Glossary

Control Mapping

Control mapping is the practice of linking a single control to the multiple framework requirements it satisfies, so that one piece of evidence can support several frameworks at once.

Compliance frameworks overlap substantially — many share controls for access management, encryption, change management, and monitoring. Control mapping makes that overlap explicit by relating each internal control to the requirements it satisfies across frameworks such as SOC 2, ISO 27001, GDPR, and the EU AI Act.

With a mapped control library, an organization implements and evidences a control once and reuses it everywhere it applies. This avoids duplicated effort and inconsistent answers across frameworks, and it makes adding a new framework largely a matter of identifying the incremental controls not already covered.

Cross-framework mapping is a core capability of modern compliance platforms. It turns a portfolio of separate audits into a unified program built on a shared control and evidence base.

Related terms