Test Once. Satisfy Many.
ISO 27001
Australian Privacy Act
CPS 234
NIST CSF
Client framework
Normalised control objectives
Mandatory requirements
Discretionary requirements
SCF backbone
Regulator
Boardroom
Supply chain partner
Customer
Build the Tailored Assessment Profile (TAP) - OUTPUT
Company & product context - INPUT
Obligation & scope mapping - AI + CLIENT
Crown jewels & system context - CLIENT
Risk appetite & target maturity - CLIENT
Phase Milestone
1. Design Assessment – Controls reviewed against SCF criteria
2. Tailored Test Procedures – AI drafts · client reviews & approves
3. Operational Effectiveness Testing – Evidence-based validation
4. Gap & compensating controls – Workflow with documented justifications
Maturity scoring – Current vs. target across the framework
Phase Milestone
One assessment, many lenses - OUTPUT
Regulator report - LENS
Boardroom view - LENS
Supply chain attestation - LENS
Customer-facing summary - LENS
Phase Milestone
Obligation discovery
Normalising control objectives
Document reading
Technology-context extraction
Control-description derivation
Design-gap detection
Tailored test generation
Evidence interpretation
Maturity scoring
Multi-framework translation
Rules-based obligation logic
Validated scope matrix
Maturity floors for mandatory obligations
Client approvals
Documented justifications
Evidence trails for every score
Compensating-control workflows
Report metadata: date · scope · obligations · methodology
Flagship Outcome
Multi-lens reporting
Defensible governance
Human oversight
Tier 01 · Founding

1 of 3 claimed

33.3%
Tier 02 · Early

10 of 50 claimed

20%
Tier 03 · Charter

0 of 50 claimed

0%
Tier 04 · Standard

Open

100%
Strategic partners
Development partners