The organization sets the tone from the top that security and ethics are non-negotiable. This shows up in a Code of Conduct that staff actually sign, policies that spell out consequences for violations, and leadership behavior that reinforces rather than undermines the rules. Auditors will look for whether the policies exist AND whether violations were ever acted upon.
These are typical controls and implementation steps. Your systems and environment may differ.
Typical Control Code of Conduct with annual acknowledgement
Implementation Steps
Publish a Code of Conduct that covers ethical expectations, conflicts of interest, acceptable use, and consequences for violations. This document must be version-controlled
Require every employee and contractor to acknowledge the Code of Conduct in writing at hire and annually thereafter. Use your GRC platform to automate the acknowledgement workflow
Confirm policy acknowledgements are tracked with timestamps; incomplete acknowledgements within 30 days of due date are a finding
Include a section on reporting violations and confirm a confidential reporting channel exists (hotline, anonymous form, or designated HR contact)
Tools / Systems
Google Workspace (policy distribution)BambooHR / Rippling (HR policy workflows)GRC platform (e.g., Vanta, Drata, your GRC platform, Scrut)
Typical Control Documented disciplinary process for security policy violations
Implementation Steps
Include a disciplinary section in the Information Security Policy or a standalone Disciplinary Action Policy that explicitly covers security violations
Define the escalation tiers: minor violation (warning), repeated or serious violation (termination), the policy must be specific enough that enforcement is consistent
Ensure HR and management are aligned on the process; security policy violations must flow through the same HR process as other disciplinary matters
If violations occur during the audit period, document the incident, the policy cited, and the action taken, this is evidence that the control operates
Tools / Systems
Information Security Policy (policy document)HRIS (HR incident tracking)Jira (incident documentation)GRC platform (e.g., Vanta, Drata, your GRC platform, Scrut)
Typical Control Code of Conduct with annual acknowledgement
Evidence Artifacts
Current Code of Conduct document (version-controlled, with effective date)
your GRC platform or GRC platform screenshot showing 100% acknowledgement completion rate for the period, with dates
Any documented disciplinary actions for policy violations during the audit period (or a signed statement that no violations occurred)
📅Annual acknowledgement cycle; policy reviewed and re-approved by management annually
Typical Control Documented disciplinary process for security policy violations
Evidence Artifacts
Information Security Policy or Code of Conduct containing explicit disciplinary consequences language
If violations occurred: redacted incident record showing the violation type and action taken
If no violations: management attestation signed and dated during the audit period
📅Policy reviewed annually; incident records maintained per-event
Cross-framework mappings coming in v1.1
When we add ISO 42001 and ISO 27001, you'll see which controls map to this criterion.
ISO
ISO 42001
AI Management Systems
ISO
ISO 27001
Information Security
Mapping data will appear here automatically when the frameworks are published.
