One control, six frameworks: how cross mapping really works

Why a control-centred architecture is superior to single-standard tools — explained using a practical example of multi-factor authentication.

The iComply Team
AI Governance

Cross Mapping

Most compliance tools are organised around a single standard. You buy one for ISO 27001, another for SOC 2, a spreadsheet for NIS2, and the same evidence is uploaded three times. Cross-mapping breaks this pattern by making the control — rather than the framework — the unit of work.

Frameworks overlap far more than they differ

ISO 27001, NIS2, DORA, SOC 2, the GDPR and the AI Act were drawn up by different bodies for different reasons, but they all require many of the same things: access control, encryption, logging, incident response and supplier management. The wording differs; the underlying controls are the same.

A practical example: MFA

Consider a single control — “Multi-factor authentication enforced for all privileged access.” Implement it once and it simultaneously fulfils:

  • ISO 27001 — access control objectives set out in Annex A.
  • NIS2 — cybersecurity risk management measures.
  • DORA — ICT access and authentication requirements.
  • SOC 2 — logical access criteria.
  • GDPR — security of processing in accordance with Article 32.

One check, one piece of evidence, five frameworks ticked off. In a single-standard tool, I would track this five times.

The architecture that makes it possible

Cross-mapping requires a shared model: laws and standards are mapped to a common library of controls; the controls are linked to risks and evidence. When you attach a document to a control, all requirements that reference it inherit the evidence — with the version history intact.

What you get

  • No duplication of effort — implement and record it once.
  • Faster audits — auditors see the same control mapped to their framework.
  • Honest coverage — the gaps are visible across all frameworks at a glance.
  • A more cost-effective expansion — adding a new standard reuses controls that are already in place.

It is the architecture on which the world’s best GRC platforms are built — and it is at the heart of iComply.

Here’s how iComply puts this into practice

A platform for every regulation, law and risk — focused on controls and powered by AI.

Read on

Two interconnected circles representing the relationship between the ISO 42001 standard and the European AI Regulation

A management system meets a regulation — and why you operationalise both as a single AI governance suite.

Bar chart showing salaries within a defined range, illustrating an analysis of the gender pay gap at iComply

Analysis of pay gaps, pay bands and auditable remuneration criteria — what to implement now.

Seven ascending layers representing the stages involved in building a unified governance programme with iComply

A step-by-step approach to scope, controls, evidence and ongoing assurance — designed to be scalable across domains.