{
  "meta": {
    "version": "sha256-0c4035fbf3a780b06f32d1049236fbdb83f06a11d522110101cf1303d4b9a348",
    "name": "Keel compliance crosswalks",
    "description": "Canonical, framework-agnostic security and quality controls, each mapped (crosswalked) to the clauses it satisfies across multiple compliance frameworks. Maintained by Keel.",
    "source": "https://keelgrc.com/open-source/",
    "license": "CC-BY-4.0",
    "attribution": "Keel GRC LLC (https://keelgrc.com)",
    "controlCount": 123,
    "frameworks": [
      {
        "key": "ai-governance-essentials",
        "name": "AI Governance Essentials"
      },
      {
        "key": "amazon-child-directed",
        "name": "Amazon Appstore Child-Directed Apps"
      },
      {
        "key": "apple-kids",
        "name": "Apple App Store Kids Category"
      },
      {
        "key": "cis-controls",
        "name": "CIS Controls"
      },
      {
        "key": "coppa",
        "name": "COPPA"
      },
      {
        "key": "esg-essentials",
        "name": "ESG Essentials"
      },
      {
        "key": "eu-ai-act",
        "name": "EU AI Act"
      },
      {
        "key": "gdpr",
        "name": "GDPR"
      },
      {
        "key": "google-play-families",
        "name": "Google Play Families"
      },
      {
        "key": "hipaa",
        "name": "HIPAA"
      },
      {
        "key": "iso-27001",
        "name": "ISO/IEC 27001"
      },
      {
        "key": "iso-42001",
        "name": "ISO/IEC 42001"
      },
      {
        "key": "iso-9001",
        "name": "ISO 9001"
      },
      {
        "key": "nist-800-171",
        "name": "NIST SP 800-171"
      },
      {
        "key": "nist-800-53",
        "name": "NIST SP 800-53"
      },
      {
        "key": "nist-ai-rmf",
        "name": "NIST AI Risk Management Framework"
      },
      {
        "key": "nist-csf",
        "name": "NIST Cybersecurity Framework"
      },
      {
        "key": "pci-dss",
        "name": "PCI DSS"
      },
      {
        "key": "soc-2",
        "name": "SOC 2"
      },
      {
        "key": "sox",
        "name": "SOX (Sarbanes-Oxley) Section 404"
      },
      {
        "key": "us-employment-federal",
        "name": "US Employment Law (federal baseline)"
      }
    ]
  },
  "controls": [
    {
      "key": "information-security-policy",
      "name": "Information security policy",
      "description": "A board-approved policy set covering information security and the handling of personal data, sized to the scale of the organization and the type of activities it actually carries out, reviewed at least annually and communicated to the workforce. The policy set states the direction the organization is taking on information security - what it commits to, and what it requires of everyone doing work for it - so it sets where the programme is going rather than only recording what it already does. One or more named individuals are designated to coordinate the programme the policies describe - the person in charge of it, named rather than implied, with the designation recorded in writing, made known to the people who need it and kept current as roles change - so there is someone who answers for the policies being carried out and not only for their being published. How far the policies go, and how far the measures they require go, is judged against four things together: the organization’s size, complexity and capabilities; its technical infrastructure and the security capabilities of its hardware and software; what the measures cost; and how likely the risks they address are and how much damage they would do. A policy may be changed at any time, provided the change is documented and is actually put into effect rather than only written down.",
      "crosswalks": {
        "iso-27001": [
          "5.2",
          "A.5.1"
        ],
        "soc-2": [
          "CC5.3"
        ],
        "nist-csf": [
          "GV.PO-01"
        ],
        "pci-dss": [
          "12.1"
        ],
        "hipaa": [
          "164.316(a)",
          "164.530(i)(1)"
        ],
        "esg-essentials": [
          "G.9"
        ],
        "gdpr": [
          "Art.24(2)"
        ],
        "nist-800-53": [
          "PL-1"
        ],
        "coppa": [
          "312.8(a)",
          "312.8(b)(1)"
        ],
        "sox": [
          "P12"
        ]
      }
    },
    {
      "key": "risk-assessment",
      "name": "Risk assessment & treatment",
      "description": "A documented process to identify, analyze, evaluate, and treat information security risks on a defined cadence, and again whenever a significant change is proposed or has happened - a new system, a new supplier, a reorganization, a serious incident - so the picture is refreshed by events and not only by the calendar. The process is repeatable: the criteria for accepting risk and for deciding when an assessment is performed are set in advance and applied the same way each time, so repeated assessments produce consistent, comparable and valid results rather than a different answer depending on who ran it. Every risk has a named owner who approves how it will be treated and accepts what is left afterwards. The assessment covers risks and vulnerabilities to the confidentiality, the integrity and the availability of the data the organization holds - all three, not confidentiality alone - and is accurate and thorough enough to be relied on by the decisions taken from it. Treatment brings each risk down to a level that is reasonable and appropriate for this organization, which is the target the process is judged against rather than merely recording that a risk exists. Each assessment and its results are retained as documented information.",
      "crosswalks": {
        "iso-27001": [
          "6.1",
          "8.2"
        ],
        "soc-2": [
          "CC3.2"
        ],
        "pci-dss": [
          "12.3"
        ],
        "hipaa": [
          "164.308(a)(1)(ii)(A)",
          "164.308(a)(1)(ii)(B)"
        ],
        "nist-800-171": [
          "3.11.1"
        ],
        "nist-800-53": [
          "RA-3",
          "RA-7"
        ],
        "coppa": [
          "312.8(b)(2)"
        ]
      }
    },
    {
      "key": "access-control-policy",
      "name": "Access control policy",
      "description": "Rules for granting, reviewing, and revoking access to systems and data based on business need and least privilege; anyone who works with sensitive data, or in a place from which it can be reached, is individually authorized for that work or supervised while doing it; and a documented emergency route exists to obtain the data when the normal access path is unavailable, with every use of that route recorded and reviewed afterwards.",
      "crosswalks": {
        "iso-27001": [
          "A.5.15"
        ],
        "soc-2": [
          "CC6.1",
          "CC6.3"
        ],
        "nist-csf": [
          "PR.AA-05"
        ],
        "pci-dss": [
          "7.1",
          "7.2"
        ],
        "hipaa": [
          "164.308(a)(3)(ii)(A)",
          "164.308(a)(4)(ii)(B)",
          "164.312(a)(2)(ii)"
        ],
        "nist-800-171": [
          "3.1.1",
          "3.1.5"
        ],
        "cis-controls": [
          "6.8"
        ],
        "gdpr": [
          "Art.32(1)"
        ],
        "nist-800-53": [
          "AC-1",
          "AC-2",
          "AC-3",
          "AC-6"
        ],
        "coppa": [
          "312.8(b)(3)"
        ],
        "sox": [
          "P11"
        ]
      }
    },
    {
      "key": "user-lifecycle",
      "name": "User provisioning & deprovisioning",
      "description": "Joiner/mover/leaver process to grant, change, and promptly remove access across systems, in which every person is issued an account of their own carrying a unique name or number, so an action in a log traces back to one named individual rather than to a shared or generic login. Each person’s right of access is recorded when it is established and reviewed on a schedule thereafter, as well as granted and changed - so what someone holds is a documented position that has been looked at again, not the accumulated residue of past requests - and what may be granted follows the organization’s access authorization rules rather than the judgement of whoever processes the request.",
      "crosswalks": {
        "iso-27001": [
          "A.8.3"
        ],
        "soc-2": [
          "CC6.2",
          "CC6.3"
        ],
        "nist-csf": [
          "PR.AA-01"
        ],
        "pci-dss": [
          "8.2"
        ],
        "hipaa": [
          "164.308(a)(4)(ii)(B)",
          "164.308(a)(4)(ii)(C)",
          "164.312(a)(2)(i)"
        ],
        "nist-800-171": [
          "3.1.1"
        ],
        "cis-controls": [
          "5.3",
          "6.1",
          "6.2"
        ],
        "gdpr": [
          "Art.32(1)"
        ],
        "nist-800-53": [
          "AC-2",
          "PS-4",
          "PS-5"
        ],
        "sox": [
          "P11"
        ]
      }
    },
    {
      "key": "mfa",
      "name": "Multi-factor authentication",
      "description": "Documented procedures verify that a person or system seeking access to sensitive data is the one it claims to be, on every path by which that data can be reached - and multi-factor authentication is the enforced mechanism for remote access, administrative access, and access to sensitive systems and data. The multi-factor mechanism itself is configured so it cannot be bypassed, so the factors it uses are genuinely independent of one another - one factor’s success granting no knowledge of and no route around another - and so access is refused unless every factor required has succeeded.",
      "crosswalks": {
        "iso-27001": [
          "A.8.5"
        ],
        "soc-2": [
          "CC6.1"
        ],
        "nist-csf": [
          "PR.AA-03"
        ],
        "pci-dss": [
          "8.4",
          "8.5"
        ],
        "hipaa": [
          "164.312(d)"
        ],
        "nist-800-171": [
          "3.5.3"
        ],
        "cis-controls": [
          "6.3",
          "6.5"
        ],
        "gdpr": [
          "Art.32(1)"
        ],
        "nist-800-53": [
          "IA-2"
        ],
        "coppa": [
          "312.8(b)(3)"
        ],
        "sox": [
          "P11"
        ]
      }
    },
    {
      "key": "credential-management",
      "name": "Password & credential management",
      "description": "Rules for the authentication credentials themselves: passwords are unique per account and meet a defined strength standard, a new or changed password is screened against a list of commonly used, expected and compromised passwords and refused if it appears there, a credential issued for first use must be replaced immediately, reuse of previous passwords is refused, changes follow a defined procedure, repeated failed authentication attempts lock the account for a defined period, and passwords, keys and other authentication secrets are stored and transmitted only in protected form.",
      "crosswalks": {
        "iso-27001": [
          "A.5.17"
        ],
        "pci-dss": [
          "8.3"
        ],
        "hipaa": [
          "164.308(a)(5)(ii)(D)"
        ],
        "cis-controls": [
          "5.2"
        ],
        "nist-800-171": [
          "3.5.7",
          "3.5.8",
          "3.5.9",
          "3.5.10"
        ],
        "nist-800-53": [
          "IA-5",
          "IA-5(1)"
        ]
      }
    },
    {
      "key": "encryption",
      "name": "Encryption in transit & at rest",
      "description": "Strong cryptography protects sensitive data in transit over public networks and at rest in storage.",
      "crosswalks": {
        "iso-27001": [
          "A.8.24"
        ],
        "soc-2": [
          "CC6.7"
        ],
        "nist-csf": [
          "PR.DS-01",
          "PR.DS-02"
        ],
        "pci-dss": [
          "3.5",
          "4.2"
        ],
        "hipaa": [
          "164.312(a)(2)(iv)",
          "164.312(e)(2)(ii)"
        ],
        "nist-800-171": [
          "3.13.8"
        ],
        "cis-controls": [
          "3.11"
        ],
        "gdpr": [
          "Art.32(1)"
        ],
        "nist-800-53": [
          "SC-13",
          "SC-28",
          "SC-8"
        ],
        "coppa": [
          "312.8(b)(3)"
        ],
        "sox": [
          "P11"
        ]
      }
    },
    {
      "key": "logging-monitoring",
      "name": "Logging & monitoring",
      "description": "Security-relevant events - including successful and failed log-in attempts - are logged, protected, retained, and reviewed for anomalies, and the discrepancies that review finds are reported to the people who act on them. The review runs on a defined cadence and covers the records of system activity as a set - the audit logs, the reports of who accessed what, and the record of security incidents - rather than the log stream alone.",
      "crosswalks": {
        "iso-27001": [
          "A.8.15",
          "A.8.16"
        ],
        "soc-2": [
          "CC7.2"
        ],
        "nist-csf": [
          "DE.CM-09"
        ],
        "pci-dss": [
          "10.2",
          "10.3",
          "10.4"
        ],
        "hipaa": [
          "164.308(a)(1)(ii)(D)",
          "164.308(a)(5)(ii)(C)",
          "164.312(b)"
        ],
        "nist-800-171": [
          "3.3.1",
          "3.3.5",
          "3.3.8"
        ],
        "cis-controls": [
          "8.1",
          "8.2"
        ],
        "gdpr": [
          "Art.32(1)"
        ],
        "nist-800-53": [
          "AU-2",
          "AU-6",
          "AU-12"
        ],
        "coppa": [
          "312.8(b)(3)"
        ],
        "sox": [
          "P11"
        ]
      }
    },
    {
