Cross-mapping your controls helps to streamline your compliance efforts and improve audit readiness. The most common approach to cross-map controls is to use evidence items as the link between frameworks. This way, a single piece of evidence can satisfy multiple controls across different programs. When that evidence is updated, you only need to update the version once, and it will apply across all mapped controls.
Getting Started
Many clients use their most recent audit, using the collected evidence set for a full framework as the foundation.
From there, the Complyance team can bulk upload the evidence (with the correct validity dates) and map it to the correct controls in-platform.
Those same evidence items can then be linked out to relevant controls in other frameworks as desired. This will cross-map those controls to the same piece of evidence.
Follow this step-by-step guide that shows how to upload and link evidence to controls: How to Upload and Link Evidence to Controls
Using AI Suggestions
The AI feature in Complyance can also support this process.
- Open an evidence item
- Navigate to the Controls tab
-
Click Link control
An AI-generated suggestion will appear based on the content of the evidence and the control wording.
- Select the controls you want to link to the evidence item
These controls will then be mapped to the evidence item and when the validity of the evidence item changes, this will pull through to all the controls it is linked to.
Optional Custom Fields
Some clients create cross-mapped references in custom fields for additional traceability.
For example, adding a “PCI Linked Criteria” field to SOC 2 controls (and vice versa).
Note: these references are static
These custom fields are most often brought into platform as part of the initial implementation - and so are added in bulk at the import stage.
Still have questions? Reach out to our support team via the Support Center for assistance.