C1Risk uses crosswalks to show relationships between requirements and controls from different regulatory frameworks, standards, and control libraries.
Because no single organization publishes an authoritative crosswalk for every framework combination, C1Risk uses several mapping methods depending on the availability and quality of published reference materials.
Each crosswalk should be treated as a reference that helps identify related requirements. A crosswalk does not mean that two controls are identical, interchangeable, or sufficient to demonstrate compliance with another framework.
C1Risk currently uses the following three methods to determine crosswalk relationships.
Method 1: Adopt a Published Third-Party Crosswalk
When a recognized organization has published a crosswalk, C1Risk may adopt that mapping after reviewing the source, versions, scope, and methodology.
Example: NIST AI RMF to ISO/IEC 42001
For the NIST AI Risk Management Framework to ISO/IEC 42001 crosswalk, C1Risk adopted the mapping developed by Microsoft and listed in NIST’s AI Resource Center repository.
Method 2: Derive a Crosswalk Through a Common Intermediary Framework
When no direct published crosswalk exists, C1Risk may derive a relationship by using a recognized intermediary control framework.
Example: HIPAA to ISO/IEC 27001
There is no official, directly published HIPAA-to-ISO/IEC 27001 crosswalk issued by HHS, NIST, ISO, or another recognized authority.
C1Risk therefore uses NIST SP 800-53 Revision 5 as the intermediary framework.
For example:
1. A HIPAA control is mapped to one or more NIST SP 800-53 controls.
2. Those NIST controls are mapped to one or more ISO/IEC 27001 controls.
3. C1Risk derives a crosswalk between the HIPAA control and the related ISO/IEC 27001 controls.
Conceptually: If HIPAA Control 1 maps to NIST Control 1, and NIST Control 1 maps to ISO Control 1, C1Risk may create a derived relationship from HIPAA Control 1 to ISO Control 1.
Accuracy dependency
The accuracy of the derived HIPAA-to-ISO crosswalk depends on the accuracy and completeness of the two underlying mappings maintained in the C1Risk Master Account:
* HIPAA to NIST SP 800-53
* ISO/IEC 27001 to NIST SP 800-53
If either underlying relationship is incomplete, outdated, overly broad, or incorrect, the resulting HIPAA-to-ISO relationship may also be affected.
Mapping limitations
A shared intermediary control does not always mean that the source and target requirements are equivalent.
For example, a NIST control may address only one portion of a HIPAA requirement and one portion of an ISO control. The resulting relationship may therefore be partial rather than direct.
Method 3: Use the ISO Harmonized Structure
Many ISO management system standards use the ISO Harmonized Structure, sometimes referred to as HS or the former Annex SL structure.
The Harmonized Structure establishes a common clause format for management system standards, including:
1. Scope
2. Normative references
3. Terms and definitions
4. Context of the organization
5. Leadership
6. Planning
7. Support
8. Operation
9. Performance evaluation
10. Improvement
Examples of standards that generally follow this structure include:
* ISO 9001
* ISO 14001
* ISO/IEC 27001
* ISO 22301
* ISO 37301
* ISO/IEC 42001
How C1Risk uses the Harmonized Structure
C1Risk may use common clause structure, terminology, and management system concepts to identify potential relationships between ISO standards.
Examples include:
* Context of the organization
* Leadership responsibilities
* Policy requirements
* Risk and opportunity planning
* Competence and awareness
* Documented information
* Internal audits
* Management reviews
* Corrective actions
* Continual improvement
These common areas can support crosswalk suggestions between ISO standards.
Important limitation
The Harmonized Structure is not itself an official control-by-control crosswalk.
The fact that two ISO standards use the same clause number does not mean that their requirements are identical.
For example, Clause 6 in two standards may both address planning, but one may focus on information security risks while another focuses on AI-related risks or business continuity risks.
Crosswalks developed using the Harmonized Structure must therefore include a substantive comparison of:
* Requirement text
* Purpose
* Scope
* Expected evidence
* Responsible roles
* Risk domain
* Implementation outcome
Important Notice
Crosswalks are intended to support compliance analysis, control reuse, gap assessments, and audit preparation.
They do not guarantee compliance with a regulation or certification against a standard.
Organizations remain responsible for reviewing the original requirements, evaluating their own implementation, and determining whether their controls satisfy the applicable legal, regulatory, contractual, and certification requirements.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article