      "key": "vulnerability-management",
      "name": "Vulnerability management",
      "description": "Regular scanning, prioritization, and remediation of vulnerabilities across systems and applications, fed by current information about threats and weaknesses collected from outside the organization as well as from its own scans - vendor and industry security advisories for the software actually in use, and the threat feeds, bulletins and sector reporting that describe how systems like these are being attacked now - which is gathered continuously rather than at the next scan, evaluated for whether it applies here, and used to decide what is looked for and what is fixed first.",
      "crosswalks": {
        "iso-27001": [
          "A.5.7",
          "A.8.8"
        ],
        "soc-2": [
          "CC7.1"
        ],
        "nist-csf": [
          "ID.RA-01"
        ],
        "pci-dss": [
          "6.3",
          "11.3"
        ],
        "nist-800-171": [
          "3.11.2",
          "3.11.3"
        ],
        "cis-controls": [
          "7.1",
          "7.3"
        ],
        "gdpr": [
          "Art.32(1)"
        ],
        "nist-800-53": [
          "RA-5",
          "SI-2"
        ],
        "coppa": [
          "312.8(b)(4)"
        ],
        "sox": [
          "P11"
        ]
      }
    },
    {
      "key": "penetration-testing",
      "name": "Penetration testing programme",
      "description": "A defined penetration-testing programme - who tests, what is in scope, on what schedule and to what rules of engagement - under which testers attempt real attacks against externally exposed systems and, separately, from inside the network; findings are prioritised by risk and remediated; and the fix is retested to confirm the security measure now works as intended.",
      "crosswalks": {
        "pci-dss": [
          "11.4"
        ],
        "cis-controls": [
          "18.1",
          "18.2",
          "18.3",
          "18.4",
          "18.5"
        ]
      }
    },
    {
      "key": "malware-protection",
      "name": "Malware protection",
      "description": "Anti-malware controls prevent, detect, and respond to malicious software on endpoints and servers, and detections are reported to the people who act on them. The mechanism is kept live rather than merely installed: signatures, definitions and detection engines update automatically as the vendor issues them rather than on someone remembering to apply them, what it detects and what it does about it is logged, and it runs where an ordinary user cannot switch it off, uninstall it or exclude their way around it - only a documented, authorized change may disable it, and then for a stated period.",
      "crosswalks": {
        "iso-27001": [
          "A.8.7"
        ],
        "soc-2": [
          "CC6.8"
        ],
        "pci-dss": [
          "5.2",
          "5.3"
        ],
        "hipaa": [
          "164.308(a)(5)(ii)(B)"
        ],
        "cis-controls": [
          "10.1",
          "10.2"
        ],
        "nist-800-53": [
          "SI-3"
        ]
      }
    },
    {
      "key": "backups",
      "name": "Backups",
      "description": "Regular, tested backups of critical data and systems with defined retention, each one a RETRIEVABLE EXACT COPY of the data it protects - complete and restorable, not a partial or lossy snapshot - including a copy taken before equipment holding that data is moved.",
      "crosswalks": {
        "iso-27001": [
          "A.8.13"
        ],
        "soc-2": [
          "A1.2"
        ],
        "nist-csf": [
          "PR.DS-11"
        ],
        "hipaa": [
          "164.308(a)(7)(ii)(A)",
          "164.310(d)(2)(iv)"
        ],
        "cis-controls": [
          "11.2",
          "11.5"
        ],
        "gdpr": [
          "Art.32(1)"
        ],
        "nist-800-53": [
          "CP-9"
        ],
        "sox": [
          "P11"
        ]
      }
    },
    {
      "key": "business-continuity",
      "name": "Business continuity & disaster recovery",
      "description": "BC/DR plans with defined RTO/RPO, tested periodically AND REVISED on what the testing finds and on what has changed since, to restore service after disruption - including how the critical processes that protect sensitive data keep running while the organization is operating in emergency mode, and an assessment of how critical each application and data set is, which is what sets those recovery targets and the order in which things come back.",
      "crosswalks": {
        "iso-27001": [
          "A.5.30"
        ],
        "soc-2": [
          "A1.2",
          "A1.3"
        ],
        "nist-csf": [
          "RC.RP-01"
        ],
        "hipaa": [
          "164.308(a)(7)(ii)(B)",
          "164.308(a)(7)(ii)(C)",
          "164.308(a)(7)(ii)(D)",
          "164.308(a)(7)(ii)(E)"
        ],
        "gdpr": [
          "Art.32(1)"
        ],
        "nist-800-53": [
          "CP-2",
          "CP-10"
        ],
        "sox": [
          "P11"
        ]
      }
    },
    {
      "key": "incident-response",
      "name": "Incident response",
      "description": "A documented, tested plan to detect, triage, contain, remediate, and communicate security incidents, and to mitigate - so far as is practicable - the harmful effect of a use or disclosure of personal data the organization knows breached its own policies or the law. Each incident is recorded together with its outcome - what happened, what was done about it and how it ended - as a record of that incident, which is a different artifact from the plan being documented. The mitigation duty runs to violations by the organization itself AND to violations by the processors, vendors and other parties handling that data on its behalf: the plan reaches an incident somebody else caused with the organization’s data, so learning of one triggers the same containment and remediation as an incident inside its own walls rather than a request that the other party deal with it. Where an incident carries a duty to tell someone outside the organization, the plan discharges it on the clock the applicable law sets rather than whenever the investigation happens to conclude: whether an incident is notifiable is decided against written criteria rather than argued after the fact, the regulator or supervisory authority is notified inside the deadline that regime states, the people whose data is affected are told where the risk to them warrants it, and where a deadline is missed the notification itself explains the delay instead of passing over it.",
      "crosswalks": {
        "iso-27001": [
          "A.5.24",
          "A.5.26"
        ],
        "soc-2": [
          "CC7.3",
          "CC7.4"
        ],
        "nist-csf": [
          "RS.MA-01"
        ],
        "pci-dss": [
          "12.10"
        ],
        "hipaa": [
          "164.308(a)(6)(ii)",
          "164.530(f)"
        ],
        "nist-800-171": [
          "3.6.1",
          "3.6.2",
          "3.6.3"
        ],
        "cis-controls": [
          "17.1",
          "17.4"
        ],
        "gdpr": [
          "Art.33(1)",
          "Art.34(1)"
        ],
        "nist-800-53": [
          "IR-4",
          "IR-5",
          "IR-6",
          "IR-8"
        ],
        "coppa": [
          "312.8(a)"
        ],
        "sox": [
          "P11"
        ]
      }
    },
    {
      "key": "change-management",
      "name": "Change management",
      "description": "Changes to systems and software are requested, reviewed, tested, approved, and tracked.",
      "crosswalks": {
        "iso-27001": [
          "A.8.32"
        ],
        "soc-2": [
          "CC8.1"
        ],
        "pci-dss": [
          "6.5"
        ],
        "nist-csf": [
          "PR.PS-01"
        ],
        "nist-800-53": [
          "CM-3"
        ],
        "sox": [
          "P9",
          "P11"
        ]
      }
    },
    {
      "key": "vendor-management",
      "name": "Third-party / vendor risk management",
      "description": "Due diligence, contractual safeguards, and ongoing monitoring of vendors that handle your data: the agreement obliges the vendor to comply in its own right with the security requirements that apply to it - an absolute standard, not a promise to match whatever you happen to do - to pass those obligations down to any subcontractor it brings in BY ENTERING INTO a contract or equivalent written arrangement with that subcontractor rather than by merely requiring equivalent practice of it, and to report to you, within a stated time, security incidents it becomes aware of and confirmed breaches of your data. Where a contract is not the instrument available, an equivalent written arrangement carrying the same obligations discharges the duty. The same obligations, together with the separation that keeps a related organization out of data it is not entitled to, are written into the governing document of any other arrangement that puts your data in the hands of a sponsor, parent, affiliate or plan. Diligence is not confined to security where the relationship warrants more: for suppliers significant enough to matter, the organization states the standards of conduct it expects of them - how they behave commercially and how they treat the environment around their operations - and screens candidates and incumbents against those stated expectations as part of the same selection and monitoring cycle, rather than accepting a signature on a code as evidence of it.",
      "crosswalks": {
        "iso-27001": [
          "A.5.19"
        ],
        "soc-2": [
          "CC9.2"
        ],
        "nist-csf": [
          "GV.SC-01"
        ],
        "pci-dss": [
          "12.8"
        ],
        "hipaa": [
          "164.308(b)(3)",
          "164.314(a)(2)",
          "164.314(b)(2)"
        ],
        "iso-9001": [
          "8.4.1",
          "8.4.3"
        ],
        "esg-essentials": [
          "G.7",
          "E.7"
        ],
        "cis-controls": [
          "15.4",
          "15.5",
          "15.6"
        ],
        "gdpr": [
          "Art.28(1)",
          "Art.28(3)"
        ],
        "nist-800-53": [
          "SA-9",
          "SR-3",
          "SR-6"
        ],
        "coppa": [
          "312.8(c)"
        ],
        "sox": [
          "P11",
          "P15"
        ]
      }
    },
    {
      "key": "security-awareness-training",
      "name": "Security awareness training",
      "description": "Ongoing security and data-handling awareness training for all personnel, with completion tracking, and periodic security updates - reminders, bulletins and alerts - issued to the workforce between training cycles. New joiners are trained within a defined period of starting, anyone whose work is affected is retrained within a defined period after a material change to the policies or procedures, and every completion is recorded.",
      "crosswalks": {
        "iso-27001": [
          "A.6.3"
        ],
        "soc-2": [
          "CC1.4"
        ],
        "nist-csf": [
          "PR.AT-01"
        ],
        "pci-dss": [
          "12.6"
        ],
        "hipaa": [
          "164.308(a)(5)(ii)(A)",
          "164.530(b)(2)"
        ],
        "esg-essentials": [
          "S.5"
        ],
        "nist-800-171": [
          "3.2.1"
        ],
        "cis-controls": [
          "14.1"
        ],
        "gdpr": [
          "Art.32(4)"
        ],
        "nist-800-53": [
          "AT-2",
          "AT-3",
          "AT-4"
        ],
        "sox": [
          "P4",
          "P14"
        ]
      }
    },
    {
      "key": "asset-inventory",
      "name": "Asset inventory",
      "description": "An inventory of hardware, software, and information assets with assigned owners, in which the movement of equipment and removable media into, out of, and within the organization’s premises is recorded against the person responsible for it.",
      "crosswalks": {
        "iso-27001": [
          "A.5.9"
        ],
        "nist-csf": [
          "ID.AM-01",
          "ID.AM-02"
        ],
        "pci-dss": [
          "12.5"
        ],
        "hipaa": [
          "164.310(d)(2)(iii)"
        ],
        "nist-800-171": [
          "3.4.1"
        ],
        "cis-controls": [
          "1.1",
          "2.1"
        ],
        "nist-800-53": [
          "CM-8"
        ],
        "sox": [
          "P11"
        ]
      }
    },
    {
      "key": "data-classification",
      "name": "Data classification & handling",
      "description": "Information is classified and handled per its sensitivity, with rules for labeling and protection - including the everyday handling rules that stop it being seen, overheard or picked up by people with no business reading it, so exposure that happens incidentally alongside legitimate work is limited rather than accepted. The handling rules are written to cover disclosure that nobody intended as much as disclosure that somebody chose, they say what an unauthorized disclosure is against the organization’s own privacy and confidentiality rules rather than leaving that to judgement in the moment, and they reach every medium the information travels in - spoken, on paper, on a screen and in a system - because the incidental exposure they exist to limit does not respect the boundary between an administrative, a physical and a technical safeguard.",
      "crosswalks": {
        "iso-27001": [
          "A.5.12"
        ],
        "soc-2": [
          "C1.1"
        ],
        "nist-csf": [
          "ID.AM-05"
        ],
        "hipaa": [
          "164.530(c)(2)"
        ],
        "nist-800-171": [
          "3.8.4"
        ],
        "cis-controls": [
          "3.7"
        ],
        "gdpr": [
          "Art.5(1)"
        ],
