Knowledge BaseOperating ModelTemplatesServicesAboutWork With Me
← All Templates
Compliance & Controls

Unified Control Framework Mapping

Running one control set per framework is how programs drown. This is 45 controls, written once in auditable language, each cited to every framework it serves — so a change to one control updates every assessment at the same time.

$299one-time · instant download · free updates
Get the Workbook See the Bundles
What you get
  • 45 controls across 8 domains, in auditable "The organization…" language
  • Control-level citations: SOC 2 TSC, ISO 27001:2022 Annex A, NIST CSF 2.0, DORA articles, FFIEC booklets
  • Preventive / Detective / Corrective typing and operating frequency
  • Formula-driven gap analysis: coverage % per framework from your implementation status
  • Evidence tracker with auto due dates and OVERDUE / DUE SOON flags
  • Excel (.xlsx) · no macros · also opens in Google Sheets & LibreOffice
Why one library

Map once. Maintain one source of truth.

Most teams write the same MFA control five slightly different ways for five frameworks, then maintain five spreadsheets that drift apart. Here every control exists once, and the frameworks hang off it as citations. Your SOC 2 auditor, your ISO assessor, and your DORA program all read the same row — and when your implementation status changes, every framework's coverage number moves with it, automatically.

What's inside

Six tabs from library to audit-ready.

Control Library

45 controls across Governance, Access & Identity, Data Protection, Change, Vulnerability, Logging, Incident Response & Resilience, and Third-Party Risk — each with evidence expectations.

Gap Analysis

Per-framework coverage computed from your implementation statuses, plus a 200-row remediation worksheet with owners, target dates, and overdue flags.

Evidence Tracker

What an auditor will ask for, who owns it, when it was last collected — with next-due dates and OVERDUE / DUE SOON flags that run themselves.

Coverage Dashboard

Implementation %, domain × status grid, framework coverage bars, and evidence currency — one page for your audit-readiness forum.

Glossary

Every column defined, with sources — including why citations stay at control/article level on purpose.

Start Here

A five-step walkthrough: adopt, assess, read the gaps, track evidence, report.

Built to be evidence

Citations you can defend

Accurate, not invented

Citations sit at the control and article level — specific enough to be useful, stable enough not to rot. Where a framework doesn't speak to a control, the cell is blank. A blank beats a made-up reference.

Honest by design

The coverage math only counts what you mark Implemented. "Partially Implemented" with a gap entry beats "Implemented" with an audit surprise.

Feeds the connected model

The same library structure plugs into the Integrated Risk & Control Register, where control effectiveness drives residual risk.

The thinking: The Case for a Unified Control Library and Frameworks Worth Your Time.

FAQ

Before you buy

What format is it?

A single Microsoft Excel workbook (.xlsx). No macros, no add-ins. Also opens in Google Sheets and LibreOffice.

Are the 45 controls examples I delete?

No — the library is the product. Adapt the statements to how you actually operate, set honest implementation statuses, and add your own controls using the same ID scheme. The gap and evidence example rows are the demo data you delete.

Can I use it with clients?

Yes — internally or in client engagements. You can't resell the template itself as a template.

Need it tailored?

If you need it adapted to a specific framework set or regulator, get in touch — customization and advisory are available.

Stop maintaining five control sets

One library, five frameworks, coverage that computes itself.

Get the Workbook — $299 Or get all 12 in the Bundle ($2,497)