Frameworks

Your standard, treated like any other.

Many enterprises run their own control set. In most tools it has nowhere to live. In TruOps it is a first-class framework.

Custom frameworks · readinessevidence current
Custom frameworks · coverage import progress
Parsed into requirementssatisfied · 94%
Mapped · exactsatisfied · 96%
Mapped · partialpartial · 61%
Mapped · for reviewopen · 35%
The same work also counts toward
SOC 249% · partials shown
ISO 2700152% · partials shown
NIST CSF52% · partials shown

Mappings are typed exact, partial, or inferred, each with a citation.

Illustrative example
In short

TruOps supports custom frameworks: upload your internal control standard, and the Data Room parses it into a requirement tree, proposes mappings to other frameworks with confidence scores and citations, and lets you run assessments and monitoring against it. Adding a framework is an upload and a mapping review, not an engineering project.

This page is for you if
  • Your internal standard is the real program and GRC tools only ship ISO and SOC 2
  • You have a control catalog in Excel that maps, badly, to customer frameworks
  • A new customer framework should not be an engineering ticket

How it works

  1. UploadYour standard, in a document or spreadsheet.
  2. ParseTruOps builds the requirement tree down to each testable requirement.
  3. MapMappings to SOC 2, ISO 27001, NIST, and others are proposed, each marked exact, partial, or inferred, with a citation.
  4. ReviewHigh-confidence mappings can be accepted by rule; the rest go to one-click review.
  5. RunAssess, monitor, and report against your standard like any other framework.

The actual challenge

Enterprises already have a language for controls. Forcing them into a vendor library is why implementations take a year and why the tool never matches how people work.

  • The internal standard is the SoA; customer frameworks are translations.
  • Every new law is a consulting map.
  • Assessments still run in the customer's words, so teams never work in their own.

Bring one real document. Watch the program get set up from it.

What you are probably using today

Almost nobody starts Custom frameworks from zero. You already have a program somewhere. TruOps is built to take that over, not make you start again.

What you use nowWhere it breaksWith TruOps
Spreadsheets, shared drives, and emailThe program lives in folders named after last year's audit. Owners paste screenshots the week before fieldwork. Nothing is dated, so you cannot show what was true last quarter.Upload those same files. TruOps pre-fills the assessment from them, cites every answer, and keeps technical checks running so evidence exists for the whole period.
SOC 2 automation toolsThey are strong at certification: automated tests, a broad framework library, and often a trust center. Maturity scoring, custom frameworks, and deep risk or vendor work can sit outside that model.Keep the automation. Run any framework as the anchor, map the rest with partials shown as partial, and run vendor and risk on the same engine. Upload the policies and reports you already have.
Enterprise GRC suitesThey can model almost anything. That flexibility usually comes through implementation partners and administrators, so a change can become a project.AI reads your existing documents and sets up the program. The first assessment opens pre-filled from them, with sources. Changes are a request in plain language, not a project.
An internal control catalog workbookIt is the source of truth and it cannot run an assessment, collect evidence, or show overlap.Upload it. TruOps parses the requirement tree, proposes cited mappings, and lets you assess and monitor against it like any other framework.

Anchor on your own

Make your internal standard the anchor and every external framework maps to it, so your teams work in your language while auditors see theirs.

If this is your situation

Bring the catalog. In a demo TruOps will parse it and show proposed maps to SOC 2 or ISO for you to accept or reject.

How TruOps helps

Any format
Documents or spreadsheets.
Cited mappings
Every proposed mapping points to its source.
Anchor option
Run your program on your own standard.
No code change
New frameworks are uploads, not tickets.

Questions

Can I upload my company's own control standard?

Yes. It becomes a first-class framework you can assess, monitor, and map.

How accurate are AI-proposed mappings?

Each carries a confidence score and citation. You set the threshold for automatic acceptance; everything else is reviewed by a person.

Do we have to rip out the tools we already use?

No. Connectors are read-only: they observe cloud, identity, endpoint, vulnerability, and code tools; they do not change them. Spreadsheets, prior reports, and policies upload into the Data Room. If you are on a SOC 2 automation tool or an enterprise GRC suite, you migrate the program (frameworks, evidence, vendors, risks), not the business.

Can we bring our existing assessments, control lists, and vendor files?

Yes. Upload workbooks, reports, policies, and vendor exports. TruOps turns them into structured questionnaires, controls, and register entries, each cited back to the file they came from, for you to review.

Does TruOps replace our auditor, QSA, or certification body?

No. Only a licensed auditor, QSA, C3PAO, or accredited certification body can issue the opinion. TruOps gets the evidence current, cited, and dated so fieldwork is a review, not an archaeology project.

See it run on your own data.

Thirty minutes with a GRC expert, not an SDR. Bring one real document (a SOC 2 report, a risk register, a vendor list; redacted is fine) and watch TruOps set up a live program from it, with an assessment already pre-filled.