For licensed Collaborators with permission for this task. Check the selected organisation; feature availability and record access still apply.
What you will achieve
Create an organisation-specific framework programme and connect its requirements to controls your organisation actually operates.
Before you start
Agree the framework, edition, scope and programme owner. Adoption records a programme of work; it does not certify the organisation.
Check whether the framework is already adopted. The catalogue offers Open adoption for an existing adoption rather than creating a duplicate.
Adopt the framework
- Open the Frameworks catalogue and select the intended framework.
- Read its identity, structure and requirements. Confirm that it is the correct edition for the agreed work.
- Select Adopt framework. Read the confirmation: adoption creates an organisation programme and initial implementation rows.
- Confirm the action and open the resulting adoption.
- Review programme details. Set a meaningful name, description, responsible team, owner and relevant target or assessment dates using the adoption editor.
- Reopen the programme and verify those details before assigning wider work.
Map requirements
- Open the adoption's Controls list and choose one requirement.
- Read Framework requirement and any implementation guidance. This is different from an organisation control describing your own safeguard.
- Under Mapped organisation controls, choose the appropriate Organisation control.
- Enter a Mapping rationale explaining which part of the requirement the control addresses and any limitations. Save through the mapping action.
- Open the mapped control and check its implementation and evidence. Repeat only where another control adds meaningful coverage.
- Review remaining gaps. An unmapped requirement remains a gap; a mapped one still needs sound implementation evidence.
Check it worked
Reload the requirement and follow the mapping back to the organisation control. Confirm its scope, owner and evidence. Review the adoption's gap view and programme status without treating a progress percentage as certification.
If something goes wrong
| Problem | Next action |
|---|---|
| The catalogue says Already adopted | Open that programme and check its scope before changing it |
| You cannot see mapped controls | Check control-view access as well as framework access |
| No suitable control exists | Create or commission the actual safeguard; do not map an unrelated control to fill a gap |
| A mapping is wrong | Use Remove mapping, then add the correct mapping with rationale; this is not deletion of the control itself |
Human judgement matters
Framework wording, organisational implementation and independent certification are different things. Review any AI-drafted implementation notes against what actually happens.
What next?
For the wider context, see Manage policies, controls and frameworks.
Assign owners to unresolved gaps and schedule evidence reviews. Keep the programme's assessment dates and evidence current as the framework or your operations change.
Get help
Ask your Organisation Administrator about access or the task owner about the content. For a platform error, include this guide reference, the affected page and a sanitised message, not confidential evidence or session details.