CRAFT — Control, Risk & Audit Framework Tool
CRAFT is Audirium's shared framework library: one place where legislation, control frameworks and individual controls come together in a searchable, cross-linked structure. No more separate framework documents per project: one library that keeps growing and feeds other Audirium apps directly, from the NIS2 Scanner to GRIP and AQUA.
The challenge
Every framework speaks its own language, and lives in its own spreadsheet
Organisations working with multiple frameworks (BIO, ISO 27001, NIS2, DORA, GDPR, NEN 7510) keep running into the same problem: each framework has its own terminology, numbering and scope. Proving that a single control satisfies ISO 27001, NIS2 and DORA at once means cutting and pasting between spreadsheets.
Crosswalks expire immediately
Manual comparison tables between frameworks are out of date by the time the next revision lands.
Overlap stays invisible
The same control gets tested three times separately because nobody sees the link.
Legislation and controls sit apart
Statutes and concrete controls are disconnected. There is no traceability from law to measure.
Every project starts from zero
Every audit or assessment project starts over, rebuilding the framework from scratch.
What CRAFT offers
One library, automatically cross-linked
CRAFT brings frameworks, controls and legislation together in one maintained library, with links that replace the manual work.
Shared controls as the bridge
Underneath the frameworks sits a layer of shared, framework-neutral controls. Every framework maps onto these shared controls, so CRAFT automatically sees which controls from different frameworks cover the same ground. Nobody has to work that out by hand.
From legislation to control, and back
Statutory articles are linked directly to the controls that implement them. At a glance you can see which measure covers which legal obligation, and where a gap remains.
Cross-references between frameworks
Controls from different frameworks are linked to each other based on actual overlap. A single assessment can then cover multiple frameworks at once, instead of testing framework by framework from scratch.
The library behind other apps
CRAFT isn't a standalone reference book: it's the library the NIS2 Scanner draws its gap analysis from, that GRIP pulls its ENSIA framework from, and that AQUA builds its self-assessment on. One maintained source, multiple applications.
How it works
How it works
From framework selection to a working control set in four steps.
Choose your framework(s)
Select one or more frameworks from the library, for example ISO 27001 together with NIS2 and DORA, as the basis for an audit, assessment or review.
Automatic mapping
CRAFT maps the selected controls onto the underlying shared controls and surfaces the cross-references to other frameworks and to relevant legislation.
Coverage and overlap made visible
You immediately see which controls have already been tested elsewhere, where frameworks overlap and where a genuine gap remains, instead of working through each framework in isolation.
Put it to work
The assembled framework flows straight into the work programme and the report, and, where relevant, into apps such as the NIS2 Scanner or GRIP that build further on the same library.
Quality
A foundation for a QAIP: reproducible and comparable
A Quality Assurance and Improvement Program needs a framework the internal audit function can measure itself against periodically, in the same way each time, not an ad-hoc set of spreadsheets rebuilt every year. Because CRAFT is one maintained library rather than project-bound documents, the yardstick for a self-assessment (such as AQUA's) stays the same year over year: the same shared controls, the same links to legislation, the same definition of coverage.
That makes a QAIP self-assessment comparable over time: improvement or regression is demonstrable, because the underlying framework doesn't quietly shift between two measurements.
The library in numbers
Verified counts, not estimates
These are the current counts from the CRAFT framework library.
38 frameworks
From BIO and ISO 27001 to DORA, NEN 7510 and the AI Act: 38 frameworks in one library.
1,691 controls
All controls searchable, per framework and per domain.
2,224 cross-references
Links between controls from different frameworks, based on actual overlap.
136 shared controls
The framework-neutral control set that all frameworks map onto.
212 legislation-to-control links
Direct references between statutory articles (GDPR, NIS2, Dutch Police Data Act) and concrete controls.
Trust
Evidence for an External Quality Assessment
IIA standards require the internal audit function to undergo a periodic External Quality Assessment (EQA), where an independent reviewer tests whether quality is demonstrably and traceably assured. A recurring question in that review is: can you show how a legal obligation is actually implemented through a concrete control, and is that trail consistent?
Because CRAFT explicitly links legislation, controls and cross-references to each other rather than leaving that implicit in a separate document, the library produces a traceable trail that can serve as supporting evidence when preparing for an EQA. CRAFT does not replace the EQA itself, that remains an independent review, but it makes the underlying framework auditable instead of a black box.
One framework library, for the whole suite
CRAFT is the layer that brings BIO, ISO 27001, NIS2, DORA, GDPR and dozens of other frameworks together. That same layer directly feeds the NIS2 Scanner, GRIP and AQUA. Curious what the library could look like for your organisation?