Frameworks & Controls
One control library, every framework as a view onto it
Jurisdictions and authorities are data. Model the regulator that supervises you, map your controls to it, and the rest of the platform inherits that mapping automatically.
- Jurisdiction, authority, domain, and subdomain modelled explicitly
- Mappings graded rather than boolean: a partial mapping says so
- Each control has one primary standard, detected at import
- Custom company controls with generated identifiers, isolated per tenant
Control
Privileged access is reviewed each quarter by the system owner
PPTDF applicability
One owner · one procedure · one evidence trail
Mapping
Map once, satisfy many, with the caveats intact
Control equivalence and crosswalk application are recorded, so when a control is claimed to satisfy a requirement in another standard, the reasoning is auditable.
- Question-to-standard mappings carry a mapping level
- Control equivalences with a crosswalk application log
- Company frameworks scope which standards apply to whom
- Evidence request items define what a control expects to see
- PaymentsDomain
- Card acquiringCapability3 risks2 policies
- Merchant settlementService4 controls2 assets
- Daily reconciliationProcess1 risk2 controls1 finding
Every level links out to risks, controls, policies, findings, assessments, and assets
Applicability
PPTDF tags on every control
Controls are tagged People, Process, Technology, Data, or Facility, so a technology-only remediation programme can be scoped without reading every control text.
- PPTDF applicability imported alongside the control
- Domains and subdomains for navigation and reporting
- Control test runs recorded against the control
- Header-based Excel import: columns may appear in any order
Level 3: Well Defined
A standard process is defined and followed across the organisation.
Every question in the control library carries its own written descriptor at each level.
Releases
The library is versioned before it is published
A release stages a validated snapshot for review before anything reaches production, and a content gate keeps internal test content out of production environments entirely.
- Staged payload validated before publication
- Content tiers separating internal test material from production
- Custom controls mapped to a dedicated standard, per company
- Full authorship trail on every custom control
| Action | asset-viewer | asset-coordinator | asset-approver | asset-admin |
|---|---|---|---|---|
| View | Allowed | Allowed | Allowed | Allowed |
| Create and edit | Not allowed | Allowed | Not allowed | Allowed |
| Submit for intake | Not allowed | Allowed | Not allowed | Allowed |
| Send to review | Not allowed | Allowed | Not allowed | Allowed |
| Send back | Not allowed | Allowed | Allowed | Allowed |
| Approve | Not allowed | Not allowed | Allowed | Allowed |
| Activate | Not allowed | Not allowed | Allowed | Allowed |
| Module settings | Not allowed | Not allowed | Not allowed | Allowed |
Every module ships bundles at this granularity. Segregation-of-duties conflicts are declared as rules, with logged exceptions.
Framework alignment
Works with your control frameworks
This module shares the platform control library. Map national frameworks and global standards alongside jurisdiction-specific authorities.
Solutions by role
Built for your team
See frameworks and controls in your environment
A walkthrough scoped to your entities, your frameworks, and the way your programme is actually run.