Cross-framework

How to reduce duplicated effort across ISO 27001, SOC 2, ISO 42001, and regulatory obligations without flattening their differences.

Begin with the work, not the labels

An access review may support ISO/IEC 27001, SOC 2, and an ISO/IEC 42001 AI management system when the same systems are genuinely in scope. Each asks a different question. ISO/IEC 27001 addresses information security management and risk treatment. SOC 2 examines controls relevant to a described service and period. ISO/IEC 42001 governs AI uses, impacts, decisions, and the lifecycle. NIS2 and DORA add legal and sector-specific obligations where they apply.

The common foundation is an inventory of real controls: what is done, by whom, for which systems, how often, and with what evidence. Only then should the organization map a control to framework requirements.

Create one owner and one evidence path

Duplicate policies and evidence requests exhaust control owners. Define a single operational control where the underlying activity is genuinely the same, with one owner and a reliable evidence location. Add framework-specific attributes such as scope, reporting threshold, or review cadence where they differ.

A good control register records the objective, procedure, accountable owner, assets in scope, frequency, source system, evidence, exceptions, and related obligations. That record makes gaps visible without pretending that all frameworks are interchangeable.

Keep the differences explicit

Some requirements cannot be collapsed into a shared control. SOC 2 system descriptions and reporting periods, ISO/IEC 27001 risk treatment, and ISO/IEC 42001 AI inventories and impact decisions have distinct purposes. NIS2 incident reporting and DORA ICT third-party registers add other specific duties where they apply. Maintain a mapping that identifies where a shared activity covers a requirement and where additional work is needed.

This distinction matters during independent assessment. A tidy spreadsheet may show broad coverage while the underlying records fail to demonstrate the required scope or period.

Maintain the system as the business changes

Revisit mappings when services, suppliers, jurisdictions, and standards change. Treat the control library as an operating asset: owners use it to run controls, leaders use it to see risk, and assessors use it to understand evidence.

Put it into practice

  • Inventory operating controls before mapping frameworks.
  • Give each common control one owner and one primary evidence source.
  • Record framework-specific scope, periods, and thresholds explicitly.
  • Review the mapping whenever services, suppliers, or obligations change.

Primary sources

Normstone resources are general information, not legal advice or an independent assessment.

All resources