Skip to main content

Development trial ยท sample information only

Adopt a framework and map its obligations

For licensed Collaborators with permission for this task. Check the selected organisation; feature availability and record access still apply.

What you will achieve

Create an organisation-specific framework programme and connect its requirements to controls your organisation actually operates.

Before you start

Agree the framework, edition, scope and programme owner. Adoption records a programme of work; it does not certify the organisation.

Check whether the framework is already adopted. The catalogue offers Open adoption for an existing adoption rather than creating a duplicate.

Adopt the framework

  1. Open the Frameworks catalogue and select the intended framework.
  2. Read its identity, structure and requirements. Confirm that it is the correct edition for the agreed work.
  3. Select Adopt framework. Read the confirmation: adoption creates an organisation programme and initial implementation rows.
  4. Confirm the action and open the resulting adoption.
  5. Review programme details. Set a meaningful name, description, responsible team, owner and relevant target or assessment dates using the adoption editor.
  6. Reopen the programme and verify those details before assigning wider work.

Map requirements

  1. Open the adoption's Controls list and choose one requirement.
  2. Read Framework requirement and any implementation guidance. This is different from an organisation control describing your own safeguard.
  3. Under Mapped organisation controls, choose the appropriate Organisation control.
  4. Enter a Mapping rationale explaining which part of the requirement the control addresses and any limitations. Save through the mapping action.
  5. Open the mapped control and check its implementation and evidence. Repeat only where another control adds meaningful coverage.
  6. Review remaining gaps. An unmapped requirement remains a gap; a mapped one still needs sound implementation evidence.

Check it worked

Reload the requirement and follow the mapping back to the organisation control. Confirm its scope, owner and evidence. Review the adoption's gap view and programme status without treating a progress percentage as certification.

If something goes wrong

Problem Next action
The catalogue says Already adopted Open that programme and check its scope before changing it
You cannot see mapped controls Check control-view access as well as framework access
No suitable control exists Create or commission the actual safeguard; do not map an unrelated control to fill a gap
A mapping is wrong Use Remove mapping, then add the correct mapping with rationale; this is not deletion of the control itself

Human judgement matters

Framework wording, organisational implementation and independent certification are different things. Review any AI-drafted implementation notes against what actually happens.

What next?

For the wider context, see Manage policies, controls and frameworks.

Assign owners to unresolved gaps and schedule evidence reviews. Keep the programme's assessment dates and evidence current as the framework or your operations change.

Get help

Ask your Organisation Administrator about access or the task owner about the content. For a platform error, include this guide reference, the affected page and a sanitised message, not confidential evidence or session details.

Was this article helpful?