Skip to content

Compliance Framework

What is Compliance Framework?

A structured set of guidelines, best practices, and standards that organisations follow to meet regulatory requirements, manage risks, and demonstrate compliance. Examples include ISO 27001, SOC 2, NIST CSF, and GDPR.

Compliance

Each of these is named in at least one of the same controls as compliance framework. The number is how many controls name both.

What the standards actually require on compliance framework

Requirements naming compliance framework across 5 standards, quoted from the control text.

Coordination positions ICDPA within the broader US and international privacy regulatory landscape. (1) Utah UCPA Template Parent: Iowa CDPA most closely follows Utah CDPA (UCPA effective 31 December 2023) template - shared narrow Sale definition + opt-out (NOT...

ICDPA-Coord-USStatePrivacy-UCPA-Template-VCDPA-CPA-CTDPA-Federal-FTC-GDPR-International · Iowa CDPA Coordination - Utah CDPA Template Parent + US State Privacy Patchwork + Federal Sectoral (HIPAA/GLBA/FCRA/FERPA/COPPA) + FTC Section 5 + GDPR + India DPDP + International

Institute of Risk Management (IRM) Enterprise Risk Management (ERM) Framework principally embodied in A Risk Management Standard published 2002 + co-authored by AIRMIC (Association of Insurance and Risk Managers in Industry and Commerce) + ALARM (UK Public Ris...

IRM-Scope-ARM-Standard-2002-AIRMIC-ALARM-IRM-ISOGuide73-ISO31000-Definitions-Upside-Downside · IRM ERM Framework Scope + A Risk Management Standard (2002) + Co-Authored AIRMIC/ALARM/IRM + ISO Guide 73 Vocabulary + Upside/Downside Risk + CMIRM Qualification

Coordination positions INCDPA within the broader US and international privacy regulatory landscape. (1) US State Privacy Law Patchwork: 20+ comprehensive US state privacy laws as of 2026 (California CCPA/CPRA + Virginia VCDPA + Colorado CPA + Utah UCPA + Conne...

INCDPA-Coord-USStatePrivacy-VCDPA-CPA-CTDPA-CCPA-Federal-FTC-DPDP-GDPR-International · Indiana CDPA Coordination - US State Privacy Laws (Virginia/Colorado/Connecticut/Utah/Texas/Iowa+) + Federal Sectoral (HIPAA/GLBA/FCRA/FERPA/COPPA) + FTC Section 5 + GDPR + India DPDP + International Privacy Frameworks
MITRE ATT&CK1 control

Integrate ATT&CK with broader cybersecurity ecosystem and frameworks. MITRE Engenuity ATT&CK Evaluations - rigorous evaluations of cybersecurity vendor solutions against real adversary tradecraft (APT3 + APT29 + Carbanak/FIN7 + Wizard Spider + Sandworm + Turla...

MITRE-ATTACK-Integration-Engenuity-Evaluations-CALDERA-NIST-CSF-CIS-Lockheed-Kill-Chain-Diamond-Model-STIX-TAXII · MITRE ATT&CK Integration + MITRE Engenuity + ATT&CK Evaluations + CALDERA + NIST CSF + CIS + STIX + TAXII

Per OFAC Sanctions Compliance Framework: Senior Management Commitment to Sanctions Compliance + Board oversight + resources + clear accountability.

USOFAC-1 · Senior Management Commitment

Questions people ask about compliance framework

What is Compliance Framework?
A structured set of guidelines, best practices, and standards that organisations follow to meet regulatory requirements, manage risks, and demonstrate compliance. Examples include ISO 27001, SOC 2, NIST CSF, and GDPR.
Why is Compliance Framework important for compliance?
Compliance Framework is a key concept in Compliance. Understanding compliance framework helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Compliance Framework?
Compliance Framework appears in the requirement text of Iowa Consumer Data Protection Act, IRM Enterprise Risk Management Framework (Institute of Risk Management), Indiana Consumer Data Protection Act, MITRE ATT&CK, US OFAC Sanctions Compliance Framework. Across these standards we have identified 6 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Compliance Framework?
Explore our compliance framework pages to see how compliance framework applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Compliance Framework applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.