        "nist-800-53": [
          "RA-2"
        ]
      }
    },
    {
      "key": "physical-security",
      "name": "Physical security",
      "description": "Physical access to facilities and equipment holding sensitive data is restricted and monitored, and a person’s access is validated against the role or function that justifies it rather than only logged; visitors are controlled as a case of their own, and so is access to software programs held for testing and revision. The facility and the equipment in it are safeguarded against tampering and theft as well as against unauthorized entry. The people who have to reach the site and the equipment when a continuity or recovery plan is invoked can still get in, by a route that is planned rather than improvised; and repairs and modifications to the physical security components of a facility - doors, locks, walls, and the hardware that controls entry - are recorded.",
      "crosswalks": {
        "iso-27001": [
          "A.7.1",
          "A.7.2"
        ],
        "soc-2": [
          "CC6.4"
        ],
        "pci-dss": [
          "9.2"
        ],
        "hipaa": [
          "164.310(a)(2)(i)",
          "164.310(a)(2)(ii)",
          "164.310(a)(2)(iii)",
          "164.310(a)(2)(iv)"
        ],
        "gdpr": [
          "Art.32(1)"
        ],
        "nist-800-53": [
          "PE-2",
          "PE-3",
          "PE-6"
        ],
        "sox": [
          "P11"
        ]
      }
    },
    {
      "key": "secure-development",
      "name": "Secure software development",
      "description": "Secure coding, review, and testing practices across the development lifecycle.",
      "crosswalks": {
        "iso-27001": [
          "A.8.25"
        ],
        "soc-2": [
          "CC8.1"
        ],
        "pci-dss": [
          "6.2"
        ],
        "cis-controls": [
          "16.1",
          "16.12"
        ],
        "nist-800-53": [
          "SA-3",
          "SA-8",
          "SA-11"
        ],
        "sox": [
          "P11"
        ]
      }
    },
    {
      "key": "network-security",
      "name": "Network security controls",
      "description": "Firewalls/segmentation and network controls restrict traffic to and from sensitive environments.",
      "crosswalks": {
        "iso-27001": [
          "A.8.20",
          "A.8.22"
        ],
        "soc-2": [
          "CC6.6"
        ],
        "nist-csf": [
          "PR.IR-01"
        ],
        "pci-dss": [
          "1.2",
          "1.3"
        ],
        "cis-controls": [
          "4.4",
          "4.5",
          "12.2",
          "13.4"
        ],
        "nist-800-53": [
          "SC-7",
          "AC-4"
        ],
        "sox": [
          "P11"
        ]
      }
    },
    {
      "key": "data-retention-disposal",
      "name": "Data retention & secure disposal",
      "description": "Data is retained per policy and securely destroyed when no longer needed. The hardware and media that held it reach a defined final disposition at end of life, by a route the organization has decided in advance rather than by whatever happens to the box; and any media that stays in service is cleared of that data before it is reused, reassigned, or passed to anyone else.",
      "crosswalks": {
        "iso-27001": [
          "A.8.10"
        ],
        "soc-2": [
          "C1.2"
        ],
        "pci-dss": [
          "3.2"
        ],
        "hipaa": [
          "164.310(d)(2)(i)",
          "164.310(d)(2)(ii)"
        ],
        "cis-controls": [
          "3.5"
        ],
        "gdpr": [
          "Art.5(1)"
        ],
        "nist-800-53": [
          "MP-6",
          "SI-12"
        ],
        "us-employment-federal": [
          "us.recordkeeping.eeo",
          "us.recordkeeping.i9-retention"
        ],
        "coppa": [
          "312.10"
        ]
      }
    },
    {
      "key": "hr-security",
      "name": "Personnel security (HR)",
      "description": "Background screening, confidentiality agreements, and onboarding/offboarding security steps. Before a person is given access to sensitive data, and again whenever their role changes, a documented determination is made that the access their work calls for is appropriate to it - the screening informs that decision but is not the decision. What screening may ask is itself bounded: enquiries about a candidate’s health, disability or medical history are not made, and medical examinations are not required, before a conditional offer of the role has been made, and where such enquiries or examinations are made after an offer they are applied to everyone entering that role rather than to the individuals somebody chose to ask. Access is ended when their employment, or any other arrangement under which they worked for the organization, comes to an end, and whenever that determination says they should no longer hold it.",
      "crosswalks": {
        "iso-27001": [
          "A.6.1",
          "A.6.5"
        ],
        "soc-2": [
          "CC1.4"
        ],
        "pci-dss": [
          "12.7"
        ],
        "hipaa": [
          "164.308(a)(3)(ii)(B)",
          "164.308(a)(3)(ii)(C)"
        ],
        "gdpr": [
          "Art.32(4)"
        ],
        "nist-800-53": [
          "PS-2",
          "PS-3",
          "PS-6",
          "PS-7"
        ],
        "us-employment-federal": [
          "us.hiring-onboarding.ada-preoffer",
          "us.hiring-onboarding.fcra-background"
        ],
        "sox": [
          "P4"
        ]
      }
    },
    {
      "key": "security-privacy-officers",
      "name": "Named security & privacy officers",
      "description": "One named individual is accountable for developing and implementing the organization’s security policies and procedures, and one for the policies and procedures governing personal data - the same person where the organization is small enough that saying so is honest. A named contact point receives questions and complaints about how personal data is handled. The same naming discipline runs down through the rest of the programme: the responsibilities and authorities for the security duties the organization depends on are assigned by leadership to named roles - including who answers for the management system meeting its requirements and who reports on how it is performing to leadership - and each holder is told what they hold and what they may decide, as are the people who have to go to them. Every designation and assignment is recorded in writing, published where the people who need it will find it, kept current as roles change, and reviewed when the organization changes shape.",
      "crosswalks": {
        "iso-27001": [
          "5.3"
        ],
        "hipaa": [
          "164.308(a)(2)",
          "164.530(a)(2)"
        ]
      }
    },
    {
      "key": "disciplinary-process",
      "name": "Disciplinary & sanctions process",
      "description": "A defined process for acting on a member of the workforce who breaches the organization’s security or personal-data policies: how a suspected breach is established, who decides, what range of sanctions is available and how the response is kept proportionate to what was done, and who is told when a sanction is initiated. Each sanction applied is recorded. The workforce is told the process exists and will be used, because a sanction nobody knew was possible deters nobody.",
      "crosswalks": {
        "iso-27001": [
          "A.6.4"
        ],
        "hipaa": [
          "164.308(a)(1)(ii)(C)",
          "164.530(e)(2)"
        ],
        "nist-800-53": [
          "PS-8"
        ]
      }
    },
    {
      "key": "data-segregation",
      "name": "Segregation of regulated data inside a larger organization",
      "description": "Where a function that carries its own regulatory duties runs inside a larger organization or on shared infrastructure, the data it holds is kept logically separate from the rest of that organization - separate stores or partitions, separate access groups, and a default denial for anyone outside the function - so the wider organization cannot reach the data without being separately and deliberately authorized to.",
      "crosswalks": {
        "hipaa": [
          "164.308(a)(4)(ii)(A)"
        ]
      }
    },
    {
      "key": "endpoint-security",
      "name": "Workstation & endpoint security",
      "description": "The devices people use to reach sensitive data are governed on three axes. What may be done on them and how - the permitted functions, software and networks, and the way each is to be carried out. Where they may be used - the physical surroundings a screen can be overlooked from, and what has to be true of a place before work happens there. And how the device itself is protected so only authorized users reach it - screens and desks cleared when unattended, devices locked down or taken with the person when they leave. Two separate mechanisms run here and a screen lock does not stand in for the other. A device left idle LOCKS after a defined period, concealing what is on screen, and stays locked until the user re-establishes access through identification and authentication. Separately, a user session on an application or system holding sensitive data is automatically TERMINATED - torn down, not merely obscured - so it cannot be resumed by whoever is at the keyboard. The conditions and trigger events that require termination are defined by the organization and written down rather than left to be inferred: a predetermined period of user inactivity is one of them and is the one required wherever health data is in scope, but the set also reaches a targeted response to particular kinds of incident and restrictions on the time of day a system may be used.",
      "crosswalks": {
        "iso-27001": [
          "A.7.7",
          "A.8.1"
        ],
        "hipaa": [
          "164.310(b)",
          "164.310(c)",
          "164.312(a)(2)(iii)"
        ],
        "nist-800-53": [
          "AC-11",
          "AC-12"
        ]
      }
    },
    {
      "key": "data-integrity",
      "name": "Data integrity verification",
      "description": "Mechanisms that would actually detect sensitive data being altered or destroyed without authorization, rather than assuming it has not been: checksums, hashes or digital signatures computed over stored records and re-verified rather than written once; integrity monitoring over the files and systems holding them; integrity verification of the software and firmware those systems run - signed packages and images, and detection of unauthorized change to executables, configuration and device firmware, because data that verifies clean under code that does not is not verified at all; and integrity protection on data in transit, so a change made between sender and receiver is detected before the data is relied on. A failed check raises an alert to someone who investigates it, and what was found is recorded.",
      "crosswalks": {
        "hipaa": [
          "164.312(c)(2)",
          "164.312(e)(2)(i)"
        ],
        "nist-800-53": [
          "SI-7"
        ]
      }
    },
    {
      "key": "quality-policy",
      "name": "Quality policy & objectives",
      "description": "A leadership-endorsed quality policy with measurable quality objectives, communicated across the organization.",
      "crosswalks": {
        "iso-9001": [
          "5.2.1",
          "5.2.2",
          "6.2.1"
        ]
      }
    },
    {
      "key": "risk-opportunity-planning",
      "name": "Risk & opportunity planning",
      "description": "Working from the organization’s context and what its interested parties require, the risks and opportunities the management system must address are determined and recorded; an action is planned for each and built into the system’s own processes rather than run alongside them; and those actions are afterwards evaluated for whether they worked, in proportion to the potential impact of the risk or opportunity.",
      "crosswalks": {
        "iso-9001": [
          "6.1.1",
          "6.1.2"
        ],
        "iso-42001": [
          "6.1.1"
        ]
      }
    },
    {
      "key": "document-control",
      "name": "Document & records control",
      "description": "Documented information is created, approved, versioned, and controlled; records are retained and protected for a defined minimum period - measured from the document’s creation OR from the date it last was in effect, whichever is later, so a policy that stayed in force for years does not start its clock on the day it was written - and are available to the people who have to act on the procedures they describe. Documentation is reviewed on a schedule and updated when an operational, environmental or legal change has made the current version wrong. A change forced by law is documented and put into effect promptly, and where that legal change materially affects what the organization has published to individuals about how it handles their data, THAT NOTICE IS REVISED TOO, as part of the same prompt action rather than as a separate task left to whoever owns the notice. Any other change may be made at any time provided the revised version still complies and IS DOCUMENTED BEFORE THE CHANGE TAKES EFFECT - the record precedes the effective date, so a routine that documents changes in arrears does not discharge this.",
      "crosswalks": {
        "iso-9001": [
          "7.5.2",
          "7.5.3.1",
          "7.5.3.2"
        ],
        "soc-2": [
          "CC5.3"
        ],
        "iso-27001": [
          "7.5",
          "A.5.37"
        ],
        "hipaa": [
          "164.316(b)(2)(i)",
          "164.316(b)(2)(ii)",
          "164.316(b)(2)(iii)",
          "164.530(i)(3)",
          "164.530(i)(5)",
