI Act (EUR-Lex)
- Regulation (EU) 2026/1744, the Digital Omnibus on AI (EUR-Lex)
- Checked 1 October 2026.
Questions
What is a control mapping (crosswalk)?
A table that links one control to the requirement it answers in each framework, so one piece of evidence can serve several audits.
Is this mapping official?
No. It is our own mapping to the official references named on this page. Auditors and certification bodies make their own judgement; use it as a starting point and record your reasoning.