
10
ISO Standards
27001 · 42001 · 22301 · 31000 · 37001 · 37301 · 45001 · 27017 · 27018 · 27701
Every one with mapped controls, guided assessments, AI document generation and its own training course — included in the single platform price.


ISO Standards
27001 · 42001 · 22301 · 31000 · 37001 · 37301 · 45001 · 27017 · 27018 · 27701

Regulatory & Certification
GDPR · SOC 2 · PCI DSS · NIST CSF 2.0 · DORA · HIPAA

UK Cyber & Assurance
Cyber Essentials · CE Plus · IASME CA · IASME MSP · DCC Level 1 · NCSC CAF

ESG & Sustainability
GRI · CSRD/ESRS · TCFD · CDP · ISSB · SASB · UN SDGs
Access control appears in ISO 27001, SOC 2, PCI DSS, Cyber Essentials, NIST CSF and DORA. In most tools that means evidencing it six times, on six schedules — and discovering during an audit that three copies have drifted apart.

Control counts are the mapped control library. Questions drive the guided assessment. Templates are the AI-generated documents available for that framework.
| Standard / framework | Controls | Questions | Templates |
|---|---|---|---|
| ISO/IEC 27001 — Information Security | 116 | 150 | 30 |
| ISO/IEC 42001 — AI Management | 65 | 160 | 32 |
| ISO 22301 — Business Continuity | 46 | 47 | 40 |
| ISO 31000 — Risk Management | 39 | 40 | 35 |
| ISO 37001 — Anti-Bribery | 64 | 48 | 42 |
| ISO 37301 — Compliance Management | 62 | 45 | 40 |
| ISO 45001 — Occupational H&S | 41 | 121 | 48 |
| ISO/IEC 27017 — Cloud Security | 7 | 45 | 9 |
| ISO/IEC 27018 — Cloud Privacy | 5 | 30 | 30 |
| ISO/IEC 27701 — Privacy Information Management | 13 | 47 | 36 |
| GDPR | 67 | 150 | 30 |
| SOC 2 | 61 | 205 | 40 |
| PCI DSS v4.0.1 | 75 | 170 | 33 |
| NIST Cybersecurity Framework 2.0 | 95 | 162 | 34 |
| DORA — Regulation (EU) 2022/2554 | 46 | 56 | 18 |
| HIPAA | 67 | 54 | 18 |
| Cyber Essentials v3.3 | 28 | 36 | 21 |
| Cyber Essentials Plus v3.1 | 15 | 20 | 18 |
| IASME Cyber Assurance v7 | 5 | 56 | 37 |
| Defence Cyber Certification Level 1 | 148 | 22 | 13 |
| NCSC Cyber Assessment Framework v4.0 | 41 | 58 | 18 |
| IASME MSP — coming soon | — | 10 | 10 |
| GRI Standards 2021 | — | 63 | 26 |
| CSRD / ESRS | — | 33 | 14 |
| TCFD Recommendations | — | 25 | 10 |
| CDP Questionnaires | — | 27 | 12 |
| ISSB — IFRS S1 & S2 | — | 18 | 8 |
| SASB Standards | — | 24 | 10 |
| UN Sustainable Development Goals | — | 25 | 10 |
— means no mapped control pack: those frameworks are delivered through guided assessments and document templates rather than a control library. Counts verified against the production platform on 11 August 2026.
Two regimes that do not fit a control library get purpose-built modules instead.

A guided obligations wizard that takes a system from classification through to the requirements that actually apply, tied into the AI portfolio and model registry.
Explore AI governance
Board-level declaration on material controls: principal risks register, oversight tracking, effectiveness testing and AI annual report generation.
Provision 29 overviewAll 29, from day one, for the same price.