Controls & Frameworks
Track the implementation of your security, privacy and resilience controls across every framework you're working toward, all in one place.
Controls are the safeguards that protect your organisation. PilotVantage comes with 14 frameworks pre-loaded — around 490 controls in total — so you can start tracking implementation on day one rather than building a spreadsheet from scratch.
Frameworks included
| Framework | What it covers | Controls |
|---|---|---|
| ISO 27001:2022 | Information security management — all Annex A controls, with SoA generation | 93 |
| SOC 2 (Type II) | The full Trust Services Criteria — Security, Availability, Confidentiality, Processing Integrity and Privacy | 61 |
| GDPR / UK GDPR | Data protection compliance controls | 19 |
| HIPAA | US Security Rule safeguards and breach notification for ePHI | 25 |
| ISO 9001:2015 | Quality management systems | 28 |
| ISO 22301:2019 | Business continuity management systems | 25 |
| ISO 27701:2019 | Privacy information management for PII controllers and processors | 49 |
| ISO 42001:2023 | AI management systems — responsible AI governance | 38 |
| CIS Controls v8 | The 18 prioritised critical security controls | 18 |
| NIST CSF 2.0 | Govern, Identify, Protect, Detect, Respond, Recover | 22 |
| PCI DSS v4 | All 12 payment card security requirements | 63 |
| Cyber Essentials | UK government-backed baseline scheme | 20 |
| DORA | EU Digital Operational Resilience Act for financial entities | 20 |
| NIS2 | EU cybersecurity directive — risk measures and incident reporting | 16 |
You can manage several frameworks side by side, which is ideal if you're pursuing more than one certification — and controls cross-map, so work done for one framework counts everywhere it applies.
Enabling and disabling frameworks
You choose your first frameworks in the setup wizard, and you can add more at any time from Controls → All Frameworks: the Add a framework section lists every standard not yet in your workspace, and enabling one seeds its full control set instantly. Administrators and Risk & Compliance users can also disable a framework that has no linked records — it disappears from the menu but its data is preserved, so you can re-enable it later with nothing lost.
Custom frameworks
Need a standard that isn't in the list — an internal control set, a client questionnaire, or a niche regulation? Create a custom framework with your own domains and controls from Controls → Create Custom Framework. Custom controls behave exactly like built-in ones: statuses, owners, evidence, risk links and reporting all work the same way.
What each control holds
Every control carries a reference, a domain (its grouping), an owner, and an implementation status. You link evidence to each control to prove it's genuinely operating — not just documented.
Implementation statuses
| Status | What it means |
|---|---|
| Not implemented | The control isn't in place yet. |
| Planned | Implementation is scheduled but hasn't started. |
| Partially implemented | Work has started but the control isn't fully operating. |
| Implemented | The control is in place and operating, with evidence to show it. |
| Not applicable | The control doesn't apply to your scope; record a justification. |
Each framework page rolls these up into a live compliance score, so you always know how far along you are.
How to manage your controls
Assign an owner
Give each control an owner so responsibility is clear.
Set the status
Mark where each control stands and keep it current as you make progress.
Link evidence
Attach the documents, screenshots or records that prove the control is operating.
Build your SoA
Mark each control applicable or not, with a justification, ready for your certification body.
Statement of Applicability
Your Statement of Applicability (SoA) is generated straight from your controls. Mark each control as applicable or not applicable, add a justification, and you have a document you can hand directly to your auditor.
Continuous control monitoring
Marking a control "implemented" proves it worked once — continuous control monitoring proves it keeps working. Through the integrations panel, PilotVantage connects to the systems where your controls actually operate and verifies them automatically: fresh evidence flows in on a schedule rather than being gathered by hand, so a control that drifts out of effectiveness is surfaced instead of silently going stale between audits.