ControlFrame maps evidence domains across the company's assurance, privacy, security, sector, and AI obligations, then shows what carries forward, what needs refresh, and what is truly net-new.
The public atlas shows a seed model. Production workspaces expand the framework set by client industry, geography, customer commitments, and source-native package requirements.
Answer once · live engine
Answer once. Surface the next framework's reusable candidates.
These numbers are computed by the same engine that runs in the product — the sandbox register's met controls, projected through source-cited equivalence clusters. Answer 6 controls once in SOC 2, and 27 equivalent controls across 6 other frameworks surface as source-cited candidate mappings for qualified reviewer validation.
Answered once
6
→
Candidate mappings surfaced
27
HIPAA Security4 of 10 controls
NIST CSF 2.04 of 9 controls
ISO 270014 of 9 controls
HITRUST CSF4 of 11 controls
PCI DSS 4.0.17 of 9 controls
CMS EDE4 of 6 controls
Every candidate mapping requires reviewer confirmation and contributes zero credit until accepted — never an auto-granted status. Seed atlas today: 13 equivalence clusters · 64 mapped controls · 10 frameworks. Each curated proposition carries the authority or informative reference used to support review; it is represented as an official crosswalk only when the cited publisher says so.
Follow one versioned evidence object from its native CMS record into NIST and HIPAA. The artifact stays singular; every target mapping keeps its own authority, reviewer decision, freshness gate, and delta.
Synthetic reference workflowNo tenant data or write
Propose: The cited atlas proposes where the accepted source artifact may help. Every cross-framework edge remains a candidate and contributes zero.
Governed evidence objectSource accepted
consent-confirmation-event.json
EV-2048 · Runtime event
Version
v1.2
Digest
sha256:8df1…a43c
Source
Enrollment API
Owner
EDE product assurance
Sensitivity
Restricted · synthetic
Native mappings
2
Collection run
RUN-8837
Source review
Reviewer 01 · accepted
Freshness gatecurrent · 30-day policy
Current
Reuse invalidates when freshness expires, source version changes, scope changes, control changes.
Stage 01 · decision register
Find applicable controls
The cited atlas proposes where the accepted source artifact may help. Every cross-framework edge remains a candidate and contributes zero.
Computing activity and technology usage monitoring
Candidate support for monitoring evidence; it does not satisfy the outcome alone.
NIST CSF 2.0
Candidate · 0 creditNo status or request avoidance
NIST CSF 2.0PR.DS-01
Confidentiality, integrity, and availability of data at rest
Candidate support from digest and custody metadata; reviewer confirmation is pending.
NIST CSF 2.0
Candidate · 0 creditNo status or request avoidance
HIPAA164.312(b)
Audit controls
Candidate support for an audit-control record within the scoped system.
45 CFR
Candidate · 0 creditNo status or request avoidance
HIPAA164.312(c)(1)
Integrity
Candidate support from the validated digest; it does not establish compliance alone.
45 CFR
Candidate · 0 creditNo status or request avoidance
A named reviewer must confirm scope, sufficiency, and the remaining delta.
Collection policyAsk the owner only for the delta—not for evidence already governed.
A repeat request is avoided only after a named reviewer accepts the mapping and while the exact artifact version remains current. The counts above explain this reference workflow; they are not measured customer savings.
Instructional projection over checked-in synthetic evidence. Stage controls do not write tenant state or represent customer, assessor, or regulator acceptance.
One evidence spine
Controls map once, then project into each audit.
Carryover math
Reusable, refresh-needed, and net-new evidence stay separate.
AI review
Agents flag policy deltas, stale proof, and missing framework language.
Evidence spine
One proof model. Multiple audit outputs.
Frameworks should not create duplicate evidence rooms. ControlFrame captures a clean proof object once, preserves its chain of custody, and projects it into the audit package each client actually needs. The examples here are a target set, not a ceiling.
01
Capture
Policies, tickets, screenshots, logs, API traces, videos, inventories, and approvals enter one evidence model.
02
Normalize
Every artifact keeps owner, source system, date, scope, reviewer state, hash, and freshness metadata.
03
Project
Framework modules read from the same proof object, then add only the native IDs, formats, and deltas each audit requires.