          "164.530(j)(2)"
        ],
        "sox": [
          "P12"
        ]
      }
    },
    {
      "key": "competence-management",
      "name": "Competence management",
      "description": "The competence each role in the management system needs is determined and written down, and the people in those roles are established as having it - on the basis of their education, training or experience rather than on the basis of holding the job. Where the competence is not there, something is done about it - training, mentoring, supervision, reassignment or hiring - and the action is afterwards evaluated for whether it produced the competence, not merely for whether it was delivered. The records that show all of this are retained.",
      "crosswalks": {
        "iso-27001": [
          "7.2"
        ],
        "iso-9001": [
          "7.2"
        ],
        "sox": [
          "P4"
        ]
      }
    },
    {
      "key": "management-system-awareness",
      "name": "Management-system awareness",
      "description": "Everyone doing work under the organization’s control can say what the policy governing their work commits to, which of the objectives their own work affects, how what they do contributes to the management system working - including what improving it is worth - and what the consequences are when its requirements are not met.",
      "crosswalks": {
        "iso-9001": [
          "7.3"
        ],
        "iso-27001": [
          "7.3"
        ],
        "iso-42001": [
          "7.3"
        ]
      }
    },
    {
      "key": "internal-audit-program",
      "name": "Internal audit program",
      "description": "A risk-based internal audit program evaluates conformity and effectiveness at planned intervals, and again when an environmental or operational change could have undermined what was last evaluated; each evaluation covers both technical testing and non-technical review of whether the documented policies and procedures are actually being met. The programme itself is written down - how often audits run, what methods they use, who is responsible for them, what each one covers and how it reports - and nobody audits their own work, so a finding is an independent judgement rather than a self-assessment. The results of each audit go to the management responsible for the area audited, and the programme and its results are retained as evidence that it ran.",
      "crosswalks": {
        "iso-9001": [
          "9.2.1",
          "9.2.2"
        ],
        "soc-2": [
          "CC4.1"
        ],
        "iso-27001": [
          "9.2",
          "A.5.35"
        ],
        "iso-42001": [
          "9.2"
        ],
        "hipaa": [
          "164.308(a)(8)"
        ],
        "nist-800-53": [
          "CA-2"
        ],
        "coppa": [
          "312.8(b)(5)"
        ],
        "sox": [
          "P16"
        ]
      }
    },
    {
      "key": "management-review",
      "name": "Management review",
      "description": "Leadership reviews how the management system is performing at planned intervals and decides what to do about it: what will be improved, and what about the system itself has to change. Each decision leaves the review with a named owner and a date rather than as a sentiment in the minutes, the previous review’s decisions are picked back up at the next one so nothing is decided twice and never done, and the record of the review and its outputs is retained.",
      "crosswalks": {
        "iso-27001": [
          "9.3"
        ],
        "iso-9001": [
          "9.3.1",
          "9.3.3"
        ],
        "soc-2": [
          "CC4.1"
        ],
        "esg-essentials": [
          "G.14"
        ],
        "sox": [
          "P16"
        ]
      }
    },
    {
      "key": "nonconformity-capa",
      "name": "Nonconformity & corrective action (CAPA)",
      "description": "When something fails to meet a requirement, the first response is to contain it: the nonconforming output is controlled so it goes no further, what has already gone wrong is corrected, and the consequences of it are dealt with. Then the question of cause is asked - why it happened, and whether the same failure exists somewhere else or could happen somewhere else - and where the answer warrants action, that action is taken and tracked to closure. Afterwards the action is reviewed for whether it actually removed the cause rather than only for whether it was completed, the management system is changed where the review shows it has to be, and the nonconformity, what was done about it and the result of doing it are all recorded.",
      "crosswalks": {
        "iso-27001": [
          "10.2"
        ],
        "iso-9001": [
          "8.7.1",
          "8.7.2",
          "10.2.1",
          "10.2.2"
        ],
        "sox": [
          "P17"
        ]
      }
    },
    {
      "key": "customer-requirements",
      "name": "Customer requirements & satisfaction",
      "description": "Requirements for products/services are determined and reviewed; customer satisfaction is monitored.",
      "crosswalks": {
        "iso-9001": [
          "8.2.2",
          "8.2.3.1",
          "9.1.2"
        ]
      }
    },
    {
      "key": "organizational-context",
      "name": "Organizational context",
      "description": "The internal and external issues that bear on the management system are determined and written down: what the organization does and how it is structured, the technology and information it depends on, the people and culture inside it, and outside it the markets it sells into, the laws and contracts binding it, the threat environment it operates in and whatever else could affect whether the system achieves what it exists to achieve. Each issue is recorded with enough reasoning that a reader can see why it matters here rather than in general, and the record is revisited on a defined cadence and whenever something material changes - an acquisition, a new market, a new regulator, a new class of threat - so it is the current picture and not the one taken when the system was first set up.",
      "crosswalks": {
        "iso-27001": [
          "4.1"
        ]
      }
    },
    {
      "key": "interested-parties-requirements",
      "name": "Interested parties & their requirements",
      "description": "The parties with a stake in the management system are identified - customers, regulators and supervisory authorities, employees, owners and investors, suppliers, insurers, and anyone else whose requirements bear on it - and what each of them requires is recorded specifically enough to be tested against rather than as a category. That includes the legal, regulatory and contractual obligations that follow from each relationship. The organization then records which of those requirements it will meet through the management system and which it will not, so the boundary is a decision on the record with a reason attached rather than an omission nobody noticed. The list is reviewed on a cadence, and whenever a new obligation, contract, relationship or regulator arrives.",
      "crosswalks": {
        "iso-27001": [
          "4.2"
        ]
      }
    },
    {
      "key": "management-system-scope",
      "name": "Management system scope statement",
      "description": "The boundaries of the management system are decided and written down as a scope statement: which parts of the organization, which locations, which activities, which information and which technology sit inside it, and what sits outside. The statement is reasoned from the issues determined about the organization’s context and from what interested parties require, rather than drawn to be convenient, and it states the interfaces and dependencies between what the organization does itself and what is done for it by others - so a boundary drawn around a service someone else runs is visible on the page instead of implied by its absence. The scope is available as documented information, and it is revisited when the organization, its activities, or those dependencies change.",
      "crosswalks": {
        "iso-27001": [
          "4.3"
        ]
      }
    },
    {
      "key": "management-system-processes",
      "name": "Management system processes & interactions",
      "description": "The management system is run as one connected set of processes rather than as a pile of separate activities that happen to share a binder. The processes it needs are identified, each with what goes into it and what comes out, the order they run in and how they hand off to one another, the criteria and methods that tell whether it is working, who owns it, and what it needs to run. The map is kept current as processes are added, merged or dropped, and it is used - improvement of the system is driven from it, and a change to one process is traced through to the processes it feeds - rather than drawn once for an audit and filed.",
      "crosswalks": {
        "iso-27001": [
          "4.4"
        ]
      }
    },
    {
      "key": "leadership-commitment",
      "name": "Leadership commitment & accountability",
      "description": "Top management is accountable for whether the management system works, and the accountability is exercised rather than asserted. It approves the policy and the objectives and satisfies itself that they fit the direction the organization is actually going in; it requires the system’s requirements to be built into how the business already runs rather than bolted alongside it; it makes sure the resources the system needs are available; it tells the organization why conforming to the system matters, in its own voice; it directs and supports the people whose work makes the system effective; it promotes improvement; and it backs other managers in exercising leadership over the parts of the system that are theirs. What it decided, when, and on what basis is recorded, so the commitment is evidenced by acts rather than by a signature on a policy.",
      "crosswalks": {
        "iso-27001": [
          "5.1"
        ]
      }
    },
    {
      "key": "security-objectives",
      "name": "Information security objectives & planning",
      "description": "Information security objectives are set at the functions and levels that actually have to deliver them, consistent with the security policy, and stated so that whether they were met can be measured rather than argued about afterwards. What they are set against is the security requirements the organization has and the results of its risk assessment and treatment, so the objectives answer the risks on the register rather than restating good intentions. Each objective carries a plan: what will be done, what resources it needs, who is responsible for it, when it is to be finished, and how the result will be evaluated. Objectives are communicated to the people whose work affects them, monitored, updated as circumstances change, and kept as documented information.",
      "crosswalks": {
        "iso-27001": [
          "6.2"
        ]
      }
    },
    {
      "key": "management-system-change-planning",
      "name": "Planned change to the management system",
      "description": "When the management system itself needs to change - its scope, its policy, its objectives, the processes it runs, the roles and authorities inside it, or the method by which it assesses risk - the change is carried out in a planned way rather than absorbed. Before it is made, its purpose and what it is likely to cause are stated; the integrity of the system while the change is in progress is considered, so it does not stop working half way through; the resources the change needs are identified and made available; and the responsibilities and authorities it moves are reallocated and communicated to the people gaining and losing them. The change, the reasoning and the approval are recorded, and afterwards the result is checked against the purpose the change was made for.",
      "crosswalks": {
        "iso-27001": [
          "6.3"
        ],
        "iso-9001": [
          "6.3"
        ]
      }
    },
    {
      "key": "management-system-resources",
      "name": "Resources for the management system",
      "description": "The resources the management system needs in order to be established, run, kept running and improved are determined and provided, not assumed: the people and the time they are actually given rather than the time the plan says they have, the tools and technology, the information, and the budget. The determination distinguishes what the organization can meet from its own capability from what it has to obtain from outside, and it is written down so a shortfall is visible as a shortfall. It is revisited when the system’s scope, its workload or the organization changes, so a system that has grown is not still resourced for the size it was when it started.",
      "crosswalks": {
        "iso-27001": [
          "7.1"
        ]
      }
    },
    {
      "key": "management-system-communication",
      "name": "Management system communication plan",
      "description": "What the management system has to communicate is decided in advance and written down rather than left to whoever remembers: on what subjects, when, to whom inside the organization, to whom outside it, by whom, and by what means. The plan covers what goes out routinely - policy changes, objectives, how the system is performing, the obligations people are under - and what goes out on a trigger, and it names who is authorised to speak externally so a communication that carries an obligation is not made by whoever picked up the phone. It is reviewed when the audience, the obligations or the system change, and what was communicated, to whom and when is recorded, so the plan can be shown to have been followed rather than merely written.",
