Overview
The Frameworks module in Formalize lets you build custom frameworks or use pre-built compliance frameworks that reflect your organization's specific requirements. This module makes compliance management, auditing, and reporting more coherent and structured.
In this article, we will cover how to:
Do the Statement of Applicability (SoA)
Create a Custom Framework
Map Overlapping Controls
Define Control Statuses for Risk Management
How to do the Statement of Applicability
In Formalize, your Statement of Applicability (SoA) is built by documenting the status of individual controls.
Navigate to Compliance > Frameworks in the main sidebar menu.
Open the specific Framework you want to work on.
Here you will see all your frameworks. Each framework displays a waffle chart showcasing its overall level of implementation of the controls.
To implement a specific control, click on the relevant Control.
Click Options, then select Edit.
Update the Applicability and Status fields, then save your changes.
Related articles:
See our Custom Fields article for further guidance on how to use custom fields.
See our Dashboards article for guidance on how to customise the waffle chart.
Creating a Custom Framework
Navigate to Settings > Compliance > Frameworks.
Click + Add and enter a name for your Custom Framework.
Organize its structure by clicking Manage structure, then click Add group.
Give the new group a Name and a numeric Identifier.
Within the group, click Add control to add your individual controls (or add additional subgroups). Give each new control a Name and numeric Identifier.
Click Save to keep your progress.
After saving, you can navigate back to the main Frameworks tab in the sidebar to preview how your custom framework looks. Previewing this structure will help you refine your naming conventions for Controls and Groups.
Mapping Overlapping Controls
If you manage multiple frameworks, you may find that some controls contain similar or identical requirements (for example, DORA and ISO27001). We call these Overlapping Controls.
Mapping them reduces duplicate work and ensures consistent audit documentation across multiple frameworks.
Open a Control that shares requirements with another framework.
Click Add next to the Overlapping Controls section.
Define the degree of overlap by selecting either Partial Overlap or Full Overlap.
Leave a comment to document your rationale for the mapping, if needed.
Click Save.
Updating Overlapping Controls: Once mapped, whenever you edit and save the primary Control, the platform will prompt you to update its Overlapping Controls. You can explicitly define whether your edits to Applicability, Status, and Evidence should be inherited by the overlapping controls.
Defining Control Status
Controls are commonly used as part of your risk mitigation process. The implementation level of a control influences your risk score, reflecting how effective a control is in practice.
By default, control statuses include three options:
Not implemented (Risk Effect Percentage: 0%)
Partially implemented (Risk Effect Percentage: 50%)
Fully implemented (Risk Effect Percentage: 100%)
How to edit control statuses:
Navigate to Settings > Compliance > Controls.
Go to the Control statuses section and click Edit.
Adjust the statuses or percentages as needed.
Within these settings, you can also define a Default mitigation effect for the risks for when a Control is marked as "Fully implemented" .
This default value can be manually overwritten during the individual risk mitigation.
Common Questions
Can I add Custom Fields to Controls?
Yes. Just like other Resources in Formalize, you can add Custom Fields to Controls. You can choose whether they appear in the body of the Control or in the Statement of Applicability section. Navigate to Settings > Compliance > Controls to configure these sections.Take a look at our Custom Fields article for more.
What is the difference between Evidence and Connections?
Think of Evidence as a library where you store records and documents that prove a control has been implemented. Connections are used to mark structural dependencies or relationships with other items in the system, rather than providing documentation.
We hope this article was helpful!
If you have any additional questions, please reach out to us via chat in the bottom right corner of the page — our team is always happy to assist you further.








