Framework library

CRAFT — Control, Risk & Audit Framework Tool

CRAFT is Audirium's shared framework library: one place where legislation, control frameworks and individual controls come together in a searchable, cross-linked structure. No more separate framework documents per project: one library that keeps growing and feeds other Audirium apps directly, from the NIS2 Scanner to GRIP and AQUA.

Every framework speaks its own language, and lives in its own spreadsheet

Organisations working with multiple frameworks (BIO, ISO 27001, NIS2, DORA, GDPR, NEN 7510) keep running into the same problem: each framework has its own terminology, numbering and scope. Proving that a single control satisfies ISO 27001, NIS2 and DORA at once means cutting and pasting between spreadsheets.

Crosswalks expire immediately

Manual comparison tables between frameworks are out of date by the time the next revision lands.

Overlap stays invisible

The same control gets tested three times separately because nobody sees the link.

Legislation and controls sit apart

Statutes and concrete controls are disconnected. There is no traceability from law to measure.

Every project starts from zero

Every audit or assessment project starts over, rebuilding the framework from scratch.

One library, automatically cross-linked

CRAFT brings frameworks, controls and legislation together in one maintained library, with links that replace the manual work.

Shared controls as the bridge

Underneath the frameworks sits a layer of shared, framework-neutral controls. Every framework maps onto these shared controls, so CRAFT automatically sees which controls from different frameworks cover the same ground. Nobody has to work that out by hand.

From legislation to control, and back

Statutory articles are linked directly to the controls that implement them. At a glance you can see which measure covers which legal obligation, and where a gap remains.

Cross-references between frameworks

Controls from different frameworks are linked to each other based on actual overlap. A single assessment can then cover multiple frameworks at once, instead of testing framework by framework from scratch.

The library behind other apps

CRAFT isn't a standalone reference book: it's the library the NIS2 Scanner draws its gap analysis from, that GRIP pulls its ENSIA framework from, and that AQUA builds its self-assessment on. One maintained source, multiple applications.

How it works

From framework selection to a working control set in four steps.

1

Choose your framework(s)

Select one or more frameworks from the library, for example ISO 27001 together with NIS2 and DORA, as the basis for an audit, assessment or review.

2

Automatic mapping

CRAFT maps the selected controls onto the underlying shared controls and surfaces the cross-references to other frameworks and to relevant legislation.

3

Coverage and overlap made visible

You immediately see which controls have already been tested elsewhere, where frameworks overlap and where a genuine gap remains, instead of working through each framework in isolation.

4

Put it to work

The assembled framework flows straight into the work programme and the report, and, where relevant, into apps such as the NIS2 Scanner or GRIP that build further on the same library.

A foundation for a QAIP: reproducible and comparable

A Quality Assurance and Improvement Program needs a framework the internal audit function can measure itself against periodically, in the same way each time, not an ad-hoc set of spreadsheets rebuilt every year. Because CRAFT is one maintained library rather than project-bound documents, the yardstick for a self-assessment (such as AQUA's) stays the same year over year: the same shared controls, the same links to legislation, the same definition of coverage.

That makes a QAIP self-assessment comparable over time: improvement or regression is demonstrable, because the underlying framework doesn't quietly shift between two measurements.

Verified counts, not estimates

These are the current counts from the CRAFT framework library.

Frameworks

38 frameworks

From BIO and ISO 27001 to DORA, NEN 7510 and the AI Act: 38 frameworks in one library.

Controls

1,691 controls

All controls searchable, per framework and per domain.

Links

2,224 cross-references

Links between controls from different frameworks, based on actual overlap.

Shared

136 shared controls

The framework-neutral control set that all frameworks map onto.

Legislation

212 legislation-to-control links

Direct references between statutory articles (GDPR, NIS2, Dutch Police Data Act) and concrete controls.

Evidence for an External Quality Assessment

IIA standards require the internal audit function to undergo a periodic External Quality Assessment (EQA), where an independent reviewer tests whether quality is demonstrably and traceably assured. A recurring question in that review is: can you show how a legal obligation is actually implemented through a concrete control, and is that trail consistent?

Because CRAFT explicitly links legislation, controls and cross-references to each other rather than leaving that implicit in a separate document, the library produces a traceable trail that can serve as supporting evidence when preparing for an EQA. CRAFT does not replace the EQA itself, that remains an independent review, but it makes the underlying framework auditable instead of a black box.

One framework library, for the whole suite

CRAFT is the layer that brings BIO, ISO 27001, NIS2, DORA, GDPR and dozens of other frameworks together. That same layer directly feeds the NIS2 Scanner, GRIP and AQUA. Curious what the library could look like for your organisation?