      "crosswalks": {
        "iso-27001": [
          "7.4"
        ]
      }
    },
    {
      "key": "operational-planning-control",
      "name": "Operational planning & control",
      "description": "The processes that deliver what the management system requires are planned before they are run and controlled while they run. The criteria each process has to meet are set in advance; the process is carried out to those criteria; and enough is recorded to give confidence afterwards that it ran as planned, rather than only that it ran. Changes to those processes are controlled: a planned change has its consequences considered before it is made, and an unintended change - something that drifted, broke or was worked around - is reviewed after the fact and acted on where it did harm. Processes, products and services provided from outside the organization but relied on inside it are brought within the same criteria and the same control, because a process that has been handed to someone else is still one the system depends on.",
      "crosswalks": {
        "iso-27001": [
          "8.1"
        ]
      }
    },
    {
      "key": "risk-treatment-plan",
      "name": "Risk treatment plan & residual risk acceptance",
      "description": "The treatment decisions coming out of the risk assessment are drawn together into one plan somebody can be held to: for each risk, what will be done about it, which control does it, who owns that work, and by when. The people who own the risks approve the plan and accept, in writing, the risk that will still be there once it is done - so residual risk is a decision a named person made rather than the remainder nobody looked at. The plan is then carried out; progress is tracked to closure rather than to first action; and the result of each item is recorded - what was actually implemented, and what it changed about the risk it was raised against.",
      "crosswalks": {
        "iso-27001": [
          "8.3"
        ]
      }
    },
    {
      "key": "security-performance-measurement",
      "name": "Security performance measurement",
      "description": "What the organization will monitor and measure in order to know whether information security is working is decided in advance and written down: which processes and which controls, by what method, who performs the measurement, when it is performed, and who analyses and evaluates the results and when. The methods are chosen so that repeating them produces comparable and reproducible results, rather than a different answer depending on who ran it and in which week. The results are retained, and the evaluation - what the numbers say about whether the management system is performing and whether its controls are effective, not merely what they count - reaches the people who decide what to do about it, in time for them to do it.",
      "crosswalks": {
        "iso-27001": [
          "9.1"
        ]
      }
    },
    {
      "key": "continual-improvement",
      "name": "Continual improvement",
      "description": "Improvement of the management system is run as an activity with a record, not held as an intention. Opportunities are captured from everywhere they arise - audit findings, the results of measurement and evaluation, decisions out of management reviews, incidents and near misses, and suggestions from the people actually doing the work - and held in one place instead of in the meeting each came out of. Each is evaluated and either taken forward with an owner and a date or closed with the reason it was not, so a rejected idea is a decision rather than a silence. Once an improvement is made, its effect on the suitability, adequacy and effectiveness of the system is checked, so improvement is something that can be shown to have happened rather than asserted at the next audit.",
      "crosswalks": {
        "iso-27001": [
          "10.1"
        ]
      }
    },
    {
      "key": "environmental-policy",
      "name": "Environmental policy",
      "description": "A written environmental policy stating the organization’s commitments, scope, and responsibilities.",
      "crosswalks": {
        "esg-essentials": [
          "E.1"
        ]
      }
    },
    {
      "key": "energy-emissions-tracking",
      "name": "Energy, emissions & resource use tracking",
      "description": "Regular measurement of energy consumption, an operational (Scope 1 & 2) greenhouse-gas inventory, and metering of the other material resources the business consumes, such as water.",
      "crosswalks": {
        "esg-essentials": [
          "E.2",
          "E.3",
          "E.5"
        ]
      }
    },
    {
      "key": "waste-recycling",
      "name": "Waste & recycling program",
      "description": "Waste streams are tracked and recycling or diversion is implemented where practical.",
      "crosswalks": {
        "esg-essentials": [
          "E.4"
        ]
      }
    },
    {
      "key": "environmental-targets",
      "name": "Environmental reduction targets",
      "description": "At least one measurable environmental reduction target is set and progress is reviewed.",
      "crosswalks": {
        "esg-essentials": [
          "E.6"
        ]
      }
    },
    {
      "key": "health-safety",
      "name": "Health & safety program",
      "description": "A safe working environment with incident recording, review, and corrective action. Recording is not the end of it where the law says otherwise: the incidents that meet a statutory reporting threshold - a death at work, and the serious outcomes the regime names, such as an admission to hospital, an amputation or the loss of an eye - are reported to the regulator within the window that regime sets, counted from when the organization learned of the event, and someone is accountable for making that call quickly enough that the window can still be met.",
      "crosswalks": {
        "esg-essentials": [
          "S.1"
        ],
        "us-employment-federal": [
          "us.health-safety.general-duty",
          "us.health-safety.injury-recordkeeping",
          "us.health-safety.severe-incident-reporting"
        ]
      }
    },
    {
      "key": "dei-commitment",
      "name": "Diversity, equity & inclusion commitment",
      "description": "A DEI commitment with representation tracked where lawful and appropriate.",
      "crosswalks": {
        "esg-essentials": [
          "S.2"
        ]
      }
    },
    {
      "key": "fair-labor-practices",
      "name": "Fair labor practices",
      "description": "Compliance with wage, hour, and anti-discrimination obligations for all workers.",
      "crosswalks": {
        "esg-essentials": [
          "S.3",
          "S.13"
        ],
        "us-employment-federal": [
          "us.wage-hour.minimum-wage",
          "us.wage-hour.overtime",
          "us.wage-hour.child-labor",
          "us.pay-equity.equal-pay-act",
          "us.pay-equity.title-vii-compensation"
        ]
      }
    },
    {
      "key": "individual-privacy",
      "name": "Personal data privacy",
      "description": "A plain-language privacy notice tells employees and customers what personal data is held about them, why, and how employees are monitored at work - and each request to access, correct, erase, or object to that data is logged, identity-checked, decided, and actioned.",
      "crosswalks": {
        "esg-essentials": [
          "S.8"
        ],
        "iso-27001": [
          "A.5.34"
        ],
        "gdpr": [
          "Art.12(1)",
          "Art.12(2)",
          "Art.15(1)",
          "Art.16",
          "Art.17(1)",
          "Art.21(1)"
        ]
      }
    },
    {
      "key": "records-of-processing",
      "name": "Record of processing activities (RoPA)",
      "description": "A register of every activity in which the organisation processes personal data, kept current as processing changes rather than assembled for an audit — each entry recording the purpose, the lawful basis relied on, the categories of individuals and of personal data, who the data is disclosed to, how long it is kept, any transfer outside the region with the safeguards relied on, and the security measures protecting it.",
      "crosswalks": {
        "gdpr": [
          "Art.30(1)"
        ]
      }
    },
    {
      "key": "dpia-process",
      "name": "Data protection impact assessment (DPIA) process",
      "description": "Before a new processing activity begins — and before an existing one changes in a way that alters the risk it poses — it is screened for whether it is likely to result in a high risk to people, and where it is, an impact assessment of that specific processing is completed before the processing starts: describing the processing and its purposes, testing its necessity and proportionality against them, assessing the risks to the people affected, and setting out the measures, safeguards and security mechanisms that address those risks.",
      "crosswalks": {
        "gdpr": [
          "Art.35(1)",
          "Art.35(7)"
        ]
      }
    },
    {
      "key": "breach-notification",
      "name": "Breach assessment & notification",
      "description": "A standing procedure for a suspected compromise of protected health information. It decides against documented criteria whether the incident is notifiable, and then issues each notice that decision requires - without unreasonable delay and in no case later than 60 calendar days, counted from the day the incident was discovered rather than the day it was understood. To the affected individuals: in plain language, what happened and when, what data was involved, what those people should do to protect themselves, what the organization is doing to investigate it, mitigate harm and protect against further breaches, and how to ask questions or learn more - the last given as contact procedures that MUST include a toll-free telephone number, an e-mail address, a website or a postal address, not merely an invitation to get in touch - sent by first-class mail to the last known address, or by email where the person has agreed to electronic notice and has not withdrawn that agreement, or, where the individual is known to have died and an address is held, to the next of kin or personal representative. Where contact details are missing or stale, substitute notice is given: by another written form, telephone or other means for fewer than ten such individuals; for ten or more, by a conspicuous posting on the home page of the organization’s website for 90 days or a conspicuous notice in major print or broadcast media where those affected likely live, with a toll-free number that stays active for at least 90 days. To prominent media serving a State or jurisdiction, on the same clock and carrying the same content, when the breach involves more than 500 residents of it. To the regulator on its own clock and in the form the regulator specifies: at the same time as the individual notices where 500 or more individuals are involved, and for breaches involving fewer than 500 through a maintained log filed no later than 60 days after the end of each calendar year, covering the breaches discovered in it. Where the organization holds the data on another organization’s behalf, the notice goes to that organization instead, identifying every individual affected and everything it needs for its own notifications. A notification, notice or posting is delayed only where a law-enforcement official states it would impede an investigation or damage national security - for the period a written statement specifies, or, where the statement is spoken, for no longer than 30 days from the date it was made, with the statement and the identity of the official who made it written down at the time and the delay ending sooner if no written statement follows. The procedure is issued as policy, the people who operate it are trained on it, complaints about it are handled, failures to follow it are sanctioned like any other policy breach, nobody is penalized for raising one, and nobody is required to give up a right in order to receive treatment, payment, enrolment or benefits. Every determination and every notice - its content, its recipients, the method and the date - is retained for six years from creation or from when it last was in effect, whichever is later, so the organization can show either that it notified as required or that the incident was not notifiable.",
      "crosswalks": {
        "hipaa": [
          "164.404(b)",
          "164.404(c)",
          "164.404(d)",
          "164.406(b)",
          "164.406(c)",
          "164.408(b)",
          "164.408(c)",
          "164.410(b)",
          "164.410(c)",
          "164.412",
          "164.414(a)",
          "164.414(b)"
        ]
      }
    },
    {
      "key": "privacy-notice",
      "name": "Privacy notice & transparency",
