Home Frameworks
Frameworks Library

Every framework your organization needs. One platform to manage them all.

Operlity supports a comprehensive and growing library of global compliance frameworks, regulations, and industry standards — giving your team the structured programs, pre-loaded controls, and compliance workflows to meet your obligations wherever you operate.

Operlity's multi-framework library showing pre-loaded global compliance frameworks with cross-framework control mapping
Compliance never lives in isolation

Most organizations answer to multiple frameworks at once.

Compliance obligations don't exist in isolation. Most organizations must simultaneously meet requirements from multiple frameworks — security standards, privacy regulations, industry mandates, and regional requirements — often with overlapping controls and shared evidence requirements.

Operlity's multi-framework architecture lets you manage all of your compliance obligations from a single platform — with cross-framework control mapping that eliminates duplicated effort and a unified compliance posture view that gives leadership a consolidated picture of where you stand across every framework you're accountable to.

Information security

Frameworks for managing information security at scale.

FrameworkRegionTypeWhat it covers
ISO 27001GlobalCertificationInformation security management system requirements covering 114 controls across 14 domains
NIST CSF 2.0GlobalFrameworkCybersecurity framework covering six functions: Govern, Identify, Protect, Detect, Respond, and Recover (CSF 2.0, Feb 2024)
SOC 2GlobalAudit StandardTrust Services Criteria covering security, availability, processing integrity, confidentiality, and privacy — Type I and Type II
UK Cyber EssentialsUnited KingdomCertificationFive foundational technical controls protecting against the most common cyber threats
Saudi ECCSaudi ArabiaMandatoryEssential cybersecurity controls for government agencies and critical infrastructure operators
UAE IAS (formerly NESA)UAEMandatoryUAE Cybersecurity Council Information Assurance Standards for federal government entities and critical infrastructure operators
Saudi SAMA CSFSaudi ArabiaMandatoryCybersecurity framework for SAMA-regulated financial institutions
Data protection & privacy

Privacy regulations governing personal data — across every jurisdiction.

FrameworkRegionTypeWhat it covers
GDPREuropean UnionRegulationComprehensive data protection regulation governing personal data of EU residents
CCPA / CPRAUnited StatesRegulationCalifornia's comprehensive consumer privacy law governing personal information of California residents
DPDPAIndiaRegulationDigital Personal Data Protection Act governing personal data of Indian residents
Saudi PDPLSaudi ArabiaRegulationPersonal Data Protection Law governing personal data of Saudi residents
UAE PDPLUAERegulationFederal data protection law governing personal data of UAE residents
Industry & sector

Standards for the industries that face the most demanding compliance environments.

FrameworkRegionTypeWhat it covers
PCI DSSGlobalStandardPayment card industry data security standard for organizations handling cardholder data
HIPAAUnited StatesRegulationHealth Insurance Portability and Accountability Act governing protected health information
ISO 22301GlobalCertificationBusiness continuity management system requirements
AI governance

Frameworks for the responsible development and deployment of AI.

FrameworkRegionTypeWhat it covers
EU AI ActEuropean UnionRegulationWorld's first comprehensive AI regulation covering development, deployment, and use of AI systems
ISO/IEC 42001:2023GlobalCertificationAI management system standard for responsible development and use of AI (published December 2023)
NIST AI RMF 1.0GlobalFrameworkAI risk management framework covering Govern, Map, Measure, and Manage functions (published January 2023)
Risk management

Frameworks for structured enterprise risk management.

FrameworkRegionTypeWhat it covers
ISO 31000GlobalStandardRisk management principles and guidelines for enterprise risk programs
COSO ERMGlobalFrameworkEnterprise risk management framework covering strategy, performance, and governance
Multi-framework management

One platform. Every framework. Zero duplication.

Managing compliance across multiple frameworks simultaneously is one of the most resource-intensive challenges any compliance team faces. Operlity's multi-framework architecture is designed to eliminate the duplication and fragmentation that makes it so difficult.

Can't find your framework?

Operlity's framework library is continuously expanding.

If the framework or regulation your organization needs to meet is not yet in our library, our team can work with you to configure a custom compliance program tailored to your specific requirements.

Your compliance obligations span multiple frameworks, geographies, and regulators. Your GRC platform should too. See how Operlity's multi-framework architecture helps your team manage every compliance obligation from one place.
Book a Demo