Target framework families
The catalog prioritizes the obligations enterprise teams buy and audit against: common assurance, sector-specific mandates, and the fast-moving AI and resilience layer.
Enterprise assurance
Buyer-trust and board-level security proof that shows up across SaaS procurement.
SOC 2 · ISO 27001 · NIST CSF 2.0 · CIS Controls
Regulated sectors
Healthcare, payment, public-sector, defense, and marketplace programs with prescriptive evidence asks.
Control narratives that already describe cloud, identity, monitoring, and security operations.
Refresh
24%
Policies need CMS EDE-specific language for consumer handling, roles, oversight, and EDE operating responsibilities.
Evidence freshness needs to match the CMS audit window and source row expectations.
Net new
18%
Application UI Toolkit screenshots and browser traces.
Eligibility/API FIT outputs, partner test cases, communications toolkit artifacts, RIDP/FARS, IDM/Okta, and CMS UAT-gated evidence.
CMS EDE · answer once
The audit vertical no GRC dashboard touches.
CMS Enhanced Direct Enrollment is the hardest connection in US healthcare marketplaces — an annual third-party Business Audit before a partner can touch the Federally-Facilitated Marketplace. ControlFrame maps each EDE safeguard onto the common assurance and security frameworks, so evidence proven once for the EDE audit can surface candidate mappings for SOC 2, HIPAA, HITRUST, and NIST CSF review.
Each candidate carries the authority or informative reference used to support review; NIST SP 800-63 applies specifically to the identity-proofing candidate. Every candidate requires reviewer validation and contributes zero credit until accepted. Run it live with CMS EDE as the source framework.
The live answer-once workspace is available above; this section keeps the CMS EDE-specific mapping rationale in view.
Pick any two regimes. See what carries over and what is left.
This runs the same equivalence-cluster engine behind the "answer once" numbers above, for every framework pair in the seeded atlas — not only SOC 2. Every candidate carries the published crosswalk it is grounded in; the delta list is arithmetic, not an estimate.
Pick a regime pair
Evidence produced forcarries into
EU AI Act — high-risk provider obligations (Art. 9–15) controls met
4/ 7
ISO/IEC 42001:2023 — AI management system candidates surfaced
3/ 6
Gap remaining
3/ 6
Carries over — 3 of 6 (50%)
Cl. 6.1.2medium confidence
AI risk assessment
ISO 27001 6.1.2, HIPAA §164.308(a)(1), NIST CSF GV.RM, HITRUST category 03, and PCI DSS Requirement 12.3 overlap on documented risk identification, evaluation, and treatment. PCI is CDE-specific and includes targeted-risk-analysis conditions. The AI controls extend the discipline to AI risk, so confidence remains medium rather than implying interchangeability.
EU AI Act Art. 12 (record-keeping / logging) aligns with ISO 42001 7.5 (documented information) for traceability and with NIST CSF DE.CM (continuous monitoring) for the operational logging substrate — strong directional overlap; AI-scoped, so medium.
EU AI Act Art. 14 (human oversight, incl. stop/override) and NIST AI RMF MANAGE 2.4 (mechanisms to supersede/disengage/deactivate) are near 1:1 on the human-control intent. ISO 42001 8.3 / A.6.2 (impact assessment) is the design-time analogue feeding oversight design.
Delta — 3 ISO/IEC 42001:2023 — AI management system controls with no suggested carryover
Cl. 6.1.3AI risk treatment
Cl. 9.2Internal audit
Cl. 10.2Nonconformity & corrective action
Every candidate is a zero-credit SUGGESTION a qualified reviewer confirms — never an automatic met-status. Control IDs and references are the same ones the sandbox register scores; the driving satisfaction state is synthetic reference data, not a certification. The gap list is arithmetic — this framework's controls minus the candidates above — not a completeness claim about the target standard.
ControlFrame never reproduces AICPA Trust Services Criteria text or the HITRUST CSF catalogue on a public page — where a mapping touches either, the candidate above cites the control identifier and a plain-language paraphrase only, and links the authoritative source in full at the SOC 2 module and the HITRUST module. A mapping without a named published source above is ControlFrame's own judgement, not a citation to an external crosswalk.