Frameworks Available Now

ISO/IEC 27001:2022

Live

Information security management system standard covering risk assessment, the Statement of Applicability, Annex A controls, internal audit and management review.

See The Framework

ISO/IEC 42001:2023

Live

AI management system standard covering governance, impact assessment and the AI system life cycle.

See The Framework

SOC 2

Live

Trust Services Criteria attestation programme covering the control environment, access management, change management, monitoring and vendor oversight. Security always applies, other categories as scoped.

See The Framework

Bank of Ghana Cyber and Information Security Directive 2026

Live

Bank of Ghana directive covering governance, cyber risk management, technology operations, incident reporting and regulatory returns, applied proportionally to institution tier.

See The Framework

GDPR Programme

Live

A compliance programme for the EU General Data Protection Regulation. GDPR is a regulation, not a certification.

See The Framework

NIS2 Directive

Live

A compliance programme for the EU Network and Information Security Directive. NIS2 is a directive transposed into national law, not a certification.

See The Framework

DORA Programme

Live

A compliance programme for the EU Digital Operational Resilience Act for financial entities and their critical ICT providers.

See The Framework

ISO 9001:2015

Live

Quality management system standard covering context, leadership, process control, design, supplier management and continual improvement.

See The Framework

ISO 14001:2026

Live

Environmental management system standard covering environmental aspects, compliance obligations, the life cycle perspective and emergency preparedness.

See The Framework

ISO 45001:2018

Live

Occupational health and safety management system standard covering hazard identification, worker consultation, operational control and incident investigation.

See The Framework

ISO 22301:2019

Live

Business continuity management system standard covering business impact analysis, continuity strategies, response plans, exercising and recovery.

See The Framework

IEC 62443-2-1:2024

Live

Industrial control system security programme for asset owners, covering zones and conduits, configuration management, component security and operational resilience.

See The Framework