When something relevant to security happens, a breach, a change in your privacy commitments, a material change in your service, you have a process to communicate that to customers, regulators, and other external parties. Your public-facing documents (privacy policy, terms of service, system description) must be accurate and current. Auditors will check whether your published commitments match your actual controls.
These are typical controls and implementation steps. Your systems and environment may differ.
Typical Control Published privacy policy, terms of service, and security commitments
Implementation Steps
Publish a Privacy Policy on your website that accurately describes your data collection, use, retention, and disclosure practices, ensure it is updated whenever practices change
Publish Terms of Service or a Master Service Agreement that includes your security commitments to customers
Create a Trust Center or security page on your website that communicates your security posture: frameworks, certifications, encryption standards, and incident notification procedures
When a security incident affects customers, follow contractual and regulatory notification timelines, document the notification in your incident record
Tools / Systems
Company website (Privacy Policy, ToS)Legal counsel (Privacy Policy and ToS drafting)GRC platform (e.g., Vanta, Drata, your GRC platform, Scrut)
Typical Control Published privacy policy, terms of service, and security commitments
Evidence Artifacts
Screenshot of published Privacy Policy on company website, with last updated date
Screenshot of Terms of Service or MSA security addendum
Trust Center page or security page URL showing security commitments are publicly accessible
Sample customer incident notification (if an incident occurred during the period) or attestation that none occurred
📅Annual review of public-facing documents; per-incident notification records
Cross-framework mappings coming in v1.1
When we add ISO 42001 and ISO 27001, you'll see which controls map to this criterion.
ISO
ISO 42001
AI Management Systems
ISO
ISO 27001
Information Security
Mapping data will appear here automatically when the frameworks are published.
CC3.1
Specifies objectives with sufficient clarity
Risk Assessment
3 evidence1 control
CC3.2
Identifies and analyzes risks to achievement of objectives
Risk Assessment
3 evidence1 control
CC3.3
Considers potential for fraud in assessing risks
Risk Assessment
3 evidence1 control
CC3.4
Identifies and assesses significant changes
Risk Assessment
3 evidence1 control
CC4.1
Selects, develops, and performs ongoing and separate evaluations
Monitoring Activities
6 evidence2 controls
CC4.2
Evaluates and communicates internal control deficiencies
Monitoring Activities
3 evidence1 control
CC5.1
Selects and develops control activities that mitigate risks
Control Activities
3 evidence1 control
CC5.2
Selects and develops general controls over technology
Control Activities
6 evidence2 controls
CC5.3
Deploys control activities through policies and procedures
Control Activities
3 evidence1 control
CC6.1
Logical access security infrastructure
Logical and Physical Access Controls
11 evidence3 controls
CC6.2
Registration and authorization prior to issuing credentials
Logical and Physical Access Controls
6 evidence2 controls
CC6.3
Role-based access management
Logical and Physical Access Controls
6 evidence2 controls
CC6.4
Physical access restrictions
Logical and Physical Access Controls
3 evidence1 control
CC6.5
Disposal and destruction of information assets
Logical and Physical Access Controls
3 evidence1 control
CC6.6
Controls against threats from outside system boundaries
Logical and Physical Access Controls
8 evidence2 controls
CC6.7
Restricts transmission and movement of information
Logical and Physical Access Controls
7 evidence2 controls
CC6.8
Controls to prevent or detect unauthorized software
Logical and Physical Access Controls
6 evidence2 controls
CC7.1
Detection and monitoring for vulnerabilities
System Operations
8 evidence2 controls
CC7.2
Monitoring for anomalies and security events
System Operations
4 evidence1 control
CC7.3
Evaluation of security events as security incidents
System Operations
4 evidence1 control
CC7.4
Incident response program
System Operations
4 evidence1 control
CC7.5
Recovery from security incidents
System Operations
4 evidence1 control
CC8.1
Authorized change management process
Change Management
8 evidence2 controls
CC9.1
Risk mitigation for business disruptions
Risk Mitigation
4 evidence1 control
CC9.2
Vendor and business partner risk management
Risk Mitigation
4 evidence1 control
Help us build what matters.
Vote for the next framework, subscribe for updates, and let us know if you'd contribute.
What should we add next?
Vote for the framework you need most.
0
ISO 42001
0
ISO 27001
0
CMMC
0
CPCSC
Stay Updated
Get notified when new frameworks and features are added.
On-premises implementation and evidence
Published privacy policy, terms of service, and security commitments
Implementation steps
Maintain a published Privacy Policy and Terms of Service that accurately reflect current data handling practices
Publish a network and infrastructure architecture overview or system description, this is required for your SOC 2 report and supports customer due diligence requests
When customers request security questionnaires or due diligence documents, route them through a defined process that ensures accuracy and version control
Tools / systems
Company website (Privacy Policy, ToS)
GRC platform (e.g., Vanta, Drata, your GRC platform, Scrut)
Evidence artifacts
Published Privacy Policy with last updated date
Terms of Service or customer contract template with security obligations
Network or system description document shared with auditors or customers on request