CC1.2
Board independence and oversight of internal control
Control Environment
3 evidence1 control
CC1.3
Organizational structure, reporting lines, and authority
Control Environment
3 evidence1 control
CC1.4
Commitment to attract, develop, and retain competent individuals
Control Environment
6 evidence2 controls
CC1.5
Accountability for internal control responsibilities
Control Environment
3 evidence1 control
CC2.1
Obtains or generates and uses relevant quality information
Communication and Information
3 evidence1 control
CC2.2
Internal communication of information to support internal control
Communication and Information
6 evidence2 controls
CC2.3
External communication regarding matters affecting internal control
Communication and Information
4 evidence1 control
CC3.1
Specifies objectives with sufficient clarity
Risk Assessment
3 evidence1 control
CC3.2
Identifies and analyzes risks to achievement of objectives
Risk Assessment
3 evidence1 control
CC3.3
Considers potential for fraud in assessing risks
Risk Assessment
3 evidence1 control
CC3.4
Identifies and assesses significant changes
Risk Assessment
3 evidence1 control
CC4.1
Selects, develops, and performs ongoing and separate evaluations
Monitoring Activities
6 evidence2 controls
CC4.2
Evaluates and communicates internal control deficiencies
Monitoring Activities
3 evidence1 control
CC5.1
Selects and develops control activities that mitigate risks
Control Activities
3 evidence1 control
CC5.2
Selects and develops general controls over technology
Control Activities
6 evidence2 controls
CC5.3
Deploys control activities through policies and procedures
Control Activities
3 evidence1 control
CC6.1
Logical access security infrastructure
Logical and Physical Access Controls
11 evidence3 controls
CC6.2
Registration and authorization prior to issuing credentials
Logical and Physical Access Controls
6 evidence2 controls
CC6.3
Role-based access management
Logical and Physical Access Controls
6 evidence2 controls
CC6.4
Physical access restrictions
Logical and Physical Access Controls
3 evidence1 control
CC6.5
Disposal and destruction of information assets
Logical and Physical Access Controls
3 evidence1 control
CC6.6
Controls against threats from outside system boundaries
Logical and Physical Access Controls
8 evidence2 controls
CC6.7
Restricts transmission and movement of information
Logical and Physical Access Controls
7 evidence2 controls
CC6.8
Controls to prevent or detect unauthorized software
Logical and Physical Access Controls
6 evidence2 controls
CC7.1
Detection and monitoring for vulnerabilities
System Operations
8 evidence2 controls
CC7.2
Monitoring for anomalies and security events
System Operations
4 evidence1 control
CC7.3
Evaluation of security events as security incidents
System Operations
4 evidence1 control
CC7.4
Incident response program
System Operations
4 evidence1 control
CC7.5
Recovery from security incidents
System Operations
4 evidence1 control
CC8.1
Authorized change management process
Change Management
8 evidence2 controls
CC9.1
Risk mitigation for business disruptions
Risk Mitigation
4 evidence1 control
CC9.2
Vendor and business partner risk management
Risk Mitigation
4 evidence1 control
Help us build what matters.
Vote for the next framework, subscribe for updates, and let us know if you'd contribute.
What should we add next?
Vote for the framework you need most.
0
ISO 42001
0
ISO 27001
0
CMMC
0
CPCSC
Stay Updated
Get notified when new frameworks and features are added.
On-premises implementation and evidence
Code of Conduct with annual acknowledgement
Implementation steps
Distribute the Code of Conduct via email or the intranet and collect signed paper or digital acknowledgements, store in personnel files or a shared drive
Set a calendar reminder to run the annual acknowledgement cycle; track completions in a spreadsheet and upload to your GRC platform as evidence
Document any policy violations during the audit period and the disciplinary action taken, auditors want to see that consequences are real
Ensure the Code of Conduct references the Information Security Policy so the two documents are explicitly connected
Tools / systems
Active Directory / intranet (policy distribution)
HR file storage (signed acknowledgements)
Email (annual policy reminder workflow)
GRC platform (e.g., Vanta, Drata, your GRC platform, Scrut)
Evidence artifacts
Code of Conduct with effective date and management sign-off
Acknowledgement log or signed forms for all staff, dated within the audit window
Evidence that violations (if any) were handled; or management attestation of no violations
Evidence frequency: Annual; acknowledgement log exported at each audit window close
Documented disciplinary process for security policy violations
Implementation steps
Reference disciplinary consequences in at least one policy document that all staff have acknowledged, the Code of Conduct is the most common vehicle
When a security violation occurs, open a formal incident or HR ticket documenting the event and resolution, this creates an audit trail
Confirm that the disciplinary policy applies equally to all levels including management; auditors are sensitive to policies that only apply downward
Tools / systems
Code of Conduct / Information Security Policy
HR file storage
Incident ticketing system
GRC platform (e.g., Vanta, Drata, your GRC platform, Scrut)
Evidence artifacts
Policy document containing disciplinary consequences section, with effective date
HR or incident record for any security violations during the period (redacted as needed)