Control Mapping: One Evidence Base, Many Frameworks
control mapping · framework crosswalk · multi-framework compliance · Updated 2026-07-15
The reason a startup can be ready for SOC 2, ISO 27001, PCI DSS, and CBN AML at once is not effort — it is mapping. A single well-captured record satisfies a control in each framework simultaneously. This is control mapping, and it is the economic engine of Trust Infrastructure.
The crosswalk
Frameworks overlap heavily. Access control, change management, encryption, monitoring, and incident response appear, in different language, in nearly every framework. Control mapping expresses each piece of evidence once and links it to every control it satisfies.
| Evidence | SOC 2 | ISO 27001 | PCI DSS | CBN AML |
|---|---|---|---|---|
| Access grant/review record | CC6.x | A.9 / A.5.15 | Req. 7–8 | Access governance |
| Change/deploy record | CC8.x | A.12 / A.8.32 | Req. 6 | Change control |
| Monitoring/alert record | CC7.x | A.12 / A.8.16 | Req. 10–11 | Ongoing monitoring |
Illustrative crosswalk; exact control identifiers depend on scope and current framework versions.
Why mapping-once is the whole game
Without mapping, each framework is a separate evidence-collection project and cost scales linearly with frameworks. With mapping, the marginal cost of an additional framework is small — you are reusing an evidence base you already maintain. This is why Evidence Architecture treats "Stored & Connected" as its own deliberate layer.
From mapping to readiness
Mapped evidence feeds directly into evidence intelligence, which reports readiness per framework in real time. The commercial expressions are SOC 2, ISO 27001, and PCI DSS readiness.
What this relates to
- Evidence ArchitectureThe three-layer model for how compliance evidence is created, connected, and consumed: Created & Captured → Stored & Connected → Verified & Consumed.
- Engineering ControlsControls implemented and enforced through engineering systems — configuration, code, and automation — rather than through policy and manual process.
- SOC 2 Readiness for African Fintechs and B2B SaaSSOC 2 Type I and Type II readiness delivered as an evidence pipeline — engineered controls that run in production and generate continuous evidence across the audit period.
- ISO 27001 ReadinessISO 27001 ISMS readiness built on engineered controls and a mapped evidence base that also serves your other frameworks.