      "description": "A privacy notice the organization owns, versions and dates, written in plain language and carrying the content it is required to carry: a prominent statement of what the notice is for, how personal data is used and disclosed with examples, what rights the individual has and how to exercise them, what the organization is obliged to do, a statement that the individual may complain both TO THE ORGANIZATION AND TO THE SECRETARY of Health and Human Services, with a brief description of how to complain to the organization and an assurance that nobody is retaliated against for doing so, the name or title and telephone number of a contact person or office, and the date it takes effect. It is available on request to anyone who asks, and it reaches the individual by the route their relationship with the organization sets: a health plan gives it at enrolment and tells those it covers where to get it at least once every three years; a provider treating people directly gives it no later than the first time it delivers a service - not before data is collected, which is a different and later trigger than a consent-first regime uses - or as soon as practicable after an emergency, and makes a good-faith effort to get a written acknowledgement of receipt, recording the attempt where none is obtained. Where the organization runs a website describing its services or benefits, the notice is posted prominently on it; where it has a physical site people come to, a copy is kept there for individuals to take away and the notice is posted in a clear and prominent place where someone waiting to be seen can read it. Where a notice is issued jointly with other organizations, each of them agrees to abide by its terms, and the notice describes with reasonable specificity both the organizations (or classes of organization) and the SERVICE DELIVERY SITES (or classes of site) it applies to, and says, where it is so, that those organizations WILL SHARE the individual’s data with each other to carry out the work the arrangement exists for - so a reader learns from the notice which premises they are covered at and that their data moves between the participants. Issue by any one participant discharges the duty for all of them. A copy of every version issued is retained, along with any acknowledgement of receipt and, where one could not be obtained, the record of the good-faith attempt. When a practice the notice describes changes, the notice is revised and made available before the change takes effect - not after it.",
      "crosswalks": {
        "hipaa": [
          "164.520(b)",
          "164.520(c)",
          "164.520(d)",
          "164.520(e)",
          "164.530(i)(4)"
        ]
      }
    },
    {
      "key": "individual-rights-requests",
      "name": "Individual rights request handling",
      "description": "Every request an individual makes about their own personal data - to see it or get a copy, to have it corrected or amended, to restrict how it is used or disclosed, or to be contacted only by a particular means or at a particular address - is logged when it arrives, the requester’s identity is checked, and the request is answered inside the window that right carries - 30 days for a request to see or copy, 60 days for a request to amend - with at most one 30-day extension, and only if the individual is told in writing why and by when. What is provided is what was asked for - INSPECTION, a copy, or both - in the form and format asked for where that is readily producible, arranging with the individual a convenient time and place to inspect or collect it, or mailing it where they ask; transmitted to a third party where the individual directs it in a signed writing naming that person and where to send it; and charged at no more than a reasonable cost-based fee. A refusal is given in writing in plain language with the reason; anything else that was asked for and is not refused is still provided; where the organization does not hold the data at all and knows who does, it tells the individual where to send the request instead of simply refusing; and the individual is told what to do next - review by a LICENSED HEALTH CARE PROFESSIONAL whom the organization designates and who took no part in the original decision, where that route exists, or the right to file a statement of disagreement with the record - and how to complain BOTH to the organization and to the Secretary of Health and Human Services, with the name or title and telephone number of the contact person or office to use. An accepted correction is made by identifying the records it affects and APPENDING the correction, or a link to where it lives, to them - the original entry stays and the record is added to, because a record that is silently overwritten loses the history a later reader needs and destroys the evidence of what was relied on at the time; the individual is told the correction was accepted and asked to identify, and agree to, the people it should be shared with, and those people are then notified along with anyone known to hold the data who may rely on it to the individual’s detriment; a correction notified to the organization by another organization is applied to its own copy the same way, by appending rather than replacing. Where a correction is refused, the individual may file a statement of disagreement; the organization may write a rebuttal and gives the individual a copy of it when it does; and the request, the refusal, the statement and any rebuttal are appended or linked to the record and travel with it - or an accurate summary does - on any later disclosure of the data they concern. An agreed restriction or an agreed alternative contact arrangement is recorded, and it ends only where the individual agrees to or asks for the ending IN WRITING, where they agree ORALLY AND THAT ORAL AGREEMENT IS WRITTEN DOWN, or by the organization telling the individual it is ending the agreement - and that last, one-sided route does not work AT ALL against a restriction the organization had no choice but to accept - the restriction on disclosing to a health plan an item or service the individual paid for in full out of pocket - and otherwise takes effect only for data created or received after the individual has been told; a request for alternative contact may be required in writing but never conditioned on the individual explaining why they are asking, and may otherwise be conditioned only on being told how any payment will be handled and on being given a workable alternative address or contact method. The organization records which sets of records these requests reach and which roles receive and process them, retains the request records for six years from creation or from when they last were in effect, whichever is later, penalizes nobody - inside or outside the organization - for making a request, complaining, or taking part in an investigation, and requires nobody to give up any of these rights as a condition of getting a service, a payment or a benefit.",
      "crosswalks": {
        "hipaa": [
          "164.522(a)(2)",
          "164.522(a)(3)",
          "164.522(b)(2)",
          "164.524(b)",
          "164.524(c)",
          "164.524(d)",
          "164.524(e)",
          "164.526(b)",
          "164.526(c)",
          "164.526(d)",
          "164.526(e)",
          "164.526(f)",
          "164.530(g)",
          "164.530(h)"
        ]
      }
    },
    {
      "key": "disclosure-accounting",
      "name": "Record & accounting of disclosures",
      "description": "A record is kept of the disclosures of an individual’s personal data made to other parties, each entry carrying the date, who received it and where they are if that is known, a short description of what was disclosed, and the purpose - or, where a written request prompted it, a copy of that request. On request, the individual is given an account of those disclosures covering the six years before the request, within 60 days and with at most one 30-day extension on written notice, and the first account asked for in any twelve-month period is provided without charge. A reasonable cost-based fee may be charged for a further account asked for by the same individual inside that twelve-month period only if the individual is TOLD THE FEE IN ADVANCE and is given the chance to WITHDRAW OR NARROW the request to avoid or reduce it - the fee is disclosed before the work is done, never billed after it. The organization records what an account has to contain, keeps a copy of each account it has provided, and records which roles receive and process these requests.",
      "crosswalks": {
        "hipaa": [
          "164.528(b)",
          "164.528(c)",
          "164.528(d)"
        ]
      }
    },
    {
      "key": "esg-oversight",
      "name": "ESG leadership oversight",
      "description": "Leadership accountability for the ESG program with periodic review of performance.",
      "crosswalks": {
        "esg-essentials": [
          "G.1"
        ]
      }
    },
    {
      "key": "code-of-conduct",
      "name": "Code of business conduct",
      "description": "A code of conduct - including conflicts of interest - acknowledged by staff.",
      "crosswalks": {
        "esg-essentials": [
          "G.2",
          "G.4"
        ],
        "sox": [
          "P1"
        ]
      }
    },
    {
      "key": "anti-bribery",
      "name": "Anti-corruption & bribery",
      "description": "Bribery and facilitation payments are prohibited, with training for relevant staff.",
      "crosswalks": {
        "esg-essentials": [
          "G.3"
        ],
        "sox": [
          "P1"
        ]
      }
    },
    {
      "key": "whistleblower-channel",
      "name": "Whistleblower channel",
      "description": "A confidential, non-retaliatory channel to report misconduct.",
      "crosswalks": {
        "esg-essentials": [
          "G.5"
        ],
        "sox": [
          "P14"
        ]
      }
    },
    {
      "key": "delegation-of-authority",
      "name": "Delegation of authority & segregation of duties",
      "description": "Approval authority and spending limits are defined, assigned to named roles, reviewed as the organization changes, and enforced in the systems that execute transactions - so no one person can initiate, approve, record and reconcile the same transaction.",
      "crosswalks": {
        "iso-27001": [
          "A.5.3"
        ],
        "soc-2": [
          "CC1.3"
        ],
        "nist-800-53": [
          "AC-5"
        ],
        "sox": [
          "P3",
          "P5",
          "P10"
        ]
      }
    },
    {
      "key": "fraud-risk-assessment",
      "name": "Fraud risk assessment",
      "description": "A periodic assessment of how fraud could occur here - fraudulent reporting, misappropriation, corruption, and management override of controls - naming the specific schemes considered and the control responding to each.",
      "crosswalks": {
        "soc-2": [
          "CC3.3"
        ],
        "sox": [
          "P8"
        ]
      }
    },
    {
      "key": "information-completeness-accuracy",
      "name": "Completeness & accuracy of information used by controls",
      "description": "Every report, extract, query result, spreadsheet, system-generated listing and third-party statement that a control depends on is identified and listed, and for each one the organization can show why it may be relied upon rather than asserting that it came out of a system. Recorded with the output, not remembered: where the data came from, the parameters, filters and date range that produced it, who produced it and when. Established rather than assumed: that it is COMPLETE, so nothing that belongs in it is missing, and ACCURATE, so what is in it is right - by reconciliation to an independent source, by agreeing a record count or a total back to it, by reperformance of the extract, or by another check stated in advance and evidenced when performed. Information obtained from outside the organization carries the same burden as information it produced itself; its origin is not the reason to trust it. The information reaches the person who has to act on it early enough to be acted on, since data that arrives after the decision it was meant to inform is unusable however accurate it is. The output and the evidence of its check are retained together so the same conclusion can be re-reached later by someone who was not there, and when the underlying system, query or report definition changes, the basis for relying on it is established again rather than carried over.",
      "crosswalks": {
        "soc-2": [
          "CC2.1"
        ],
        "sox": [
          "P13"
        ]
      }
    },
    {
      "key": "esg-reporting",
      "name": "ESG reporting & disclosure",
      "description": "An accurate summary of ESG performance is maintained or published for stakeholders.",
      "crosswalks": {
        "esg-essentials": [
          "G.8"
        ]
      }
    },
    {
      "key": "environmental-aspects-impacts",
      "name": "Environmental aspects & impacts register",
      "description": "The environmental effects of the organization’s activities are identified and kept in a register - emissions to air, discharges to water and land, hazardous materials handled, and effects on habitats or land use - each with what is being done to avoid, reduce or restore it.",
      "crosswalks": {
        "esg-essentials": [
          "E.8",
          "E.10"
        ]
      }
    },
    {
      "key": "climate-risk-assessment",
      "name": "Climate risk & adaptation assessment",
      "description": "A periodic assessment of how physical climate hazards and transition effects could disrupt sites, supply, demand or costs, with the response for each significant exposure and an owner.",
      "crosswalks": {
        "esg-essentials": [
          "E.9"
        ]
      }
    },
    {
      "key": "product-lifecycle-stewardship",
      "name": "Product & service life-cycle stewardship",
      "description": "Environmental impact is considered across design, materials, packaging, use and end of life for what the organization sells, and customers are given the information they need to use, maintain and dispose of it with less impact.",
      "crosswalks": {
        "esg-essentials": [
          "E.11",
          "S.19"
        ]
      }
    },
    {
      "key": "environmental-obligations-register",
      "name": "Environmental obligations register",
