Essential Compliance
Standards, frameworks & regulations
Manage the compliance programs that matter to your organization, while reusing controls and evidence wherever requirements overlap.
Selected standards, frameworks & regulations
Start with the obligations that matter to your organization
Tracker gives each program its own structure while connecting shared controls, evidence, risks, and remediation across the library. Start with the examples below, add your own, or ask us about the many other frameworks available. If you need something different, we can quickly configure it for you.
Information Security
- Featured
standard
ISO 27001
Connect ISO 27001 requirements, controls, risks, evidence, owners, and remediation in one continuously managed compliance program.
Explore ISO 27001 framework
NIST CSF 2.0
Put the NIST Cybersecurity Framework (CSF) 2.0 into practice with Essential Compliance. Connect cybersecurity outcomes to controls, evidence, accountable owners and risk-based action plans.
Explore NIST CSF 2.0attestation
SOC 2
Manage your SOC 2 program with Essential Compliance. Connect Trust Services Criteria to accountable owners, shared controls, recurring evidence, and remediation, while keeping the related business risks in view.
Explore SOC 2
AI Governance
- Featured
standard
ISO 42001
Manage AI policies, risks, controls, evidence, impact assessments, and improvement work against ISO 42001.
Explore ISO 42001 - Featured
regulation
EU AI Act
Organize regulatory obligations by AI system and regulatory role, map them to controls and evidence, track applicable requirements, surface gaps, and coordinate accountable remediation.
Explore EU AI Act framework
NIST AI RMF
Connect AI governance and compliance activities with the Govern, Map, Measure, and Manage approach to AI risk management.
Explore NIST AI RMF
European Cybersecurity
- Featured
regulation
NIS2
Map existing ISO 27001 and cybersecurity controls to applicable NIS2 obligations, including country-specific requirements, reuse existing evidence and focus remediation on the gaps that actually remain.
Explore NIS2 regulation
DORA
Map DORA digital operational resilience obligations to existing ICT risk, incident, testing and third-party controls, then reuse evidence across NIS2 and related cybersecurity programs.
Explore DORA
Canadian Financial Services
guidance
OSFI
Manage overlapping requirements across B-13, B-10, E-21 and other OSFI guidelines through a common set of controls, risks, evidence and actions.
Explore OSFIlegislation
FINTRAC / PCMLTFA
Manage AML/ATF obligations under the PCMLTFA and associated regulations, linking requirements to policies, controls, risks, evidence, training and accountable owners.
Explore FINTRAC / PCMLTFAguidance
FSRA
Manage IT risk, operational resilience and related FSRA requirements for Ontario-regulated financial services through connected controls, risks, evidence and actions.
Explore FSRArules
CIRO
Manage dealer compliance obligations across CIRO rules, linking requirements to policies, controls, evidence, risks and accountable owners.
Explore CIRO
Canadian Payments
UK Financial Services
rules & guidance
FCA/PRA Operational Resilience
Manage operational resilience requirements across important business services, impact tolerances, mapping, testing, vulnerabilities, incidents and remediation.
Explore FCA/PRA Operational Resilienceguidance
PRA SS2/21
Manage outsourcing and third-party risk requirements, linking suppliers to risks, controls, evidence, due diligence, monitoring and exit plans.
Explore PRA SS2/21rules & guidance
FCA Consumer Duty
Manage Consumer Duty requirements and evidence across products and services, price and value, consumer understanding and consumer support.
Explore FCA Consumer Duty
Privacy & Data Protection
regulation
GDPR
Manage GDPR obligations across privacy governance, data protection, individual rights, security, breach response and accountability, with connected controls, risks and evidence.
Explore GDPRlegislation
PIPEDA
Manage Canadian privacy obligations across accountability, consent, safeguards, access, breach management and evidence of compliance.
Explore PIPEDAregulation
UK GDPR
Manage UK data protection requirements across privacy governance, individual rights, security, breach response, accountability and supporting evidence.
Explore UK GDPRlegislation
Quebec Law 25
Manage Quebec privacy requirements across governance, privacy impact assessments, consent, individual rights, incidents and accountability.
Explore Quebec Law 25
US Financial Services
regulation
GLBA Safeguards Rule
Manage information security requirements across risk assessments, safeguards, access controls, service providers, monitoring, incidents and accountable owners.
Explore GLBA Safeguards Ruleregulation
NYDFS Part 500
Manage cybersecurity requirements across governance, risk assessments, controls, third parties, incident response, reporting and evidence.
Explore NYDFS Part 500
Irish Financial Services
guidance
CBI Operational Resilience
Manage operational resilience requirements across critical business services, impact tolerances, mapping, testing, third-party dependencies and remediation.
Explore CBI Operational Resilienceregulation
Consumer Protection Code 2025
Manage consumer protection requirements across governance, products and services, customer communications, support, vulnerable customers and evidence of compliance.
Explore Consumer Protection Code 2025regulatory regime
Individual Accountability Framework
Manage accountability requirements across senior management responsibilities, conduct standards, certification, fitness and probity, and supporting evidence.
Explore Individual Accountability Framework
US Defense
US Healthcare
Payment Security
Don't see your framework?
The examples above are just a selection. Ask us about other frameworks already available, or let us know what you need and we can quickly configure it for you.
Ask us about other frameworksCross-framework compliance
Map once. Comply many times.
Connect a control and its evidence to every requirement it supports. Tracker helps teams see overlap, preserve framework-specific context, and focus effort on the gaps that remain.
Shared control
Third-party risk assessment
Your program, connected