Risk and Compliance
Answer every auditor from one control set
Three different reviews this year asked for versions of the same evidence, and your team assembled it three times from scratch. The findings were not the expensive part.
Most mid-market compliance programs are not under-resourced. They are duplicated. The bank wants a questionnaire. The largest customer sends a security addendum. The insurer has its own form, the board wants a risk register, and somewhere a framework document from four years ago describes controls that no longer match how anyone works. Each request lands on the same two people, who answer it honestly and separately, and the answers drift apart.
The fix is unglamorous. One inventory of controls. Each control mapped to every framework that asks about it. Evidence gathered once and reused.
IT21 does that mapping and then does the harder part, which is deciding what to fix and in what order. Not every gap deserves a project. Some deserve a policy sentence and a calendar reminder. A few deserve real money, and those are worth arguing about in front of the board with the reasoning visible.
What you get:
- One control set mapped across the frameworks you are actually held to, so a single piece of evidence answers several questions
- Gap analysis against COBIT, NIST, ISO 27001, or System and Organization Controls (SOC) criteria, depending on who is asking
- A remediation plan sequenced by risk and effort, with owners and dates, not a list of everything wrong
- Readiness work ahead of a SOC examination so the auditor’s first visit is not a discovery exercise
- An evidence repository your staff can maintain after we leave
General framework work sits here: COBIT (Control Objectives for Information and Related Technologies), the National Institute of Standards and Technology (NIST) publications, ISO 27001, and SOC readiness. If your requirement is the Cybersecurity Maturity Model Certification for defense work, that has its own enclave design and Department of Defense portal mechanics, and it lives on the Defense Contractors page.
Assess is the gap analysis and the mapping. Transform is remediation, run as a sequenced plan rather than a scramble before a deadline. Optimize is the maintenance rhythm: who re-tests which control, how often, and where the evidence lands, so the program does not quietly rot between audits.
A word on readiness assessments, because we see a lot of them second-hand. The weak ones share a tell: whoever wrote them has never had a finding pushed back by an auditor with the authority to hold the report. Evidence that reads well in a slide deck and evidence that survives a testing procedure are not the same thing, and the difference is learned from the auditor’s chair — which our principal has occupied since 1997.
[PROOF: multi-framework compliance engagement — sector, region, frameworks in scope, outcome — supply]
The IT Risk & Readiness Assessment is where this starts. It tells you which controls exist, which are documented but not running, and which are absent, before you commit to a remediation budget or an audit date.
- Assess
- Transform
- Optimize
Oscar Chacon, CISA
Certified Information Systems Auditor since 1997
What this covers
- COSO / COBIT Readiness Assessment
- Framework Alignment (ISO, CMMC, SOC 2)Cross-framework alignment lives here; CMMC-specific enclave and DoD-portal work is under Defense Contractors (CMMC).
Generic framework work lives here; CMMC-specific enclave and DoD-portal work sits under Defense Contractors (CMMC).
Not sure where you stand? Start with the assessment.
Request the AssessmentThe IT Risk & Readiness Assessment — overview
What the assessment covers, how it runs, and what you get back — the low-commitment first step, measured against a recognized control framework.
Get the PDF — enter your email
HubSpot form — assessment-request — not configured
Set portalId and forms.assessment-request in src/lib/hubspot.ts.
Start with the IT Risk & Readiness Assessment
A defined engagement, measured against a recognized control framework, that shows you which controls exist, which are documented but not operating, and which are absent — before you commit a budget.