      "description": "A current list of the environmental permits, licences, legal requirements and customer commitments that apply to the organization, each with a named owner, a renewal or reporting date, and evidence of the last check.",
      "crosswalks": {
        "esg-essentials": [
          "E.12"
        ]
      }
    },
    {
      "key": "employee-wellbeing",
      "name": "Employee wellbeing & feedback",
      "description": "Workers have a routine way to give feedback and raise concerns about their working experience, and the organization acts on what it hears - supporting wellbeing and development, and recording what changed.",
      "crosswalks": {
        "esg-essentials": [
          "S.4"
        ]
      }
    },
    {
      "key": "human-rights-due-diligence",
      "name": "Human rights commitment & due diligence",
      "description": "A stated commitment to respect internationally recognized human rights, backed by a periodic review of where the organization could cause, contribute to, or be linked to harm - through its own operations, its workers, its supply chain, or partners it benefits from - with particular attention to groups more exposed to that harm.",
      "crosswalks": {
        "esg-essentials": [
          "S.6",
          "S.9",
          "S.11"
        ]
      }
    },
    {
      "key": "grievance-mechanism",
      "name": "Grievance & complaint handling",
      "description": "Anyone affected by the organization - a worker, a customer, a neighbour - has a reachable route to raise a concern or a complaint, including a complaint about how their personal data is handled; every complaint received is recorded together with what was decided and done about it; cases are resolved without undue cost or delay; and outcomes are tracked so recurring causes get fixed.",
      "crosswalks": {
        "esg-essentials": [
          "S.10",
          "S.17"
        ],
        "iso-9001": [
          "8.2.1",
          "10.2.1"
        ],
        "hipaa": [
          "164.530(d)(2)"
        ]
      }
    },
    {
      "key": "responsible-marketing",
      "name": "Responsible marketing & substantiated claims",
      "description": "Marketing, pricing and contract terms are presented truthfully, and every environmental or social claim is backed by evidence held before the claim is published.",
      "crosswalks": {
        "esg-essentials": [
          "S.15"
        ],
        "iso-9001": [
          "8.2.2"
        ]
      }
    },
    {
      "key": "product-service-safety",
      "name": "Product & service safety",
      "description": "The safety of what the organization sells is assessed before it reaches customers, residual risks are communicated in the instructions and warnings that ship with it, and safety reports and defects are investigated and acted on.",
      "crosswalks": {
        "esg-essentials": [
          "S.16"
        ],
        "iso-9001": [
          "8.3.5",
          "8.5.5"
        ]
      }
    },
    {
      "key": "accessible-inclusive-service",
      "name": "Accessible & inclusive service",
      "description": "Products, services and support channels are checked for use by people with disabilities and by customers the market underserves, with the barriers found recorded and a plan to remove them.",
      "crosswalks": {
        "esg-essentials": [
          "S.18"
        ]
      }
    },
    {
      "key": "stakeholder-engagement",
      "name": "Stakeholder identification & engagement",
      "description": "The people and groups affected by the organization’s decisions are identified - including the communities around its operations - engaged before decisions that change that impact, and the organization records what it changed as a result.",
      "crosswalks": {
        "esg-essentials": [
          "G.10",
          "S.7",
          "S.20"
        ],
        "iso-9001": [
          "4.2"
        ]
      }
    },
    {
      "key": "community-contribution",
      "name": "Local employment, skills & community investment",
      "description": "Hiring, training and giving are directed toward the communities the organization operates in - local recruitment, apprenticeships or placements where practical, and donations, volunteering or in-kind support aimed at needs the community itself has identified - with what was done recorded.",
      "crosswalks": {
        "esg-essentials": [
          "S.21",
          "S.23"
        ]
      }
    },
    {
      "key": "responsible-procurement",
      "name": "Responsible purchasing practice",
      "description": "Significant purchasing decisions consider local and smaller suppliers alongside price, and suppliers are paid on the terms agreed - with payment performance monitored, not assumed.",
      "crosswalks": {
        "esg-essentials": [
          "S.22"
        ]
      }
    },
    {
      "key": "responsible-political-engagement",
      "name": "Responsible political involvement",
      "description": "Rules govern lobbying, political contributions and the positions taken through trade associations; what is spent and where is recorded and disclosed where required, and none of it is used to obtain improper influence.",
      "crosswalks": {
        "esg-essentials": [
          "G.11"
        ]
      }
    },
    {
      "key": "fair-competition",
      "name": "Fair competition",
      "description": "Price fixing, bid rigging, market allocation and abuse of a dominant position are prohibited, and the staff who deal with competitors, trade associations or tenders are trained on the line they must not cross.",
      "crosswalks": {
        "esg-essentials": [
          "G.12"
        ]
      }
    },
    {
      "key": "property-rights-respect",
      "name": "Respect for property & intellectual property rights",
      "description": "The organization uses others’ physical, intellectual and traditional property only with the rights to do so - licences held and tracked for the software, content and brands it uses, and fair payment where use is agreed.",
      "crosswalks": {
        "esg-essentials": [
          "G.13"
        ]
      }
    },
    {
      "key": "ai-system-inventory",
      "name": "AI system inventory",
      "description": "A maintained inventory of the AI systems the organization develops, deploys, or uses, with each system's purpose, owner, and risk classification.",
      "crosswalks": {
        "nist-ai-rmf": [
          "GOVERN-1.6"
        ],
        "ai-governance-essentials": [
          "GV.3"
        ]
      }
    },
    {
      "key": "ai-impact-assessment",
      "name": "AI system impact assessment",
      "description": "A process to assess the potential impacts of AI systems on individuals, groups, and society, and to document and act on the results.",
      "crosswalks": {
        "iso-42001": [
          "A.5.2",
          "A.5.4"
        ],
        "nist-ai-rmf": [
          "MAP-5.1"
        ],
        "ai-governance-essentials": [
          "RM.1",
          "RM.2"
        ]
      }
    },
    {
      "key": "human-oversight",
      "name": "Human oversight of AI",
      "description": "Appropriate human oversight of AI systems, so people can understand, monitor, and intervene in how an AI system operates - the named people who hold that oversight have the competence, the authority and the access to the system to exercise it, and the system is operated in the way the instructions supplied with it specify, inside the purpose it was assessed and approved for rather than whatever use it turns out to support.",
      "crosswalks": {
        "iso-42001": [
          "A.6.2.6",
          "A.9.2"
        ],
        "eu-ai-act": [
          "HREQ-6",
          "HOBL-5"
        ],
        "ai-governance-essentials": [
          "HO.1",
          "HO.2"
        ]
      }
    },
    {
      "key": "ai-policy",
      "name": "AI policy",
      "description": "A documented, leadership-approved policy for the responsible development and use of AI, aligned with the organization’s other policies and reviewed at planned intervals.",
      "crosswalks": {
        "iso-42001": [
          "A.2.2",
          "A.2.3",
          "A.2.4"
        ],
        "nist-ai-rmf": [
          "GOVERN-1.2"
        ]
      }
    },
    {
      "key": "ai-roles-responsibilities",
      "name": "AI roles & accountability",
      "description": "Defined and allocated responsibilities for AI across the organization, plus a way for staff to raise concerns about the organization’s AI.",
      "crosswalks": {
        "iso-42001": [
          "A.3.2",
          "A.3.3"
        ],
        "nist-ai-rmf": [
          "GOVERN-2.1"
        ]
      }
    },
    {
      "key": "ai-risk-management",
      "name": "AI risk management process",
      "description": "A process to identify, analyze, prioritize, and treat the risks an AI system can pose, tracked over its lifecycle.",
      "crosswalks": {
        "nist-ai-rmf": [
          "MEASURE-1.1",
          "MANAGE-1.2",
          "MANAGE-1.3"
        ],
        "eu-ai-act": [
          "HREQ-1"
        ]
      }
    },
    {
      "key": "ai-data-governance",
      "name": "Data governance for AI",
      "description": "Governance of the data used to develop and operate AI systems: sourcing, quality, provenance, and preparation of training and operational data.",
      "crosswalks": {
        "iso-42001": [
          "A.4.3",
          "A.7.2",
          "A.7.3",
          "A.7.4",
          "A.7.5",
          "A.7.6"
        ],
        "eu-ai-act": [
          "HREQ-2"
        ]
      }
    },
    {
      "key": "ai-responsible-development",
      "name": "Responsible AI development lifecycle",
      "description": "Objectives and processes for responsible design and development of AI systems, including requirements, design documentation, and controlled deployment.",
      "crosswalks": {
        "iso-42001": [
          "A.6.1.2",
          "A.6.1.3",
          "A.6.2.2",
          "A.6.2.3",
          "A.6.2.5"
        ]
      }
    },
    {
      "key": "ai-verification-validation",
      "name": "AI verification, validation & robustness",
      "description": "Testing that an AI system meets its requirements and performs with appropriate accuracy, robustness, and security before and during use.",
      "crosswalks": {
        "iso-42001": [
          "A.6.2.4"
        ],
        "nist-ai-rmf": [
          "MEASURE-2.3",
          "MEASURE-2.4",
          "MEASURE-2.5",
          "MEASURE-2.7"
        ],
        "eu-ai-act": [
          "HREQ-7"
        ]
      }
    },
    {
      "key": "ai-technical-documentation",
      "name": "AI technical documentation",
      "description": "Maintained technical documentation of an AI system’s design, development, and impact assessments, sufficient to demonstrate how it works and was built.",
      "crosswalks": {
        "iso-42001": [
          "A.5.3",
          "A.6.2.7"
        ],
        "eu-ai-act": [
          "HREQ-3"
        ]
      }
    },
    {
      "key": "ai-logging-records",
      "name": "AI system logging & record-keeping",
      "description": "Automatic recording of events over an AI system’s lifetime, retained to support traceability, monitoring, and post-incident review.",
      "crosswalks": {
        "iso-42001": [
          "A.6.2.8"
        ],
        "eu-ai-act": [
          "HREQ-4"
        ]
      }
    },
    {
      "key": "ai-transparency-disclosure",
      "name": "AI transparency & disclosure",
      "description": "Clear information for users and interested parties, including disclosing when people are interacting with an AI system and how to use it appropriately.",
      "crosswalks": {
        "iso-42001": [
          "A.8.2",
          "A.8.5"
        ],
        "eu-ai-act": [
          "TRANS-1",
          "HREQ-5"
        ]
      }
    },
    {
      "key": "ai-monitoring-incidents",
      "name": "AI monitoring & malfunction reporting",
      "description": "Ongoing monitoring of AI systems in operation, with a process to detect, communicate, and report malfunctions and serious incidents.",
      "crosswalks": {
        "iso-42001": [
          "A.6.2.6",
          "A.8.4"
        ],
        "eu-ai-act": [
          "HOBL-5",
          "HOBL-6",
          "HOBL-7"
        ],
        "nist-ai-rmf": [
          "MANAGE-4.1",
          "MANAGE-4.3"
        ]
      }
    },
    {
      "key": "ai-responsible-use",
      "name": "Responsible use of AI",
      "description": "Processes and objectives for using AI systems responsibly and within their intended purpose, so deployment stays inside approved boundaries.",
      "crosswalks": {
        "iso-42001": [
          "A.9.2",
          "A.9.3",
          "A.9.4"
        ]
      }
    },
    {
      "key": "ai-supplier-management",
      "name": "AI supplier & third-party management",
      "description": "Allocation of responsibilities with, and oversight of, the suppliers and third parties involved in developing or providing AI systems and components.",
      "crosswalks": {
        "iso-42001": [
          "A.10.2",
          "A.10.3"
        ],
        "nist-ai-rmf": [
          "GOVERN-6.1",
          "MANAGE-3.1"
        ]
      }
    },
    {
      "key": "employment-classification",
      "name": "Worker classification review",
      "description": "Exempt/non-exempt and employee/contractor determinations are documented against the governing tests and re-reviewed when a role or engagement changes.",
      "crosswalks": {
        "esg-essentials": [
          "S.12"
        ],
        "us-employment-federal": [
          "us.classification.exempt",
          "us.classification.independent-contractor"
        ]
      }
    },
    {
      "key": "leave-administration",
      "name": "Statutory leave administration",
