Custom controls with clear labels
Some requirements come from customers, auditors or internal policies rather than a public standard. Treat them as explicit controls with owners, evidence and review notes.
Who this is for: For teams that need flexibility without blurring the difference between preparation and certification.
Use custom mapping carefully
A custom framework can track obligations and evidence expectations, but it should be labelled clearly before being shown externally.
Reuse evidence where it fits
A single access review, policy or vendor record may support multiple requirements when the connection is documented.
Label unsupported work clearly
If a framework is not formally supported, describe it as custom-mapped preparation rather than compliance automation.
Common questions
Do we still need an auditor?
Yes. We help you prepare the work: scope, owners, policies, risks and evidence. An auditor still decides what is acceptable for certification, and legal interpretation stays with qualified advisers.
Which integrations are available today?
The current evidence sources are GitHub, Google Workspace and AWS. Jira can be used for remediation work. Other systems should be treated as manual evidence unless they are scoped separately.
What can AI help with?
AI can prepare drafts, summarise notes and suggest first-pass wording. Scope, evidence approval, legal interpretation and customer-facing statements still need owner review.
Which standards should we lead with?
ISO 27001 and GDPR are the strongest starting points. SOC 2, NIS2 and DORA can be handled as preparation or mapping work once the exact scope is agreed.
Related practical guides
- Audit preparation checklist: what to review first — A review-week preparation checklist for evidence freshness, owners, policies, vendors, access reviews and audit packs.
- Security questionnaire automation starts with reviewed answers — How to automate questionnaire responses from approved answers, evidence links, policy records and owner review.
- Vendor security review template — A vendor security review template for supplier intake, evidence requests, risk scoring, approval and reassessment.