Running one control set per framework is how programs drown. This is 45 controls, written once in auditable language, each cited to every framework it serves — so a change to one control updates every assessment at the same time.
Most teams write the same MFA control five slightly different ways for five frameworks, then maintain five spreadsheets that drift apart. Here every control exists once, and the frameworks hang off it as citations. Your SOC 2 auditor, your ISO assessor, and your DORA program all read the same row — and when your implementation status changes, every framework's coverage number moves with it, automatically.
45 controls across Governance, Access & Identity, Data Protection, Change, Vulnerability, Logging, Incident Response & Resilience, and Third-Party Risk — each with evidence expectations.
Per-framework coverage computed from your implementation statuses, plus a 200-row remediation worksheet with owners, target dates, and overdue flags.
What an auditor will ask for, who owns it, when it was last collected — with next-due dates and OVERDUE / DUE SOON flags that run themselves.
Implementation %, domain × status grid, framework coverage bars, and evidence currency — one page for your audit-readiness forum.
Every column defined, with sources — including why citations stay at control/article level on purpose.
A five-step walkthrough: adopt, assess, read the gaps, track evidence, report.
Citations sit at the control and article level — specific enough to be useful, stable enough not to rot. Where a framework doesn't speak to a control, the cell is blank. A blank beats a made-up reference.
The coverage math only counts what you mark Implemented. "Partially Implemented" with a gap entry beats "Implemented" with an audit surprise.
The same library structure plugs into the Integrated Risk & Control Register, where control effectiveness drives residual risk.
The thinking: The Case for a Unified Control Library and Frameworks Worth Your Time.
A single Microsoft Excel workbook (.xlsx). No macros, no add-ins. Also opens in Google Sheets and LibreOffice.
No — the library is the product. Adapt the statements to how you actually operate, set honest implementation statuses, and add your own controls using the same ID scheme. The gap and evidence example rows are the demo data you delete.
Yes — internally or in client engagements. You can't resell the template itself as a template.
If you need it adapted to a specific framework set or regulator, get in touch — customization and advisory are available.
One library, five frameworks, coverage that computes itself.