      "description": "A consistent process for statutory leave: eligibility determination, employee and employer notices, designation, and reinstatement on return.",
      "crosswalks": {
        "us-employment-federal": [
          "us.leave.fmla",
          "us.leave.userra",
          "us.leave.federal-jury"
        ]
      }
    },
    {
      "key": "benefits-administration",
      "name": "Benefit plan administration",
      "description": "Benefit plans are administered against their plan documents, with participant disclosures and continuation-coverage notices issued within the required windows.",
      "crosswalks": {
        "us-employment-federal": [
          "us.benefits.cobra",
          "us.benefits.erisa",
          "us.benefits.aca-employer",
          "us.termination.cobra-election-notice"
        ]
      }
    },
    {
      "key": "anti-discrimination-program",
      "name": "Anti-discrimination & accommodation program",
      "description": "A published anti-discrimination and anti-harassment policy with reporting routes, a documented investigation procedure, and a consistent process for handling accommodation requests.",
      "crosswalks": {
        "esg-essentials": [
          "S.3"
        ],
        "us-employment-federal": [
          "us.antidiscrim.title-vii",
          "us.antidiscrim.ada",
          "us.antidiscrim.adea",
          "us.antidiscrim.gina",
          "us.antidiscrim.pregnancy",
          "us.antidiscrim.pwfa"
        ]
      }
    },
    {
      "key": "workplace-notices",
      "name": "Workplace notices & postings",
      "description": "Required workplace notices are posted where employees can see them, including for remote staff, and individual notices are delivered when a triggering event occurs.",
      "crosswalks": {
        "us-employment-federal": [
          "us.posting.federal-workplace-posters"
        ]
      }
    },
    {
      "key": "labor-relations-practice",
      "name": "Protected activity & labor relations",
      "description": "Policies, handbooks, and manager practice are reviewed so they do not restrain employees acting together on terms and conditions of employment.",
      "crosswalks": {
        "esg-essentials": [
          "S.14"
        ],
        "us-employment-federal": [
          "us.labor.nlra-protected-activity"
        ]
      }
    },
    {
      "key": "workforce-reduction-notice",
      "name": "Workforce reduction notice assessment",
      "description": "Layoffs, closures, and relocations are assessed against advance-notice thresholds before the decision is executed, so any required notice period can still be met.",
      "crosswalks": {
        "us-employment-federal": [
          "us.termination.warn"
        ]
      }
    },
    {
      "key": "childrens-privacy-program",
      "name": "Children’s online privacy programme",
      "description": "A documented assessment of whether the service is directed to children under 13 or has a mixed audience, which operators collect through it, and the notice, consent, parental-rights, minimisation, security and retention duties that follow. Where the app ships through an app store, the same assessment carries that store’s audience determination — note Amazon treats under 16 as a child in the EU, Australia and Japan, so the age band recorded must be the widest one that applies.",
      "crosswalks": {
        "coppa": [
          "312.3"
        ],
        "apple-kids": [
          "1.3/childrens-privacy-law"
        ],
        "google-play-families": [
          "families/console/target-audience",
          "families/requirements/legal-compliance"
        ],
        "amazon-child-directed": [
          "child-directed/scope/determination",
          "child-directed/legal/coppa-compliance"
        ]
      }
    },
    {
      "key": "childrens-privacy-notice",
      "name": "Children’s privacy notice (direct & online)",
      "description": "Direct notices to parents for each circumstance that triggers one, and a prominent online children’s privacy notice carrying the operator details, collection, use, disclosure and retention information the rule requires. The same notice work satisfies the app stores’ requirements to publish a privacy policy and to disclose everything collected from children, including through SDKs.",
      "crosswalks": {
        "coppa": [
          "312.4(a)",
          "312.4(b)",
          "312.4(c)(1)",
          "312.4(c)(2)",
          "312.4(c)(3)",
          "312.4(c)(4)",
          "312.4(d)"
        ],
        "apple-kids": [
          "5.1.1(i)",
          "5.1.4(b)"
        ],
        "google-play-families": [
          "families/requirements/data-disclosure"
        ]
      }
    },
    {
      "key": "parental-consent",
      "name": "Verifiable parental consent",
      "description": "Verifiable parental consent is obtained and recorded before a child’s personal information is collected, used or disclosed, using a method reasonably calculated to confirm the person consenting is the parent, with separate consent for disclosure to third parties. Note that an app-store parental gate is not the same thing as verifiable parental consent, and neither substitutes for the other.",
      "crosswalks": {
        "coppa": [
          "312.5(a)(1)",
          "312.5(a)(2)",
          "312.5(b)(1)"
        ],
        "gdpr": [
          "Art.8(1)",
          "Art.8(2)"
        ],
        "apple-kids": [
          "5.1.4(a)/birthdate-parental-contact"
        ]
      }
    },
    {
      "key": "childrens-consent-exceptions",
      "name": "Consent-exception handling for children’s data",
      "description": "Where children’s personal information is collected without prior parental consent under one of the rule’s narrow exceptions, the purpose limit, use limit, notice and prompt-deletion conditions attached to that exception are documented and enforced.",
      "crosswalks": {
        "coppa": [
          "312.5(c)(1)",
          "312.5(c)(2)",
          "312.5(c)(3)",
          "312.5(c)(4)",
          "312.5(c)(5)",
          "312.5(c)(6)",
          "312.5(c)(7)",
          "312.5(c)(8)",
          "312.5(c)(9)"
        ]
      }
    },
    {
      "key": "parent-review-deletion",
      "name": "Parent review, refusal & deletion requests",
      "description": "A documented route for a parent to see the categories of personal information collected from their child, review it after the requester is confirmed to be the parent, refuse further use or collection, and require deletion.",
      "crosswalks": {
        "coppa": [
          "312.6(a)(1)",
          "312.6(a)(2)",
          "312.6(a)(3)"
        ],
        "gdpr": [
          "Art.15(1)",
          "Art.17(1)"
        ]
      }
    },
    {
      "key": "child-data-minimization",
      "name": "Minimised collection in children’s activities",
      "description": "Games, prize offerings and other activities aimed at children are reviewed so participation is never conditioned on disclosing more personal information than the activity reasonably needs, and the technical identifiers and location signals the app stores prohibit in children’s apps are neither collected nor transmitted.",
      "crosswalks": {
        "coppa": [
          "312.7"
        ],
        "gdpr": [
          "Art.5(1)"
        ],
        "apple-kids": [
          "1.3/no-third-party-transfer"
        ],
        "google-play-families": [
          "families/requirements/child-only-identifiers",
          "families/requirements/ad-id-permission",
          "families/requirements/mixed-identifiers",
          "families/requirements/phone-number",
          "families/requirements/child-only-location"
        ]
      }
    },
    {
      "key": "childrens-app-store-declarations",
      "name": "App-store audience declarations & metadata",
      "description": "The age and audience declarations made in each app store’s console, and the store-listing metadata, are accurate, kept current when the app changes, and consistent with how the app is actually built and marketed — including the data-safety and content-rating answers the store enforces against.",
      "crosswalks": {
        "apple-kids": [
          "2.3.8/for-kids-metadata"
        ],
        "google-play-families": [
          "families/console/accurate-answers",
          "families/social/rating-disclosure"
        ]
      }
    },
    {
      "key": "childrens-experience-safeguards",
      "name": "Child-appropriate experience & parental gates",
      "description": "Everything a child can reach in the app is age-appropriate, and links out of the app, purchasing opportunities and other adult-facing paths sit behind a parental gate or an equivalent barrier. Covers the store rules on content suitability, thin webview wrappers, augmented-reality safety warnings, and requirements that persist after a kids category is deselected.",
      "crosswalks": {
        "apple-kids": [
          "1.3/parental-gate",
          "1.3/persisting-requirements"
        ],
        "google-play-families": [
          "families/requirements/app-content",
          "families/requirements/app-functionality",
          "families/requirements/ar-safety-warning",
          "families/requirements/ar-device"
        ],
        "amazon-child-directed": [
          "child-directed/content/age-appropriate"
        ]
      }
    },
    {
      "key": "childrens-ads-monetization",
      "name": "Children’s advertising & monetisation controls",
      "description": "Ads and monetisation reaching children or users of unknown age come only from sources the store permits, carry no interest-based targeting or remarketing, present age-appropriate creative, and follow the store’s format rules on ad walls, closeability, launch interstitials, multiple placements and virtual currency. Note the stores differ sharply here: Amazon bars its own advertising and affiliate programmes outright and parental consent does not lift that, while Google permits certified SDKs and Apple permits contextual advertising only from vendors with published kids policies including human creative review.",
      "crosswalks": {
        "coppa": [
          "312.5(c)(7)"
        ],
        "apple-kids": [
          "1.3/third-party-advertising",
          "5.1.4(a)/no-third-party-analytics-advertising"
        ],
        "google-play-families": [
          "families/ads/certified-sdk-only",
          "families/ads/no-interest-based-or-remarketing",
          "families/ads/child-appropriate-content",
          "families/ads/legal-and-industry-standards",
          "families/ads-format/no-deceptive-or-inadvertent-clicks",
          "families/ads-format/no-ad-walls",
          "families/ads-format/closeable-after-5-seconds",
          "families/ads-format/no-launch-interstitial",
          "families/ads-format/no-multiple-placements",
          "families/ads-format/distinguishable-from-content",
          "families/ads-format/no-manipulative-tactics",
          "families/ads-format/no-forced-click-through",
          "families/ads-format/virtual-currency-distinction"
        ],
        "amazon-child-directed": [
          "child-directed/ads/no-amazon-programs-to-children",
          "child-directed/ads/child-only-no-amazon-programs"
        ]
      }
    },
    {
      "key": "childrens-sdk-governance",
      "name": "Third-party SDK & API governance for children’s apps",
      "description": "Every third-party SDK and API in a child-directed app is inventoried with what it collects and transmits, checked against terms that permit child-directed use, and either confirmed suitable for children or gated so it collects nothing from them. This is one inventory that answers Apple’s analytics limits, Google’s approved-SDK rules, Amazon’s child-suitability test and COPPA’s diligence duty at once.",
      "crosswalks": {
        "coppa": [
          "312.8(c)"
        ],
        "apple-kids": [
          "1.3/third-party-analytics"
        ],
        "google-play-families": [
          "families/requirements/child-only-sdk",
          "families/requirements/mixed-sdk",
          "families/requirements/mixed-sdk-gating"
        ],
        "amazon-child-directed": [
          "child-directed/sdk/child-suitable",
          "child-directed/sdk/prohibited-terms"
        ]
      }
    },
    {
      "key": "neutral-age-screen",
      "name": "Neutral age screening for mixed audiences",
      "description": "A mixed-audience app establishes a user’s age band with a neutral screen that does not steer or reward a user into misstating their age, treats an unknown age as a child, and uses the result to gate data collection, third-party SDKs and advertising. One implementation is the evidence for the identifier, SDK and ad-serving rules that all depend on knowing which users are children.",
      "crosswalks": {
        "google-play-families": [
          "families/ads-sdk/mixed-age-screening"
        ],
        "amazon-child-directed": [
          "child-directed/sdk/mixed-audience-gating"
        ]
      }
    },
    {
      "key": "childrens-social-safety",
      "name": "Online-safety controls for children’s social features",
      "description": "Where children can share freeform content or communicate with others, an in-app safety reminder is shown before the first exchange, adults can manage or disable the social features, and adult action is required before a child exchanges personal information. Apps whose main focus is chatting with strangers do not target children at all.",
      "crosswalks": {
        "google-play-families": [
          "families/social/online-safety-reminder",
          "families/social/adult-action-gate",
          "families/social/adult-management",
          "families/social/anonymous-chat"
        ]
      }
    }
  ]
}
